
Claude Skills by Nmor
github.com/NmorReconcile intended business events with persisted records and downstream effects, investigating uncertain writes, duplicates, missing replication and safe repair.
Database migration best practices for schema changes, data migrations, rollbacks, and zero-downtime deployments across PostgreSQL, MySQL, and common ORMs (Prisma, Drizzle, Django, TypeORM, golang-migrate).
Principal-level datacenter operations — Uptime Institute tier model, BICSI / ANSI-TIA-942 structured cabling, power + cooling + space (PUE / WUE / CUE), physical security, capacity planning, change + incident management, vendor + SLA management, colocation strategy, and the operational discipline that keeps physical infrastructure running through grid events, hardware failures, and growth pressure.
Dependency hygiene — dependency-pinning (lockfiles committed, image digest pins, Actions SHA-pinned), dependency-vulnerabilities (CVE gate: MODERATE+ blocks), dependency-overrides-not-exceptions (fix the tree first via pnpm.overrides), license-allowlist-gate (SPDX allowlist + Trove cross-check), install-allowlist (no silent global installs; publisher allowlist). Select explicitly when this guidance applies.
Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications.
Principal-level design system practice — design tokens, multi-platform theming, component API design, accessibility built-in, versioning + governance, contribution model, documentation, and the discipline that turns "one team's component library" into a load-bearing capability for every product surface — including producing high-fidelity, NON-generic ("anti-AI-slop") UIs by building on the real system + curated blocks + design-MCP tooling (shadcn / 21st.dev / Figma).
Human-centred problem solving via Stanford d.school / IDEO five-stage cycle (Empathize → Define → Ideate → Prototype → Test). Activates on UX research, service design, innovation workshops, problem-framing sessions, or when the solution space is unknown and the users are not the designers.
Django + Django REST Framework implementation discipline — project layout, model design, DRF serializers/viewsets, service layer, caching, signals, middleware, query performance, AND the full Django security surface (SECURE_* settings, authentication, authorization, SQL-injection and XSS prevention, CSRF, file-upload hardening, API security, security headers, secret handling, security event logging). Use when writing or reviewing any Django models.py, views.py, serializers.py, urls.py, settin...
Django testing discipline — TDD workflow for Django/DRF (RED-GREEN-REFACTOR against models, views, serializers, permissions), pytest-django and factory patterns, database and transaction handling in tests, API client testing, AND the verification gates a Django change must pass before it ships (migrations check, coverage floor, lint/type gates, deployment checks). Use when writing Django tests or verifying a Django change is done.
Docker and Docker Compose patterns for local development, container security, networking, volume strategies, and multi-service orchestration. Also lazy-loads docker-deployment.md / docker-localhost-binding.md content migrated from rules/common/ on 2026-06-02.
Dockerfile + container discipline — multi-stage builds (build → runtime); pinned base image with tag + sha256 digest; non-root USER mandatory; COPY over ADD (except verified tarball); chained apt-get install + cache cleanup in same RUN layer; explicit WORKDIR; exec-form CMD/ENTRYPOINT; layer ordering least-frequent → most-frequent change; EXPOSE documentary; HEALTHCHECK for long-running services; OCI labels (org.opencontainers.image.*); .dockerignore mandatory; Hadolint at strict ruleset; Bui...
DynamoDB single-table design, composite keys, GSI design, conditional writes, BatchWrite/BatchGet chunking, atomic counters, TTL, streams, and cross-tenant isolation patterns. Select explicitly when this guidance applies.
Playwright E2E testing patterns — Page Object Model, configuration, CI/CD integration, artifact management, flaky test strategies, PLUS the decision-time patterns that come before the first test is written (black-box helper scripts, static-vs-dynamic routing, multi-server orchestration, reconnaissance-then-action, application-state readiness assertions).
Principal-level patterns for K-12 + higher-ed + corporate-learning platforms — LTI 1.3 / LTI Advantage, xAPI 2.0 (IEEE 9274.1.1-2023), cmi5, SCORM 1.2 + 2004 (4th Ed), OneRoster 1.2, Caliper Analytics 1.2, QTI 3.0, Common Cartridge 1.3, Open Badges 3.0 (W3C VC), AccessForAll 3.0, IRT-based adaptive assessment, UDL 3.0, WCAG 2.2 AAA for learners, proctoring + integrity, learning-analytics ethics. Sister to ferpa-coppa-compliance (regulation), wcag-accessibility (a11y), interaction-design (UX).
Evaluate ventures and product opportunities through customer evidence, distribution, unit economics, runway and affordable experiments with explicit go, change or stop decisions.
