mustflow
mustflow contiene 278 skills recopiladas de 0disoft, con cobertura ocupacional por repositorio y páginas de detalle dentro del sitio.
Skills en este repositorio
Apply this skill when self-hosted Coolify or Coolify Cloud servers, applications, services, databases, build servers, destinations, Docker Compose stacks, domains, TLS certificates, Traefik or Caddy proxies, health checks, rolling updates, preview deployments, environment variables, build secrets, API tokens, teams, backups, restores, updates, monitoring, cleanup, resource limits, networking, firewalls, or deployment and rollback behavior are created, changed, reviewed, diagnosed, migrated, secured, or operated.
Apply this skill when PostgreSQL-specific schema, query, transaction, migration, indexing, extension, role, row-level security, connection pooling, replication, backup, restore, managed Postgres, or runtime behavior is created, changed, reviewed, or reported, including PostgreSQL 18 asynchronous I/O, B-tree skip scan, UUIDv7, virtual generated columns, RETURNING OLD/NEW, OAuth, logical-replication conflicts, observability, or 17-to-18 upgrades.
Apply this skill when Ubuntu Server or Ubuntu cloud images, especially Ubuntu 24.04 LTS or 26.04 LTS, are installed, upgraded, tuned, secured, diagnosed, backed up, restored, rebooted, or operated, including APT, dpkg, Snap, PPA, deb822 sources, unattended-upgrades, phased updates, needrestart, Livepatch, kernels, systemd services and timers, journald, cgroup v2, PSI, sysctl, CPU, memory, storage, network, SSH socket activation, AppArmor, UFW, Docker or Podman host integration, release upgrades, and remote recovery.
Apply this skill when deciding whether an AI agent, workflow automation, internal tool, or operational integration is economically worth building, expanding, replacing, or retiring by comparing human touch and wait time, exception density, stable machine-readable boundaries, expected cost per accepted outcome, human alternatives, supervision, failure recovery, maintenance, break-even volume, throughput value, effective lifetime, NPV, and independent safety gates.
Apply this skill when production automation, scheduled jobs, cron, polling, webhooks, events, queues, workers, durable workflows, approval steps, connectors, or operational pipelines are designed, changed, reviewed, or reported and the task must choose trigger responsibilities, prevent missed or duplicate work, detect silent wrong results, place human approval at the irreversible boundary, minimize credentials and personal data, control useful-effect cost, and keep an owned versioned automation registry.
Apply this skill when cloud, infrastructure, Kubernetes, serverless, database, storage, logging, telemetry, CDN, NAT, egress, autoscaling, quota, budget, tagging, snapshot, container registry, Marketplace, LLM API, or third-party SaaS usage is created, changed, reviewed, or reported and the risk is whether normal, growth, or incident usage can silently explode spend without scenario bills, account or project isolation, quotas, tags, lifecycle, retention, caps, commitment discipline, or automated shutoff guardrails.
Apply this skill when a PRD, requirement, proposal, policy, operating procedure, game rule, system design, API contract, data model, code-change plan, review comment, decision memo, or agent answer needs consequence-driven critique that replaces vague praise, hedging, false balance, abstract adjectives, or unactionable criticism with an evidence-backed judgment, plausible competing readings, the first divergent decision, a concrete failure and late-discovery path, calibrated severity, a bounded correction, and an observable completion criterion.
Apply this skill when choosing, comparing, adding, replacing, upgrading, rejecting, or standardizing a technology stack, framework, runtime, database, cache, queue, auth provider, payment provider, AI provider, SDK, managed service, SaaS, hosting platform, deployment tool, build tool, ORM, observability tool, or vendor integration, especially when the decision depends on cost per accepted outcome, workload growth, saturation and tail performance, failure semantics, support and incident history, commitment pricing, migration and rollback, exit tax, lock-in, operating toil, or solo-maintainer survivability.
Apply this skill when browser automation, UI automation, Playwright, Selenium, Puppeteer, WebDriver, computer-use/browser-driving agents, visual browser verification, flaky selectors, page readiness, authentication state, CAPTCHA or anti-bot handling, rate limits, screenshot checks, retry, timeout, human approval, or browser automation observability is created, changed, reviewed, triaged, or reported.
Apply this skill when code, configuration, docs, templates, logs, telemetry, traces, baggage, behavior analytics, core events, credentials, data flows, data residency policy, region or processing-location claims, AI-generated code, AI prompts outputs usage cost records budgets policies or cache keys, authentication, authorization, server-side permission checks, admin operations, audit logs, file uploads or downloads, signed URLs, API responses, cache policy, cache-as-authority decisions, claim or policy data, comparison or affiliate data, user-generated content, webhooks, job queues, search logs, analytics SaaS exports, external API call records, network calls, dependencies, runtime security patch policy, vulnerability scanner advisories, development servers, test UI servers, third-party terms or data-use promises, cryptography, secure transport, agent configuration, or release surfaces affect secrets, personal data, retention, access control, vendor disclosure, or external disclosure.
Apply this skill when security-sensitive code or behavior changes need abuse-case regression tests.
