All authors

Claude Skills by HoangNguyen0403
github.com/HoangNguyen04031,434 skills30 installs1,975 views
- Common Code Review[BLOCKER] [PR] Approval requested without an evidence-based review Why: The **Evidence First** and **review completeness** guardrails require checking logic, security, edge cases, and tests; green CI does not replace review. Fix: Stop approval and restart with the PR diff, requirements/AC, test coverage, and edge-case evidence. Approval can proceed only after those checks are documented.Votes: 0GitHub stars: 549
- Common Code Review[BLOCKER] [Evidence required] A style-only review violates the common-code-review guardrails: Substance > Style and mandatory checks for security, logic, edge cases, and tests. Why: No code or diff evidence was supplied, so code quality and risk cannot be assessed reliably. Fix: Stop and restart the review with the relevant diff/files, requirements or AC, and test/CI evidence. Check security, efficiency, logic, clean code, tests, and edge cases before concluding.Votes: 0GitHub stars: 549
- Common Context OptimizationThe context is already large enough to require both observation masking and state compaction. 1. Consume the 2,000-line JSON once and extract only information needed for the active task: relevant errors, timestamps, IDs, counts, and the event sequence. Do not keep reasoning over the raw dump. 2. Replace the raw tool result with a short semantic reference, for example: ```text [Masked tool output: 2,000 JSON log lines consumed. Relevant findings: 3 errors, request ID ..., failure at ..., next ...Votes: 0GitHub stars: 549
- Common Context OptimizationUse a rolling-state compaction strategy. At 30 turns, the conversation has passed the skill's recommended compaction interval, so do not keep the full dialogue as the working context. Create a compact project-state record containing: ```yaml Current_State: Goal: "the original user goal, stated precisely" Active_Task: "what the agent is doing now" Status: "current progress or blocker" Key_Decisions: ["decisions that still constrain the solution"] Current_Errors: ["unresolved errors only"] Acti...Votes: 0GitHub stars: 549
- Common Context OptimizationTreat this as a context-shape problem as well as a token-volume problem. A growing, frequently changing history can reduce KV-cache reuse because the model no longer sees the same prefix. Apply these controls: - Keep the prompt in a stable order: `System -> Tools -> RAG -> User`. Keep the system instructions, tool definitions, and other static material unchanged and at the front. - Make the conversation append-only. Do not insert new messages into the middle or rewrite earlier turns. Put new ...Votes: 0GitHub stars: 549
- Common Dast ToolingRun the assessment only against a staging replica, with test accounts and seeded non-production data. Keep the scan bounded with a maximum duration or depth, and obtain authorization from the service owner. Use a layered toolset: 1. Import the OpenAPI specification into ZAP, then run a bounded authenticated spider/active scan. This exercises routes and parameters for SQL injection, XSS, CSRF, session, and CORS issues. Supply an `Authorization: Bearer <staging-token>` header or configure ZAP's...Votes: 0GitHub stars: 549
- Common Dast ToolingYou can perform a bounded manual/API-focused DAST pass with `curl`, a browser automation tool, and small endpoint fuzzing tools if available. Use only a local or staging target—never production—and use authenticated staging headers for protected routes. Record the exact target and cap request count, concurrency, and duration. Start by enumerating the OpenAPI document and known routes, then probe representative methods and roles. Examples (replace placeholders and keep the host in staging): ``...Votes: 0GitHub stars: 549
- Common Dast ToolingServer version disclosure is usually a P1 information-leakage finding in this standard, with a suggested deduction of 10 points. It reveals technology and version information that can make targeted exploitation and vulnerability matching easier. It is not, by itself, proof of compromise, and severity should be adjusted for context: an exact outdated version with a known exploitable CVE, broad internet exposure, or other correlated weaknesses raises the practical risk; a generic banner on an i...Votes: 0GitHub stars: 549
- Common DebuggingTreat this as an environment-specific failure until evidence shows otherwise; do not add a blind fallback first. 1. Observe: capture the production stack trace, source-map position, request/user/context identifiers, input payload, deployment version, and the exact expression whose value is undefined. Compare production logs with the corresponding successful local case, including API responses, feature flags, environment variables, build mode, data shape, and dependency versions. Check recent ...Votes: 0GitHub stars: 549
