Skip to content
Back to skills

Best Practices 7

ASecurity

Project-specific best practices - auto-loads based on detected project type

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
developmentpythongokotlinbashreactnextjsfastapispringapiperformance

Works with

  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill best-practices-7 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Best Practices 7?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Best Practices 7
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-best-practices-7/badge)](https://www.skillsdirectory.com/skills/david-li0406-best-practices-7)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: best-practices
description: Project-specific best practices - auto-loads based on detected project type
---

# Best Practices Skill

Comprehensive best practices with **40+ rules per framework**. Auto-activates based on project type and **auto-audits codebase** for violations.

## Activation Triggers

This skill activates automatically when:
- Working in a detected project type (React, Go, Flutter, FastAPI, Kotlin Spring)
- Writing or reviewing code
- Optimizing performance
- `/feature-dev` is invoked

## How It Works

1. **Auto-detect** project type (vite.config, go.mod, pubspec.yaml, build.gradle.kts with spring-webflux, etc.)
2. **Load** appropriate rules from templates directory (see paths below)
3. **Scan codebase** for anti-pattern violations using Grep
4. **Generate TodoWrite items** for detected issues
5. **Apply** rules throughout the session

## Template Locations

Templates are located at `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/`. Each template is a directory containing `SKILL.md` with the full ruleset.

**Base Path**: `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates`

| Project Type | Template Path |
|-------------|---------------|
| react-vite | `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/react-vite/SKILL.md` |
| nextjs | `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/nextjs/SKILL.md` |
| go-gin | `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/go-gin/SKILL.md` |
| flutter | `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/flutter/SKILL.md` |
| python-fastapi | `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/python-fastapi/SKILL.md` |
| kotlin-multiplatform | `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/kotlin-multiplatform/SKILL.md` |
| kotlin-spring | `${CLAUDE_PLUGIN_ROOT}/plugins/best-practices/skills/best-practices/templates/kotlin-spring/SKILL.md` |

**To load rules**: Read the appropriate template SKILL.md using the full path above. The `${CLAUDE_PLUGIN_ROOT}` variable resolves to the plugin installation directory.

## Auto-Audit Mode

**IMPORTANT**: After loading rules, you MUST scan the codebase for violations using Grep.

### Quick Scan Patterns (MANDATORY)

For **React/Vite/Next.js** projects, scan for these CRITICAL patterns:

```bash
# Barrel file imports (CRITICAL)
Grep: pattern="from ['\"']@/components['\"]" glob="*.tsx,*.ts"

# Lodash full import (CRITICAL)
Grep: pattern="from ['\"']lodash['\"]" glob="*.tsx,*.ts"

# Inline style objects (HIGH)
Grep: pattern="style=\{\{" glob="*.tsx"
```

For **Go/Gin** projects:

```bash
# Ignored errors (CRITICAL)
Grep: pattern="json\.(Unmarshal|Marshal)\([^)]+\)$" glob="*.go"

# Unwrapped error returns (HIGH)
Grep: pattern="return nil, err$" glob="*.go"
```

For **Kotlin Multiplatform** projects:

```bash
# GlobalScope usage (CRITICAL)
Grep: pattern="GlobalScope\.(launch|async)" glob="*.kt"

# MutableStateFlow without asStateFlow (CRITICAL)
Grep: pattern="val.*MutableStateFlow" glob="*.kt"

# Missing @Immutable/@Stable annotations (HIGH)
Grep: pattern="data class.*\(" glob="*.kt"
```

For **Kotlin Spring** (Coroutines + WebFlux) projects:

```bash
# GlobalScope usage (CRITICAL)
Grep: pattern="GlobalScope\.(launch|async)" glob="*.kt"

# Blocking calls in suspend functions (CRITICAL)
Grep: pattern="Thread\.sleep" glob="*.kt"

# JDBC instead of R2DBC (CRITICAL)
Grep: pattern="JdbcTemplate|spring-boot-starter-jdbc" glob="*.kt,*.gradle.kts"

# Catching CancellationException (HIGH)
Grep: pattern="catch.*Exception\)" glob="*.kt"

# runBlocking in tests (MEDIUM)
Grep: pattern="runBlocking" glob="*Test.kt"
```

### Audit Workflow

1. **Run Grep** for each critical pattern above
2. **Report findings** with file:line format
3. **Group by severity**: πŸ”΄ CRITICAL β†’ 🟠 HIGH β†’ 🟑 MEDIUM
4. **Create TodoWrite items** for CRITICAL and HIGH violations
5. **Show summary**: `πŸ’‘ Fix with: /feature-workflow "fix: best-practice violations"`

### Skip Audit

Use `--no-audit` flag to load rules without scanning.

### Example Output

```
πŸ” Detecting project type...
πŸ“ Found: vite.config.ts

βœ… best-practices loaded
Project: react-vite | Rules: 45+

πŸ”Ž Scanning codebase...
πŸ“‚ Scanned: 127 files in 342ms

⚠️ Found 12 violations:

πŸ”΄ CRITICAL (2):
  ❌ [bundle-optimization] Barrel file imports
     src/components/index.ts:1

🟠 HIGH (5):
  ❌ [rerender-prevention] Missing useMemo
     src/hooks/useData.ts:23

πŸ“‹ 7 items added to TodoWrite

πŸ’‘ Fix with: /feature-workflow "fix: best-practice violations"
```

### Filtering by Severity

Use `--severity` to report only violations at or above a threshold:
```bash
/best-practices:best-practices --severity HIGH
```

## Templates Available

| Project Type | Rules | Categories |
|-------------|-------|------------|
| react-vite | 45+ | 5 |
| nextjs | 45+ | 5 |
| go-gin | 48 | 8 |
| flutter | 42 | 8 |
| python-fastapi | 48 | 8 |
| kotlin-multiplatform | 44 | 8 |
| kotlin-spring | 48 | 8 |

See "Template Locations" section above for full paths.

## Rule Structure

Each template includes:
- **Priority levels**: CRITICAL β†’ HIGH β†’ MEDIUM β†’ LOW
- **Rule prefixes**: For easy reference (e.g., `err-wrap`, `async-block`)
- **Quick Reference**: All rules at a glance
- **Examples**: Incorrect vs correct patterns

## React/Next.js Integration

For React/Next.js projects, best practices **extend `/vercel-react-best-practices`**:

```
/vercel-react-best-practices  ← Primary (45 Vercel rules)
     ↓
best-practices templates      ← Framework-specific additions
```

Files in this skill

  • SKILL.md5.6 KB
  • templates/flutter/SKILL.md33 KB
  • templates/flutter/rules/widget-optimization.md4 KB
  • templates/go-gin/SKILL.md35.1 KB
  • templates/go-gin/rules/error-handling.md3.2 KB
  • templates/go-gin/rules/uber-fx.md8.8 KB
  • templates/kotlin-multiplatform/SKILL.md47.7 KB
  • templates/kotlin-multiplatform/rules/compose-effects.md3.9 KB
  • templates/kotlin-multiplatform/rules/compose-recomposition.md5 KB
  • templates/kotlin-multiplatform/rules/compose-state.md3.3 KB
  • templates/kotlin-multiplatform/rules/coroutine-scope.md5.4 KB
  • templates/kotlin-multiplatform/rules/coroutine-structured.md6.6 KB
  • templates/kotlin-multiplatform/rules/expect-actual.md7.1 KB
  • templates/kotlin-multiplatform/rules/koin-injection.md4.8 KB
  • templates/kotlin-multiplatform/rules/koin-modules.md5.1 KB
  • templates/kotlin-multiplatform/rules/ktor-client.md4.7 KB
  • templates/kotlin-multiplatform/rules/ktor-error.md7.7 KB
  • templates/kotlin-multiplatform/rules/navigation.md7.6 KB
  • templates/kotlin-multiplatform/rules/testing.md10.5 KB
  • templates/kotlin-multiplatform/rules/viewmodel-state.md8.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…