Apply this skill when existing tests are proposed for deletion, consolidation, replacement, layer migration, shadow retirement, or portfolio reprioritization and the change must preserve unique defect-detection evidence, incident regressions, semantic contracts, and a thin end-to-end wiring spine.
Apply this skill when a native process crash, core dump, minidump, segmentation fault, access violation, bus error, heap corruption, stack corruption, illegal instruction, sanitizer crash, native plugin crash, optimized-build-only crash, or CPU/compiler/allocator-specific memory failure must be diagnosed from exact binary identity, symbols, fault instruction, registers, memory maps, object lifetime, corruption evidence, and a reproducible environment rather than blaming the top stack frame.
Apply this skill when a coverage-guided fuzz target, harness, corpus, dictionary, custom mutator, sanitizer matrix, instrumentation or feedback setup, stateful protocol or object-lifetime operation campaign, schedule fuzzing, deterministic N-th failure injection, state-transition coverage, fuzz artifact triage path, or fuzzing effectiveness claim is created, changed, reviewed, debugged, or reported. Do not use it for one small deterministic generated-input regression with no campaign or harness lifecycle; use test-maintenance or security-regression-tests instead.
Apply this skill when code is created, changed, reviewed, reproduced, or reported and shared state can be observed across interleaving execution flows, including logical race versus data-race classification, forbidden-outcome assertions, deterministic schedule gates, record and replay, happens-before evidence, check-then-act, read-modify-write, stale reads after await or I/O, lock scope and order, lock removal, mutex, semaphore, condition, channel, atomic and memory ordering choices, CAS and ABA, concurrent memory reclamation, immediate address reuse, linearizability, database transaction races, distributed locks, queues, shutdown, cancellation, object reuse, optimized native builds, and schedule-sensitive tests.
Apply this skill when charts, graphs, tables, diagrams, flowcharts, timelines, dashboards, infographics, data stories, or text-to-visual summaries are selected, specified, created, reviewed, or reported and the visual form must match the reader decision, semantic relationship, exact-value need, uncertainty, failure path, abstraction level, accessibility, or source evidence instead of merely looking plausible.
Apply this skill when AI-generated, assistant-authored, vibe-coded, or broad code changes need evidence-backed hardening against symptom-only fixes, pinpoint hardcoding, duplicate helpers or shapes, hidden coupling, fake small-sample performance confidence, weak tests, swallowed errors, excessive complexity, and boundary drift.
Apply this skill when authentication, authorization, permissions, roles, RBAC or ABAC policy decisions, tenants, organization or team memberships, sessions, cookies, JWTs, refresh tokens, OAuth or OIDC, passkeys, MFA, account recovery, API keys, route guards, admin access, database policies, object-level access control, atomic mutation authorization, authentication-expiry and denial taxonomy, resource-hiding responses, decision obligations, refresh retry safety, scoped long-running job authority, signed delivery URLs, credentialed event streams, private cache behavior, or account-takeover response paths are created or changed.
Apply this skill when code is created, changed, reviewed, or reported and maintainability needs review by predicting the next-change blast radius, historical co-change spread, deletion path, policy owner, workflow owner, controller or service responsibility, boolean and option-mode sprawl, scattered domain rules, scattered authorization, state-transition ownership, direct time or randomness, transaction and external-call coupling, retry idempotency, cache-as-truth decisions, config flag combinations, tenant or partner hardcoding, legacy branch isolation, DTO/entity/view model mixing, nullable meaning, swallowed exceptions, low-context logs, implementation-coupled tests, mock-heavy tests, decorative abstraction, premature DRY, hidden ordering dependency, event contract visibility, migration/runtime compatibility, or feature removal boundary.
Apply this skill when CLI options, flags, positional arguments, aliases, defaults, parser behavior, raw-to-resolved option types, prompt controls, config or environment precedence, option renames, or automation-facing argument contracts are created, changed, reviewed, or reported.
Apply this skill when code, tests, docs, or reports create, change, review, or claim safety for process-crash, power-loss, forced-termination, disk-full, short-write, flush, atomic-replace, multi-file publication, startup recovery, local journal, resumable upload or download, stale-worker fencing, or fault-injection behavior where persisted state must remain a complete old or complete new generation and incomplete work must resume, roll back, quarantine, or reconcile safely.
Apply this skill when file paths, URI path components, directories, file descriptors or handles, symlinks, hard links, reparse points, junctions, mount points, real paths, path traversal, reserved names, null bytes, NTFS alternate data streams, Windows 8.3 short names, Windows namespace prefixes, atomic file writes, temporary files, file copies, archive extraction, generated outputs, clone or checkout materialization, Windows/POSIX path behavior, TOCTOU safety, line endings, file permissions, durable writes, failure classification, or filesystem cleanup are created, changed, reviewed, or reported.
Apply this skill when one business outcome spans multiple commands, persisted entities, services, callbacks, timers, approvals, retries, or compensations and must resume after process loss or deployment through a versioned durable workflow instance.