- Common DebuggingStop random edits. They destroy causal information and make it unclear which change helped or whether the bug was merely masked. Reset the debugging process without reverting other people’s work: record the symptom, exact reproduction steps, expected versus actual behavior, environment, and current diff. Preserve the state in a branch or patch if needed. Then: 1. Observe the complete error/stack trace, relevant logs, inputs, timing, recent changes, and dependency/configuration versions. 2. Bu...Votes: 0GitHub stars: 549
- Common DebuggingUse version control and a controlled comparison to identify the change, rather than scanning or editing code by intuition. First record the exact failure: command/request, input, expected and actual result, stack trace, environment, and whether the failure is deterministic. Confirm the baseline and working/broken revisions are correctly checked out or deployed. Then inspect changes in a narrowing sequence: - Compare the last known-good and first known-bad commits with `git log --oneline --dec...Votes: 0GitHub stars: 549
- Common DebuggingDo not add null checks everywhere as the first action. That may stop one crash while converting a violated data contract into silent empty behavior, hiding the root cause and potentially corrupting results. For the urgent outage, mitigate safely while investigating: capture the failing stack trace and request/context identifiers, identify the affected release and input shape, and use an existing rollback, feature-flag disablement, traffic reduction, or known-good artifact if one is available ...Votes: 0GitHub stars: 549
- Common DebuggingTwo more untested fixes would be more random debugging. Stop and reopen the root cause instead. 1. Create a minimal deterministic reproduction from the exact failing input and capture the full stack trace, runtime values/types, timing, environment, recent diff, and deployment version. Compare it with the last known-good case. 2. Choose one falsifiable hypothesis from that evidence and run one experiment that changes only its suspected variable—for example, replay the same request with the ups...Votes: 0GitHub stars: 549
- Common DocumentationAssuming a TypeScript/JavaScript retry function: ```ts /** * Retries an operation using exponential backoff with jitter. * * JSDoc documents the public API, while inline comments explain why * each retry decision exists. * * @param operation Operation that may temporarily fail. * @param maxRetries Maximum number of retries after the initial attempt. * @param baseDelayMs Initial backoff duration in milliseconds. * @param maxDelayMs Upper bound for the calculated delay. * @returns The successfu...Votes: 0GitHub stars: 549
- Common DocumentationA REST service for registering users, authenticating credentials, and issuing JWT access and refresh tokens. > Assumption: this README targets Node.js 20+, TypeScript, PostgreSQL, and Docker. Adjust commands and configuration names if the implementation uses another stack.Votes: 0GitHub stars: 549
- Common DocumentationAssumption: each TODO represents a real follow-up rather than intentionally deferred work. 1. Inventory every TODO and assign an owner. 2. Create or link a ticket for each actionable item. 3. Rewrite comments using the required format: ```ts // TODO(alice): Explain why retry jitter is required to prevent the thundering herd. // Ticket: PROJ-123 ``` 4. Make comments explain `why`, not mechanics or obvious code behavior. 5. Convert public API comments to JSDoc, including `Args`, `Returns`, and ...Votes: 0GitHub stars: 549
- Common Error HandlingAssumption: TypeScript API with a global exception handler. Move the Postgres boundary into the infrastructure layer, replace sensitive details, and let the API layer map the safe error globally. ```ts // infrastructure/orders-repository.ts export class DatabaseOperationError extends Error { readonly code = 'DATABASE_OPERATION_FAILED'; constructor(message: string, options?: { cause?: unknown }) { super(message, options); this.name = 'DatabaseOperationError'; } } async function saveOrder(order...Votes: 0GitHub stars: 549
- Common Error HandlingAssumption: REST/JSON API using `net/http`, with errors mapped centrally by a global HTTP handler. Domain errors must contain business meaning only—never HTTP status codes. ```go package app import "errors" var ( ErrValidation = errors.New("validation failed") ErrNotFound = errors.New("not found") ErrConflict = errors.New("conflict") ) type CodeError struct { Code string Message string Cause error } func (e *CodeError) Error() string { return e.Code + ": " + e.Message } func (e *Code...Votes: 0GitHub stars: 549
- Common Error HandlingReplace every empty catch with deliberate handling: ```ts try { await processOrder(); } catch (error) { throw new Error("process order failed", { cause: error }); } ``` Choose the appropriate action: - Log the error when intentionally continuing, including useful context. - Handle it with an explicit fallback or recovery branch. - Wrap it with context (`new Error("...", { cause: error })` or `fmt.Errorf("process: %w", err)`). - Rethrow it when the caller or boundary must decide. - Map it at t...Votes: 0GitHub stars: 549
- Common Exploit VerificationThis is a validation procedure, not a confirmed finding. Under the exploit-verification standard, the issue must not be reported unless the payload reaches the database and produces demonstrable impact. Scanner output or a suspicious query alone is insufficient.Votes: 0GitHub stars: 549
- Common Exploit Verification**ID:** IDOR-ORDERS-001 **Vulnerability:** CWE-639: Authorization Bypass Through User-Controlled Key **Platform:** Backend API **Component:** `GET /api/v1/orders/{id}` **Severity:** High (CVSS: 8.1, provisional; recalculate if the validated data or privileges differ) **OWASP:** API1:2023 – Broken Object Level AuthorizationVotes: 0GitHub stars: 549
- Common Feedback Reporter🚨 SKILL VIATION DETECTED Skill: common-feedback-reporter File: user_name.dart:1–5 Rule: No hardcoded colors; use the theme. Violation: `Text(name, style: const TextStyle(color: Colors.blue))` Fix: `Text(name, style: TextStyle(color: Theme.of(context).colorScheme.primary))` Auto-fixed: YES Root Cause: PATTERN_MISMATCH User Intent: Display the user's name in blue text. Skill Gap: none; the guidance already specifies the themed-color replacement. Co-ski...Votes: 0GitHub stars: 549
- Common Feedback ReporterUse function components. Do not create class components for new React code.Votes: 0GitHub stars: 549
- Common Feedback Reporter🚨 SKILL VIOLATION DETECTED Skill: common-feedback-reporter File: [planned TypeScript file] Rule: Use functions for React components. Violation: `class MyComponent extends React.Component { ... }` Fix: `function MyComponent(): JSX.Element { ... }` Auto-fixed: YES Root Cause: PATTERN_MISMATCH User Intent: Add a React component implemented in TypeScript. Skill Gap: The guidance should clarify that class-component requests are converted to function comp...Votes: 0GitHub stars: 549
- Common Feedback Reporter🚨 SKILL VIOLATION DETECTED Skill: Next.js routing guidance File: skill guidance Rule: Put the route in `pages/` Violation: `pages/` is Pages Router guidance, not the requested Next.js 14 App Router structure. Fix: Use the `app/` directory and App Router conventions. Auto-fixed: YES Root Cause: OUTDATED_GUIDANCE User Intent: Place the route correctly in a Next.js 14 App Router application. Skill Gap: Update the guidance to distinguish `pages/` (Pages Router) from `app/` (App Router). Co-skill...Votes: 0GitHub stars: 549
- Common Git CollaborationUse two commits. Fixing the login bug and adding a user profile feature are separate logical changes, so they should be independently reviewable, revertible, and deployable. Use Conventional Commit messages in the imperative mood, for example: ```text fix(auth): correct login validation feat(profile): add user profile feature ``` If the work is currently mixed together, separate the changes carefully before committing. Put the commits on a task branch such as `fix/login-and-profile` or, prefe...Votes: 0GitHub stars: 549
- Common Git CollaborationAn 800-line PR is likely too large to review effectively. Split it into smaller, independently understandable logical changes, keeping each PR preferably below 300 changed lines where practical. Separate refactors, formatting-only changes, behavior changes, tests, and documentation when they do not need to be reviewed together. Before splitting, self-review the diff and identify dependencies. Create focused branches with the appropriate prefix, such as `refactor/...`, `feat/...`, or `fix/...`...Votes: 0GitHub stars: 549
- Common Git CollaborationTreat the API key as compromised immediately. 1. Revoke or rotate the key with the provider, and update the application to use the replacement through secure secret management. Do not leave the old key active while investigating. 2. Remove the key from the working tree and prevent recurrence with `.gitignore`, secret scanning, and appropriate pre-commit hooks such as Husky or Lefthook. Do not merely delete it in a new commit: the key remains in Git history. 3. Purge the key from all affected ...Votes: 0GitHub stars: 549
- Common Learning LogAppend one structured entry to `AGENTS_LEARNING.md` before retrying the corrected action. Signal: User correction. Mistake: Recommended storing authentication tokens in `localStorage` instead of `HttpOnly` cookies. Better Approach: Store auth tokens in `HttpOnly` cookies and apply the project's secure cookie settings before continuing.Votes: 0GitHub stars: 549
