
Claude Skills by Nmor
github.com/NmorPrincipal-level networking patterns — OSI / TCP-IP layering, IP addressing + CIDR design, routing, DNS, TLS, load balancing, CDN, service mesh, network security (firewalls / WAF / DDoS / segmentation), zero-trust networking, and the operational discipline that keeps packets flowing reliably + securely across single-region, multi-region, and hybrid topologies.
Process, convert, OCR, extract, redact, sign, and fill documents via the Nutrient DWS (Document Web Services) API. Supports PDF, DOCX, XLSX, PPTX, HTML, and image inputs through a single multipart endpoint. Use for document conversion, OCR of scanned content, PII redaction, watermarking, digital signing, and PDF form fill.
Structured logging, EMF metrics, request-id propagation, per-tenant dimensions, and CloudWatch / OTEL conventions for serverless and long-running services. Select explicitly when this guidance applies. Also lazy-loads observability.md content migrated from rules/common/ on 2026-06-02.
Principal-level OKR (Objectives + Key Results) design, deployment, grading, and anti-pattern avoidance for teams and organisations.
Principal-level organisational design — team topologies, span of control, reporting structures, decision rights (DACI / RACI), Conway's Law, coordination cost, scaling from 10 to 1000, the difference between functional / divisional / matrix / network structures, and the discipline that aligns the org chart to the product strategy.
OWASP Application Security Verification Standard 4.0.3 — the canonical control catalogue for application security, mapped per L1 / L2 / L3 with implementation patterns and verification commands.
Principal-level patterns for accepting card / bank / wallet / instant-rail payments — idempotency, 3DS2 + SCA, network tokenization, subscriptions, dunning, refunds + chargebacks, payouts, ledger reconciliation. Sister to pci-dss-patterns (compliance) and bookkeeping-patterns (double-entry).
PCI-DSS v4.0 implementation patterns for systems that store, process, or transmit cardholder data — scope reduction via tokenization, SAQ selection, segmentation, encryption requirements, and the 12 PCI-DSS requirements mapped to concrete engineering controls.
Perform authorized penetration-test planning, attack-path validation and remediation retesting with scoped proof, reproducible findings and bounded effects.
Principal-level performance management — feedback systems, calibration, ratings (or no ratings), career frameworks, performance improvement plans, and the operational discipline that turns reviews from anxiety-inducing theatre into a real engine of growth, retention, and accountability.
Planning + verification discipline for multi-phase work — code-graph-validation (incremental per-task + phase-boundary + pre-push sweeps), ADR template (MADR / Nygard format), runbook template (canonical incident-response structure). Invoke when writing or reviewing a plan, an ADR or a runbook, and before acting on the detail of plan-completion-before-push.md.
Principal-level portfolio construction — Markowitz mean-variance optimisation, CAPM, factor models, risk budgeting, rebalancing discipline, drawdown and tail-risk management. Diversification is the only free lunch; respect transaction costs and behavioural traps.
PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
Template for authoring a project-specific skill in `<workspace>/.claude/skills/`. Demonstrates the canonical shape — Architecture / File Structure / Code Patterns / Testing Requirements / Deployment Workflow / Critical Rules — that workspace skills follow when they extend global guidance with project-specific specifics. Use this file as a starting point; copy + customise per the project's actual stack.
Principal-level prompt engineering — task decomposition, role + context + instructions + examples + output-format structure, few-shot patterns, chain-of-thought, tool-use prompts, evaluation, prompt versioning, and the discipline that separates "works once on the demo" from "production-grade prompt that survives model upgrades". Select explicitly when this guidance applies.
Transforms vague or under-specified prompts into actionable, research-grounded requests through systematic codebase + workspace + open-source + online research. Wires the user's directive flow into the Council Protocol Phase 0 and the global task-intake-due-diligence.md questionnaire. Invoked by the UserPromptSubmit hook when a prompt lacks specificity OR when a clear-but-significant prompt needs the full intake before execution.
Read and cite primary-source provider documentation BEFORE writing any integration code against an external API. Enforces the official-docs-first rule across calendar, identity, payment, mail, push, ML, and observability providers.
Pythonic idioms, PEP 8 standards, type hints, and best practices for building robust, efficient, and maintainable Python applications.
