QA a native Android build end-to-end on the emulator. Use for "test on emulator", "QA Android build", "verify native build", "white screen", "cache rehydration", "Expo dev-client QA", "adb reverse". Pairs Metro/adb walk with Supabase + Sentry MCPs for three-layer CRUD verification.
Polish an existing React Native screen to feel intentional, native, and human-crafted. Use for "this screen looks off", "feels clunky on iOS", "Android version looks wrong", "jank when scrolling", "button is unreachable", or any RN-specific UX polish pass.
Pass/fail health check across every Mushi Mushi pipeline component β CLI credentials, API reachability, edge functions, BYOK key pool, QA cron. Use when "is mushi working", "mushi health check", "check mushi pipeline", "mushi deploy check", "pipeline not responding", or right after setup.
Full end-to-end Mushi Mushi integration smoke test: bug capture β AI triage β story mapping β TDD test generation β approval β execution β PDCA cycle. Use when "test mushi integration", "verify full pipeline", "mushi e2e check", "does mushi work end-to-end", "smoke test mushi", or after deploying changes.
Audit a site for answer-engine / GEO citation readiness (ChatGPT, Perplexity, AI Overviews), then a phased plan. Use when "AEO", "GEO", "show up in ChatGPT/Perplexity", "AI search visibility", "llms.txt", or "am I blocking AI crawlers". Classic SEO meta/sitemap β enhance-web-seo.
Plan-only authenticity / AI-slop audit across prose, UI, code, and IA. Use when "looks like AI slop", "reads like ChatGPT", or "authenticity burndown". One-page UX apply β enhance-web-ux. Visual polish β enhance-web-ui.
Audit App Store and Google Play listings for discoverability and conversion β keywords, localized metadata, screenshots, ratings prompts β then emit a prioritized ASO plan. Use when "optimize our store listing", "improve app downloads", or "ASO". Submission mechanics β plan-mobile-readiness. Plan only.
Audit whether a project can actually recover from data loss β not just whether backups exist β then emit a phased DR plan. Use when "can we recover if the DB dies", "audit our backups", "what's our RPO/RTO", or "disaster recovery". Plan only. Destructive-op gates stay on plan-data-integrity.
Plan-only Capacitor/Ionic native-layer security audit: WebView, token storage, deep links/OAuth, cleartext traffic, exported activities. Use when "is my Capacitor app secure?", "harden my hybrid app", or pre-store hardening. Store readiness β plan-mobile-readiness.
Audit a project for destructive-operation and migration safety gaps, then produce a phased safeguard plan. Use when "is my migration safe", "could I lose data", "my agent might delete prod", or "safe schema changes". Restore drills and RPO/RTO belong to plan-backup-dr. Source transforms β audit-codemod-safety.
Audit dependencies for hallucinated or slopsquatted packages, supply-chain risk, and licensing gaps, then a remediation plan. Use when "check my dependencies", "is this package real", "slopsquatting", "SBOM", or "did the AI hallucinate a package".
Audit documentation against actual code behavior and plan corrections β no rewrites in this pass. Use when asked to "docs drift", "sync docs with code", "audit documentation", "stale README", "onboarding docs broken", "doc sync plan", "phantom docs", or "docs out of date". Why-we-chose-X / ADRs β docs-adr.
Audit silent failures and observability gaps (Sentry/Langfuse), then a phased plan β no implementation. Use when "errors aren't showing in Sentry", "things fail silently", or "empty catch blocks". Apply patterns β backend-error-handling.
Plan-only trust-boundary audit for missing validation, injection, XSS, and forged requests across forms/APIs/webhooks. Use when "validate my inputs", "is my app injection-safe?", "check my forms", or "can someone forge requests?". Apply fixes only after plan approval.
Audit an LLM-powered app for runaway-cost and quota-abuse exposure, then produce a phased guardrail plan. Use when the user says "cap my AI costs", "my LLM bill could blow up", "rate limit my AI", "token budget", "runaway agent loop", or is hardening LLM features before launch.
Plan-only App Store/Google Play submission audit for Capacitor/React Native: manifests, permissions, privacy forms, signing/config, listing prerequisites. Use when "ready for App Store?", "will Google Play reject this?", or "pre-submission check". Native security β plan-capacitor-hardening.
Plan-only performance audit across web/mobile/backend/data; measures first and emits a burndown, no fixes. Use when "performance audit plan", "perf burndown", "measure before optimize", or "N+1 audit plan". Apply runtime fixes β audit-performance. JS bundle-only β audit-bundle-size.
Plan-only audit mapping real personal-data flows to the privacy policy, GDPR, Japan APPI, and store labels. Use when "privacy compliance", "what data do we collect?", "App Store privacy labels", or a consumer launch. Analytics consent instrumentation β audit-analytics.
Audit a Supabase/Postgres project for Row-Level Security and access-control gaps, then produce a phased remediation plan. Use when "RLS", "is my Supabase secure", "anyone can read my data", "lock down my tables". App-layer session/route gates β audit-auth-flows.
Audit the working tree and git history for exposed credentials and mis-scoped keys, then a rotate-vs-relocate plan. Use when "hardcoded secrets", "did I commit a key", "secret scan", "is my .env safe", or "rotate keys". Do not fire for "RLS audit" or generic "security burndown".
Exhaustive audit for stubs, dead buttons, fake components, unwired handlers, and dead links β then a wiring plan, no implementation. Use when "find dead buttons", "stub checker", "fake components", "unwired handlers", or "dead links". Live QA β test-qa.
User-story-driven test coverage audit and plan β no test writing in this pass. Use when "test coverage plan", "coverage audit", "traceability matrix", "fake-green tests", "uncovered user stories", "plan tests for critical flows", or "whats not tested". Mutation score / assertion theater β test-mutation.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page β the rest are on their repository pages: