skill-sets
skill-sets에는 TykoDev에서 수집한 skills 21개가 있으며, 저장소 수준 직업 범위와 사이트 내 skill 상세 페이지를 제공합니다.
이 저장소의 skills
This skill should be used when the user or build-management asks to "write the code", "implement this feature", "build this component", "create the implementation", "code this module", "translate this design to code", "fix these build findings", "address security remediation", "resolve TODO items", "implement these changes", "write production code", or "build from the spec". It is the senior development engineer and primary code producer that translates approved implementation plans into production-ready, clean, well-documented code following established patterns and the project's tech stack conventions.
This skill should be used when the user asks to "build this project", "implement this design", "start the build pipeline", "execute the implementation plan", "run the Build Team SkillSet", "build from this spec", "implement this architecture", "start coding from the design", or provides an approved design specification that requires translation into production code. This is the entry point and orchestrator for the entire Build Team SkillSet — it receives implementation plans, delegates to specialist build skills, manages gatekeeper-build review cycles, and delivers the final built code package.
This skill should be used when the user or build-management asks to "scan for incomplete code", "check for TODOs", "find placeholder code", "verify no scaffold remains", "confirm implementation completeness", "check for fake data", "scan for mockups", "verify no temporary code", "ensure nothing was missed", "final completeness check", "confirm build is production-ready", "check for stubs", "find leftover scaffolding", "verify all features are implemented", "verify the server starts", "test runtime startup", "check if the app runs", or "verify dev servers work". It is the final specialist completeness gate that scans the entire codebase for scaffold code, TODOs, placeholders, mockups, fake data, temporary implementations, and incomplete features — and verifies that backend and frontend dev servers actually start and respond — delegating all findings back to bob-the-builder until the codebase is clean.
This skill should be used when the user or build-management asks to "review this build", "validate the implementation", "gate-check the code", "challenge these build results", "verify code quality", "approve this phase", "validate build correctness", "review before advancing", "quality-gate this output", "challenge the test suite", or "validate the security audit". It is the adversarial review agent that validates build outputs from bob-the-builder, test-builder, security-builder, and cross-check-build-confirm. It produces NO code — it challenges, validates, and either approves or rejects work from other skills. Reports are only forwarded after this skill marks them as validated.
This skill should be used when the user or build-management asks to "audit code security", "check for vulnerabilities", "review security of the build", "scan for security issues", "validate input handling", "check authentication code", "review access control implementation", "audit cryptography usage", "check for injection vulnerabilities", "assess dependency security", "verify OWASP compliance in the code", or "run a security audit". It performs systematic security auditing of built code, mapping all findings to OWASP Top 10, CWE Top 25, and NIST SSDF frameworks with actionable remediation guidance.
This skill should be used when the user or build-management asks to "write tests", "create test suite", "add unit tests", "build integration tests", "create E2E tests", "improve test coverage", "validate test quality", "write regression tests", "ensure test meaningfulness", "test this implementation", or "build the test harness". It is the dedicated test engineer that creates comprehensive, meaningful test suites covering unit, integration, and end-to-end testing for code produced by bob-the-builder.
This skill should be used when the user asks to "find bugs in this code", "review for defects", "check for edge cases", "analyze error handling", "look for concurrency issues", "validate test quality", "check for null handling", "review boundary conditions", "check for race conditions", or "assess error paths". It performs systematic bug detection across code changes using CWE-driven checklists, defect classification, and test-driven review methodology.
This skill should be used when the user asks to "do a full code review", "run the Code-Check SkillSet", "review this codebase comprehensively", "run all review skills", "start the review pipeline", "do a complete audit", "run code-chief", or provides any codebase or changeset that requires multi-dimensional review. This is the entry point and orchestrator for the entire Code-Check SkillSet — it receives the review target, delegates to all specialist review skills, manages gatekeeper-code review cycles, and delivers a consolidated validated review package.
This skill should be used when the user asks to "review this code", "do a code review", "review this pull request", "check this PR", "evaluate code changes", "review for design and complexity", "assess code readiness for merge", "review this diff", or "give feedback on this code". It performs comprehensive code review covering design, functionality, complexity, tests, naming, comments, style, and documentation using Google's 8-dimension framework with risk-tiered PR assessment.
This skill should be used when the user asks to "review the frontend", "audit UI/UX", "check web performance", "test accessibility", "review Core Web Vitals", "check frontend security", "audit CSS/HTML", "review component architecture", "check WCAG compliance", "run frontier", "assess frontend quality", or wants comprehensive frontend-specific code review covering performance, accessibility, security, and UI/UX best practices.
