Skip to content
Back to skills

Review Standards

ASecurity

Merge criteria per stack (TypeScript/Next.js, Python, .NET, Expo) plus cross-cutting rules on secrets, contracts, migrations, tests, CRS. Apply during code review or before a PR.

  • 8 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
developmenttypescriptpythonnextjsflaskapidatabasebackend

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 19, 2026

npx -y skills add Adilmunawar/ZD-claude-plugin --skill review-standards --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Review Standards?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Review Standards
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/adilmunawar-review-standards/badge)](https://www.skillsdirectory.com/skills/adilmunawar-review-standards)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: review-standards
description: Merge criteria per stack (TypeScript/Next.js, Python, .NET, Expo) plus cross-cutting rules on secrets, contracts, migrations, tests, CRS. Apply during code review or before a PR.
---

Cross-cutting
- No credentials, project ids or hostnames in code; config by environment name.
- Client/server contract changes land on both sides in one PR or behind a flag; DTO names verbatim.
- Database changes ship as migrations; additive-only unless the release note says otherwise.
- Every bug fix adds the test that would have caught it. Every new command/script has a `--dry-run` or a smoke test.
- CRS stated wherever geometry is created or transformed; area never computed in EPSG:4326.

TypeScript / Next.js
- `npm run typecheck` and `npm run lint` clean; no `any` in exported types; server-only secrets never `NEXT_PUBLIC_`.
- API routes validate input (zod) and cap payload/geometry size; errors mapped to 4xx/5xx without stack traces.
- Heavy libraries dynamically imported; map components `ssr:false`; long work in workers or the backend.

Python (pipeline, Flask)
- Stage constants documented; paths relative to `working_directory`; resumable loops; counts logged per stage.
- No bare `except:`; explicit dtypes on read; `make_valid` before write; `to_crs` vs `set_crs` used correctly.
- Flask: request size limits, timeouts, `/health` cheap, job state survives restarts or the UI handles loss.

.NET
- `dotnet build` warnings as errors on new code; async all the way; `CancellationToken` on IO; EF Core queries projected (no `ToList()` before `Where`); spatial indexes declared; secrets via user-secrets / SSM.

Expo
- Strings through `Txt` and all language tables; logical start/end; tokens in secure store; formatters from `src/lib/format.ts`; tests for any new rule.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…