Merge branch 'dev' into feature/universal-scraping-architect

This commit is contained in:
Mehansh Barthwal 2026-05-27 12:03:18 +05:30 • committed by GitHub
commit b453dd1041
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
181 changed files with 8332 additions and 2416 deletions

View file

@ -4,12 +4,12 @@
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
},
"description": "329 production-ready skill packages for Claude AI across 14 domains: engineering advanced (76 — incl. 4 Matt Pocock-derived productivity skills + v2.7.3 security-guidance PreToolUse hook), engineering core (51), marketing (47 — incl. v2.7.3 AEO/Answer Engine Optimization), c-level advisory (66), product (17), regulatory/QMS (18), project management (9), business growth (5), finance (4), productivity (4, v2.7.0), marketing top-level (2, v2.7.0), research (8, v2.7.0), business-operations (7, v2.8.0), and commercial (8, v2.8.0). Includes ~441 Python tools, ~594 reference documents, 48+ agents, 77+ slash commands.",
"description": "338 production-ready skill packages for Claude AI across 16 domains: engineering advanced (76 — incl. 4 Matt Pocock-derived productivity skills + v2.7.3 security-guidance PreToolUse hook), engineering core (51), marketing (47 — incl. v2.7.3 AEO/Answer Engine Optimization), c-level advisory (66), product (17), regulatory/QMS (18), project management (9), business growth (5), finance (4), productivity (4, v2.7.0), marketing top-level (2, v2.7.0), research (8, v2.7.0), business-operations (7, v2.8.0), and commercial (8, v2.8.0). Includes ~441 Python tools, ~594 reference documents, 48+ agents, 77+ slash commands.",
"homepage": "https://github.com/alirezarezvani/claude-skills",
"repository": "https://github.com/alirezarezvani/claude-skills",
"metadata": {
"description": "329 production-ready skill packages across 14 domains (engineering, marketing, product, c-level, project management, RA/QM, business growth, finance, productivity, marketing (top-level), research, business-operations [v2.8.0], commercial [v2.8.0], plus standards). ~444 Python tools, ~598 reference guides, 49+ agents (cs-* + personas), 79+ slash commands. v2.8.0 adds 2 new top-level domains (business-operations + commercial) with 15 new skills, context: fork chaining via Matt Pocock grill-with-docs discipline. v2.7.3 adds AEO + security-guidance PreToolUse hook. Compatible with Claude Code, Codex CLI, Gemini CLI, Cursor, OpenClaw, Hermes Agent, Mistral Vibe, and 5 more coding agents.",
"version": "2.8.0"
"description": "338 production-ready skills across 16 domains (engineering, engineering-core, marketing, product, c-level, compliance-os, project management, RA/QM, business growth, finance, productivity, marketing (top-level), research, research-ops, business-operations, commercial, plus standards). 533 Python tools, 676 reference guides, 51+ agents (cs-* + personas), 87+ slash commands across 62 marketplace plugins. v2.9.0 adds the research-ops domain — enterprise Research Operations (clinical-research + research-finance + market-research + product-research + orchestrator) with per-skill onboarding, customization config, and an opt-in autoresearch bridge. Compatible with Claude Code, Codex CLI, Gemini CLI, Cursor, OpenClaw, Hermes Agent, Mistral Vibe, and 5 more coding agents.",
"version": "2.9.0"
},
"plugins": [
{
@ -879,7 +879,7 @@
"category": "development"
},
{
"name": "handoff",
"name": "handoff-engineering",
"source": "./engineering/handoff",
"description": "Conversation-handoff document generator. Compacts the current session into a markdown handoff for a fresh agent — references existing artifacts (PRDs, plans, ADRs, issues, commits) by path/URL instead of duplicating them. Derived from Matt Pocock's MIT-licensed handoff with: (1) 3 stdlib Python tools (template generator tailored to 5 next-session emphases, artifact deduplicator across 5 categories of duplication, skill recommender matching content to 14 skills in this repo), (2) 4 references citing 7-8 sources (handoff structure, deduplication discipline, next-session skill matching, companion tooling), (3) cs-handoff-author persona agent + /cs:handoff slash command. Matt's no-duplication discipline + mktemp convention preserved verbatim per MIT.",
"version": "2.6.0",
@ -971,7 +971,7 @@
"category": "productivity"
},
{
"name": "handoff",
"name": "handoff-productivity",
"source": "./productivity/handoff",
"description": "Compact the current conversation into a handoff document for another agent to pick up. Configurable save location, redaction enforcement, SessionStart auto-load + SessionEnd reminder, self-check fidelity script, --refresh flag, mtime-guarded cleanup. Inspired by Matt Pocock's handoff (MIT).",
"version": "2.8.2",
@ -1331,6 +1331,51 @@
"automation"
],
"category": "development"
"name": "research-ops-skills",
"source": "./research-ops",
"description": "Enterprise / cross-functional Research Operations domain — the managed counterpart to the academic research/ domain. v2.9.0 ships 5 skills: orchestrator (context: fork) + clinical-research (study design: protocol synopsis + endpoint selection + sample-size/power for means/proportions/survival + phase-gate feasibility) + research-finance (R&D program budgeting with F&A split + burn/runway + capitalize-vs-expense routing + portfolio ROI) + market-research (TAM/SAM/SOM computed both top-down and bottoms-up + survey sampling with FPC and per-segment minima + Kotler segmentation scoring) + product-research (goal-matched study design + method-based saturation with confidence + insight synthesis that flags single-source anecdotes). Hard rules: clinical outputs are estimates with a named clinical owner (never fact), finance outputs surface assumptions and route capex-vs-opex to a named finance owner (never auto-decide), market sizes show method + assumptions (never a single number), product insights require recurrence across independent participants. Each sub-skill ships per-skill onboarding questions (onboard.py), a customization config consumed by every tool, and an isolated opt-in autoresearch evaluator (ar_evaluator.py) bridging to engineering/autoresearch-agent. 24 stdlib Python tools (12 analysis + 12 onboarding/customization/autoresearch), 12 reference docs. Distinct from ra-qm-team (regulatory/QM submission), finance (corporate close/valuation), research/grants (funding discovery), product-team (persona/journey/live experiments), marketing-skill (campaign analytics).",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani"
},
"keywords": [
"research-ops",
"research-operations",
"clinical-research",
"study-design",
"endpoint-selection",
"sample-size",
"power-analysis",
"phase-gate",
"biostatistics",
"research-finance",
"rd-budget",
"burn-rate",
"runway",
"fa-rate",
"capitalize-vs-expense",
"portfolio-roi",
"market-research",
"tam-sam-som",
"market-sizing",
"survey-design",
"sampling",
"segmentation",
"competitive-intelligence",
"product-research",
"ux-research",
"jtbd",
"usability",
"saturation",
"insight-synthesis",
"research-repository",
"onboarding",
"customization",
"autoresearch",
"matt-pocock",
"grill-with-docs"
],
"category": "research-ops"
}
]
}

