mit einem Klick
fullstack-forge-skill
fullstack-forge-skill enthält 46 gesammelte Skills von thethunderbolt, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.
Skills in diesem Repository
Own the full feature lifecycle (frame, plan, implement, check, done, resume, accept-risk, abandon) with CLI-enforced statuses. Use for building, continuing, or shipping a specific feature in build mode.
Audit, fix, verify, and report on production full-stack applications using evidence-backed checks across architecture, code, UX, accessibility, APIs, identity, security, data, operations, specialized features, and release readiness. Use for repository audits, feature completion reviews, hardening, remediation, or pre-release verification.
Audit, fix, verify, and report on production full-stack applications using evidence-backed checks across architecture, code, UX, accessibility, APIs, identity, security, data, operations, specialized features, and release readiness. Use for repository audits, feature completion reviews, hardening, remediation, or pre-release verification.
Guide the new-project foundation workflow that frames product, users, business rules, risk class, stack rationale, non-goals, design direction, and an initial feature list. Use for starting a new product or codebase in build mode.
Audit conformance with WCAG 2.2 AA using automated evidence plus keyboard and assistive-technology reasoning. Use for any user or operator interface.
Audit model boundaries, prompt injection, tool authority, data handling, output validation, evaluation, fallback, and cost. Use for llm, embedding, classifier, agent, retrieval, or generative-media features.
Discover the project, select applicable modules, run safe independent checks, merge evidence, and prioritize remediation. Use for repository-wide audits.
Audit event semantics, consent, data quality, identity, privacy, delivery, and decision usefulness. Use for product, marketing, operational, or experimentation analytics.
Audit API contracts, boundary validation, authorization, consistency, pagination, errors, and idempotency. Use for http, graphql, rpc, or event-consumed application interfaces.
Evaluate system boundaries, dependency direction, failure domains, and the fitness of the current topology. Use for multi-component applications.
Inspect identity proofing, credentials, sessions, recovery, federation, and reauthentication controls. Use for applications identifying users, services, or administrators.
Verify deny-by-default function, object, role, tenant, and administrative authorization on every path. Use for any private, role-gated, owned, tenant, or administrative resource.
First decide whether caching is justified, then audit keys, invalidation, consistency, privacy, and failure behavior. Use for detected caches, cdns, memoization, or a measured proposal to add caching.
Find correctness, maintainability, type-safety, error-handling, and dead-code risks in changed and critical paths. Use for source changes.
Tie resource and vendor cost to workloads, ownership, unit economics, budgets, and safe optimization choices. Use for paid infrastructure, apis, ai, storage, messaging, or observability.
Inspect schema integrity, migrations, constraints, tenancy, lifecycle, recovery, and production-safe evolution. Use for applications with a database or durable structured store.
Inspect build promotion, configuration, migrations, rollout, rollback, health, and environment parity. Use for deployable applications and services.
Build an evidence-backed application profile and architecture map before any specialized audit begins. Use for every repository audit.
Verify that user, contributor, architecture, operations, security, and release documentation is accurate and executable. Use for every maintained or distributed project.
Inspect rendering, state, network, hydration, browser security, and bundle behavior in frontend applications. Use for browser applications.
Find locale, translation, formatting, expansion, fallback, and bidirectional-layout defects. Use for localized or locale-sensitive products.
Audit infrastructure as code, network and identity boundaries, encryption, state, drift, and least privilege. Use for cloud, container, orchestration, network, or infrastructure-as-code configuration.
Audit outbound and inbound integrations for authentication, validation, failure isolation, drift, and replay safety. Use for third-party apis, webhooks, sdks, and service-to-service calls.
Inspect queued and scheduled work for durability, idempotency, retries, poison messages, and operability. Use for queues, workers, cron, scheduled functions, and outbox consumers.
Inspect email, SMS, push, and in-app notifications for authorization, preferences, retries, privacy, and deliverability. Use for transactional, security, lifecycle, or marketing messages.
Verify that logs, metrics, traces, events, alerts, and dashboards answer concrete operational questions safely. Use for long-running or production services.
Audit local persistence, queued actions, synchronization, conflicts, revocation, privacy, and recovery under intermittent connectivity. Use for offline-capable web, mobile, or desktop applications.
Audit money movement, pricing, entitlements, provider events, reconciliation, idempotency, and sensitive data boundaries. Use for payments, billing, subscriptions, refunds, credits, invoices, or financial ledgers.
Measure and improve user- and system-visible latency, throughput, resource use, and stability without guessing. Use for performance-sensitive workflows.
Inspect personal-data inventory, purpose, minimization, consent, retention, access, deletion, export, and logging. Use for applications processing personal, device, behavioral, or sensitive data.
Find correctness, injection, overfetching, N+1, pagination, locking, and index-use risks in data access. Use for database, search, analytics, and remote query code.
Inspect WebSocket, SSE, subscription, and presence flows for authorization, lifecycle, ordering, abuse, and recovery. Use for websockets, sse, subscriptions, live presence, or collaborative state.
Verify recoverability of data and service against explicit RPO, RTO, corruption, deletion, and regional scenarios. Use for durable production data or stateful critical services.
Audit timeouts, retries, overload, dependencies, degradation, consistency, and operational objectives. Use for services and critical workflows with availability or durability expectations.
Trace business rules and acceptance criteria to executable behavior, including adverse and recovery paths. Use for feature work.
Assess growth limits, contention, partitioning, quotas, backpressure, and cost against explicit demand scenarios. Use for expected growth, load concentration, or capacity incidents.
Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases. Use for every production-bound application.
Conditionally inspect public web content for crawlability, canonicalization, metadata, structured data, and rendering. Use for public indexable web routes.
Enforce a fail-closed release gate across project checks, findings, generated assets, packages, licenses, and installation. Use for a candidate release or deployment.
Inspect object naming, access control, encryption, lifecycle, consistency, integrity, and recovery. Use for object stores, file systems, blob databases, and cdn-backed assets.