Development
Programming, frameworks, implementation, frontend, backend, and app development
Browse development skills
Showing 3,841–3,864 of 69,488 skills
Repository または subsystem を対象に、source-only で明示的なセキュリティ監査を行う entry skill。 通常の PR セキュリティレビューとは分離し、reconnaissance、scope 固定、既存 security skill への委譲、 evidence と unresolved hypothesis、observe-only SecurityAuditCoverage、coverage critic、 structured audit artifact と repeat-run coverage を扱う。target-controlled code は実行しない。
Notes for `docs/research/118-phase-256-the-architecture-that-explains-itself.md`. Everything below was read at `/Users/gdc/as-built-architecture` (read only, never written, `git log` head `aa0428d`) and measured by RUNNING the helpers over scratch copies. Line numbers are of the files as they stand at that head.
Audit interface source with HIG Doctor when the user asks to scan, lint, review, or remediate Swift, UIKit, AppKit, React, Vue, Svelte, Angular, Compose, Android XML, Flutter, CSS, or HTML for HIG-aligned interface and accessibility concerns. Do not activate for general design advice without source to audit; use the relevant HIG guidance skill instead.
Create, edit, review, arm, and debug vincent event triggers, the YAML under {config_dir}/triggers and the poll scripts they run. Use for trigger sources (command, github_issues, github_prs, http, schedule), match and if filters, dedupe keys, limits, on_fire, permission, arming, dry runs, the delivery ledger, or trigger validation errors. Do not use for vincent workflows, including the workflow a trigger's action.workflow names (use vincent-workflows), or for GitHub Actions.
Implement a piece of work based on a spec or set of tickets.
Ask which skill or flow fits your situation. A router over the skills in this repo.
The SOFTWARE domain profile for the strategist. A domain profile answers the five questions the strategist's method deliberately leaves open: what surveying the current state means, what two concurrent tickets contend for, which capabilities the work routes to, what sections a plan carries, and what sections a ticket carries. This profile answers all five for a code project — survey the codebase, contend over file paths, route to developer/test-writer/reviewer, and carry Codebase Analysis and...
Teach decision-seat holders the CLI contract through a bundled system skill. Select that skill from the seat-derived advisory action and make the review and approval prompts require the command as their final action.
Record the current workflow step decision through the task-bound Office CLI.
Author a Kandev task canvas as a self-contained web application.
Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel, nested, tree, org chart, layer stack, Venn, pyramid/funnel, treemap, bar, line, Gantt and scatter charts, high-level, process, medallion, data flow, DP integration, DP security matrix, Sankey, fishbone, Wardley map, kanban, user journey, deployment, dependency graph, UML class, story map, or database s...
Print your own north-star row from your own record, and nothing else. Reads .claude/harness/decision-log.md, the canvas and the hook logs in this project; prints one line (decisions before the first source file, of which citing outside evidence, kills before code, sessions). Sends nothing anywhere. Opt-in; paste the line where you like or not at all.
Write or edit a Session Sitter practices file — the markdown that decides permission prompts. Use when the user wants to add a rule, block a command, allow something without approval, set up a practices file, or asks why a clause did not fire.
Read and interpret the Session Sitter audit trail — what agents were allowed to do, which clause was applied, who decided, and how long it took. Use when the user asks what happened overnight, why a call was denied or rewritten, which rules are firing, or wants to export the decision log.
Find out whether Session Sitter will allow a tool call, and which written clause decides it, BEFORE running it. Use when about to run something plausibly governed — a push, a deploy, a migration, anything touching secrets or infrastructure — or when the user asks what the policy allows, or why a call was denied.
Set up Session Sitter for a user, or change an existing configuration. Use when someone has just installed the extension, asks how to turn on supervision, Telegram cards or remote control, wants auto-approve rules or workspace colours, asks why a setting is not taking effect, or wants their configuration reviewed. Interviews the user, writes the settings, and validates the result with a script rather than from memory.
Read and manage the user's built-in My todos list in Very Happy through its official CLI. Use when asked to capture, review, update or complete personal todos in Very Happy.
Very Happy UI design and visual refactoring. Use when creating or changing App pages, shared components, responsive layouts, loading, branding, Landing, docs, login, or product screenshots. Preserve real features while applying the approved compact workspace style.
Run development changes through realistic user workflows after every change and before ending each development turn, including small UI and copy edits. Also use when asked to tophat, manually verify a feature or fix, or smoke-test a branch or PR.
Write, change, review, or debug Codevisor tests. Use whenever adding tests, changing test fixtures, investigating flaky failures, or optimizing test runtime in TypeScript, Swift, or scripts.
Runs an inspection walkthrough over a running app with the operator. Measures each finding off the built page, drafts arms as served HTML pages lifted from the app's own markup and stylesheet, hands over the localhost link before every pick question, records findings and picks with the arms they beat in one walkthrough file, and relays picks only in batches the operator calls. Use when asked to "run a first-use walkthrough", "do an operator walkthrough", "go through my findings one by one", "...
Measures paint, processor, and layout cost against a running interface and reports numbers against published thresholds. Detects the project's existing browser harness rather than requiring one. Use when asked "how fast is this page", "measure the UI", "what does this cost to render", "check Core Web Vitals", or "profile the interface". Do NOT use to judge UI quality by reading source, which is `ux-audit`.
Audits the current UI for incomplete, inconsistent, or confusing patterns. Reads DESIGN.md and canon/wireframes/ for intent, scans UI files, and outputs observations grouped by surface. Use when asked "audit the UX", "audit the UI", "UX audit", or "find UI roughness". Do NOT use for new feature planning or code changes, and do NOT use to measure what a running interface costs to paint, which is `ux-measure`.
Writes the visual checklist a reviewer reads beside the evidence screenshots, and names each changed behavior shipping with no test so `test-craft` can place one. Use after implementing UI changes, or when asked "what should I look at", "what do I verify", or "give me a visual checklist". Do NOT use in empty sessions with no implementation context, and do NOT use to write the tests themselves.