View file

@ -3,7 +3,7 @@
"name": "claude-code-skills",
"description": "Production-ready skill packages for AI agents - Marketing, Engineering, Product, C-Level, PM, and RA/QM",
"repository": "https://github.com/alirezarezvani/claude-skills",
"total_skills": 323,
"total_skills": 328,
"skills": [
{
"name": "business-growth-skills",
@ -567,7 +567,7 @@
"name": "code-reviewer",
"source": "../../engineering-team/skills/code-reviewer",
"category": "engineering",
"description": "Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, and .NET. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports. Use when reviewing pull requests, analyzing code quality, identifying issues, generating review checklists."
"description": "Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, .NET, and Java. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports. Use when reviewing pull requests, analyzing code quality, identifying issues, generating review checklists."
},
{
"name": "coverage",
@ -683,18 +683,18 @@
"category": "engineering",
"description": ">-"
},
{
"name": "review",
"source": "../../engineering-team/playwright-pro/skills/review",
"category": "engineering",
"description": ">-"
},
{
"name": "review",
"source": "../../engineering-team/self-improving-agent/skills/review",
"category": "engineering",
"description": "Analyze auto-memory for promotion candidates, stale entries, consolidation opportunities, and health metrics."
},
{
"name": "review",
"source": "../../engineering-team/playwright-pro/skills/review",
"category": "engineering",
"description": ">-"
},
{
"name": "security-pen-testing",
"source": "../../engineering-team/skills/security-pen-testing",
@ -1942,6 +1942,36 @@
"source": "../../research/syllabus/skills/syllabus",
"category": "research",
"description": "Generates a curated supplementary reading list from any course syllabus using Consensus academic search. Grill-me intake (syllabus input format + course audience + year range) plus a grouping forcing-options checkpoint before any search runs \u2014 so the reading list matches the course's level and recency need. Parses the syllabus to extract topics and learning outcomes, searches Consensus for recent peer-reviewed papers per topic, and produces a professionally formatted .docx with clickable Consensus links, plain-language summaries calibrated to audience level, and Bloom-higher-order discussion questions tied to course learning goals. Triggers whenever a user uploads a syllabus, course outline, or curriculum document and wants supplementary readings. Also triggers on: 'syllabus reading list', 'find papers for my course', 'create a reading list from this syllabus', 'recent research for my class', 'supplementary readings', 'find journal articles for these topics', 'what recent papers cover this material', 'any new research on these course topics', 'update my syllabus with recent papers'. Even casual mentions when a syllabus is attached should trigger this skill."
},
{
"name": "clinical-research",
"source": "../../research-ops/skills/clinical-research",
"category": "research-ops",
"description": "Use when designing a prospective clinical study before submission \u2014 selecting and classifying endpoints (primary / key-secondary / exploratory, with surrogate-endpoint flagging), estimating sample size and power for two-arm designs (means / proportions / survival), or scoring a study plan for feasibility and a GO / GO-WITH-CONDITIONS / REDESIGN / NO-GO phase-gate decision. Every output is an ESTIMATE plus a named human owner (clinician / biostatistician / regulatory owner) \u2014 never clinical fact, never a finished protocol. Distinct from ra-qm-team, which handles the regulatory/QM submission (ISO 13485, EU MDR, FDA 510(k)/PMA/QSR), not the study design."
},
{
"name": "market-research",
"source": "../../research-ops/skills/market-research",
"category": "research-ops",
"description": "Use when doing upstream market-research methodology \u2014 sizing a market as TAM/SAM/SOM computed BOTH top-down and bottoms-up (never a single unsourced number), planning a survey sample size with finite-population correction and per-segment minimums, or scoring candidate market segments against Kotler's measurable/substantial/accessible/differentiable/actionable criteria. Outputs always show the method and the assumptions. For market-research analysts and product-marketing at the sizing/survey/segmentation moment. Distinct from marketing-skill (campaign analytics, attribution, demand-gen) \u2014 this is the evidence-building methodology, not live-campaign optimization."
},
{
"name": "product-research",
"source": "../../research-ops/skills/product-research",
"category": "research-ops",
"description": "Use when planning and synthesizing product/user research as a method-and-repository discipline \u2014 selecting the right method for the goal (generative interviews vs usability test vs concept test vs validation), computing method-based saturation/sample size with an explicit confidence level, or synthesizing coded observations into insights while flagging single-source anecdotes. Never fabricates user insight; an insight requires recurrence across independent participants. Distinct from product-team/ux-researcher-designer (persona/journey artifacts), product-discovery (discovery-sprint planning), and experiment-designer (live A/B) \u2014 this is the research-ops method + insight-repository layer."
},
{
"name": "research-finance",
"source": "../../research-ops/skills/research-finance",
"category": "research-ops",
"description": "Use when managing the money for an internal R&D program or portfolio \u2014 building a multi-period program budget with the F&A (indirect) split, tracking burn rate and runway against value-inflection milestones, or routing R&D cost items to a capitalize-vs-expense determination. Every budget output surfaces its assumptions block; capitalize-vs-expense is decision-support only and routes to a named finance owner \u2014 it never books an entry or decides accounting treatment. Distinct from finance/financial-analysis (corporate DCF, close, valuation) and research/grants (funding discovery \u2014 this manages money already won)."
},
{
"name": "research-ops-skills",
"source": "../../research-ops/skills/research-ops-skills",
"category": "research-ops",
"description": "Use when planning, funding, scoping, or synthesizing enterprise research across workstreams \u2014 clinical study design, R&D program finance, market sizing/surveys, or product/user research. Triggers on \"design this clinical study\", \"what sample size\", \"R&D budget\", \"burn rate\", \"capitalize or expense\", \"TAM SAM SOM\", \"market sizing\", \"survey design\", \"segment the market\", \"plan user interviews\", \"usability test\", \"synthesize research insights\". Forks context to route to one of four Research-Operations sub-skills (clinical-research, research-finance, market-research, product-research) and returns a digest. Distinct from ra-qm-team (regulatory submission), finance (corporate close/valuation), research/grants (funding discovery), product-team (persona/journey/live experiments), and marketing-skill (campaign analytics)."
}
],
"categories": {
@ -2009,6 +2039,11 @@
"count": 8,
"source": "../../research",
"description": "Research orchestrator + 6 specialists (pulse, litreview, grants, dossier, patent, syllabus, notebooklm)"
},
"research-ops": {
"count": 5,
"source": "../../research-ops",
"description": "Enterprise Research Operations skills (v2.9.0): clinical study design, R&D program finance, market research methodology, product/user research"
}
}
}

View file

@ -0,0 +1 @@
../../research-ops/skills/clinical-research

View file

@ -0,0 +1 @@
../../research-ops/skills/market-research

View file

@ -0,0 +1 @@
../../research-ops/skills/product-research

View file

@ -0,0 +1 @@
../../research-ops/skills/research-finance

View file

@ -0,0 +1 @@
../../research-ops/skills/research-ops-skills

View file

@ -1 +1 @@
../../engineering-team/self-improving-agent/skills/review
../../engineering-team/playwright-pro/skills/review

View file

@ -1,7 +1,7 @@
{
"version": "1.0.0",
"name": "gemini-cli-skills",
"total_skills": 395,
"total_skills": 400,
"skills": [
{
"name": "README",
@ -826,7 +826,7 @@
{
"name": "code-reviewer",
"category": "engineering",
"description": "Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, and .NET. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports. Use when reviewing pull requests, analyzing code quality, identifying issues, generating review checklists."
"description": "Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, .NET, and Java. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports. Use when reviewing pull requests, analyzing code quality, identifying issues, generating review checklists."
},
{
"name": "coverage",
@ -1977,6 +1977,31 @@
"name": "syllabus",
"category": "research",
"description": "Generates a curated supplementary reading list from any course syllabus using Consensus academic search. Grill-me intake (syllabus input format + course audience + year range) plus a grouping forcing-options checkpoint before any search runs \u2014 so the reading list matches the course's level and recency need. Parses the syllabus to extract topics and learning outcomes, searches Consensus for recent peer-reviewed papers per topic, and produces a professionally formatted .docx with clickable Consensus links, plain-language summaries calibrated to audience level, and Bloom-higher-order discussion questions tied to course learning goals. Triggers whenever a user uploads a syllabus, course outline, or curriculum document and wants supplementary readings. Also triggers on: 'syllabus reading list', 'find papers for my course', 'create a reading list from this syllabus', 'recent research for my class', 'supplementary readings', 'find journal articles for these topics', 'what recent papers cover this material', 'any new research on these course topics', 'update my syllabus with recent papers'. Even casual mentions when a syllabus is attached should trigger this skill."
},
{
"name": "clinical-research",
"category": "research-ops",
"description": "Use when designing a prospective clinical study before submission \u2014 selecting and classifying endpoints (primary / key-secondary / exploratory, with surrogate-endpoint flagging), estimating sample size and power for two-arm designs (means / proportions / survival), or scoring a study plan for feasibility and a GO / GO-WITH-CONDITIONS / REDESIGN / NO-GO phase-gate decision. Every output is an ESTIMATE plus a named human owner (clinician / biostatistician / regulatory owner) \u2014 never clinical fact, never a finished protocol. Distinct from ra-qm-team, which handles the regulatory/QM submission (ISO 13485, EU MDR, FDA 510(k)/PMA/QSR), not the study design."
},
{
"name": "market-research",
"category": "research-ops",
"description": "Use when doing upstream market-research methodology \u2014 sizing a market as TAM/SAM/SOM computed BOTH top-down and bottoms-up (never a single unsourced number), planning a survey sample size with finite-population correction and per-segment minimums, or scoring candidate market segments against Kotler's measurable/substantial/accessible/differentiable/actionable criteria. Outputs always show the method and the assumptions. For market-research analysts and product-marketing at the sizing/survey/segmentation moment. Distinct from marketing-skill (campaign analytics, attribution, demand-gen) \u2014 this is the evidence-building methodology, not live-campaign optimization."
},
{
"name": "product-research",
"category": "research-ops",
"description": "Use when planning and synthesizing product/user research as a method-and-repository discipline \u2014 selecting the right method for the goal (generative interviews vs usability test vs concept test vs validation), computing method-based saturation/sample size with an explicit confidence level, or synthesizing coded observations into insights while flagging single-source anecdotes. Never fabricates user insight; an insight requires recurrence across independent participants. Distinct from product-team/ux-researcher-designer (persona/journey artifacts), product-discovery (discovery-sprint planning), and experiment-designer (live A/B) \u2014 this is the research-ops method + insight-repository layer."
},
{
"name": "research-finance",
"category": "research-ops",
"description": "Use when managing the money for an internal R&D program or portfolio \u2014 building a multi-period program budget with the F&A (indirect) split, tracking burn rate and runway against value-inflection milestones, or routing R&D cost items to a capitalize-vs-expense determination. Every budget output surfaces its assumptions block; capitalize-vs-expense is decision-support only and routes to a named finance owner \u2014 it never books an entry or decides accounting treatment. Distinct from finance/financial-analysis (corporate DCF, close, valuation) and research/grants (funding discovery \u2014 this manages money already won)."
},
{
"name": "research-ops-skills",
"category": "research-ops",
"description": "Use when planning, funding, scoping, or synthesizing enterprise research across workstreams \u2014 clinical study design, R&D program finance, market sizing/surveys, or product/user research. Triggers on \"design this clinical study\", \"what sample size\", \"R&D budget\", \"burn rate\", \"capitalize or expense\", \"TAM SAM SOM\", \"market sizing\", \"survey design\", \"segment the market\", \"plan user interviews\", \"usability test\", \"synthesize research insights\". Forks context to route to one of four Research-Operations sub-skills (clinical-research, research-finance, market-research, product-research) and returns a digest. Distinct from ra-qm-team (regulatory submission), finance (corporate close/valuation), research/grants (funding discovery), product-team (persona/journey/live experiments), and marketing-skill (campaign analytics)."
}
],
"categories": {
@ -2043,6 +2068,10 @@
"research": {
"count": 8,
"description": "Research resources"
},
"research-ops": {
"count": 5,
"description": "Research-ops resources"
}
}
}

