---
name: straion-check-compliance
description: |
  Validates code, specifications, and tasks against project rules using Straion rule matching. Use when checking compliance, validating PRs, reviewing specs against rules, or when user asks "does this meet rules", "check compliance", "validate this/with/against".
---

# Validating Rules

## Process

1. Receive description of what to validate (spec, task, or code)
2. Run `straion find-rules`:

   ```bash
   straion find-rules \
     --title "<spec title>" \
     --body "<full spec content>" \
     --summary "<brief summary>" \
     --files "<key files involved>" \
     --tags "<applicable scope tags>" \
     --keywords "<relevant technical keywords>"
   ```

   - `--title` (required) with a short title of the spec, task, or change
   - `--body` (required) with the detailed description of the spec, task, or change
   - `--summary` with higher-level context (the overall plan or feature)
   - `--files` with the key files involved (languages are derived from extensions)
   - `--tags` with applicable scope tags (e.g. `api,domain,testing,security`)
   - `--keywords` with relevant technical keywords (e.g. `jwt,auth,caching`)

   Run `straion find-rules --help` for the full flag list and scope-tag whitelist.

3. Analyze compliance against each returned rule
4. Report structured findings

## Validation Levels

| Level | What                 | Check Against                             |
| ----- | -------------------- | ----------------------------------------- |
| Spec  | PRDs, ADRs, RFCs     | Architecture, security, design principles |
| Task  | Implementation tasks | Technical rules, API contracts, testing   |
| Code  | Actual changes       | Coding standards, security, performance   |

## Compliance Analysis

For each rule returned by the CLI:

1. Read and understand what it mandates/prohibits
2. Compare against the input
3. Identify gaps or violations
4. Assess severity (critical, important, minor)

## Citing rules

`straion find-rules` prints each rule prefixed with a short `[shortcode]`, e.g.
`- [3kQ9fX2a] Users must be able to log in with email and password`. **Always
cite a rule by its exact `[shortcode]`** in your verdict lines — copy the
shortcode verbatim from the CLI output. This shortcode links each verdict back
to its rule in the audit trail, so never invent or paraphrase a shortcode.

## Output Format

```
## Rules Validation Report

### Summary
[X rules checked, Y compliant, Z issues]

### Compliant ✅
- [3kQ9fX2a] [Rule summary] — ✅ [What was done correctly]

### Partial Compliance ⚠️
- [7mB1cV4d] [Rule summary] — ⚠️ [What's missing]
  - **Recommendation**: [Specific fix]

### Violations ❌
- [9pR2dN8e] [Rule summary] — ❌ [The violation]
  - **Risk**: [Impact]
  - **Fix**: [Concrete solution]
```

## Severity Guidelines

- **Critical**: Block until fixed
- **Important**: Address before proceeding
- **Minor**: Note for consideration

## Validation Loop

When violations are found:

1. Report specific violations with concrete fixes
2. User applies fixes
3. Re-validate to confirm compliance
4. Repeat until critical violations are resolved
