用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/trycompai/comp --skill data命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Run all audit checks (RBAC, hooks, design system, tests) and verify build
Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it ships. Use after editing any API controller, guard, or auth code (apps/api/src/auth/**), a Prisma schema/query, a file-upload/webhook handler, or before committing/pushing security-sensitive changes.
How to reuse ANY integration check's results in a feature via the universal CheckResultsService (apps/api integration-platform). Use whenever a feature needs data produced by an integration check — "show 2FA status on People", "surface AWS S3 findings in X", "reuse a check's results", "per-user/per-resource results from a connected integration", "which integrations feed task T". Read this BEFORE writing your own IntegrationCheckResult / CheckRunRepository query — don't hand-roll it.
基于 SOC 职业分类
正在显示 SKILL.md
| name | data |
| description | Use when implementing data fetching, API calls, server/client components, or SWR hooks |
Source Cursor rule: .cursor/rules/data.mdc.
Original Cursor alwaysApply: false.
// app/(app)/[orgId]/tasks/page.tsx
export default async function TasksPage({ params }: { params: Promise<{ orgId: string }> }) {
const { orgId } = await params; // From URL, NOT session
const tasks = await getTasks(orgId);
return <TaskListClient organizationId={orgId} initialTasks={tasks} />;
}
// components/TaskListClient.tsx
'use client';
export function TaskListClient({ organizationId, initialTasks }: Props) {
const { tasks, createTask, updateTask } = useTasks({
organizationId,
initialData: initialTasks,
});
// Initial render is instant - no loading state
}
// hooks/useTasks.ts
export function useTasks({ organizationId, initialData }: UseTasksOptions) {
const { data, mutate } = useSWR(
['/v1/tasks', organizationId], // Include orgId for cache isolation
async ([endpoint, orgId]) => {
const response = await apiClient.get(endpoint, orgId);
return response.data?.tasks ?? [];
},
{ fallbackData: initialData }
);
const createTask = async (input: CreateTaskInput) => {
await apiClient.post('/v1/tasks', input, organizationId);
mutate(); // Revalidate
};
const updateTask = async ({ taskId, input }: { taskId: string; input: UpdateTaskInput }) => {
await apiClient.put(`/v1/tasks/${taskId}`, input, organizationId);
mutate(); // Revalidate
};
return { tasks: data ?? [], createTask, updateTask, mutate };
}
Use apiClient from @/lib/api-client:
import { apiClient } from '@/lib/api-client';
await apiClient.get<ResponseType>('/v1/endpoint', organizationId);
await apiClient.post<ResponseType>('/v1/endpoint', body, organizationId);
await apiClient.put<ResponseType>('/v1/endpoint', body, organizationId);
await apiClient.delete('/v1/endpoint', organizationId);
Layouts = server. Interactive logic in separate client components.
// layout.tsx (server)
export default function Layout({ children }) {
return (
<PageLayout>
<PageHeader title="Title" />
<ClientTabs /> {/* Client component */}
{children}
</PageLayout>
);
}
// components/ClientTabs.tsx
'use client';
export function ClientTabs() {
const router = useRouter();
// Interactive logic here
}
No nuqs - use React state or Next.js patterns:
// ✅ React state for UI
const [isOpen, setIsOpen] = useState(false);
// ✅ Next.js for URL state
const router = useRouter();
const searchParams = useSearchParams();
// ❌ No nuqs
import { useQueryState } from 'nuqs';
// ✅ Always
const { orgId } = await params; // From URL params
const { data } = useSWR(key, f, { fallbackData }); // With initial data
await apiClient.get('/v1/endpoint', orgId); // Use apiClient
useSWR(['/v1/tasks', orgId], fetcher); // Include orgId in key
// ❌ Never
const orgId = session?.activeOrganizationId; // From session
const { data } = useSWR('/api/data'); // No initial data
await fetch('/api/endpoint'); // Direct fetch
app/(app)/[orgId]/tasks/
├── page.tsx # Server - fetches data
├── components/
│ └── TaskListClient.tsx # Client - receives initialData
├── hooks/
│ └── useTasks.ts # SWR hook with mutations
└── data/
└── queries.ts # Server-side queries