View file

@ -0,0 +1 @@
../../../research-ops/skills/clinical-research/SKILL.md

View file

@ -0,0 +1 @@
../../../research-ops/skills/market-research/SKILL.md

View file

@ -0,0 +1 @@
../../../research-ops/skills/product-research/SKILL.md

View file

@ -0,0 +1 @@
../../../research-ops/skills/research-finance/SKILL.md

View file

@ -0,0 +1 @@
../../../research-ops/skills/research-ops-skills/SKILL.md

View file

@ -0,0 +1 @@
../../../../research-ops/skills/clinical-research

View file

@ -0,0 +1 @@
../../../../research-ops/skills/market-research

View file

@ -0,0 +1 @@
../../../../research-ops/skills/product-research

View file

@ -0,0 +1 @@
../../../../research-ops/skills/research-finance

View file

@ -0,0 +1 @@
../../../../research-ops/skills/research-ops-skills

File diff suppressed because it is too large Load diff

View file

@ -6,7 +6,7 @@ This file provides guidance to Claude Code (claude.ai/code) when working with co
This is a **comprehensive skills library** for Claude AI and Claude Code - reusable, production-ready skill packages that bundle domain expertise, best practices, analysis tools, and strategic frameworks. The repository provides modular skills that teams can download and use directly in their workflows.
**Current Scope:** 330 production-ready skills across 14 domains with ~451 Python automation tools, ~590 reference guides, 50+ agents (cs-* + 7 personas), and 81+ slash commands. **v2.8.0 (complete)** added 2 new top-level domains — **business-operations/** (7 internal-ops skills: orchestrator + process-mapper + vendor-management + capacity-planner + internal-comms + knowledge-ops + procurement-optimizer) and **commercial/** (8 per-deal-economics skills: orchestrator + pricing-strategist + deal-desk + partnerships-architect + channel-economics + commercial-policy + rfp-responder + commercial-forecaster) — with orchestrator skills using `context: fork` for chaining, Matt Pocock docs-anchored "Forcing-question library" in every SKILL.md, plus `/cs:grill-bizops` and `/cs:grill-commercial`. **v2.8.2** adds a productivity-shaped `handoff` skill (sibling to engineering/handoff) inspired by Matt Pocock — first-run setup with configurable save location, redaction linter, SessionStart + SessionEnd hooks, fidelity self-check, `--refresh` flag. **v2.8.1** upgraded the engineering role-skills (senior-fullstack / senior-frontend / senior-backend) with karpathy-coder + Matt Pocock decision engines + per-role forcing questions. v2.7.3 ports `alirezarezvani/aeo-box` — AEO (Answer Engine Optimization) skill into marketing-skill/ + security-guidance PreToolUse hook into engineering/. v2.7.0 added 13 Path-B skills across 3 top-level domains (productivity, marketing, research). v2.6.0 added 4 Matt Pocock-derived productivity skills.
**Current Scope:** 338 production-ready skills across 16 domains with 533 Python automation tools, 676 reference guides, 51+ agents (cs-* + 7 personas), and 87+ slash commands, distributed as 62 marketplace plugins. **v2.9.0 (complete)** added the **research-ops/** top-level domain — enterprise Research Operations (orchestrator + clinical-research + research-finance + market-research + product-research), the managed counterpart to the academic research/ domain, with `context: fork` orchestration and a Matt Pocock "Forcing-question library" in every SKILL.md plus `/cs:grill-research-ops`. **v2.8.0 (complete)** added 2 new top-level domains — **business-operations/** (7 internal-ops skills: orchestrator + process-mapper + vendor-management + capacity-planner + internal-comms + knowledge-ops + procurement-optimizer) and **commercial/** (8 per-deal-economics skills: orchestrator + pricing-strategist + deal-desk + partnerships-architect + channel-economics + commercial-policy + rfp-responder + commercial-forecaster) — with orchestrator skills using `context: fork` for chaining, Matt Pocock docs-anchored "Forcing-question library" in every SKILL.md, plus `/cs:grill-bizops` and `/cs:grill-commercial`. **v2.8.2** adds a productivity-shaped `handoff` skill (sibling to engineering/handoff) inspired by Matt Pocock — first-run setup with configurable save location, redaction linter, SessionStart + SessionEnd hooks, fidelity self-check, `--refresh` flag. **v2.8.1** upgraded the engineering role-skills (senior-fullstack / senior-frontend / senior-backend) with karpathy-coder + Matt Pocock decision engines + per-role forcing questions. v2.7.3 ports `alirezarezvani/aeo-box` — AEO (Answer Engine Optimization) skill into marketing-skill/ + security-guidance PreToolUse hook into engineering/. v2.7.0 added 13 Path-B skills across 3 top-level domains (productivity, marketing, research). v2.6.0 added 4 Matt Pocock-derived productivity skills.
**Key Distinction**: This is NOT a traditional application. It's a library of skill packages meant to be extracted and deployed by users into their own Claude workflows.
@ -39,6 +39,7 @@ This repository uses **modular documentation**. For domain-specific guidance, se
| **RA/QM Compliance** | [ra-qm-team/CLAUDE.md](ra-qm-team/CLAUDE.md) | ISO 13485, MDR, FDA, GDPR, ISO 27001 compliance |
| **Business & Growth** | [business-growth/CLAUDE.md](business-growth/CLAUDE.md) | Customer success, sales engineering, revenue operations |
| **Finance** | [finance/CLAUDE.md](finance/CLAUDE.md) | Financial analysis, DCF valuation, budgeting, forecasting, SaaS metrics |
| **Research Operations** | [research-ops/CLAUDE.md](research-ops/CLAUDE.md) | Clinical study design, R&D finance, market research, product research (enterprise counterpart to academic research/) |
| **Standards Library** | [standards/CLAUDE.md](standards/CLAUDE.md) | Communication, quality, git, security standards |
| **Templates** | [templates/CLAUDE.md](templates/CLAUDE.md) | Template system usage |
@ -49,17 +50,22 @@ This repository uses **modular documentation**. For domain-specific guidance, se
```
claude-code-skills/
├── .claude-plugin/ # Plugin registry (marketplace.json)
├── agents/ # 27 agents (20 cs-* + 7 personas)
├── commands/ # 33 slash commands (changelog, tdd, saas-health, prd, code-to-prd, plugin-audit, sprint-plan, slo-design, etc.)
├── engineering-team/ # 32 core engineering skills + Playwright Pro + Self-Improving Agent + Security Suite
├── engineering/ # 44 POWERFUL-tier advanced skills (incl. AgentHub, self-eval, llm-wiki, tc-tracker, ship-gate, slo-architect, write-a-skill, caveman, grill-me, handoff)
├── product-team/ # 13 product skills (incl. apple-hig-expert) + Python tools
├── marketing-skill/ # 44 marketing skills (7 pods) + Python tools
├── c-level-advisor/ # 28 C-level advisory skills (10 roles + orchestration)
├── agents/ # 32 standalone agents (cs-* + 7 personas); 51+ cs-* agents repo-wide
├── commands/ # slash commands (changelog, tdd, saas-health, prd, code-to-prd, plugin-audit, sprint-plan, slo-design, etc.); 87+ repo-wide
├── engineering-team/ # 51 core engineering skills + Playwright Pro + Self-Improving Agent + Security Suite
├── engineering/ # 78 POWERFUL-tier advanced skills (incl. AgentHub, autoresearch-agent, self-eval, llm-wiki, tc-tracker, ship-gate, slo-architect, write-a-skill, caveman, grill-me, handoff)
├── product-team/ # 17 product skills (incl. apple-hig-expert) + Python tools
├── marketing-skill/ # 46 marketing skills (8 pods) + Python tools
├── c-level-advisor/ # 66 C-level advisory skills (full C-suite + founder-mode agents + orchestration)
├── project-management/ # 9 PM skills + bundled Atlassian Remote MCP (.mcp.json)
├── ra-qm-team/ # 14 RA/QM compliance skills
├── ra-qm-team/ # 18 RA/QM compliance skills
├── compliance-os/ # 9 compliance-OS skills
├── business-growth/ # 5 business & growth skills + Python tools
├── finance/ # 3 finance skills + Python tools
├── business-operations/ # 7 internal-ops skills (orchestrator + 6 sub-skills)
├── commercial/ # 8 per-deal-economics skills (orchestrator + 7 sub-skills)
├── finance/ # 4 finance skills + Python tools
├── research/ # 8 academic research skills (orchestrator + 7 specialists)
├── research-ops/ # 5 research-ops skills (orchestrator + clinical-research + research-finance + market-research + product-research)
├── eval-workspace/ # Skill evaluation results (Tessl)
├── standards/ # 5 standards library files
├── templates/ # Reusable templates
@ -137,7 +143,18 @@ See [standards/git/git-workflow-standards.md](standards/git/git-workflow-standar
## Current Version
**Version:** v2.8.4 (released — productivity/andreessen v1.0)
**Version:** v2.9.0 (released — research-ops/ domain: enterprise Research Operations)
**v2.9.0 highlights — research-ops/ domain (new top-level domain):**
New `research-ops/` top-level domain — the enterprise / cross-functional counterpart to the academic `research/` domain (which finds literature, grants, patents). Single domain plugin (commercial/ + business-operations/ pattern): orchestrator (`context: fork`) + 4 managed sub-skills.
- **`clinical-research`** — prospective clinical STUDY design (not regulatory submission, which stays in `ra-qm-team`). 3 stdlib tools: `sample_size_estimator.py` (closed-form power/n for means/proportions/survival with a built-in z-table, dropout inflation, "ESTIMATE — confirm with a biostatistician" banner), `endpoint_selector.py` (5-dimension scoring → PRIMARY/KEY-SECONDARY/EXPLORATORY, penalizes unvalidated surrogates), `phase_gate_scorer.py` (feasibility 0-100 → GO/GO-WITH-CONDITIONS/REDESIGN/NO-GO + named owner chain). Canon: ICH E8/E9/E9(R1), CONSORT, SPIRIT, FDA Multiple Endpoints, Cohen, Schoenfeld.
- **`research-finance`** — internal R&D PROGRAM/portfolio finance (not corporate close `finance/`, not grant discovery `research/grants`). 3 tools: `program_budget_planner.py` (multi-period budget + F&A/MTDC split + assumptions block), `burn_runway_tracker.py` (trailing burn, runway, milestone-vs-cash), `capex_vs_opex_router.py` (IAS 38 / ASC 730 routing → CAPITALIZE-CANDIDATE/EXPENSE/FINANCE-OWNER-REVIEW, never auto-decides). Canon: IAS 38, ASC 730/985-20, 2 CFR 200, Cooper stage-gate, rNPV.
- **`market-research`** — upstream sizing/survey/segmentation methodology (not campaign analytics `marketing-skill`). 3 tools: `market_sizer.py` (TAM/SAM/SOM both top-down AND bottoms-up + triangulation flag, never a single number), `sample_size_planner.py` (survey n + FPC + per-segment minima), `segmentation_scorer.py` (Kotler 5-criteria + substantiality/accessibility gate). Canon: Cochran, Dillman, Groves, Kotler, Bessemer/a16z sizing.
- **`product-research`** — product/user research method + insight-repository discipline (not persona/journey/live-A-B `product-team`). 3 tools: `study_designer.py` (goal×stage → method + plan skeleton), `saturation_planner.py` (Nielsen-5 / Guest-12 with explicit confidence), `insight_synthesizer.py` (clusters coded observations, flags single-source anecdotes — never promotes them). Canon: Portigal, JTBD, Rohrer (NN/g), Nielsen, Guest et al., ResearchOps/Polaris.
- **Hard rules:** clinical outputs are estimates + named clinical owner (never fact); finance surfaces assumptions and routes treatment to a named finance owner (never auto-decides); market sizes show method + assumptions (never a single number); product insights require recurrence across independent participants. `cs-research-ops-orchestrator` agent + `/cs:research-ops` router + `/cs:grill-research-ops` (Matt docs-anchored grilling) + 4 per-skill commands.
- **Onboarding + customization + autoresearch (per sub-skill, isolated):** each sub-skill ships `onboard.py` (its own question set), `config_loader.py` (a customization config consumed by every tool, project>global>defaults precedence, `RESEARCH_OPS_NO_CONFIG=1` bypass), and `ar_evaluator.py` — an opt-in, locked-ground-truth bridge to `engineering/autoresearch-agent` (loop edits the skill's input file; metrics: clinical `feasibility_composite`↑, finance `runway_months`↑, market `tam_divergence`↓, product `validated_insights`↑). 24 stdlib tools total (12 analysis + 12 onboarding/customization/autoresearch; all pass `--help`/`--sample`), 12 reference docs (5-7 sources each). Marketplace 61 → 62 plugins; domains 15 → 16.
**v2.8.3** shipped the Mistral Vibe cross-platform sync (`scripts/sync-vibe-skills.py`, `~/.vibe/skills/claude-skills/`) — bringing first-class tool support to 13 coding agents.
@ -416,6 +433,6 @@ This repository publishes skills to **ClawHub** (clawhub.com) as the distributio
---
**Last Updated:** May 24, 2026
**Version:** v2.8.4
**Status:** 330 skills deployed across 14 domains, 61 marketplace plugins, docs site live
**Last Updated:** May 27, 2026
**Version:** v2.9.0
**Status:** 338 skills deployed across 16 domains, 62 marketplace plugins, docs site live

View file

@ -1,19 +1,19 @@
# Claude Code Skills & Plugins — Agent Skills for Every Coding Tool
**313 production-ready Claude Code skills, plugins, and agent skills for 12 AI coding tools.**
**338 production-ready Claude Code skills, plugins, and agent skills for 13 AI coding tools.**
The most comprehensive open-source library of Claude Code skills and agent plugins — also works with OpenAI Codex, Gemini CLI, Cursor, and 7 more coding agents. Reusable expertise packages covering engineering, DevOps, marketing (incl. v2.7.3 AEO — Answer Engine Optimization for LLM citation), security (PreToolUse hooks), compliance, C-level advisory (incl. founder-mode CFO/CMO/CRO/CPO/COO/CHRO/CISO/GC/CDO/CAIO/CCO/VPE personas + 21 /cs:* slash commands), productivity (capture/email/reflect), and a complete research stack (litreview/grants/dossier/patent/syllabus/pulse/notebooklm + hybrid router).
The most comprehensive open-source library of Claude Code skills and agent plugins — also works with OpenAI Codex, Gemini CLI, Cursor, and 9 more coding agents. Reusable expertise packages covering engineering, DevOps, marketing (incl. AEO — Answer Engine Optimization for LLM citation), security (PreToolUse hooks), compliance, C-level advisory (incl. founder-mode CFO/CMO/CRO/CPO/COO/CHRO/CISO/GC/CDO/CAIO/CCO/VPE personas + 21 /cs:* slash commands), productivity (capture/email/reflect), an academic research stack (litreview/grants/dossier/patent/syllabus/pulse/notebooklm + hybrid router), and enterprise Research Operations (clinical-research/research-finance/market-research/product-research, v2.9.0).
**Works with:** Claude Code · OpenAI Codex · Gemini CLI · OpenClaw · Hermes Agent[^hermes] · Mistral Vibe[^vibe] · Cursor · Aider · Windsurf · Kilo Code · OpenCode · Augment · Antigravity
[^hermes]: Hermes Agent is **BYO-sync tier**: the repo ships a pre-generated `.hermes/skills/claude-skills/` tree (305 skills across 12 domains as of v2.7.3), but you run `python scripts/sync-hermes-skills.py` once locally to install into `~/.hermes/skills/`. Uses the same agentskills.io SKILL.md standard — no format conversion.
[^vibe]: Mistral Vibe is also **BYO-sync tier**: the repo ships a pre-generated `.vibe/skills/claude-skills/` tree (306 skills across 14 domains), run `./scripts/vibe-install.sh` once locally to install into `~/.vibe/skills/`. Same agentskills.io SKILL.md standard — no format conversion. Docs: <https://docs.mistral.ai/mistral-vibe/agents-skills>.
[^hermes]: Hermes Agent is **BYO-sync tier**: the repo ships a pre-generated `.hermes/skills/claude-skills/` tree, but you run `python scripts/sync-hermes-skills.py` once locally to install into `~/.hermes/skills/`. Uses the same agentskills.io SKILL.md standard — no format conversion.
[^vibe]: Mistral Vibe is also **BYO-sync tier**: the repo ships a pre-generated `.vibe/skills/claude-skills/` tree, run `./scripts/vibe-install.sh` once locally to install into `~/.vibe/skills/`. Same agentskills.io SKILL.md standard — no format conversion. Docs: <https://docs.mistral.ai/mistral-vibe/agents-skills>.
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow?style=for-the-badge)](https://opensource.org/licenses/MIT)
[![Skills](https://img.shields.io/badge/Skills-330-brightgreen?style=for-the-badge)](#skills-overview)
[![Agents](https://img.shields.io/badge/Agents-49+-blue?style=for-the-badge)](#agents)
[![Skills](https://img.shields.io/badge/Skills-338-brightgreen?style=for-the-badge)](#skills-overview)
[![Agents](https://img.shields.io/badge/Agents-51+-blue?style=for-the-badge)](#agents)
[![Personas](https://img.shields.io/badge/Personas-7-purple?style=for-the-badge)](#personas)
[![Commands](https://img.shields.io/badge/Commands-79+-orange?style=for-the-badge)](#commands)
[![Commands](https://img.shields.io/badge/Commands-87+-orange?style=for-the-badge)](#commands)
[![Stars](https://img.shields.io/github/stars/alirezarezvani/claude-skills?style=for-the-badge)](https://github.com/alirezarezvani/claude-skills/stargazers)
[![SkillCheck Validated](https://img.shields.io/badge/SkillCheck-Validated-4c1?style=for-the-badge)](https://getskillcheck.com)
@ -26,10 +26,10 @@ The most comprehensive open-source library of Claude Code skills and agent plugi
Claude Code skills (also called agent skills or coding agent plugins) are modular instruction packages that give AI coding agents domain expertise they don't have out of the box. Each skill includes:
- **SKILL.md** — structured instructions, workflows, and decision frameworks
- **Python tools** — ~402 CLI scripts (all stdlib-only, zero pip installs)
- **Reference docs** — templates, checklists, and domain-specific knowledge
- **Python tools** — 533 CLI scripts (all stdlib-only, zero pip installs)
- **Reference docs** — 676 templates, checklists, and domain-specific knowledge files
**One repo, twelve platforms.** Works natively as Claude Code plugins, Codex agent skills, Gemini CLI skills, Hermes Agent skills, Mistral Vibe skills, and converts to 7 more tools via `scripts/convert.sh`. All ~402 Python tools run anywhere Python runs.
**One repo, thirteen platforms.** Works natively as Claude Code plugins, Codex agent skills, Gemini CLI skills, Hermes Agent skills, Mistral Vibe skills, and converts to more tools via `scripts/convert.sh`. All 533 Python tools run anywhere Python runs.
### Skills vs Agents vs Personas
@ -108,7 +108,7 @@ git clone https://github.com/alirezarezvani/claude-skills.git
## Multi-Tool Support (New)
**Convert all 156 skills to 7 AI coding tools** with a single script:
**Convert all 338 skills to 9 AI coding tools** with a single script:
| Tool | Format | Install |
|------|--------|---------|
@ -135,11 +135,11 @@ git clone https://github.com/alirezarezvani/claude-skills.git
./scripts/install.sh --tool aider --target . --force
# 3. Verify
find .cursor/rules -name "*.mdc" | wc -l # Should show 156
find .cursor/rules -name "*.mdc" | wc -l # Should show 338
```
**Each tool gets:**
- ✅ All 156 skills converted to native format
- ✅ All 338 skills converted to native format
- ✅ Per-tool README with install/verify/update steps
- ✅ Support for scripts, references, templates where applicable
- ✅ Zero manual conversion work
@ -150,24 +150,26 @@ Run `./scripts/convert.sh --tool all` to generate tool-specific outputs locally.
## Skills Overview
**313 skills across 12 domains:**
**338 skills across 16 domains:**
| Domain | Skills | Highlights | Details |
|--------|--------|------------|---------|
| **🔧 Engineering — Core** | 32 | Architecture, frontend, backend, fullstack, QA, DevOps, SecOps, AI/ML, data, Playwright, self-improving agent, security suite (6), a11y audit | [engineering-team/](engineering-team/) |
| **🎭 Playwright Pro** | 9+3 | Test generation, flaky fix, Cypress/Selenium migration, TestRail, BrowserStack, 55 templates | [engineering-team/playwright-pro](engineering-team/playwright-pro/) |
| **🧠 Self-Improving Agent** | 5+2 | Auto-memory curation, pattern promotion, skill extraction, memory health | [engineering-team/self-improving-agent](engineering-team/self-improving-agent/) |
| **⚡ Engineering — POWERFUL** | 45 | Agent designer, RAG architect, database designer, CI/CD builder, security auditor, MCP builder, AgentHub, Helm charts, Terraform, self-eval, llm-wiki, tc-tracker, **reliability portfolio** (feature-flags-architect, kubernetes-operator, chaos-engineering, slo-architect), ship-gate, **security-guidance** (✨v2.7.3 — PreToolUse hook catching 12 anti-patterns), **Matt Pocock skills** (write-a-skill, caveman, grill-me, handoff, grill-with-docs) | [engineering/](engineering/) |
| **🎯 Product** | 13 | Product manager, agile PO, strategist, UX researcher, UI design, landing pages, SaaS scaffolder, analytics, experiment designer, discovery, roadmap communicator, code-to-prd, apple-hig-expert | [product-team/](product-team/) |
| **📣 Marketing** | 45 | 8 pods: Content (8), SEO + AEO (6 incl. ✨v2.7.3 `aeo` — E-E-A-T audit, citation tracking across 5 LLMs), CRO (6), Channels (6), Growth (4), Intelligence (4), Sales (2) + context foundation + orchestration router. 58 Python tools. | [marketing-skill/](marketing-skill/) |
| **🚀 Productivity** ✨v2.8.4 | 6 | `capture` (brain-dump-to-action), `email` pair (inbox-setup + inbox-triage with 7-file KB contract), `reflect` (light-prompt journal), **`handoff`** (Matt Pocock-inspired: first-run setup, redaction linter, SessionStart + SessionEnd hooks, fidelity self-check, `--refresh`), **`andreessen`** (✨v2.8.4 — market-first decision & productivity mode: market > team > product, PMF-first, 3x5-card + Anti-Todo, fixed anti-sycophancy operating prompt). Path-B from megaprompts 05-08 + Matt Pocock + Andreessen derivation. | [productivity/](productivity/) |
| **🎨 Marketing (top-level)** ✨v2.7.0 | 1 | `landing` — single-file HTML landing-page generator (4 design styles, GSAP patterns, brand palette validator). Path-B from megaprompt 04. | [marketing/](marketing/) |
| **🔬 Research** ✨v2.7.0 | 8 | `research` orchestrator (hybrid router + fallback, megaprompt 13) + 7 specialists: `pulse` (recency), `litreview` (academic), `grants` (NIH), `dossier` (entity), `patent` (prior-art), `syllabus` (course reading), `notebooklm` (browser-automation). | [research/](research/) |
| **🔧 Engineering — Core** | 51 | Architecture, frontend, backend, fullstack, QA, DevOps, SecOps, AI/ML, data, Playwright Pro (test gen, flaky fix, migrations), self-improving agent (auto-memory curation), security suite, a11y audit | [engineering-team/](engineering-team/) |
| **⚡ Engineering — POWERFUL** | 78 | Agent designer, RAG architect, database designer, CI/CD builder, security auditor, MCP builder, AgentHub, Helm charts, Terraform, self-eval, llm-wiki, tc-tracker, autoresearch-agent, **reliability portfolio** (feature-flags-architect, kubernetes-operator, chaos-engineering, slo-architect), ship-gate, security-guidance PreToolUse hook, **Matt Pocock skills** (write-a-skill, caveman, grill-me, handoff, grill-with-docs) | [engineering/](engineering/) |
| **🎯 Product** | 17 | Product manager, agile PO, strategist, UX researcher, UI design, landing pages, SaaS scaffolder, analytics, experiment designer, discovery, roadmap communicator, code-to-prd, apple-hig-expert | [product-team/](product-team/) |
| **📣 Marketing** | 46 | 8 pods: Content, SEO + AEO (`aeo` — E-E-A-T audit, citation tracking across 5 LLMs), CRO, Channels, Growth, Intelligence, Sales + context foundation + orchestration router | [marketing-skill/](marketing-skill/) |
| **🚀 Productivity** | 6 | `capture` (brain-dump-to-action), `email` pair (inbox-setup + inbox-triage), `reflect` (journal), `handoff` (Matt Pocock-inspired), `andreessen` (market-first decision mode) | [productivity/](productivity/) |
| **🎨 Marketing (top-level)** | 1 | `landing` — single-file HTML landing-page generator (4 design styles, GSAP patterns, brand palette validator) | [marketing/](marketing/) |
| **🔬 Research (academic)** | 8 | `research` orchestrator (hybrid router + fallback) + 7 specialists: `pulse`, `litreview`, `grants` (NIH), `dossier`, `patent`, `syllabus`, `notebooklm` | [research/](research/) |
| **🧪 Research Operations** ✨v2.9.0 | 5 | Enterprise/cross-functional research: orchestrator + `clinical-research` (study design), `research-finance` (R&D program finance), `market-research` (sizing/survey/segmentation), `product-research` (user research) — each with onboarding + customization + opt-in autoresearch bridge | [research-ops/](research-ops/) |
| **📋 Project Management** | 9 | Senior PM, scrum master, Jira, Confluence, Atlassian admin, templates + bundled Atlassian Remote MCP | [project-management/](project-management/) |
| **🏥 Regulatory & QM** | 14 | ISO 13485, MDR 2017/745, FDA, ISO 27001, GDPR, SOC 2, CAPA, risk management | [ra-qm-team/](ra-qm-team/) |
| **💼 C-Level Advisory** | 28 | Full C-suite (10 roles) + orchestration + board meetings + culture & collaboration | [c-level-advisor/](c-level-advisor/) |
| **🏥 Regulatory & QM** | 18 | ISO 13485, MDR 2017/745, FDA, ISO 27001, GDPR, SOC 2, CAPA, risk management | [ra-qm-team/](ra-qm-team/) |
| **🛡️ Compliance OS** | 9 | Compliance operating system — controls, evidence, audit-readiness workflows | [compliance-os/](compliance-os/) |
| **💼 C-Level Advisory** | 66 | Full C-suite (CEO/CTO/CFO/CMO/CRO/CPO/COO/CHRO/CISO/GC/CDO/CAIO/CCO/VPE) + founder-mode agents + orchestration + board meetings + culture & collaboration | [c-level-advisor/](c-level-advisor/) |
| **📈 Business & Growth** | 5 | Customer success, sales engineer, revenue ops, contracts & proposals, BizDev toolkit | [business-growth/](business-growth/) |
| **💰 Finance** | 3 | Financial analyst (DCF, budgeting, forecasting), SaaS metrics coach, business investment advisor | [finance/](finance/) |
| **🏭 Business Operations** | 7 | Orchestrator + process-mapper, vendor-management, capacity-planner, internal-comms, knowledge-ops, procurement-optimizer | [business-operations/](business-operations/) |
| **🤝 Commercial** | 8 | Orchestrator + pricing-strategist, deal-desk, partnerships-architect, channel-economics, commercial-policy, rfp-responder, commercial-forecaster | [commercial/](commercial/) |
| **💰 Finance** | 4 | Financial analyst (DCF, budgeting, forecasting), SaaS metrics coach, business investment advisor | [finance/](finance/) |
---
@ -304,7 +306,7 @@ for MDR Annex II compliance gaps.
## Python Analysis Tools
~402 CLI tools ship with the skills (all verified, stdlib-only):
533 CLI tools ship with the skills (all verified, stdlib-only):
```bash
# SaaS health check
@ -351,7 +353,7 @@ Yes. Skills work natively with 13 tools: Claude Code, OpenAI Codex, Gemini CLI,
No. We follow semantic versioning and maintain backward compatibility within patch releases. Existing script arguments, plugin source paths, and SKILL.md structures are never changed in patch versions. See the [CHANGELOG](CHANGELOG.md) for details on each release.
**Are the Python tools dependency-free?**
Yes. All ~402 Python CLI tools use the standard library only — zero pip installs required. Every script is verified to run with `--help`.
Yes. All 533 Python CLI tools use the standard library only — zero pip installs required. Every script is verified to run with `--help`.
**How do I create my own Claude Code skill?**
Each skill is a folder with a `SKILL.md` (frontmatter + instructions), optional `scripts/`, `references/`, and `assets/`. See the [Skills & Agents Factory](https://github.com/alirezarezvani/claude-code-skills-agents-factory) for a step-by-step guide.

View file

@ -1,7 +1,7 @@
{
"name": "business-growth-skills",
"description": "5 business & growth skills: customer success manager, sales engineer, revenue operations, contract & proposal writer, and BizDev-toolkit. Agent skill and plugin for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw.",
"version": "2.2.3",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/business-growth",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
---
name: "business-growth-skills"
description: "4 business growth agent skills and plugins for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw. Customer success (health scoring, churn), sales engineer (RFP), revenue operations (pipeline, GTM), contract & proposal writer. Python tools (stdlib-only)."
version: 1.1.0
version: 2.9.0
author: Alireza Rezvani
license: MIT
tags:

View file

@ -1,7 +1,7 @@
{
"name": "c-level-skills",
"description": "33 C-level advisory skills + c-level-agents plugin layer (13 cs-* persona agents + 21 /cs:* slash commands). Complete virtual board of directors with CEO, CTO, COO, CPO, CMO, CFO, CRO, CISO, CHRO advisors plus General Counsel, Chief Data Officer, Chief AI Officer, Chief Customer Officer, and VP of Engineering (delivery throughput DORA analyzer, eng hiring funnel calculator, eng team structure designer), executive mentor, founder coach, Chief of Staff router, board meetings, decision logger, board deck builder, scenario war room, competitive intel, org health diagnostic, M&A playbook, international expansion, culture architect, change management, strategic alignment, and the founder-mode plugin (office-hours, boardroom, brief/decide/execute/post-mortem pipeline, cross-model consensus, decision freeze).",
"version": "2.5.5",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -376,5 +376,5 @@ This C-Level advisory skills collection provides executive leadership guidance f
---
**Last Updated:** January 2026
**Skills Deployed:** 2/2 C-Level advisory skills production-ready
**Skills Deployed:** 66/66 C-Level advisory skills production-ready
**Total Tools:** 6 Python analysis tools (strategy, finance, tech debt, team scaling)

View file

@ -1,7 +1,7 @@
{
"name": "c-level-agents",
"description": "Founder-mode executive team plugin: 13 cs-* C-suite agents (CFO, CMO, CRO, CPO, COO, CHRO, CISO, Chief of Staff, General Counsel, Chief Data Officer, Chief AI Officer, Chief Customer Officer, VP of Engineering) plus 21 /cs:* slash commands for forcing-question office hours (incl. /cs:vpe-review), multi-role boardroom deliberation, strategic sprint pipeline, and meta routing. Wraps the 33 c-level skills (including vpe-advisor with delivery throughput DORA analyzer + eng hiring funnel calculator + eng team structure designer) with cognitive gearing and artifact handoffs.",
"version": "1.5.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor/c-level-agents",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -83,6 +83,6 @@ Existing `cs-ceo-advisor` and `cs-cto-advisor` live in `/agents/c-level/` and in
---
**Version:** 1.0.0
**Version:** 2.9.0
**Status:** Production Ready
**License:** MIT

View file

@ -1,7 +1,7 @@
{
"name": "chief-ai-officer-advisor",
"description": "Chief AI Officer advisory: model build-vs-buy calculator (API vs fine-tune vs build with 3-year TCO across 6 paths + breakeven balancing economics with practical feasibility), AI risk classifier (EU AI Act tier with 7 Article citations + US state patchwork: NYC LL 144, CO AI Act, IL HB 53, CA SB 1001, IL BIPA + industry overlays for FDA AI/ML, CFPB Circular 2023-03, NYDFS Reg 23, NAIC, ECOA, Fed SR 11-7), AI cost economics (API vs self-hosted breakeven with 2026 pricing across A100/H100, utilization reality, hidden costs). 4 in-depth references each citing 5+ authoritative sources. Stdlib-only. Standalone-installable; also bundled in c-level-skills. Strategic only - does not duplicate engineering AI/ML skills.",
"version": "1.0.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor/chief-ai-officer-advisor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "chief-customer-officer-advisor",
"description": "Chief Customer Officer advisory for startups: retention decomposition analyzer (honest GRR vs NRR + 7-category churn taxonomy), customer segmentation designer (4-tier framework + ICP fit scoring + kill list), CS coverage calculator (pooled vs named CSM models + ratio math + 12-month hiring plan). 4 in-depth references: retention decomposition, customer segmentation strategy, CS coverage model, CS team org evolution (CSM vs Support vs AM vs IM vs CS Ops). Stdlib-only. Standalone-installable; also bundled in c-level-skills. Strategic only - does not duplicate business-growth tactical CS skills.",
"version": "1.0.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor/chief-customer-officer-advisor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "chief-data-officer-advisor",
"description": "Chief Data Officer advisory: AI training data audit (origin x class x use-case matrix with GDPR Art. 6 + EU AI Act citations -> GO/MITIGATE/NO-GO per source), data product strategy picker (warehouse vs lakehouse vs mesh + 6-layer build-vs-buy + 12-month sequencing), data asset valuator (strategic value 0-10 + M&A multiplier with carve-out penalties + 3 ranked productization paths). 4 references answering one decision each: training rights, data product strategy, customer-data-as-asset, data team org evolution. Stdlib-only. Standalone-installable; also bundled in c-level-skills. Strategic only - does not duplicate engineering data skills.",
"version": "1.0.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor/chief-data-officer-advisor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "executive-mentor",
"description": "Adversarial thinking partner for founders and executives. Stress-tests plans, prepares for board meetings, navigates hard decisions, and forces honest post-mortems.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor/executive-mentor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "general-counsel-advisor",
"description": "General Counsel advisory for startups: contract risk scanner (12 founder-killer patterns: auto-renew traps, uncapped indemnity, vague IP, MFN pricing, missing DPA, one-sided venue, broad non-solicit, perpetual license-back, etc.) and term sheet analyzer (0-100 founder-friendliness score across 12 dimensions: liquidation preference, anti-dilution, option pool, board, vesting, drag-along, protective provisions, info rights, dividends, valuation). 3 in-depth references: contracts playbook (7 startup contract types), IP + regulatory landscape (HIPAA, GDPR, FDA, fintech, EU AI Act + SOC 2 to ISO sequencing), term sheet decoder. Stdlib-only. Standalone-installable; also bundled in c-level-skills. NOT a substitute for licensed counsel.",
"version": "1.0.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor/general-counsel-advisor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "vpe-advisor",
"description": "VP of Engineering advisory: delivery throughput analyzer (DORA 4 metrics + cycle-time bottleneck identification), eng hiring funnel calculator (7-stage conversion + pipeline gap + weakest-stage fixes), eng team structure designer (squad/tribe model + manager-trigger + director-trigger + span-of-control). 4 in-depth references: DORA framework, eng hiring funnel, eng team structure (Conway's Law), production discipline (on-call, incidents, deployment, SLOs). Stdlib-only. Standalone-installable; also bundled in c-level-skills. NOT a CTO skill — VPE owns how the team ships, CTO owns what to build.",
"version": "1.0.0",
"description": "VP of Engineering advisory: delivery throughput analyzer (DORA 4 metrics + cycle-time bottleneck identification), eng hiring funnel calculator (7-stage conversion + pipeline gap + weakest-stage fixes), eng team structure designer (squad/tribe model + manager-trigger + director-trigger + span-of-control). 4 in-depth references: DORA framework, eng hiring funnel, eng team structure (Conway's Law), production discipline (on-call, incidents, deployment, SLOs). Stdlib-only. Standalone-installable; also bundled in c-level-skills. NOT a CTO skill \u2014 VPE owns how the team ships, CTO owns what to build.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/c-level-advisor/vpe-advisor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "compliance-os",
"description": "Compliance OS — meta-orchestrator for multi-framework compliance programs. Configure-then-operate four stdlib Python tools: framework_selector.py (input: company profile across industry/geography/AI/medical/financial/headcount; output: applicable frameworks ranked across all 9 supported: ISO 27001, 13485, 42001, 14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR), cross_framework_mapper.py (input: 1+ framework control libraries; output: unified control matrix with overlap percentage + mapping confidence + unified evidence requirements per merged control), audit_simulator.py (input: framework scope; output: mock internal audit with 8-15 finding scenarios across 5 severity levels + interview questions per control), evidence_pool_generator.py (input: enabled framework configs; output: consolidated evidence checklist with reuse map). 4 in-depth references citing ISO 19011, IIA Standards, AICPA AT-C, NIST CSF, COSO ERM. Plus 3 cs-* persona agents (cs-compliance-officer, cs-aims-iso42001, cs-ai-act-compliance) + 3 /cs:* slash commands (/cs:compliance-readiness, /cs:aims-audit, /cs:ai-act-readiness). Reuses the 14 existing ra-qm-team skills and the 2 new compliance-team-* plugins.",
"version": "1.2.0",
"description": "Compliance OS \u2014 meta-orchestrator for multi-framework compliance programs. Configure-then-operate four stdlib Python tools: framework_selector.py (input: company profile across industry/geography/AI/medical/financial/headcount; output: applicable frameworks ranked across all 9 supported: ISO 27001, 13485, 42001, 14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR), cross_framework_mapper.py (input: 1+ framework control libraries; output: unified control matrix with overlap percentage + mapping confidence + unified evidence requirements per merged control), audit_simulator.py (input: framework scope; output: mock internal audit with 8-15 finding scenarios across 5 severity levels + interview questions per control), evidence_pool_generator.py (input: enabled framework configs; output: consolidated evidence checklist with reuse map). 4 in-depth references citing ISO 19011, IIA Standards, AICPA AT-C, NIST CSF, COSO ERM. Plus 3 cs-* persona agents (cs-compliance-officer, cs-aims-iso42001, cs-ai-act-compliance) + 3 /cs:* slash commands (/cs:compliance-readiness, /cs:aims-audit, /cs:ai-act-readiness). Reuses the 14 existing ra-qm-team skills and the 2 new compliance-team-* plugins.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,15 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/compliance-os",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills/compliance-os", "./skills/compliance-readiness", "./skills/aims-audit", "./skills/ai-act-readiness", "./skills/iso27001-audit-prep", "./skills/iso13485-audit-prep", "./skills/gdpr-audit-prep", "./skills/soc2-audit-prep", "./skills/fda-qsr-audit-prep"]
"skills": [
"./skills/compliance-os",
"./skills/compliance-readiness",
"./skills/aims-audit",
"./skills/ai-act-readiness",
"./skills/iso27001-audit-prep",
"./skills/iso13485-audit-prep",
"./skills/gdpr-audit-prep",
"./skills/soc2-audit-prep",
"./skills/fda-qsr-audit-prep"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "a11y-audit",
"description": "WCAG 2.2 accessibility audit and fix skill for React, Next.js, Vue, Angular, Svelte, and HTML. Static scanner detecting 20+ violation types, contrast checker with suggest mode, framework-specific fix patterns, CI-friendly exit codes.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/a11y-audit",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,6 +1,6 @@
{
"name": "google-workspace-cli",
"version": "2.2.2",
"version": "2.9.0",
"description": "Google Workspace administration via the gws CLI. Install, authenticate, and automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks. 5 Python tools, 3 reference guides, 43 built-in recipes, 10 persona bundles.",
"author": {
"name": "Alireza Rezvani",
@ -8,6 +8,8 @@
},
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"],
"skills": [
"./skills"
],
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/google-workspace-cli"
}

View file

@ -1,7 +1,7 @@
{
"name": "pw",
"description": "Production-grade Playwright testing toolkit. Generate tests from specs, fix flaky failures, migrate from Cypress/Selenium, sync with TestRail, run on BrowserStack. 55+ ready-to-use templates, 3 specialized agents, smart reporting that plugs into your existing workflow.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/playwright-pro",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,6 +1,6 @@
{
"name": "si",
"version": "2.3.1",
"version": "2.9.0",
"description": "Self-Improving Agent: curate auto-memory, promote learnings to CLAUDE.md and rules, extract proven patterns into reusable skills. Provides /si:review, /si:promote, /si:extract, /si:status, and /si:remember slash commands.",
"author": {
"name": "Alireza Rezvani",
@ -8,6 +8,8 @@
},
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"],
"skills": [
"./skills"
],
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/self-improving-agent"
}

View file

@ -5,7 +5,7 @@ tier: "STANDARD"
category: "Engineering / Code Quality"
dependencies: "None (prompt-only, no external tools required)"
author: "ekreloff"
version: "1.0.0"
version: "2.9.0"
license: "MIT"
---

View file

@ -1,6 +1,6 @@
# code-reviewer
Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, and .NET. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, and generates review reports.
Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, .NET, and Java. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, and generates review reports.
The full skill spec is [`SKILL.md`](./SKILL.md). This README is a quick reference for the 3 bundled scripts.
@ -55,16 +55,17 @@ Outputs: review verdict (approve / request changes / block), score, prioritized
| File | Purpose |
|------|---------|
| [`assets/sample_csharp_smells.cs`](./assets/sample_csharp_smells.cs) | C# file with every pattern this skill detects, labelled inline |
| [`assets/sample_csharp_clean.cs`](./assets/sample_csharp_clean.cs) | Same code refactored per the standards in `references/` |
| [`expected_outputs/sample_csharp_smells_quality.json`](./expected_outputs/sample_csharp_smells_quality.json) | Expected `code_quality_checker.py --json` output for the smells fixture |
| [`expected_outputs/sample_csharp_clean_quality.json`](./expected_outputs/sample_csharp_clean_quality.json) | Expected output for the clean fixture |
| [`assets/sample_csharp_smells.cs`](./assets/sample_csharp_smells.cs) | C# file with every C#-specific pattern this skill detects, labelled inline |
| [`assets/sample_csharp_clean.cs`](./assets/sample_csharp_clean.cs) | Same code refactored per `rules/universal.md` + `languages/csharp.md` |
| [`assets/sample_java_smells.java`](./assets/sample_java_smells.java) | Java file with every Java-specific pattern this skill detects, labelled inline |
| [`assets/sample_java_clean.java`](./assets/sample_java_clean.java) | Same code refactored per `rules/universal.md` + `languages/java.md` |
| [`expected_outputs/*.json`](./expected_outputs/) | Expected `code_quality_checker.py --json` output for each fixture |
Use them as a regression-detection harness:
```bash
python scripts/code_quality_checker.py assets/sample_csharp_smells.cs --json > /tmp/check.json
diff /tmp/check.json expected_outputs/sample_csharp_smells_quality.json
python scripts/code_quality_checker.py assets/sample_java_smells.java --json > /tmp/check.json
diff /tmp/check.json expected_outputs/sample_java_smells_quality.json
# silence means the detector still behaves as documented
```
@ -74,16 +75,16 @@ diff /tmp/check.json expected_outputs/sample_csharp_smells_quality.json
See [`SKILL.md`](./SKILL.md) for the full pattern list, severity tiers, and references. Quick summary:
- **PR Analyzer** (`scripts/pr_analyzer.py`): hardcoded secrets / connection strings, SQL injection, debug statements, ESLint / Roslyn analyzer suppressions, `any` / `dynamic` overuse, TODO/FIXME, `unsafe` blocks, null-forgiving `!`, `async void`, blocking on `Task`.
- **Code Quality Checker** (`scripts/code_quality_checker.py`): long methods, large files, god classes, deep nesting, too many parameters, high cyclomatic complexity, swallowed exceptions, missing `await`, undisposed `IDisposable`, `new HttpClient()` in method body, unused `using` directives.
- **PR Analyzer** (`scripts/pr_analyzer.py`): hardcoded secrets / connection strings, SQL injection, debug statements (`console.*` / `System.out` / `printStackTrace`), analyzer suppressions (ESLint / Roslyn / `@SuppressWarnings`), `any` / `dynamic` overuse, TODO/FIXME, `unsafe` blocks, null-forgiving `!`, `async void`, blocking on `Task`.
- **Code Quality Checker** (`scripts/code_quality_checker.py`): long methods, large files, god classes, deep nesting, too many parameters, high cyclomatic complexity, swallowed exceptions, missing `await`, undisposed `IDisposable`, `new HttpClient()` in method body, unused `using` directives. Language-specific smell packs for C# and Java (e.g. empty catch, `printStackTrace`, swallowed `InterruptedException`, unclosed resources, per-call `ObjectMapper` / `Gson`).
- **Review Report Generator** (`scripts/review_report_generator.py`): combines the above into a single markdown or JSON verdict.
---
## References
## Review rules
In-depth language guides and antipattern catalog live in [`references/`](./references/):
Rules are split so every review loads exactly two files — the cross-language
baseline plus one language guide (see the dispatch table in [`SKILL.md`](./SKILL.md)):
- [`coding_standards.md`](./references/coding_standards.md) — standards for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C# / .NET (nullable reference types, async/await + `ConfigureAwait`, IDisposable, LINQ, DI lifetimes, records + pattern matching, ASP.NET Core security)
- [`common_antipatterns.md`](./references/common_antipatterns.md) — antipattern catalog with examples + fixes, including a full C# / .NET section (`async void`, blocking on async, swallowing `Exception`, undisposed `IDisposable`, `new HttpClient()` in method, missing `ConfigureAwait`, mutable public setters, `dynamic` overuse, unjustified analyzer suppression)
