programing-best-practices: Skill for Claude Code

.kiro/steering/best-practices/SKILL.md

best-practices is a skill for Claude Code, Kiro from dereknguyen269/programing-best-practices. It costs 0 tokens per session (1,337 once invoked), scanned A, original, Unlicense.

A searchable collection of more than 152 programming best practices across 30 languages and frameworks. It uses a text search to find guidance from established engineering sources.

In plain words
What is it for?
Use it to look up coding standards, style, architecture, security, performance, or clean-code guidance for a chosen language or framework.
Why use it?
It gives code reviews and design decisions a reusable reference instead of relying only on personal preference.

Skill for Claude CodeKiro

Written for Claude Code and Kiro: shipped in a Claude Code plugin, but also installed under .kiro/.

This is dereknguyen269/programing-best-practices's own configuration. It tells Claude Code and Kiro how to work on programing-best-practices itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything programing-best-practices configures →

Part of the best-practices-kb plugin — 2 skills shipped together

Reuse

Borrowing it

Nothing to install: this file belongs to dereknguyen269/programing-best-practices. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/dereknguyen269/programing-best-practices/master/.kiro/steering/best-practices/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/dereknguyen269/programing-best-practices

Made for: Claude Code, Kiro.

Or install best-practices-kb, the plugin that ships this one along with the rest of its 2 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for best-practices

README.md
[![agentmods](https://agentmods.dev/badge/skills/dereknguyen269/programing-best-practices/best-practices.svg)](https://agentmods.dev/skills/dereknguyen269/programing-best-practices/best-practices)
Your own site
<a href="https://agentmods.dev/skills/dereknguyen269/programing-best-practices/best-practices"><img src="https://agentmods.dev/badge/skills/dereknguyen269/programing-best-practices/best-practices.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,337 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.01337
Opus 5 $0.00000 $0.00668
Sonnet 5 $0.00000 $0.00267
Haiku 4.5 $0.00000 $0.00134

Measured 8d ago against content hash bef80b83e771, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

best-practices scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

The scan reads SKILL.md. This mod also ships 3 executable files (scripts/core.py, scripts/generate_csv.py, scripts/search.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.kiro/steering/best-practices/SKILL.md · 156 lines

How it starts

The opening of the file, as written. The whole thing — 156 lines — stays where its author put it; the contents beside it link to each section on GitHub.

best-practices

Searchable knowledge base of 152+ programming best practices across 30+ languages and frameworks. BM25-powered search over curated resources from industry leaders (Google, Airbnb, Uber, Mozilla, Shopify, OWASP).

Prerequisites

Python 3 must be installed:

python3 --version

How to Use This Workflow

When user asks about coding standards, best practices, style guides, code review, architecture, security, or performance for any language/framework, follow this workflow:

Step 1: Analyze User Requirements

Extract from user request:

  • Language/Framework: Python, JavaScript, Go, React, Rails, etc.
  • Topic: style guide, design patterns, performance, security, clean code, etc.
  • Depth: quick reference vs. deep dive

Step 2: Search Best Practices (REQUIRED)

Always start with --recommend to get comprehensive results (resources + deep content):

python3 .kiro/steering/best-practices/scripts/search.py "<language> <topic>" --recommend

Examples:

python3 .kiro/steering/best-practices/scripts/search.py "python style guide" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "javascript clean code" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "react performance" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "sql optimization" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "api security" --recommend

Step 3: Supplement with Domain Searches (as needed)

# Search all resources (default)
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --domain resource

# Search by language/technology overview
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --domain language

# Search by category
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --domain category

# Deep search within crawled content files
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --content

# Deep search filtered by language
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --content --lang python

Read the full file on GitHub · 156 lines

Files

What ships with it

6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 156 lines · 0 tokens per session scan A bef80b83e771

Subscribe to this mod's changes

best-practices is a skill published in the GitHub repository dereknguyen269/programing-best-practices (667 stars, last pushed 7d ago), licensed Unlicense. It costs nothing until one of its globs matches a file; then it loads 1,337 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

retro-learn

Convert delivery findings into skill, eval, workflow, and documentation improvements.

HoangNguyen0403/agent-skills-standard · 18 tokens

system-design-case-catalog

Answer classic system design problems as constraint-to-solution sketches and coach interview practice: URL shortener, rate limiter, news feed, chat, notification, autocomplete, crawler, unique id. Use for interview practice or naming the closest known shape for a new problem.

HoangNguyen0403/agent-skills-standard · 58 tokens

frontmcp-guides

Tutorials, end-to-end walkthroughs, and complete reference projects for FrontMCP. Use when you want a getting-started guide, a full worked example, or to learn best practices by following a step-by-step build rather than a single API reference. Includes a beginner weather-API server (tool plus static resource, Zod…

agentfront/frontmcp · 157 tokens

self-assessment

Interactive skill assessment with personalized learning path generation.

FlorianBruniaux/claude-code-ultimate-guide · 12 tokens

talk-stage5-script

Produces a complete 5-act pitch with speaker notes, a slide-by-slide specification, and a ready-to-paste Kimi prompt for AI slide generation. Requires validated angle and title from Stage 4. Use when you have a confirmed talk angle and need the full script, slide spec, and AI-generated presentation prompt.

FlorianBruniaux/claude-code-ultimate-guide · 69 tokens

talk-stage6-revision

Produces revision sheets with quick navigation by act, a master concept-to-URL table, Q&A cheat-sheet with 6-10 anticipated questions, glossary, and external resources list. Use when preparing for a talk with Q&A, creating shareable reference material for attendees, or building a safety-net glossary for live delivery.

FlorianBruniaux/claude-code-ultimate-guide · 70 tokens