This skill should be used when the user asks to "validate review reports", "challenge findings", "verify review accuracy", "cross-check reports", "gate the review", "quality-check the review output", "run the gatekeeper-code", "verify the bug report", "challenge the security findings", or "ensure review correctness". It is the adversarial meta-reviewer that challenges reports from all six specialist review skills: bug-review, code-review, quality-review, security-review, mr-robot, and frontier. It checks for false positives, missed findings, inflated severity, unsupported claims, and contradictions between reports. Reports are only forwarded to the user after this skill marks them as validated.
This skill should be used when the user asks to "hack this code", "penetration test this codebase", "find exploitable vulnerabilities", "do adversarial security testing", "red team this application", "test attack scenarios", "run mr-robot", "find zero-days", "test for injection attacks", "simulate an attacker", or wants systematic exploitation analysis beyond standard security review. It performs deep-dive adversarial analysis using OWASP Testing Guide, PTES, and MITRE ATT&CK methodologies with proof-of-concept exploit chains.
This skill should be used when the user asks to "review code quality", "check coding standards", "assess maintainability", "check for technical debt", "evaluate efficiency", "review best practices", "check architecture drift", or "evaluate code health". It evaluates maintainability, standards adherence, efficiency, and architectural alignment using Clean Code principles, architecture drift detection, and industry-standard metrics.
This skill should be used when the user asks to "review security", "check for vulnerabilities", "do a security audit", "review for OWASP issues", "check authentication code", "assess supply chain security", "review cryptography usage", "check for injection vulnerabilities", "assess AI security", or "check compliance with NIST SSDF". It performs systematic security analysis using NIST SSDF, OWASP ASVS, CWE Top 25, and threat modeling with risk-tiered review depth.
This skill should be used when the user or commander asks to "design the system architecture", "create C4 diagrams", "write an ADR", "define API contracts", "choose architecture patterns", "create the architecture document", "define system boundaries", "design the data model", "select between monolith and microservices", or "document architecture decisions". It produces a comprehensive architecture document with C4 diagrams, ADRs, API contracts, and pattern recommendations aligned with Arc42 v9.0.
This skill should be used when the user asks to "design a software system", "create a design specification", "architect an application", "plan a new project", "generate a full-stack spec", "create a software design package", "run the Dev Design SkillSet", "start the design pipeline", or provides any initial project description that requires a comprehensive design specification. This is the entry point and orchestrator for the entire Dev Design SkillSet — it receives user input, delegates to specialist skills, owns the gatekeeper-design review cycle in pipeline mode, and delivers the final consolidated design package.
UI/UX Architecture Specialist — Defines a project's complete frontend strategy: rendering pattern, visual design language, design token system, component architecture, styling stack, layout templates, responsive strategy, accessibility, and performance targets. Produces a gatekeeper-validated frontend design specification.
This skill should be used when the user or commander asks to "create the implementation spec", "define the code structure", "design the testing strategy", "configure CI/CD", "set up Docker", "define the .env contract", "plan the observability setup", "configure code quality tools", "design the repository structure", "create the DevOps configuration", or "specify security controls". It produces implementation-ready specifications covering repository structure, testing strategy, CI/CD pipeline, containerization, environment configuration, security controls, and observability setup.
This skill should be used when a design specification, architecture document, project plan, requirements document, implementation spec, or any deliverable from the Dev Design SkillSet pipeline requires adversarial review before handover. Trigger when the user, commander, or a directly invoked specialist asks to "review this deliverable", "validate the architecture", "gate-check the plan", "approve handover", "find errors in this spec", or "quality-gate this output". This skill acts as an adversarial quality gate rewarded for identifying errors, failures, inconsistencies, lies, and omissions.
This skill should be used when the user or commander asks to "create a project plan", "define milestones", "assess risks", "plan the delivery", "create a rollout strategy", "estimate effort", "define feature flags strategy", or "create a risk register". It produces a structured project plan with milestones, risk register, delivery strategy, and progressive rollout plan based on approved requirements.
This skill should be used when the user or commander asks to "gather requirements", "analyze the domain", "create an SRS", "identify stakeholders", "define non-functional requirements", "map bounded contexts", "conduct requirements engineering", or "research the problem space". It performs comprehensive requirements gathering, domain analysis, and produces a structured Software Requirements Specification aligned with ISO/IEC/IEEE 29148.