- [`code_review_checklist.md`](./references/code_review_checklist.md) — systematic review checklist
- [`rules/universal.md`](./rules/universal.md) — cross-language rules: security, async/concurrency, resource management, exception handling, performance
- [`languages/`](./languages/) — one self-contained guide per language (`python`, `typescript`, `go`, `swift`, `kotlin`, `csharp`, `java`), each with Security / Async / Resource Management / Exception Handling / Performance / Idioms sections

View file

@ -1,6 +1,6 @@
---
name: "code-reviewer"
description: Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, and .NET. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports. Use when reviewing pull requests, analyzing code quality, identifying issues, generating review checklists.
description: Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, .NET, and Java. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports. Use when reviewing pull requests, analyzing code quality, identifying issues, generating review checklists.
---
# Code Reviewer
@ -9,16 +9,40 @@ Automated code review tools for analyzing pull requests, detecting code quality
---
## Table of Contents
## How This Skill Is Organized
- [Tools](#tools)
- [PR Analyzer](#pr-analyzer)
- [Code Quality Checker](#code-quality-checker)
- [Review Report Generator](#review-report-generator)
- [Reference Guides](#reference-guides)
- [C# / .NET Review Notes](#c--net-review-notes)
- [Examples](#examples)
- [Languages Supported](#languages-supported)
```
code-reviewer/
SKILL.md ← you are here (tools + dispatch table)
rules/
universal.md ← security, async, resources, exceptions, performance — all languages
languages/
python.md ← Python-specific rules + idioms
typescript.md ← TypeScript / JavaScript-specific rules + idioms
go.md ← Go-specific rules + idioms
swift.md ← Swift-specific rules + idioms
kotlin.md ← Kotlin-specific rules + idioms
csharp.md ← C# / .NET-specific rules + idioms
java.md ← Java-specific rules + idioms
```
### Loading order for every review
1. This file (`SKILL.md`) — tools and thresholds
2. `rules/universal.md` — always, for every language
3. The matching `languages/*.md` — one file based on the extension table below
That's always exactly **2 additional files**, regardless of scope.
| Extension(s) | Load |
|---|---|
| `.py` | `languages/python.md` |
| `.ts`, `.tsx`, `.js`, `.jsx`, `.mjs` | `languages/typescript.md` |
| `.go` | `languages/go.md` |
| `.swift` | `languages/swift.md` |
| `.kt`, `.kts` | `languages/kotlin.md` |
| `.cs`, `.csx`, `.razor`, `.cshtml` | `languages/csharp.md` |
| `.java` | `languages/java.md` |
---
@ -39,15 +63,12 @@ python scripts/pr_analyzer.py . --base main --head feature-branch
python scripts/pr_analyzer.py /path/to/repo --json
```
**What it detects:**
**What it detects (universal — see also language file for language-specific signals):**
- Hardcoded secrets (passwords, API keys, tokens, connection strings)
- SQL injection patterns (string concatenation in queries)
- Debug statements (debugger, console.log, Debug.WriteLine)
- ESLint / Roslyn analyzer rule disabling (`#pragma warning disable`, `[SuppressMessage]`)
- TypeScript `any` types / C# `dynamic` overuse
- SQL / query injection patterns
- Debug statements left in production code
- Lint / analyzer suppression annotations
- TODO/FIXME comments
- Unsafe code blocks (`unsafe { }` in C#)
- Nullable reference type suppressions (`!` null-forgiving operator overuse)
**Output includes:**
- Complexity score (1-10)
@ -65,26 +86,14 @@ Analyzes source code for structural issues, code smells, and SOLID violations.
# Analyze a directory
python scripts/code_quality_checker.py /path/to/code
# Analyze specific language (valid values: python, typescript, javascript, go, swift, kotlin, csharp)
python scripts/code_quality_checker.py . --language python
# Analyze specific language (valid values: python, typescript, javascript, go, swift, kotlin, csharp, java)
python scripts/code_quality_checker.py . --language java
# JSON output
python scripts/code_quality_checker.py /path/to/code --json
```
**What it detects:**
- Long functions/methods (>50 lines)
- Large files (>500 lines)
- God classes (>20 methods)
- Deep nesting (>4 levels)
- Too many parameters (>5)
- High cyclomatic complexity
- Missing error handling (bare `catch` / `catch (Exception)` swallowing)
- Unused imports / unnecessary `using` directives
- Magic numbers
- C#-specific: missing `async`/`await` on async paths, `Task` not awaited, `IDisposable` not disposed
**Thresholds:**
**Universal thresholds:**
| Issue | Threshold |
|-------|-----------|
@ -95,6 +104,8 @@ python scripts/code_quality_checker.py /path/to/code --json
| Deep nesting | >4 levels |
| High complexity | >10 branches |
Language-specific checks are defined in each `languages/*.md` file.
---
### Review Report Generator
@ -114,13 +125,6 @@ python scripts/review_report_generator.py . \
--quality-analysis quality_results.json
```
**Report includes:**
- Review verdict (approve, request changes, block)
- Score (0-100)
- Prioritized action items
- Issue summary by severity
- Suggested review order
**Verdicts:**
| Score | Verdict |
@ -132,112 +136,33 @@ python scripts/review_report_generator.py . \
---
## Reference Guides
## Adding a New Language
### Code Review Checklist
`references/code_review_checklist.md`
**Reviewer guidance (required):**
Systematic checklists covering:
- Pre-review checks (build, tests, PR hygiene)
- Correctness (logic, data handling, error handling)
- Security (input validation, injection prevention)
- Performance (efficiency, caching, scalability)
- Maintainability (code quality, naming, structure)
- Testing (coverage, quality, mocking)
- Language-specific checks (including C# / .NET)
1. Create `languages/<name>.md` using any existing language file as a template — it must have sections: PR Analyzer Signals, Code Quality Checks, Security, Async, Resource Management, Exception Handling, Performance, Idioms.
2. Add the extension row to the dispatch table above.
### Coding Standards
`references/coding_standards.md`
That is all the agent-driven review needs.
Language-specific standards for:
- TypeScript (type annotations, null safety, async/await)
- JavaScript (declarations, patterns, modules)
- Python (type hints, exceptions, class design)
- Go (error handling, structs, concurrency)
- Swift (optionals, protocols, errors)
- Kotlin (null safety, data classes, coroutines)
- **C# / .NET** (nullable reference types, async/await, LINQ, dependency injection, exception handling, record types, pattern matching)
**Deterministic analyzer support (optional, recommended):** the bundled scripts
only flag a language they explicitly know. To make `code_quality_checker.py`
score the new language:
### Common Antipatterns
`references/common_antipatterns.md`
Antipattern catalog with examples and fixes:
- Structural (god class, long method, deep nesting)
- Logic (boolean blindness, stringly typed code)
- Security (SQL injection, hardcoded credentials, unvalidated input in ASP.NET)
- Performance (N+1 queries, unbounded collections, `async void`, blocking on async code with `.Result` / `.Wait()`)
- Testing (duplication, testing implementation)
- Async (floating promises, callback hell, `async void` in C#, deadlocks from `.GetAwaiter().GetResult()`)
- **C# / .NET-specific**: catching and swallowing `Exception`, missing `ConfigureAwait`, overuse of `dynamic`, not disposing `IDisposable` resources, mutable public setters on domain models
3. Add the extensions to `LANGUAGE_EXTENSIONS` in `scripts/code_quality_checker.py` (this also adds the `--language` choice).
4. Add `function` / `class` / `method` regex entries for the language in the same file; otherwise it falls back to the Python patterns.
5. Optionally add a `check_<name>_specific_smells(...)` detector (see the C# and Java ones) and call it from `analyze_file`.
6. Add `assets/sample_<name>_smells.<ext>` + `_clean` fixtures and commit the expected `--json` output under `expected_outputs/` as a regression guard.
---
## C# / .NET Review Notes
## Regression Fixtures
When reviewing C# or .NET code, pay special attention to:
### Async / Await
- Flag `async void` methods (except event handlers) — they can't be awaited and swallow exceptions
- Flag `.Result`, `.Wait()`, or `.GetAwaiter().GetResult()` on `Task` — causes deadlocks in ASP.NET contexts
- Flag missing `ConfigureAwait(false)` in library code
### Nullable Reference Types
- Flag excessive use of the null-forgiving operator (`!`) without justification
- Ensure nullable annotations are enabled at the project level (`<Nullable>enable</Nullable>`)
- Flag unchecked dereferences of potentially null values
### Resource Management
- Flag `IDisposable` objects not wrapped in `using` / `using var`
- Flag `HttpClient` instantiated with `new` inside methods (should be injected or use `IHttpClientFactory`)
- Flag `DbContext` not scoped correctly in DI
### Exception Handling
- Flag bare `catch { }` or `catch (Exception) { }` that swallows exceptions silently
- Flag catching `Exception` when a more specific type is appropriate
- Flag exceptions used for control flow
### LINQ
- Flag `.ToList()` / `.ToArray()` called prematurely on queryables, forcing unnecessary DB round-trips
- Flag `First()` where `FirstOrDefault()` is safer
- Flag complex LINQ chains that would be clearer as explicit loops
### Security (ASP.NET)
- Flag raw string interpolation in SQL queries — require parameterized queries or EF Core
- Flag missing `[ValidateAntiForgeryToken]` on state-changing controller actions
- Flag user-controlled data passed to `Process.Start()` or `File` APIs without validation
- Flag hardcoded connection strings in source (should use `appsettings.json` + secrets management)
---
## Examples
Sample fixtures live in `assets/` with their expected analyzer output in `expected_outputs/`:
| Fixture | What it demonstrates | Expected verdict |
|---------|---------------------|------------------|
| `assets/sample_csharp_smells.cs` | Every C#-specific pattern this skill detects (`async void`, blocking on `Task`, swallowed `Exception`, undisposed `IDisposable`, `new HttpClient()`, missing `await`, null-forgiving `!`, hardcoded connection string, `unsafe`, `dynamic`, `#pragma warning disable`, `[SuppressMessage]`, SQL concatenation) | F / 45 / 100, 3 HIGH smells |
| `assets/sample_csharp_clean.cs` | Same code refactored per `references/coding_standards.md` and `references/common_antipatterns.md` | A / 98 / 100, 0 HIGH smells |
Reproduce the expected output:
Labelled fixtures live in `assets/` with their committed `--json` output in
`expected_outputs/` (C# and Java). Drift from the committed JSON signals a
behaviour change in the analyzer:
```bash
python scripts/code_quality_checker.py assets/sample_csharp_smells.cs --json \
> /tmp/check.json
diff /tmp/check.json expected_outputs/sample_csharp_smells_quality.json
python scripts/code_quality_checker.py assets/sample_java_smells.java --json \
| diff - expected_outputs/sample_java_smells_quality.json
```
The expected-output JSON is regenerated after any analyzer change; drift from the committed fixture signals a behaviour change in the detector.
---
## Languages Supported
| Language | Extensions |
|----------|------------|
| Python | `.py` |
| TypeScript | `.ts`, `.tsx` |
| JavaScript | `.js`, `.jsx`, `.mjs` |
| Go | `.go` |
| Swift | `.swift` |
| Kotlin | `.kt`, `.kts` |
| **C# / .NET** | **`.cs`, `.csx`, `.razor`, `.cshtml`** |