Apply this skill when code is created, changed, reviewed, or reported and exception or failure handling can make the system lie about success, state, data, money, permissions, locks, queues, logs, metrics, or user-visible results, including missing precondition inversions, input/state/dependency/resource/race/interruption/output gaps, broad catch blocks, swallowed exceptions, log-and-continue paths, false defaults, finally masking, unsafe retry, missing timeout, cancellation swallowing, live work after timeout, async or batch result loss, queue ack/nack, lost causes, broken error transformation, partial state changes, transaction rollback, lock/resource cleanup, fail-open authorization, unsafe or unlabeled fallback, contradictory success signals, and missing failure-path or mutation evidence.
Apply this skill when planning, implementing, reviewing, or reporting a non-trivial feature whose complete repository surface must be inferred from existing sibling features, historical co-changes, control/data/authorization flows, registries, contracts, persistence, failure paths, tests, docs, observability, rollout, rollback, and removal rather than guessed from filenames; also apply when a feature appears to work but may be a partial implementation missing required roles or evidence.
Apply this skill when code is created, changed, reviewed, or reported and file upload, import, attachment, direct-to-storage upload, remote file fetch, archive extraction, thumbnailing, preview generation, image resizing, document conversion, virus scanning, CDR, file metadata, storage keys, public file URLs, signed upload or download URLs, CDN delivery, file download, uploaded filename display, or upload-related tests need security review across the full file lifecycle.
Apply this skill before implementing in an unfamiliar area where an existing local pattern may already solve the shape of the change.
Apply this skill when business decisions, validation, authorization, pricing, discounts, credits, permissions, eligibility, state transitions, domain events, effect descriptions, or calculations are mixed with I/O such as databases, ORM entities, HTTP handlers, repositories, SDK calls, files, queues, logs, metrics, clocks, randomness, environment reads, payments, emails, or framework objects; also apply when legacy effects must be characterized and extracted safely, a formerly pure module may gain new capabilities, or effect plans, import boundaries, snapshot/version commits, shadow comparison, and purity evidence need explicit contracts.
Apply this skill when planning, writing, restructuring, or reviewing project introductions, feature explanations, technical case studies, engineering retrospectives, build stories, launch posts, portfolio narratives, or product-education copy that must translate maker activity, implementation detail, or debugging experience into a reader's concrete situation, net benefit, credible evidence, limits, and next action.
Apply this skill when creating, restructuring, or substantially rewriting a repository README.md from repository evidence.
Apply this skill when planning, writing, editing, or reviewing search-friendly, ad-supported articles, blog posts, guides, reviews, comparisons, FAQs, or evergreen content.
Apply this skill before creating or duplicating a utility, component, hook, type, schema, service, adapter, route, job, or public symbol when an equivalent or reusable repository asset may exist under different names, paths, layers, exports, registrations, data shapes, failure terms, lifecycle states, side effects, or historical identities; use behavior fingerprints, boundary traces, tests, types, AST shape, references, registries, dependency graphs, and Git archaeology to produce an evidence-backed reuse decision.
Apply this skill when creating or maintaining logically rigorous `.mustflow/skills/*/SKILL.md` procedures and `.mustflow/skills/INDEX.md` routes.
Apply this skill as an adjunct for non-trivial code changes where early structure decisions affect domain rules, public contracts, external I/O, operational safety, testability, error handling, concurrency, data flow, or future change cost.
Apply this skill when designing or strengthening tests, mapping changed decisions and regression obligations, classifying RED evidence, selecting boundary, failure, concurrency, differential, property, or mutation evidence, or reviewing happy-path and coverage-only test claims.
Apply this skill when public or shared types, interfaces, generic constraints, function parameters or returns, unions, DTOs, adapters, runtime schemas, serialization forms, generated declarations or clients, fixtures, examples, or independently built consumers are created, changed, reviewed, or reported.
Apply this skill when a user provides Korean or English prose and asks to extract reusable elegant wording candidates, collect selected phrase fragments into a phrase bank, preserve practical writing-structure or style principles as skill procedure, or polish writing with previously selected modular expressions. Also apply it as a style-polish adjunct for report-style answers, final reports, GitHub issue bodies, pull request descriptions, review replies, maintainer-facing comments, release or update notes, documentation prose, summaries, and explanatory writing when facts are already established and the goal is clearer, more graceful wording.
Apply this skill when an agent needs to read, reference, message, or continue an existing top-level Codex or Hermes session, task, or thread by identifier, including a codex://threads/<uuid> reference, while discovering current host capabilities, keeping subagent identifiers separate, preserving target settings, and falling back to a bounded handoff when direct coordination is unavailable.
Apply this skill when multiple AI workers, subagents, external agent tools, delegated child sessions, worktrees, or parallel task runners are planned or used in one repository task.
Apply this skill when dependency versions, lockfiles, package manager metadata, security advisory fixes, vulnerability scanner alerts, generated dependency outputs, runtime engine constraints, Python runtime support, peer dependency contracts, framework plugins, dev servers, test runners, TypeScript compiler tracks, CI actions, Docker base images, or toolchain versions are upgraded, downgraded, pinned, widened, regenerated, reviewed, or reported.