Find the smallest useful reading set in an Obsidian-compatible project vault by following indexes, wikilinks, metadata, and task scope. Use before loading project notes for planning, architecture, security, implementation, or handoff. Do not read the whole vault when a focused path can answer the task.
Identify the target and runtime platforms, distribution channels, and platform-specific quality constraints for a project. Use after initial project inspection when architecture, testing, accessibility, performance, store policy, or security checks depend on whether the product is web, mobile, desktop, server, game…
Review pull requests or local diffs for correctness, regressions, missing tests, security, data safety, API compatibility, migration safety, performance risk, accessibility issues, operational hazards, and documentation drift. Use before merge, push, release, or whenever the user asks for code review, risk review…
Keep a repository understandable while an agent creates files, tests, scripts, documentation, fixtures, screenshots, migrations, or generated output. Use during project setup, implementation, review, release, and documentation work. Maintain a clear project map, isolated temporary artifacts, one canonical…
Plan and run verification gates for unit, integration, browser, contract, migration, security, performance, accessibility, smoke, acceptance, and eval scenarios. Use before merge or release, after implementation, when validation evidence is missing, when quality scenarios need proof, or when artifacts…
Prepare and control a software release across services, stores, registries, packages, or staged rollouts. Use when versioning, provenance, release notes, certification, deployment, monitoring, approval, or rollback must be coordinated. Combine only the quality, security, accessibility, localization, compliance, and…
Research domain context, users, jobs-to-be-done, constraints, terminology, workflows, risks, and decision pressure before requirements or architecture. Use when creating a new product, entering an unfamiliar domain, validating product assumptions, preparing 05-domain-research.md, or deciding what the system must…
Select and coordinate the smallest sufficient Agentic Skills route for broad software work. Use when a request spans product definition, architecture, implementation, validation, security, release, or several ownership areas. Do not activate for a familiar one-file change that already has clear acceptance criteria and…
Review a native iOS or Android application against current OWASP MASVS and relevant platform controls. Use before release and after changes to authentication, local storage, networking, WebViews, deep links, permissions, signing, privacy, resilience, or SDKs. Review backend and API surfaces separately with the web…
Review a tool-using or multi-agent system against the current OWASP Agentic Application risks. Use when an LLM can read, write, execute tools, retain memory, act under an identity, or delegate work. Produce risk status, autonomy and permission boundaries, tool inventory, abuse-case evidence, recovery controls, and a…
Review an LLM, RAG, embedding, fine-tuning, or model-routed feature against the current OWASP LLM risks. Use when untrusted content enters prompts or retrieval, model output affects another system, sensitive data is exposed to a provider, or cost and agency can grow. Produce a data-flow threat model, abuse-case…
Review a web application, API, or mobile backend against the current OWASP Top 10. Use before release and after material changes to authentication, authorization, data flow, dependencies, integrations, cryptography, logging, or exception handling. Produce category status, concrete evidence, remediation ownership…
Use for secret management, IAM and RBAC hardening, Vault, KMS, SOPS, Sealed Secrets, CI secrets, workload identity, supply chain security, scanning, SBOM, signing, policy gates, audit, access review, and rotation.
Repair a measured failure in agent routing, instructions, tool contracts, context, memory, or evaluation, then verify the repair and resume the original task. Use after a reproducible failed check, route mismatch, tool misuse, regression, or specific user correction. Do not activate from vague dissatisfaction or use…
Implement a bounded feature, bug fix, module, service, or migration after the expected behavior, write scope, interfaces, and validation commands are known. Use when production code must change. Preserve unrelated work and existing contracts; do not use this skill to plan a broad product or to perform an unscoped…
Define changed behavior with a failing test, verify the failure reason, hand a bounded implementation contract to the code owner, then prove the fix with the affected suite and a boundary or failure case. Use for features, bug fixes, and behavior-preserving refactors where an automated test can provide useful…
Map user journeys, story maps, interaction flows, alternate paths, failure paths, release slices, and scenario-to-task links before decomposition. Use when a product workflow, UX flow, story map, persona path, acceptance scenario, or 09-user-story-map.md and 10-user-journeys.md artifact must be clarified before epics…
Design or review a web, mobile, desktop, game, CLI, voice, or conversational user experience. Use when a feature changes navigation, interaction, content, onboarding, or screen states. Produce information structure, flows, empty/loading/error/success behaviour, content guidance, accessibility requirements, design…
★not rated 10 17d agoA69 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: