
Claude Skills by radesjardins
github.com/radesjardinsThis skill should be used when implementing idempotent webhook processing, handling "duplicate webhook events", "processed_events table", "idempotency key", "at-least-once delivery", "webhook deduplication", "event ID tracking", "reconciliation cron", "Stripe retry behavior", "crash-safe event processing", "atomic event recording", "webhook reliability patterns", or when the user asks how to prevent double-processing of Stripe webhook events.
This skill should be used when implementing security for Stripe webhook endpoints, handling "webhook rate limiting", "Stripe secret management", "webhook abuse prevention", "log redaction for billing", "STRIPE_WEBHOOK_SECRET storage", "webhook endpoint protection", "Stripe API key security", "billing security review", "sensitive data in logs", "production webhook hardening", "DDoS protection for webhooks", or when the user asks about securing Stripe webhook endpoints and billing infrastructur...
This skill should be used when writing tests for Stripe webhook handlers, implementing "fastify.inject() for webhooks", "Stripe webhook test", "webhook signature test", "idempotency test", "schema validation test", "Stripe CLI fixtures", "stripe trigger command", "mock Stripe API in tests", "webhook handler test", "billing integration test", "test invalid webhook payload", "webhook failure path test", or when the user asks how to test Stripe webhook handlers, billing endpoints, or subscriptio...
This skill should be used when defining Zod schemas for Stripe webhook handling, implementing "Zod type provider with Fastify", "webhook payload schema", "Stripe event Zod validation", "z.discriminatedUnion for events", "config schema with Zod", "env validation Zod", "z.infer for Stripe types", "Zod response schema", "request validation schema", "fastify-type-provider-zod setup", "Stripe webhook Zod", "billing Zod schemas", or when the user asks how to define type-safe validation contracts fo...
This skill should be used when reviewing TypeScript code for anti-patterns, when code contains unsafe practices, when identifying common TypeScript mistakes, when auditing AI-generated TypeScript code, or when enforcing production-grade TypeScript standards. Trigger on: "review TypeScript code", "TypeScript anti-patterns", "unsafe TypeScript", "type assertion smell", "any type misuse", "non-null assertion", "TypeScript code review", "AI generated TypeScript", "TypeScript best practices audit"...
This skill should be used when writing API endpoints, handling external data, validating HTTP requests or responses, parsing user input, working with environment variables, designing type-safe API boundaries, integrating Zod for runtime validation, implementing Fastify with type providers, sharing types in monorepos, or setting up parse-don't-validate patterns. Trigger on: "API boundary", "parse don't validate", "Zod schema", "runtime validation", "validate request body", "safe parse", "schem...
This skill should be used when implementing error handling in TypeScript, when asked about try/catch patterns, Result types, error-as-value patterns, neverthrow or errore libraries, handling async errors, classifying errors, typed error handling, or transitioning from exception-based to result-based error handling. Trigger on: "error handling TypeScript", "Result type", "neverthrow", "errore library", "errors as values", "typed errors", "catch block typing", "useUnknownInCatchVariables", "err...
This skill should be used when working with TypeScript 4.9 through 5.7 features, using the satisfies operator, const type parameters, inferred type predicates, verbatimModuleSyntax, isolated declarations, or targeting ES2024. Trigger on: "satisfies operator", "const type parameter", "TypeScript 5.0", "TypeScript 5.5", "TypeScript 5.7", "inferred type predicate", "verbatimModuleSyntax", "es2024 target", "TypeScript 4.9 features", "using declaration", "override keyword", "TypeScript new feature...
This skill should be used when configuring TypeScript projects, creating or reviewing tsconfig.json, enabling strict mode, asking what TypeScript compiler flags do, setting up a new TypeScript project for production, or reviewing existing TypeScript configuration. Trigger on: "configure tsconfig", "enable strict mode", "what does strictNullChecks do", "noUncheckedIndexedAccess", "exactOptionalPropertyTypes", "verbatimModuleSyntax", "TypeScript configuration best practices", "strict mode optio...
This skill should be used when writing TypeScript types, working with union types, implementing type guards or type predicates, using the satisfies operator, handling unknown or never types, creating discriminated unions, narrowing types, or modeling complex application state. Trigger on: "discriminated union", "type guard", "type predicate", "narrowing", "satisfies operator", "unknown type", "never type", "exhaustive switch", "is operator", "typeof check", "instanceof check", "union type pat...
