bmad-testarch-nfr

Audit non-functional requirement evidence against compliance standards and identify cross-domain risks.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/peshay/portfolixir --skill bmad-testarch-nfr-peshay
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bmad-testarch-nfr
Source: https://github.com/peshay/portfolixir/tree/main/.claude/skills/bmad-testarch-nfr
Command: npx skills add https://github.com/peshay/portfolixir --skill bmad-testarch-nfr-peshay

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill automates the audit of non-functional requirement evidence, validates it against compliance standards, and identifies cross-domain risks.

Core Features & Use Cases

  • Audit Non-Functional Requirements: Validates evidence for performance, security, reliability, and maintainability.
  • Compliance Checking: Verifies adherence to compliance standards like GDPR, HIPAA, and PCI-DSS.
  • Cross-Domain Risk Identification: Flags risks that span multiple domains like performance, security, and reliability.
  • Use Case: For a software release, use this Skill to automatically audit NFRs before deployment, ensuring compliance and minimizing risks.

Quick Start

Run the 'nfr-assess' command within the workflow.

Frequently Asked Questions about bmad-testarch-nfr

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit non-functional requirements before a software release?

To audit non-functional requirements before release, you can automate the validation of performance, security, reliability, and maintainability evidence against predefined criteria using the nfr-assess command.

What is cross-domain risk identification in software compliance?

Cross-domain risk identification in software compliance flags vulnerabilities spanning multiple domains like performance and security, ensuring post-implementation assessments catch systemic issues before deployment.

How do I validate software evidence against GDPR and HIPAA compliance standards?

You validate software evidence against GDPR, HIPAA, and PCI-DSS compliance standards by running an automated compliance checking process that verifies adherence to the specific regulatory requirements.

Can I use automated risk assessment for post-implementation software audits?

Yes, you can use automated risk assessment for post-implementation audits to evaluate non-functional requirements, identify cross-domain risks, and ensure software meets predefined compliance criteria.

Does non-functional requirement auditing work without external dependencies?

Yes, non-functional requirement auditing works without external dependencies, utilizing internal scripts and references to validate evidence and identify compliance risks independently.

What are the limitations of automating software quality and compliance checks?

A key limitation of automating software quality and compliance checks is that the process applies strictly to post-implementation assessments, validating existing evidence rather than generating new test data.