원클릭으로
skills
skills에는 cropsgg에서 수집한 skills 71개가 있으며, 저장소 수준 직업 범위와 사이트 내 skill 상세 페이지를 제공합니다.
이 저장소의 skills
Code review and cleanup across reuse, quality, and efficiency dimensions. Launches three parallel review agents against the current diff, then aggregates findings and applies fixes.
Red-team the agent's own output against OWASP Top 10 for LLM Applications and Agentic AI. Self-inject, test boundaries, check exfiltration paths. If you can't attack your own output, someone else will.
Mandatory verification of every factual claim before emission. API contracts, dependency versions, file existence, behavior promises — claims about code are hypotheses until verified against the actual source. Based on Dhuliawala et al. (Meta FAIR, ACL 2024).
Disciplined 6-step diagnosis loop with strict evidence gates between stages. Reproduce → minimise → hypothesise → instrument → fix → regression-test. Cannot advance without the required artifact per step.
Split the workflow into Evaluator and Optimizer personas. Evaluator scores output 1–10 on correctness, completeness, safety, and simplicity. Optimizer rewrites to address critiques. Loop until score ≥9 or 3 iterations. Self-improvement without measurement is guessing.
Detect fail-open security patterns: debug mode in production, permissive CORS, disabled CSRF, default admin credentials, verbose error messages, unauthenticated health endpoints. Configuration is code — review it with the same rigor.
Encode Andrej Karpathy's four LLM coding failure modes as enforceable audit gates: (1) Hallucinated APIs, (2) Over-engineered solutions, (3) Missing error handling, (4) Unverified assumptions. Every code block must pass all four gates.
Submit proposed code to an external LLM for bias-breaking review. The external model critiques with fresh eyes, uninfluenced by the session history. Tool-agnostic: uses any available external LLM API.
Flag error-prone APIs and dangerous configurations: eval(), exec(), unsafe string interpolation in SQL/Shell, missing fetch timeouts, process.exit() in library code, prototype pollution. Sharp edges aren't bugs until someone bleeds — flag them first.
Orchestrate CodeQL, Semgrep, or ESLint security rules with decision logic: pick the right tool for the language, run it, parse SARIF output, and triage results by severity and confidence. Static analysis without triage is noise.
Pre-flight and post-flight checklist for every tool invocation. Verify scope, safety, and idempotency before running. Verify output matches expectations, no side effects, and error handling worked after. Tool calls are the agent's primary write surface.
Once a bug is found and understood, systematically grep, Semgrep, or CodeQL the entire codebase to find all other occurrences of the same vulnerability class. Find the class, not just the instance.
Run the full planning pipeline in one command: CEO review → design review → engineering review → locked plan → issue decomposition. Sequential gated pipeline with pass/fail at each stage.
Manage context window as tiered memory: working (active, immediate access), reference (indexed, retrievable), and archival (compressed, summarized). Based on MemGPT/Letta tiered memory architecture.
Build a complete design system from scratch: 11-step color palettes (OKLCH-optimized), typography scale with ratio, spacing system, component tokens, and dark mode strategy. Outputs DESIGN.md and token files.
Generate 3–5 radically different UI variations for the same feature to force divergence before convergence. Each variation has a memorable name, declared trade-offs, and a failure mode.
Audit existing docs against the four Diataxis quadrants, identify empty quadrants, and generate missing documentation from scratch. Each generated doc serves its quadrant's specific user need.
Update all project docs to match shipped code; build a Diataxis coverage map showing which of the four quadrants (tutorials, how-tos, reference, explanation) have coverage and which are empty. Release-triggered documentation audit.
Rate each design dimension 0–10 (typography, spacing, color, motion, interaction, accessibility, responsiveness), define what a 10 looks like, then edit the plan before implementation.
Baseline Core Web Vitals (LCP, CLS, INP, TBT) and bundle sizes before and after every PR. Detect regressions >5% and flag them as blocking for performance-critical paths.
Real browser-based exploration using available browser automation. Navigate JS-rendered pages, extract rendered content, take screenshots, interact with forms. Tool-agnostic: Playwright MCP, Puppeteer, or Chrome DevTools Protocol.
Post-deploy monitoring loop: T+1min console errors and crash rate, T+5min error budget and p99 drift, T+15min final health vs baseline. Escalate to rollback on threshold breach.
Merge PR after CI green, monitor deployment pipeline through to production, verify health via dashboards and error budgets. Extends /ship beyond PR creation into the full land-and-verify loop.
Manage cumulative knowledge across sessions: review recent learnings, search for recurring patterns, prune outdated entries, export insights for upcoming sessions. Multi-session institutional memory.
Scaffold a new SKILL.md following the exact format contract, update all three registry files, and validate evidence and format compliance in one shot.
Analyze a repository's tech stack and generate production-ready CI/CD pipeline configurations (GitHub Actions, GitLab CI, or Azure DevOps). Includes build, test, security scan, dependency audit, and deployment stages. Enforces pipeline-as-code best practices: DRY, matrix testing, artifact management, and secrets governance.
Manage parallel git worktrees for isolated feature development, code review, and hotfix branches. Routes all git operations through a manager protocol that handles .env copying, port isolation, and dependency drift detection. Prevents cross-branch pollution and accidental commits to the wrong branch.
Build a Model Context Protocol (MCP) server from an OpenAPI specification, database schema, or internal API. Generates tool schemas, request handlers, error mapping, and server transport configuration. Enforces type safety, input validation, and least-privilege access patterns.
Build a throwaway prototype to de-risk a design decision before committing to production code. Use for state-machine validation, API ergonomics testing, UI layout exploration, or algorithmic feasibility. The prototype is explicitly disposable — no tests, no types, no polish. Goal is learning speed, not shipping quality.
Declutter code without changing behavior. Targets AI-generated slop: redundant comments, unnecessary defensive checks, over-abstraction, verbose stdlib reimplementations, and speculative generality. Applies changes in priority order and stops before touching public APIs or behavior.
Hard gate that prevents code generation until a design document is approved. Reads the codebase first, interviews the user one question at a time, proposes 2–3 named approaches with trade-offs, and saves a structured design doc to docs/brainstorms/. Use when requirements are vague or multiple valid interpretations exist.
Relentless interrogation session that challenges a plan, design, or requirement until every branch of the decision tree is resolved. Prevents misalignment between human intent and agent output by forcing explicit trade-off declarations, scope boundaries, and failure-mode analysis before any code is written.
Active incident response protocol for production outages. Provides severity classification, communication templates, rollback decision trees, and post-incident report generation. Distinguishes between incident response (during) and postmortem (after). Enforces structured command-and-control to prevent panic-driven fixes.
Ultra-compressed communication mode. Drops filler, hedging, and meta-commentary while preserving full technical accuracy. Reduces token usage ~75% without losing precision. Use when context windows are tight, iterating rapidly, or when you want raw signal over polished prose.
End-of-session retrospective that scans the full conversation for mistakes, friction points, and wins. Cites specific exchanges, proposes ranked improvements, and audits skills used for token efficiency. Captures institutional knowledge before context is lost.
Composite code quality score from linter, types, tests, and optional dead-code checks.
Systematic root-cause debugging with evidence before any fix is applied.
Diagnose and fix: agent/skills setup, toolchain, app smoke, deep debug — apply fixes in-session when evidenced, else hand off to investigate.
Find deepening opportunities and boundary fixes using domain language.
Live visual and UX audit of web UI with evidence-backed findings.