This skill should be used when the user asks about "how to use Zod", "where should I put Zod validation", "Zod best practices", "should I use Zod here", "Zod vs TypeScript types", "parse don't validate", "overvalidation", "Zod single source of truth", or when reviewing or writing TypeScript code that imports from "zod". Provides the core mental model and foundational rules for effective Zod usage.
This skill should be used when the user asks about "Zod error handling", "parse vs safeParse", "ZodError", "z.treeifyError", "z.flattenError", "z.prettifyError", "formatting Zod errors", "Zod error messages", "custom Zod errors", "z.config error map", "Zod error precedence", "Zod validation errors for API response", or "how to display Zod errors to users". Provides comprehensive guidance on Zod's error system, formatting utilities, and customization.
This skill should be used when the user asks about "Zod with Fastify", "Zod type provider", "fastify-type-provider-zod", "Zod with Next.js", "Zod server actions", "Zod React Hook Form", "zodResolver", "Zod tRPC", "Zod monorepo", "shared Zod schemas", "Zod shared package", "Zod dual instance error", "ID already exists registry", "Zod frontend backend", "Zod AI SDK", or when integrating Zod with any web framework. Provides patterns for all major framework integrations and monorepo architecture.
This skill should be used when the user asks about "composing Zod schemas", "extending a schema", "Zod pick omit partial", "discriminatedUnion vs union", "Zod transforms", "Zod refinements", "z.refine vs z.check", "Zod pipe", "input output types", "z.infer input output", "Zod branded types", "recursive schemas", "Zod lazy", or is designing data models with Zod schemas. Provides comprehensive patterns for schema composition, transformation, and refinement.
This skill should be used when the user asks about "Zod security", "Zod over-posting attack", "mass assignment Zod", "z.strictObject security", "z.custom security", "Zod coercion vulnerability", "Zod default PATCH bug", "Zod data loss", "Zod reportInput PII", "exposing ZodError to client", "Zod security review", "reviewing Zod validation code", or when performing a code review on TypeScript files that use Zod. Provides a comprehensive security model and review checklist for Zod usage.
This skill should be used when the user asks about "Zod 4", "Zod v4", "upgrading to Zod 4", "Zod 4 breaking changes", "Zod 4 migration", "z.merge deprecated", "Zod 4 error parameter", "z.config", "Zod registries", "z.meta", "ZodMini", "z.file", "z.templateLiteral", "z.toJSONSchema", "Zod 4 vs Zod 3", "Zod 4 optional default behavior", or "Zod 4 performance". Covers Zod v4 architecture, all breaking changes, new APIs, and migration strategies.
Entry-point router skill for the 1Password CLI. Use this skill when the user mentions the 1Password CLI (`op`) or 1Password generically, references the secret-reference URI scheme `op://`, asks about `OP_ACCOUNT` or `OP_SERVICE_ACCOUNT_TOKEN`, asks about biometric unlock for a CLI, or is choosing how to load secrets into an app and 1Password is a candidate. Provides general orientation, the auth-mode picker, the full command map, and routing to deeper sub-skills (`op-secrets-injection`, `op-i...
Find 1Password items by name across all accessible vaults. Returns name, vault, category, and ID for each match.
Use this skill when the user is creating, editing, getting, listing, deleting, archiving, sharing, or moving 1Password items via the CLI — anything involving `op item create`, `op item edit`, `op item get`, `op item list`, `op item delete`, `op item move`, `op item share`, `op item template`, `op document`, item field types, item categories, JSON item templates, assignment statements, or generating passwords with the CLI.
Use this skill when the user is provisioning, suspending, deleting, or recovering 1Password users; managing groups; granting or revoking vault permissions for users or groups; performing bulk onboarding/offboarding; or auditing access. Triggers include `op user`, `op group`, `op vault user`, `op vault group`, "invite a user", "remove a user from 1Password", "onboarding", "offboarding", "vault permissions".
Generate `op://` secret references for every field on a 1Password item. Output is ready to paste into a `.env` template.
Use this skill when the user is loading 1Password secrets into a running process or config file — anything involving `op run`, `op inject`, `op read`, `.env` files containing `op://...` references, secret-reference template syntax, the `{{ op://... }}` placeholder format, populating YAML/JSON/TOML config from a template, or wiring 1Password into Docker/Kubernetes/CI/CD. Also use when the user asks how to keep secrets out of `.env`, source control, or shell history.