- Common Learning LogAppend one structured entry to `AGENTS_LEARNING.md` before retrying the corrected action. Signal: Pre-write violation. Mistake: Used a React class component despite the skill violation audit identifying that pattern. Better Approach: Load and follow the applicable React guidance, use a function component, and rerun the pre-write audit before continuing.Votes: 0GitHub stars: 549
- Common Learning LogAppend one structured entry to `AGENTS_LEARNING.md` before retrying the corrected action. Signal: Session retrospective. Mistake: Missed loading the security skill before writing an API endpoint. Better Approach: Resolve and load the security skill before endpoint changes, then rerun the pre-write compliance check before continuing.Votes: 0GitHub stars: 549
- Common Llm Security🔴 **LLM01 Prompt Injection (P0, confirmed).** Concatenating the user's message into the system prompt removes the trust boundary between developer-controlled instructions and untrusted data. A user can append instructions that override the chatbot's intended behavior, reveal hidden instructions, or influence downstream actions. Under this checklist, a confirmed P0 finding caps the security score at 40/100.Votes: 0GitHub stars: 549
- Common Llm Security🔴 **LLM06 Excessive Agency (P0, confirmed).** An agent that can delete files and operates without human confirmation has destructive write access with no approval gate. A prompt injection, mistaken plan, or compromised tool call can cause irreversible data loss. The same missing controls also make arbitrary filesystem scope and unbounded agent loops immediate review concerns. A confirmed P0 finding caps the security score at 40/100.Votes: 0GitHub stars: 549
- Common Llm Security🔴 **LLM01 Prompt Injection (P0, confirmed).** Retrieved documents are untrusted external data. Injecting their chunks without validation creates an indirect prompt-injection path: a malicious document can contain instructions such as ignoring policy, exfiltrating context, or invoking tools. The pipeline also has a confirmed **LLM04 Data & Model Poisoning** concern when user-controlled text is admitted without validation, and an **LLM08 Vector & Embedding Weaknesses** concern unless namespace isVotes: 0GitHub stars: 549
- Common Mobile AnimationAssume Flutter and iOS are the target platforms. - Choose duration by interaction: - `100–150ms`: toggles and cell presses - `250–350ms`: navigation and modals - `400–600ms`: shared-element or complex-state transitions - Never exceed `600ms`. - Use platform-standard easing: - Flutter/Material: `Curves.fastOutSlowIn` - iOS: `.easeInOut` - Avoid `linear`. - Animate GPU-friendly properties such as `transform` and `opacity`. Avoid animating `width`, `height`, `padding`, or other layout-triggering...Votes: 0GitHub stars: 549
- Common Mobile AnimationCommon mobile animation anti-patterns to avoid: - Using `linear` easing; use platform-standard curves such as Flutter’s `Curves.fastOutSlowIn` or iOS `easeInOut`. - Exceeding the 600ms hard limit. Typical ranges: 100–150ms for presses, 250–350ms for navigation/modals, and 400–600ms for shared elements or complex state. - Animating layout-triggering properties such as `width`, `height`, or `padding`; prefer GPU-friendly `transform` and `opacity`. - Creating layout thrashing that causes dropped...Votes: 0GitHub stars: 549
- Common Mobile AnimationUse the **Long** range: `500ms` (within `400–600ms`). ```dart class ExpandCard extends StatefulWidget { const ExpandCard({super.key}); @override State<ExpandCard> createState() => _ExpandCardState(); } class _ExpandCardState extends State<ExpandCard> with SingleTickerProviderStateMixin { late final AnimationController controller = AnimationController( vsync: this, duration: const Duration(milliseconds: 500), ); late final Animation<double> animation = CurvedAnimation( parent: controller, curv...Votes: 0GitHub stars: 549
- Common Mobile Ux CoreBuild mobile interfaces around touch, variable insets, on-screen keyboards, and platform conventions.Votes: 0GitHub stars: 549
- Common Mobile Ux CoreAvoid these failure modes in touch-first interfaces: - **Tiny click targets:** A 16–24 px icon with no surrounding hit area is hard to tap accurately. Keep the interactive region at least 44 × 44 pt on iOS or 48 × 48 dp on Android. - **Ignoring safe areas:** Fixed headers or bottom bars that overlap a notch, gesture indicator, or navigation bar can hide content and make actions unreliable. Apply safe-area/window-inset padding, including when the keyboard opens. - **Hover-dependent interaction...Votes: 0GitHub stars: 549
- Common Mobile Ux CoreHere is a compact Flutter-style pattern for an inset-safe form with accessible controls and keyboard-aware scrolling: ```dart Scaffold( body: SafeArea( child: SingleChildScrollView( padding: const EdgeInsets.all(16), child: Column( children: [ TextField( keyboardType: TextInputType.emailAddress, textInputAction: TextInputAction.next, decoration: const InputDecoration(labelText: 'Email'), ), const SizedBox(height: 16), SizedBox( width: double.infinity, height: 48, child: ElevatedButton( onPres...Votes: 0GitHub stars: 549