Python testing strategies using pytest, TDD methodology, fixtures, mocking, parametrization, and coverage requirements.
Retrieval-Augmented Generation (RAG) system design — chunking, embeddings, vector storage, hybrid retrieval, reranking, evaluation, grounding, and the RAG-vs-fine-tune-vs-long-context decision. Select explicitly when this guidance applies.
Coordinate dependent repositories, migrations, infrastructure and releases with compatibility evidence, deployment ordering, rollback limits and exact revision tracking.
Turn ambiguous feature requests or reported defects into observable acceptance criteria, preserving user intent and tracing requirements to verification evidence.
Principal-level research methodology — primary vs secondary sources, quantitative + qualitative + mixed methods, literature review, evidence hierarchies, experimental design, survey + interview craft, bias identification, statistical inference, reproducibility, citation discipline, and the discipline that separates "I read some articles" from "I produced load-bearing evidence that supports a real decision".
Design and run bounded backup-restore, failover and recovery exercises with measured recovery objectives, data correctness, abort conditions and cleanup evidence.
Resilience patterns — circuit-breaker (per-DEPENDENCY breaker; CLOSED/OPEN/HALF-OPEN), graceful-degradation (P0-P3 criticality tiers; explicit degraded UX never silent), feature-flags (every flag has owner + expiry + decision criteria; OpenFeature spec; kill switches pre-built), idempotency (Stripe keys; RFC 9110 method semantics; webhook event-id dedupe), rate-limiting (multi-layer; per-endpoint defaults; RFC 6585), deploy-failures-become-checks (every deploy failure becomes a pre-deploy che...
Ruby 3.3+ / Rails 7-8 discipline — Sandi Metz rules (classes ≤ 100 LOC, methods ≤ 5 LOC, ≤ 4 args), frozen_string_literal mandatory, RuboCop at strict (cyclomatic ≤ 7, AbcSize ≤ 15), modern Ruby idioms (endless methods, pattern matching, hash shorthand, numbered block params), service objects + form objects + query objects + value objects, Rails 8 Solid Queue / Solid Cache / Solid Cable defaults, no monkey-patching outside Refinements / Module#prepend, Brakeman + bundler-audit + RSpec at stri...
Rust idioms — ownership-first design; types encode invariants (newtype pattern for UserId / Cents / etc.); errors as values (Result<T, E> + thiserror for libs + anyhow for apps); enums for closed sets (exhaustive match); builders for many-optional inputs; protocol-style traits for ports (dependency inversion); DI via struct composition (Arc<dyn Trait>); async/await + tokio with structured concurrency (try_join! / JoinSet); no .unwrap() outside tests (use ? or expect with reason); no panic! in...
Research-before-coding workflow. Search for existing tools, libraries, and patterns before writing custom code. Invokes the researcher agent.
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns. Also lazy-loads the security.md / security-controls-org-wide.md / secrets-management.md content migrated from rules/common/ on 2026-06-02.
Scan a Claude Code configuration surface (`.claude/` directory, `CLAUDE.md`, `settings.json`, MCP servers, hooks, agent definitions) for security vulnerabilities, misconfigurations, and prompt-injection risks using AgentShield (`ecc-agentshield`). Sister to `security-review` (broader OWASP / source-code audit). Use this skill when the target is the AGENT CONFIG, not the application source.
Audit and improve technical SEO, search intent, site architecture, content, metadata and search measurement using crawl and search evidence.
Data-driven variation reduction via DMAIC (Define / Measure / Analyse / Improve / Control), with Lean Six Sigma fusion when waste + variation co-exist. Belts framework (Yellow / Green / Black / Master Black), SPC charts, FMEA, design of experiments, hypothesis tests, capability indices (Cp / Cpk). Sister to lean-manufacturing (waste reduction).
SOC 2 Type I and Type II readiness patterns — Trust Service Criteria (Security / Availability / Processing Integrity / Confidentiality / Privacy), control-to-evidence mapping, and the operational evidence collection patterns that survive a continuous-period audit.
