Session-gated ledger tracking for project task graphs. Invoked by commit/plan/spec/handover triggers and other participating skills. Prompts the operator once per session to choose an active ledger (or opt out), then auto-updates that ledger on subsequent…
Use when context is saturated and work must be handed off to a fresh agent. Builds a copy/paste-ready handover prompt with read-first sequence, F-* metrics, hard constraints, do-NOT list, and a specific next action. Updates the project ledger…
WordPress plugin security compliance. Invoke before writing, editing, or reviewing any WordPress plugin or theme code.
Use before locking in a non-trivial approach, plan, or hypothesis — drives assumption-based reasoning to a tested CONFIRMED or REFUTED state by testing locally where possible and with operator help where not. Also a post-implementation reflex — after building…
Use when building, reviewing, or auditing any web application for security compliance. Covers authentication, API security, database safety, infrastructure hardening, and production code hygiene.
Use when reviewing a spec or design doc that belongs to a larger project. Performs a staff-engineer review flagging gaps, inconsistencies, ambiguity, errors, improvements, testability issues, risks, and missing acceptance criteria — ending with a go/no-go…