Use this skill when the user is setting up 1Password for headless / CI / production environments — anything involving service accounts (`op service-account create`), service account tokens, `OP_SERVICE_ACCOUNT_TOKEN`, Connect servers (`op connect`), `OP_CONNECT_HOST`/`OP_CONNECT_TOKEN`, GitHub Actions integration, deploying with 1Password secrets, the events-api integration, or scoping 1Password access for automation.
Use this skill when the user wants to authenticate third-party CLIs (gh, aws, stripe, doctl, hcloud, etc.) using 1Password instead of plaintext config files or environment variables — anything involving `op plugin init`, `op plugin run`, `op plugin list`, `op plugin inspect`, `op plugin clear`, `~/.op/plugins.sh`, biometric auth for CLIs, or replacing tokens in `~/.aws/credentials` / `~/.config/gh` / etc.
Sign in to the 1Password CLI. Idempotent — does nothing if already authed. Reports current account.
Use this skill when the user is generating, retrieving, importing, or using SSH keys stored in 1Password — anything involving the `SSH Key` item category, the `--ssh-generate-key` flag, the `?ssh-format=openssh` query parameter, the 1Password SSH agent, signing git commits with a 1Password key, or using a 1Password-stored key for `ssh`/`scp`/`rsync`/`git`.
Quick 1Password CLI status — current account and accessible vaults.
Use this skill when the user asks about ARIA, ARIA roles, ARIA attributes, aria-label, aria-labelledby, aria-describedby, aria-expanded, aria-hidden, aria-live, aria-required, aria-invalid, "WAI-ARIA", "ARIA Authoring Practices", "APG pattern", "accessible name", "accessible description", live regions, custom widgets, dialogs, menus, tabs, accordions, comboboxes, tooltips, tree views, carousels, or is building any custom interactive component that requires ARIA roles and keyboard behavior bey...
Use this skill when the user asks about accessible forms, form labels, form errors, input accessibility, "aria-required", "aria-invalid", "aria-describedby", fieldset and legend, "form validation accessibility", required fields, error messages, placeholder accessibility, password fields, file uploads, date inputs, select elements, checkbox groups, radio groups, "WCAG 3.3", "label instructions", or is building any form that needs to be screen reader compatible and keyboard accessible.
Use this skill when the user asks about keyboard navigation, keyboard accessibility, focus management, focus trapping, focus ring, focus indicator, ":focus-visible", skip links, "tabindex", "Tab key navigation", "focus order", "focus returns", "orphaned focus", "focus lost", "modal focus trap", "focus after close", "roving tabindex", "keyboard trap", or is building modals, dialogs, drawers, dropdowns, or any component requiring programmatic focus management. Also use when diagnosing why keybo...
Static analysis pass over JSX/HTML/CSS source for WCAG 2.2 AA failure patterns. Does NOT run axe-core, does NOT measure real contrast, does NOT test runtime behavior — pair with a11y-testing for that. Use when the user asks for an accessibility review, a11y check, WCAG review, "is this accessible?", "does my site meet WCAG?", "check my component for accessibility", "review accessibility of", "check for a11y issues", "fix accessibility issues", or any request to scan a web page, component, or ...
Use this skill when the user asks about semantic HTML structure, heading hierarchy, landmark regions, div soup, divitis, "which HTML element should I use", "semantic markup", "HTML accessibility", "ARIA landmarks", "page structure", "section vs div", "article vs section", "when to use aside", or is writing HTML templates, page layouts, or component markup that requires accessible structural decisions. Also use when reviewing HTML for screen reader compatibility or document outline correctness.
Use this skill when the user asks about accessibility testing, axe-core, jest-axe, "@testing-library", "@axe-core/playwright", "Playwright accessibility testing", "WAVE", "Lighthouse accessibility", "automated a11y tests", "accessibility CI/CD", "eslint-plugin-jsx-a11y", "a11y linting", "axe DevTools", setting up accessibility tests, writing accessibility tests for React components, integrating a11y checks into a test suite, or understanding what automated tools can and cannot catch. Also use...
Let's brainstorm, I need ideas, help me think through, brainstorm with me, what should I build, how should I approach this — open-ended exploration of possibilities. Handles blank slate to refining an existing concept.
I'm stuck, I have no ideas, I don't know where to start, writer's block, can't think of anything, I'm blocked — user unable to make progress. Warm-up exercises, creative provocation, progressive engagement to build momentum.