SonarLint / SonarQube / SonarJS rule catalogue (full 269-rule reference) plus per-language equivalents (golangci-lint, ruff, rubocop, errorlint, NullAway, clippy). Use when touching any code file to sweep against the highest-signal Sonar rules (S100, S107, S125, S138, S1192, S1481, S1854, S2068, S3358, S3776, S5547, S6571, S6606, S6594, S6644, S6759, S7755, S7773, S7780, S7781), apply per-file overrides for legitimate exceptions (test files, SSRF validators, domain nouns), and configure eslin...
Spring Boot 3.x implementation discipline — layering (controller/service/repository), dependency injection, configuration properties, transaction boundaries, JPA usage, REST API design, error handling, AND the full Spring Security surface (authentication, authorization, method security, CSRF, CORS, headers, secret handling). Use when writing or reviewing any Spring Boot controller, service, repository, entity, configuration class, application.yml or build file.
Spring Boot testing discipline — TDD workflow with JUnit 5, @SpringBootTest slicing (@WebMvcTest, @DataJpaTest), MockMvc, Testcontainers, and the verification gates a Spring Boot change must pass before it ships (build, coverage floor, static analysis, integration checks). Use when writing Spring Boot tests or verifying a Spring Boot change is done.
SQL discipline — lowercase keywords (modern convention; consistent project-wide), explicit column names (no SELECT * in production), UTC timestamps (TIMESTAMPTZ in Postgres), singular vs plural table names consistent, explicit JOIN (no implicit comma-joins), CTEs over deeply nested subqueries, named indexes, NULL-aware semantics (NULL = NULL is UNKNOWN; use IS NULL), parameterised queries always (no string interpolation), DELETE/UPDATE always with WHERE, migrations idempotent + reversible (ex...
Principal-level trade execution and broker workflow — order types, routing, transaction cost analysis (TCA), best execution duties, regulatory compliance (Reg NMS / MiFID II), suitability, and the operational discipline that turns a portfolio decision into actual settled positions.
Structural engineering literacy — loads (dead / live / wind / seismic / snow), materials (steel / concrete / timber / masonry), structural systems (frame / shear-wall / braced / shell / cable), and code regimes (Eurocode, AISC, ACI, IBC, NBCC). Activates on AEC + civil work to identify what's negotiable, what isn't, and where a licensed Structural Engineer of Record (SEOR) must own the call.
End-to-end orchestration of materials, information, and money across suppliers, manufacturers, distributors, and customers — SCOR model (Plan / Source / Make / Deliver / Return / Enable), demand sensing, S&OP, inventory positioning (safety stock, MOQ, EOQ), supplier risk management, resilience design (dual-sourcing, near-shoring, buffers), Incoterms 2020, customs + trade compliance. Sister to lean-manufacturing (in-house flow).
Thread-safe data persistence in Swift using actors — in-memory cache with file-backed storage, eliminating data races by design.
Protocol-based dependency injection for testable Swift code — mock file system, network, and external APIs using focused protocols and Swift Testing.
Use this skill when writing new features, fixing bugs, or refactoring code. Enforces test-driven development with canonical risk-appropriate coverage including unit, integration, and E2E tests.
Select risk-based verification for features and defects, choosing test boundaries, independent oracles, realistic fixtures and evidence that detects meaningful failures.
Theory of Inventive Problem Solving (Altshuller, 1946) — resolve technical contradictions via the 40 inventive principles + contradiction matrix, identify Ideal Final Result, evolve toward Ideality, escape local optima that brainstorming cannot reach. Derived from analysis of 200,000+ patents.
TypeScript implementation guidance for strict types, runtime validation, asynchronous errors and maintainable module boundaries.
Principal-level user research methodology — generative vs evaluative methods, study design, recruitment, sample sizing, qualitative coding, statistical rigour for usability tests, persona + JTBD synthesis, ethical research practice, and the discipline that turns user observations into decisions product teams actually use.
Principal-level valuation methodologies — DCF, trading comparables, precedent transactions, LBO, sum-of-the-parts, venture capital method, real options. Cite valuation outputs as ranges with explicit assumption sensitivity, never a single point estimate.
A comprehensive verification system for Claude Code sessions.
Vue 3 implementation guidance for Composition API, composables, Pinia, reactivity, performance and strict vue-tsc checks.