Generate a BRAID reasoning graph (Mermaid flowchart TD) for a complex multi-step task. Cache to .local-artifacts/braid/<task-slug>.mmd. Hand to the braid-solver agent for execution. Use before non-trivial features, multi-hypothesis debugging, architecture decisions.
Run unit-test coverage for the changed surface and block if below threshold. Backend (Go) via go test -cover. Frontend (web) via vitest --coverage. Threshold 70% now, target 80%. Reports delta vs base branch.
Audit the gap between what the code is documented to do and what it actually does. Run before claiming any feature works, before a release, and whenever a doc/README/CLAUDE.md says a subsystem is "done". Turns "Presence ≠ completeness" into a repeatable check. Especially for marketplace sync, payment, invoice.
Create a GitHub issue with required milestone + labels + body template. Enforces the "no issue, no branch" rule. Returns the issue number for the branch name.
Capture Playwright snapshots + screenshots for a list of URLs. Saves artifacts to .local-artifacts/screenshots/<branch>/. Lightweight helper invoked by wtf-ux-playwright or directly when verifying a specific surface.
Black-box pentest of the Go/Gin REST API. JWT handling, IDOR, rate limiting, payment-callback verification, business-logic abuse. Run before major releases.
Black-box pentest of the deployment surface. TLS config, security headers, exposed ports, DNS, container exposure. Run before major releases and after infra changes.
Periodic penetration testing suite. Covers web app (Next.js), REST API (Go/Gin), and deployment surface. Use before every major release and quarterly thereafter. Complements wtf-security (code review) with black-box dynamic testing.