com um clique
av-marketplace
av-marketplace contém 34 skills coletadas de AppVerk, com cobertura ocupacional por repositório e páginas de detalhe dentro do site.
Skills neste repositório
Use when designing, authoring, or reviewing a closed agent loop (test→fix→retest, audit→fix→re-audit, generate→verify→correct) in this marketplace — the minimum-bar checklist, the ground-truth oracle taxonomy, and the anti-patterns, anchored to /qa:loop as the reference implementation.
Test report format with QA-XXX issue IDs compatible with code-review plugin. Defines report structure, severity levels, issue format, and detailed results.
Bun package management, lockfile policy, workspaces, CI integration, and Bun-native tooling
Backend testing patterns — API request construction, response verification, database state checks, error handling testing, and adaptive tool detection.
Frontend testing patterns using Playwright MCP — navigation, interaction, assertions, screenshots on failure, and common UI testing scenarios.
Test plan structure, naming conventions, edge case generation rules, and file saving conventions for QA test plans.
Security scanning templates and HARD-RULES for CI/CD pipeline configuration. Covers Semgrep SAST and TruffleHog secret scanning across Bitbucket, GitHub Actions, GitLab CI, and Azure DevOps.
Enforces Python coding rules: type hints, imports, naming, error handling, and project conventions for AppVerk projects. Activates when writing or reviewing Python code.
Detects installed developer plugins (python-developer, frontend-developer, php-developer) and project stack, then provides a list of relevant skills to load for code review and fix workflows. Supports Python (FastAPI, SQLAlchemy, Pydantic, Django, Celery, asyncio, uv), Frontend (React, Tailwind, Zustand, TanStack, pnpm), and PHP (Symfony, Doctrine, DDD).
Enforces PHP coding rules: strict types, type hints, imports, naming, error handling, and PSR-12 conventions. Activates when writing or reviewing PHP code.
Manages PHP dependencies and environments with Composer: adds packages, syncs lockfiles, configures autoload. Activates when setting up projects, managing dependencies, or working with autoload.
Enforces DDD patterns: Bounded Contexts, 4-layer architecture, Aggregate Roots, Value Objects, Domain Events, repository interfaces. Activates when working with domain models, services, or cross-context communication.
Enforces Doctrine ORM patterns: mapping (YAML/XML/Attributes), repositories, migrations, QueryBuilder, filters, performance. Activates when working with database models, repositories, queries, or migrations.
Enforces Symfony patterns with DDD: thin controllers, Messenger CQRS, autowiring, security, routing attributes. Activates when working with Symfony controllers, services, or configuration.
Enforces test-driven development: writes tests before code, uses fakes over mocks, maintains 80%+ coverage. Activates when writing new features, fixing bugs, or refactoring PHP code.
Enforces Django REST Framework patterns with Pragmatic DDD: ViewSets, Serializers, Permissions, exception handling, settings, middleware. Activates when working with Django views, endpoints, or DRF serializers.
Test-driven development workflow with Vitest, React Testing Library, MSW v2, and Playwright
TypeScript + React coding standards, architecture patterns, naming conventions, ESLint configuration
Enforces FastAPI patterns with DDD and Clean Architecture: endpoint structure, UoW dependency injection, domain exception handling, pure ASGI middleware, testing. Activates when working with FastAPI routers, endpoints, or middleware.
Enforces SQLAlchemy patterns with DDD and Clean Architecture: domain entities, Repository Protocol, Unit of Work, async sessions, Alembic migrations. Activates when working with database models, repositories, queries, or migrations.
Enforces test-driven development: writes tests before code, uses fakes over mocks, maintains 80%+ coverage. Activates when writing new features, fixing bugs, or refactoring Python code.
Checklist for passive compliance and privacy assessment. Covers cookie consent, cookie inventory, privacy policy, data exposure, analytics and tracking, and third-party resources.
Checklist for passive web performance assessment. Covers Core Web Vitals, images, fonts, JavaScript, CSS, caching, compression, and resource hints.
Checklist for passive technical SEO assessment. Covers indexability, metadata quality, structured data, rendering, internal linking, OpenGraph, internationalization, and sitemap analysis.
Checklist for passive API security assessment. Covers endpoint discovery, CORS, rate limiting, authentication, GraphQL, and response security.
Checklist for passive infrastructure security assessment. Covers SSL/TLS, DNS, subdomains, server fingerprinting, CDN/WAF detection, port scanning, and exposed paths.
Checklist for passive supply chain security assessment. Covers JavaScript library identification, known CVEs, SRI, source maps, and exposed dependency files.
Checklist for passive web application security assessment. Covers HTTP security headers, cookies, TLS, secrets exposure, error handling, and common web vulnerabilities.
Analyzes codebase for SOLID principles violations, DDD patterns compliance, Clean Architecture layer dependencies, and common anti-patterns. Works with Python and TypeScript, with language-agnostic pattern detection.
Scans project dependencies for known vulnerabilities (CVEs). Supports Python (uv, pip, poetry), JavaScript, Go, Java, and other languages. Addresses OWASP A03:2025 - Software Supply Chain Failures.
Auto-detects and runs project-specific linters, formatters, and typecheckers. Supports Python (ruff, mypy, black, flake8, pylint) and TypeScript (eslint, tsc, prettier). Uses existing project configuration.
Static Application Security Testing (SAST) for multi-language codebases. Uses Semgrep and language-specific tools to detect vulnerabilities across Python, JavaScript, TypeScript, Go, Java, and more.
Detects and handles sensitive information in code. Use when reviewing code for secret leaks and hard-coded credentials.
Discovers and parses project coding standards, style guides, and architecture documentation. Searches for CONTRIBUTING, CODING_STANDARDS, STYLE_GUIDE, CONVENTIONS, ARCHITECTURE files and extracts rules for code review.