Frontend engineering and design standards — distinctive UI direction, design tokens, component quality, accessibility, responsiveness, and the pre-delivery checklist. Use when building or restyling any UI (web components, pages, dashboards, landing pages).
Mobile engineering standards — React Native/Expo/Flutter/native patterns, list and image performance, offline behavior, platform conventions, secure storage, and the device checklist. Use when building any mobile screen, navigation, or device-facing feature.
NestJS engineering standards — feature-module architecture, DI discipline, DTO validation, the guard/interceptor/pipe/filter split, config, TypeORM/Prisma, and testing. Loaded on top of backend-craft when the ticket's stack is NestJS. Use when building NestJS APIs.
Next.js App Router full-stack standards — server/client boundaries, the four caching layers, server-action security, route handlers, rendering/streaming, metadata, middleware limits, and Next-specific testing. Loaded on top of react-craft (and alongside backend-craft for server code) when the ticket's stack is…
Report-only maintenance sweep — dependency audit, test-suite health, security quick-scan, workboard grooming. Never changes code; produces a findings report and proposed backlog tickets. Use for recurring maintenance ("check the project's health") or schedule it with /loop.
Python backend engineering standards — FastAPI (primary), Django, Flask; async correctness, Pydantic v2, SQLAlchemy 2.0, DI, config, and modern tooling (ruff/mypy/uv). Loaded on top of backend-craft when the ticket's stack is Python. Use when building Python APIs.
Headless QA tooling for driving real test tools from the CLI — Postman/Newman (functional + contract), OWASP ZAP + nuclei (security/DAST, the agent-drivable substitute for Burp), and k6/JMeter/autocannon (load). Use when running a comprehensive QA/security/load sweep against a running app.
Run the QA engineer agent standalone against recent changes or a given scope — functional review, test execution, edge cases — and report findings. Use when the user asks to test/QA something outside the full /ship pipeline.
React-specific engineering standards — impact-prioritized performance rules (waterfalls, bundle, re-renders), hooks discipline, RSC/server data, TypeScript-with-React, forms, and AI-feature patterns. Loaded on top of frontend-craft when the ticket's stack is React (incl. Next.js; React Native shares much of this). Use…
Post-epic retrospective — analyze a finished epic (tickets, findings, debug logs) and distill durable lessons into the project's steering docs, so every next run is smarter and cheaper. Use after an epic closes, or when the user invokes /retro.
Run the security auditor agent standalone — OWASP-style review of recent changes or the whole codebase — and report findings by severity. Use when the user asks for a security check/audit outside the full /ship pipeline.
Full delivery pipeline — takes a feature/project request, plans it into Jira-like markdown tickets, builds each ticket with specialized developer agents, then runs QA, security and code-audit agents, loops a debugger agent over findings until clean, and closes with a final report. Use when the user asks to build a…
Strengthen the automated test suite standalone — codify untested behavior, fill coverage gaps on recent changes, add E2E for a critical flow, or stabilize flaky tests. Use when the user asks to add/improve/fix tests outside the full /ship pipeline.
Vue-specific engineering standards — Vue 3 Composition API + + TS, reactivity correctness, composables, Pinia, router guards, performance and testing. Loaded on top of frontend-craft when the ticket's stack is Vue (incl. Nuxt). Use when building Vue UI.
Web 3D engineering standards — Three.js / React Three Fiber stack selection, render-loop and performance discipline, shader cost awareness, asset pipeline (glTF/Draco/KTX2), memory disposal, and the 3D pre-delivery checklist. Use when building any WebGL/WebGPU, Three.js, R3F, shader or interactive 3D web experience.