Skip to content
Development
Command

/cyber-purple-validation

Controlled purple validation using paired action-observation evidence and explicit defensive outcomes.

From plugin
agent-skills-standard
57033 skills21 agents33 commands1 MCP
Install
$ npx -y skills add hoangnguyen0403/agent-skills-standard --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/cyber-purple-validation

Context preview

What this command does when you run it.

Controlled purple validation using paired action-observation evidence and explicit defensive outcomes.

Command definition

cyber-purple-validation.md

Cyber Purple Validation

Controlled purple validation using paired action-observation evidence and explicit defensive outcomes.

**Input:** $ARGUMENTS

Optional args: slug=<feature>, ticket=<id/url>, mode=interactive|autonomous|channel, channel=<id>, auto_continue=true|false, profile=business|hybrid|technical.

Instructions

Execute the following steps for **$ARGUMENTS**.

Cyber Purple Validation

Runtime Contract

Compose `cyber-detection-validation`, `cyber-authorization`, `cyber-evidence`, and `cyber-framework-mapping`. Use controlled synthetic/offline fixtures only. Active or modifying operations require documented engagement/scope, approved action, accountable owner, and runtime-proven controls; disruptive containment requires independent approval. No Markdown claim is enforcement or production efficacy.

Steps

1. Define control hypothesis, permitted action, entity, time window, expected observation, and stop condition. 2. Obtain authorization and verify runtime controls before any action; otherwise record blocked and do not simulate success. 3. Capture an action record and observation record linked by test ID, entity, time window, and source. 4. Classify only from paired evidence: `blocked`, `prevented`, `detected`, `responded`, or `telemetry-gap`; detection is not response. 5. Write evidence fields: engagement/scope reference, skill/version/source, observation time, finding status, evidence references, limitations, accountable owner, and framework edge provenance. 6. When findings are security-review material, use canonical `artifacts/security-review.md` with blockers, warnings, evidence gaps, and handoff notes.

Handoff Payload

Deliver the paired records, fixture provenance, runtime/authorization result, outcome rationale, negative/untested cases, and explicit limitations. Never claim coverage, compliance, or efficacy from a single log line or report prose. Carry `feature_status`, `completed_evidence`, `missing_evidence`, `decision_needed`, `recommended_next_workflow`, engagement owner and canonical artifact path.

Blocking Questions

Is the action authorized and runtime-supported? Are action and observation linked by test/entity/time/source? Who independently adjudicates? Missing prerequisites block execution or adjudication; a missing observation is `telemetry-gap`, not detected.

Next Workflow

Route completed evidence to `verify-work`; route contract gaps to `implementation-readiness`.

Output Template

# Purple Validation
## Hypothesis and Scope
## Action and Observation Evidence
## Outcome and Adjudication
## Limitations and Coverage Gaps
## Outcome Report
feature_status: implemented | partially_implemented | blocked
completed_evidence: []
missing_evidence: []
decision_needed: []
recommended_next_workflow: verify-work
Read more
Ships withagent-skills-standard

The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.

Get the whole plugin

Other commands on agent-skills-standard.