Formal evaluation framework for Claude Code sessions implementing eval-driven development (EDD) principles
Principal-level guidance for FERPA (20 USC §1232g), COPPA (15 USC §6501-6506 + 16 CFR Part 312 + 2025 FTC Final Rule), GDPR-K (Art 8), CIPA, state student-privacy laws (SOPIPA, NY Ed Law 2-d, Student Privacy Pledge), and platform compliance for K-12 + higher-ed + edtech. Sister to gdpr-ccpa-compliance, hipaa-compliance (where school-based health), audit-logging, data-retention.
Principal-level financial analyst workflow — earnings model maintenance, ratio analysis, accounting quality assessment, channel checks, sector-relative valuation, and producing the daily/weekly/quarterly analyst output that drives institutional investment decisions.
Principal-level fine-tuning lifecycle — when fine-tuning beats prompting + RAG, dataset curation, instruction tuning vs preference optimisation (SFT / DPO / RLHF), parameter-efficient methods (LoRA / QLoRA / adapters), evaluation, safety re-tuning, deployment, monitoring, and the cost / benefit framework for choosing between fine-tuning, RAG, and base-model usage.
Financial Planning & Analysis patterns for engineering teams supporting finance — budget vs actual variance, rolling forecasts, driver-based models, scenario planning, SaaS metrics (ARR, MRR, NRR, CAC, LTV, payback, magic number, Rule of 40), cohort analysis, and the data pipeline patterns that make FP&A self-serve.
Frontend development patterns for React, React Native, Vue, Next.js, SwiftUI, Flutter, state management, performance optimization, and UI best practices.
GDPR + CCPA/CPRA implementation patterns — lawful basis documentation, data subject rights, consent management, cross-border transfers, breach notification, DPIA, and RoPA. Implementation arm of the gdpr-ccpa.md rule. Also lazy-loads data-retention.md / audit-logging.md content migrated from rules/common/ on 2026-06-02.
Git + repo discipline — git-workflow (per-org identity, conventional commits, PR workflow), repo-setup-checklist (20-point first-touch security audit), docs-sync-with-code (every PR ships docs + code together), documentation-requirements (Diátaxis four-quadrant: tutorials / how-tos / reference / explanation). Select explicitly when this guidance applies.
Idiomatic Go patterns, best practices, and conventions for building robust, efficient, and maintainable Go applications.
Go testing patterns including table-driven tests, subtests, benchmarks, fuzzing, and test coverage. Follows TDD methodology with idiomatic Go practices.
Principal-level guidance for HIPAA Privacy + Security + Breach Notification + HITECH + 42 CFR Part 2 compliance — BAAs, minimum-necessary, ePHI encryption, audit controls, breach 60-day clock, OCR enforcement. Sister to gdpr-ccpa-compliance, audit-logging, data-retention, security.
Principal-level hiring system design — role definition, sourcing, structured interviewing, bar-raising, calibration, offer, and onboarding. Treat hiring as the highest-leverage decision an organisation makes and engineer the process to minimise predictable failure modes (unstructured interviews, halo effect, like-me bias, rushed decisions, weak onboarding).
Principal-level historical analysis — primary-source critique, archival methodology, periodisation, oral history, cliometrics, historiography, and the fallacies (presentism, Whig history, anachronism, hindsight bias) that turn the past into a mirror of present preoccupations rather than a foreign country worth understanding on its own terms.
Internationalisation discipline — every user-facing string in a catalog (no inline strings); ICU MessageFormat for plurals + interpolation; Intl APIs for date / number / currency / list / collation; BCP 47 locale identifiers; RTL mirroring for Arabic / Hebrew / Persian / Urdu; locale-aware sort + search; per-country address + name formats; currency placement varies by locale; transactional emails / SMS / push routed through the same i18n pipeline. Select explicitly when this guidance applies.
Financial statement preparation under IFRS and US GAAP — Balance Sheet, Income Statement, Cash Flow, Statement of Changes in Equity, revenue recognition (IFRS 15 / ASC 606), leases (IFRS 16 / ASC 842), the key IFRS↔GAAP differences, and the engineering-side patterns for producing audit-quality reports from the general ledger.
Investigate service incidents and recurring customer failures by correlating logs, traces, recordings and durable state; distinguish mitigation from demonstrated root-cause fixes.
Principal-level interaction design — affordances, signifiers, feedback, mappings, constraints, error prevention, recovery, gesture + input model design, microcopy, motion as functional language, and the discipline that turns flows into experiences users complete without thinking and don't have to recover from.
Principal-level investment research methodology — thesis development, primary research, financial modelling, valuation triangulation, risk identification, and the disciplined write-up that supports a buy / sell / hold recommendation.