Design this, create a spec, design sprint, architecture for this, write a design doc. Post-ideation: architecture, components, data flow, error handling, testing. Not for ideation — use brainstorm-session for that.
5 whys, root cause analysis, why does this keep happening, find the root cause, trace this problem. Dig beneath surface symptoms to find the real problem. Toyota production system methodology.
How might we, reframe this problem, turn this into an opportunity, HMW questions. Reframe problems as actionable opportunity questions using the Basadur/P&G HMW technique.
Evaluate these ideas, which idea is best, help me prioritize, compare these options, rank these, how do I choose. Structured evaluation via Impact/Effort Matrix, Assumption Mapping, Pre-Mortem, JTBD, Dot Voting.
Generate ideas, I need more options, what else could work, give me alternatives, more ideas please. Pure divergent ideation using SCAMPER, Reverse Brainstorming, Starbursting, Analogical Thinking. For evaluation, use idea-evaluation.
Reverse brainstorm, make it worse, flip the problem, opposite approach. Ask "How could this get worse?" then invert answers into solutions. Effective when conventional brainstorming stalls.
SCAMPER, modify this concept, improve this idea, systematic improvement. Systematically explore modifications via 7 lenses: Substitute, Combine, Adapt, Modify, Put to other use, Eliminate, Reverse.
Six hats, thinking hats, explore all perspectives, de Bono. Analyze from multiple perspectives via Six Thinking Hats: Blue (process), White (data), Green (creativity), Yellow (optimism), Black (caution), Red (intuition).
This skill should be used when working on any Chrome extension project or when the user asks about Chrome extension best practices, conventions, or patterns. Trigger when: setting up a new Chrome extension, configuring WXT, asking about MV3 architecture, "Chrome extension project structure", "WXT config", "extension entrypoints", "manifest v3 setup", "when to use content script vs service worker", "extension context boundaries", "Chrome extension build", "wxt.config.ts", "extension packaging"...
This skill should be used when implementing messaging between Chrome extension components or when the user asks about inter-process communication in extensions. Trigger when: "extension messaging", "chrome.runtime.sendMessage", "chrome.tabs.sendMessage", "content script messaging", "port.postMessage", "runtime.connect", "Protocol Map", "@webext-core/messaging", "message passing", "extension IPC", "sendMessage vs connect", "async message response", "return true onMessage", "typed messaging", "...
This skill should be used when working on Chrome extension permissions or Chrome Web Store compliance. Trigger when: declaring extension permissions, "manifest permissions", "activeTab vs tabs", "optional_permissions", "host_permissions", "Chrome Web Store rejection", "permission minimization", "over-permissioning", "CWS review", "Purple Potassium", "extension permission audit", "narrowest permission", "permission warnings", "chrome.permissions.request", "permission justification".
This skill should be used when working on security aspects of a Chrome extension or when the user asks about Chrome extension security best practices. Trigger when: implementing Content Security Policy in extensions, "extension CSP", "eval in extension", "content script security", "extension XSS", "remote code in extension", "MV3 security", "unsafe-eval", "content script isolation", "DOM safety in extension", "Trusted Types", "extension sandbox", "chrome extension security audit", "innerHTML ...
This skill should be used when working with Chrome extension service workers or background scripts. Trigger when: "service worker lifecycle", "background script", "extension service worker", "chrome.alarms", "offscreen document", "service worker restart", "top-level listener", "service worker idle", "event listener registration", "chrome.offscreen", "service worker termination", "state rehydration", "persistent background", "MV3 background", "service worker wake-up", "keepalive", "setTimeout ...
This skill should be used when working with data storage in Chrome extensions or when the user asks about extension storage patterns. Trigger when: "chrome.storage", "extension storage", "storage.local", "storage.sync", "storage.session", "IndexedDB in extension", "extension data persistence", "write-through cache", "storage quota", "unlimitedStorage", "chrome.storage.onChanged", "reactive storage", "WXT storage", "storage.defineItem", "storage migration", "sync vs local storage".
This skill should be used when writing or setting up tests for a Chrome extension. Trigger when: "test chrome extension", "extension unit test", "extension e2e test", "Vitest extension", "Playwright extension", "@webext-core/fake-browser", "test content script", "test service worker", "test messaging", "test storage", "extension integration test", "test permission flow", "extension test framework", "mock chrome API", "browser mode testing".