Use ONLY when the Tech Lead EXPLICITLY asks to run an accessibility (a11y / WCAG / axe) audit locally against a running SDDPro frontend — phrases like "audit a11y local", "lance axe sur le front", "check accessibilité", "run accessibility scan", "vérifie WCAG en local". Runs axe-core CLI against the served front…
★not rated 191▲
+4 3d agoA185 tokens
originalApache-2.0
Interactively co-build a software architecture using Simon Brown's C4 model (Context, Container, Component, Code). The skill detects the usage mode (greenfield design, retro-documenting from code or prose, review/explanation, update), runs a structured framing dialogue, proposes incremental drafts, and iterates until…
★not rated 191▲
+4 3d agoA198 tokens
originalApache-2.0
Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "codeql analysis", "build codeql database", or "find vulnerabilities with codeql". Supports "run all" (security-and-quality + security-experimental suites) and…
★not rated 191▲
+4 3d agoA102 tokens
copy · 89%Apache-2.0
Use when the user reports that an SDDPro pipeline failed, a build errored, tests failed, the API Gate is RED, the spec-compliance gate failed, an auditor returned RED, or any other SDDPro step blocked. Triggers on phrases like "ça plante", "le build échoue", "API gate RED", "/sdd-full failed", "tests failed"…
★not rated 191▲
+4 3d agoA143 tokens
originalApache-2.0
Guidance for distinctive, intentional visual design when building new UI or reshaping an existing one. Helps with aesthetic direction, typography, and making choices that don't read as templated defaults.
★not rated 191▲
+4 3d agoA40 tokens
copy · 100%Apache-2.0
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
★not rated 191▲
+4 3d agoA48 tokens
copy · 89%Apache-2.0
Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplicate alerts", or "process sarif output". Handles filtering, deduplication, format conversion, and CI/CD integration of SARIF data. Does NOT…
★not rated 191▲
+4 3d agoA91 tokens
copy · 94%Apache-2.0
Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset coverage) and "important only" (high-confidence security vulnerabilities). Automatically detects and uses Semgrep Pro for cross-file taint analysis when available. Use when asked to scan code for…
★not rated 191▲
+4 3d agoA95 tokens
copy · 100%Apache-2.0
Use when the user expresses intent to add a new feature, capability, or functionality to the project. Triggers on phrases like "I want to add", "we need a", "new feature", "let's build", "implement X", "ajouter une fonctionnalité", "nouvelle feature". Routes to the SDDPro /feat-generate pipeline instead of letting the…
★not rated 191▲
+4 3d agoA104 tokens
originalApache-2.0
Use when the user expresses intent to reverse engineer a legacy codebase, convert an existing legacy system into SDDPro FEATs, or has uploaded code under workspace/old/. Triggers strictly on phrases like "reverse engineering", "convertir l'ancien système", "migrer le legacy", "j'ai un legacy", "workspace/old". Does…
★not rated 191▲
+4 3d agoA108 tokens
originalApache-2.0
Use whenever the agent is about to write production code (a new function, class, endpoint, method, or component) to enforce the RED-GREEN-REFACTOR cycle (emprunt Superpowers v5.1). NO production code without a failing test first. Triggers on intentions to write code into workspace/src/, .cs/.ts/.py/.kt files, or any…
★not rated 191▲
+4 3d agoA141 tokens
originalApache-2.0
Use IMMEDIATELY at session start, before responding to any user message about software development, feature additions, bug fixes, code reviews, or anything that could be done with SDDPro framework commands. Loads the canonical SDDPro pipeline overview, the 13 user-facing commands, and the agent ownership model so…
★not rated 191▲
+4 3d agoA82 tokens
originalApache-2.0
Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.
★not rated 191▲
+4 3d agoA35 tokens
copy · 98%Apache-2.0
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: