Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Otopcy Softstart

ASecurity

Use when starting a new web project, or when making a structural decision on an existing one — folder layout, where server code lives, which provider to add, what to check before shipping. This is the router for the Otopcy SoftStart playbook; it carries the ten non-negotiable rules and points to the specialised skills (otopcy-architecture, otopcy-securite, otopcy-paiements, otopcy-performance, otopcy-admin, otopcy-outils, otopcy-audit). Reference stack is Next.js App Router + Prisma + Postgre...

2 stars
0 votes
0 copies
1 views
Added 10/1/2026
databasesgobashsqlnextjsnodenodejsapiperformance

Works with

cliapi

Security Analysis

A100/100

Scanned 10/1/2026

$npx -y skills add Giovannyengamba/Otopcy-Softstart --skill otopcy-softstart --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Otopcy Softstart?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Otopcy Softstart
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/giovannyengamba-otopcy-softstart/badge)](https://www.skillsdirectory.com/skills/giovannyengamba-otopcy-softstart)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: otopcy-softstart
description: Use when starting a new web project, or when making a structural decision on an existing one — folder layout, where server code lives, which provider to add, what to check before shipping. This is the router for the Otopcy SoftStart playbook; it carries the ten non-negotiable rules and points to the specialised skills (otopcy-architecture, otopcy-securite, otopcy-paiements, otopcy-performance, otopcy-admin, otopcy-outils, otopcy-audit). Reference stack is Next.js App Router + Prisma + PostgreSQL + Redis on Vercel, but the rules are stack-agnostic.
---

# Otopcy SoftStart — socle

Par Giovanny Engamba (giovannyengamba.com) · Otopcy (otopcy.com) · MIT.

Extrait d'une application en production : boutique, adhésions, billetterie,
portail d'administration, paiements mobile money et PayPal.

## Les dix règles non négociables

1. **Montants = entiers en plus petite unité.** Jamais de flottant.
2. **Webhook : vérifier la signature sur le corps brut, avant `JSON.parse`.**
3. **Effets de bord d'une transaction → boîte d'envoi**, jamais un `then()`
   après le commit.
4. **Aucune clé secrète côté client.** Une clé exposée se **révoque**, ne
   se retire pas.
5. **Un contrôle d'accès dans le navigateur n'en est pas un.**
6. **Toute écriture d'administration est journalisée** (qui, quoi, avant,
   après).
7. **Prestataire sans clé = inerte, pas fatal.**
8. **Le webhook peut ne jamais arriver** → tâche de réconciliation
   obligatoire.
9. **`headers()` dans le gabarit racine rend TOUTE l'application
   dynamique.**
10. **Aucune donnée affichée n'est inventée.** Pas de chiffre → état vide
    avec explication.

## Aiguillage

| La demande porte sur | Compétence |
|---|---|
| Structure, client/serveur, journaux, prestataires optionnels | `otopcy-architecture` |
| Connexion, CSRF, rôles, CSP, téléversements | `otopcy-securite` |
| Argent, webhooks, devises, retraits | `otopcy-paiements` |
| Lenteur, cache, ISR, crons | `otopcy-performance` |
| Back-office, audit, capacités | `otopcy-admin` |
| Choisir un service, comptes Google, DNS | `otopcy-outils` |
| Avant mise en ligne | `otopcy-audit` |

## Le motif d'une route, à reproduire tel quel

```ts
export const runtime = 'nodejs';                      // 1. sinon casse en prod

export async function POST(req: NextRequest) {
  const ctx = makeRequestContext(req.headers);
  return withRequestContext(ctx, async () => {
    const csrf = verifyCsrf(req);                     // 2. avant toute écriture
    if (csrf) return csrf;
    const auth = await requireAuth(req);              // 3. avant toute donnée privée
    if (auth instanceof NextResponse) return auth;
    const corps = Schema.safeParse(await req.json()); // 4. valider
    if (!corps.success) return erreur(400, 'INVALID_BODY');
    // 5. le travail
  });
}
```

## Quand une règle compte, écris le test

Une règle dans un document est une règle qu'on enfreindra dans six mois.
Les garde-fous qui rapportent le plus (10 à 30 lignes chacun) :

- chaque route exporte `runtime = 'nodejs'` ;
- crons déclarés ⟺ routes existantes ;
- variables utilisées ⊆ `.env.example` ;
- aucun `NEXT_PUBLIC_*` contenant `SECRET`/`KEY`/`TOKEN` ;
- toute route `/api/admin/*` qui écrit appelle `logAdminAction`.

## Barrière avant commit

```bash
pnpm format && pnpm lint && pnpm typecheck && pnpm test
pnpm build      # avant de pousser : frontière client/serveur, préenregistrement
```

## Ne fais jamais

- écrire, afficher ou commiter une clé ; concevoir un écran qui en accepte une ;
- inventer une donnée manquante ;
- affirmer « corrigé » sans montrer la commande et sa sortie ;
- étendre le rejeu automatique aux verbes qui écrivent.

Attribution

GiovannyengambaGiovannyengamba
View sourceSee grades on GitHubMore from Giovannyengamba →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Mysql Best Practices

MySQL development best practices for schema design, query optimization, and database administration

2481 votes

Jpa Patterns

Spring Boot中的JPA/Hibernate实体设计、关系、查询优化、事务、审计、索引、分页和连接池模式。

2456590 votes

Clickhouse Io

ClickHouse数据库模式、查询优化、分析和数据工程最佳实践,适用于高性能分析工作负载。

2456590 votes

Postgres Patterns

基于Supabase最佳实践的PostgreSQL数据库模式,用于查询优化、架构设计、索引和安全。

2456590 votes

Sql Pro

Master modern SQL with cloud-native databases, OLTP/OLAP

458250 votes
View all in databases →