- Common Mobile Visual TestingAssumption: the app has a list screen with a seeded long dataset and supports iOS and Android test devices. 1. Capture a baseline with `appium_screenshot` and inspect hierarchy using `appium_get_source`. 2. Verify Loading, populated, Empty, and Error states before scrolling. 3. Start `appium_mobile_performance_data` monitoring. 4. Scroll from the top to the bottom repeatedly—at least 5 full passes—using normal and rapid gestures. 5. Verify: - Smooth scrolling with no visible freezes, dropped ...Votes: 0GitHub stars: 549
- Common Mobile Visual TestingFirst inspect the state with `appium_screenshot` and `appium_get_source`/hierarchy. Then use `appium_alert`: - Tap `accept` if notifications are required for the test flow and the permission reason is expected. - Tap `dismiss` if notifications are out of scope or the popup is unexpected. Do not blindly tap before checking the alert state.Votes: 0GitHub stars: 549
- Common ObservabilityUse three coordinated signals—structured logs, distributed traces, and RED metrics—to make every request diagnosable without exposing sensitive data.Votes: 0GitHub stars: 549
- Common Observability- **Plain-text production logging:** Avoid ad hoc strings and `console.log`. They are difficult to query and correlate. Emit JSON through a structured logger. - **Broken correlation:** Do not drop `X-Request-Id` or W3C `traceparent` at an ingress, async job, queue, or outbound HTTP boundary. Carry correlation through async context and propagate it downstream. - **No distributed tracing:** Logs alone cannot reliably explain latency across services. Instrument service boundaries with OpenTeleme...Votes: 0GitHub stars: 549
- Common ObservabilityThe following TypeScript-style sketch shows the essential request flow. Adapt the logger and OpenTelemetry SDK setup to the service framework. ```ts import { context, propagation, trace, SpanStatusCode } from '@opentelemetry/api'; import pino from 'pino'; const logger = pino(); const tracer = trace.getTracer('user-service'); async function handleRequest(req: Request, res: Response) { const route = 'GET /users/:id'; const requestId = req.headers.get('x-request-id') ?? crypto.randomUUID(); cons...Votes: 0GitHub stars: 549
- Common Operator ProfileProfile: business You can launch this without coding. I recommend a mobile-friendly online shop rather than commissioning a custom app. Assumptions: - One bakery location - Customers order for pickup or local delivery - You sell standard items plus occasional custom cakes - You need card and digital-wallet payments Recommended setup: 1. Use Square Online if it supports payments in your country. Otherwise use Shopify. 2. Add your menu, prices, photos, allergens, and available quantities. 3. En...Votes: 0GitHub stars: 549
- Common Operator ProfileProfile: hybrid Assumption: you’re adding a `Payments` module to a standard NestJS TypeScript application. In NestJS, a Laravel service provider is usually split into: - `@Injectable()` service: the actual application logic - `@Module()` class: registers and exposes dependencies - lifecycle hooks such as `OnModuleInit`: equivalent to provider boot-time setup Create `payments.service.ts`: ```ts import { Injectable } from '@nestjs/common'; @Injectable() export class PaymentsService { charge(amo...Votes: 0GitHub stars: 549
- Common Operator ProfileProfile: technical I’m unable to implement REQ-12 because `prd-checkout.md` and the failing `checkout.spec.ts` contents were not supplied. Assumptions: this is a TypeScript checkout implementation, and `checkout.spec.ts` defines the required API and expected behavior. Provide those files—or the failing test output and REQ-12 text—to implement the change accurately.Votes: 0GitHub stars: 549
- Common Operator ProfileProfile: business I’ll define the first version as a simple bakery ordering app. Assumptions—confirm with “go with your suggestion”: - Sponsor: the bakery owner/operator. - SMART metric: within 90 days, reach 20 app orders per week, with at least 30% of weekly orders placed through the app. - Scope: customers browse products, view details, add items to a cart, choose pickup time, submit contact details, and receive order confirmation. Staff can manage products and orders. - Excluded initially...Votes: 0GitHub stars: 549
- Common Owasp🔴 **P0 — IDOR/BOLA (OWASP API1 / A01):** `req.params.id` is user-controlled and queried without ownership or tenant authorization. ⚠️ **API3 — Broken Property Level Authorization:** Returning `user` directly may expose sensitive fields. Use **DTO projection**. ```js const user = await db.findOne({ id: req.params.id, ownerId: req.auth.userId, // or tenantId select: ['id', 'name', 'avatar'] }); if (!user) return res.status(404).json({ error: 'Not found' }); return res.json(user); ``` Also veri...Votes: 0GitHub stars: 549