Principal-level due-diligence methodology for evaluating fund managers, private company investments, and acquisition targets — operational, financial, legal, commercial, technology, ESG, and reference diligence with a structured red-flag scoring system.
ISO/IEC 27001:2022 Information Security Management System (ISMS) implementation patterns — Annex A 93 controls in 4 themes (Organizational, People, Physical, Technological), Statement of Applicability, risk assessment / treatment, and the engineering-side controls that auditors actually verify.
Pattern for progressively refining context retrieval to solve the subagent context problem
Java coding standards for Spring Boot services: naming, immutability, Optional usage, streams, exceptions, generics, and project layout.
JPA/Hibernate patterns for entity design, relationships, query optimization, transactions, auditing, indexing, pagination, and pooling in Spring Boot.
Kotlin 2.0+ discipline — null safety (no !! force-unwrap; safe call + Elvis), immutability (val over var; data class + copy), sealed classes for closed hierarchies, scope functions (let/run/apply/also/with) used purposefully, structured concurrency via coroutines (no GlobalScope.launch; supervisor scopes + Job cancellation), CoroutineExceptionHandler for unhandled errors, ktlint + detekt at strict ruleset, expression bodies for one-liners, KDoc on public API. Select explicitly when this guida...
Lean operating philosophy — Just-in-Time, Jidoka, heijunka, kaizen, value-stream mapping, eight wastes, takt time, kanban, andon, single-piece flow. Applied to any value-producing system (manufacturing, software, healthcare, services), not just factories. Sister to six-sigma (variation reduction), supply-chain-patterns (cross-org flow).
Principal-level methodology for building products under extreme uncertainty — validated learning, build-measure-learn loops, MVPs, innovation accounting, pivot-or-persevere, customer development, and engines of growth.
Staging area for learning-loop outputs. Holds artifacts captured by continuous-learning-v2 + /learn + /evolve commands awaiting review, promotion, or demotion per the continuous-learning-mandate.md global rule.
Lua 5.x discipline — module pattern (local M = {}; return M); local-everywhere (no global pollution); pcall/xpcall for protected calls with proper handler; safe loadstring (text-only via load(s, 'chunk', 't')); OO via metatables when needed; coroutines for cooperative concurrency; embedding-specific patterns (OpenResty cosockets, Neovim vim.api, Redis EVAL determinism); luacheck strict + stylua format-check; NEVER setfenv on untrusted code; NEVER load with bytecode flag from network. Select e...
Markdown style — CommonMark + GFM compliant, yamllint-clean YAML frontmatter, markdownlint rules enforced (MD004 dashes for ul, MD022 blanks around headings, MD031 blanks around fenced code, MD032 blanks around lists, MD040 fenced code language tag, MD025 single H1, MD034 no bare URLs, MD047 single trailing newline). Line length capped at 100 chars (longer tolerated only on unbreakable table rows or URLs). One H1 per document; heading hierarchy never skips levels. Select explicitly when this ...
Develop positioning, audience research, go-to-market strategy, channel budgets and measurable marketing experiments for a product or business.
Build production-grade Model Context Protocol (MCP) servers — stdio + streamable HTTP transports, tool / resource / prompt primitives, capability negotiation, auth model, idempotency, observability, testing via MCP Inspector, 10-question evaluation framework. Use when designing a new MCP server to expose an internal API / data source / workflow as a Claude (or any MCP client) tool. Sister to install-allowlist.md (publisher gates for downstream consumers), secrets-management.md (no secrets in ...
Mechanical, Electrical, Plumbing (plus Fire Protection, Telecommunications, AV, Security, BMS) coordination through design, BIM-modelling, clash-detection, fabrication, and commissioning. Activates on building-services design, ISO 19650 BIM workflows, ASHRAE / BICSI / NFPA standards, multi-discipline AEC coordination.
Principal-level model selection framework — match problem class to model family (linear / tree / kernel / neural / foundation), evaluate via cross-validation with proper data splits, factor in inference cost + latency + interpretability + compliance constraints, and avoid the common traps that produce strong offline metrics but weak production performance.
Principal-level MLOps — feature stores, model registry, training pipelines, deployment patterns (online / batch / streaming), monitoring (drift, performance, fairness), CI/CD for models, A/B testing, rollback discipline. Treat models as software artefacts with full lifecycle management.
Principal-level negotiation methodology — interest-based negotiation (Harvard Method), BATNA + ZOPA + reservation values, tactical empathy (Voss), preparation discipline, multi-issue tradeoff design, cross-cultural patterns, and the discipline that turns adversarial bargaining into joint problem-solving with durable outcomes.