View file

@ -1,6 +1,6 @@
// Sample C# file showing the fixed version of sample_csharp_smells.cs.
// Same shape, but every smell has been resolved per the patterns documented
// in references/coding_standards.md and references/common_antipatterns.md.
// in rules/universal.md and languages/csharp.md.
//
// Run:
// python scripts/code_quality_checker.py assets/sample_csharp_clean.cs

View file

@ -0,0 +1,55 @@
// Sample Java file showing the fixed version of sample_java_smells.java.
// Same shape, but every smell has been resolved per the patterns documented
// in rules/universal.md and languages/java.md.
//
// Run:
// python scripts/code_quality_checker.py assets/sample_java_clean.java
//
// Expected: no HIGH Java-specific smells flagged.
package sample;
import java.io.FileInputStream;
import java.io.InputStream;
import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import com.fasterxml.jackson.databind.ObjectMapper;
public class UserService {
// FIX: heavy object shared as a singleton instead of constructed per call.
private static final ObjectMapper MAPPER = new ObjectMapper();
// FIX: connection string injected from configuration, never inlined.
private final String connectionString;
public UserService(String connectionString) {
this.connectionString = connectionString;
}
public String getName(Connection conn, int id) {
// FIX: try-with-resources guarantees the stream and statement close.
try (InputStream config = new FileInputStream("/etc/config");
// FIX: parameterized query, no string concatenation.
PreparedStatement stmt =
conn.prepareStatement("SELECT name FROM users WHERE id = ?")) {
stmt.setInt(1, id);
try (ResultSet rs = stmt.executeQuery()) {
return rs.next() ? rs.getString("name") : null;
}
} catch (Exception e) {
// FIX: rethrow with context instead of swallowing.
throw new IllegalStateException("Failed to load user " + id, e);
}
}
public void process() {
try {
Thread.sleep(1000);
} catch (InterruptedException e) {
// FIX: restore the interrupt flag so cancellation still propagates.
Thread.currentThread().interrupt();
}
}
}

View file

@ -0,0 +1,56 @@
// Sample Java file demonstrating the Java-specific patterns the code-reviewer
// skill detects. Each smell is labelled inline. This file is NOT meant to
// compile cleanly — it is a fixture for code_quality_checker.py and
// pr_analyzer.py.
//
// Run:
// python scripts/code_quality_checker.py assets/sample_java_smells.java
//
// Expected output: see expected_outputs/sample_java_smells_quality.json
package sample;
import java.io.FileInputStream;
import java.sql.Connection;
import java.sql.Statement;
import com.fasterxml.jackson.databind.ObjectMapper;
public class UserService {
// [hardcoded_secrets] hardcoded JDBC URL with password
public String connectionString = "jdbc:postgresql://prod/app?user=app&password=hunter2";
// [analyzer_disable] @SuppressWarnings without justification
@SuppressWarnings("unchecked")
public String getName(Connection conn, int id) throws Exception {
// [java_unclosed_resource] FileInputStream not in try-with-resources
FileInputStream fis = new FileInputStream("/etc/config");
// [java_per_use_heavy_object] new ObjectMapper() constructed per call
ObjectMapper mapper = new ObjectMapper();
try {
Statement stmt = conn.createStatement();
// [sql_concatenation] string concatenation builds SQL with user input
return stmt.executeQuery("SELECT name FROM users WHERE id = " + id).toString();
} catch (Exception e) {
// [java_empty_catch] empty catch swallows the exception
}
return null;
}
public void process() {
try {
Thread.sleep(1000);
} catch (InterruptedException e) {
// [java_swallowed_interrupt] interrupt flag not restored
// [console_log] printStackTrace used as error handling
e.printStackTrace();
}
}
public void log(String message) {
// [console_log] System.out.println left in production code
System.out.println(message);
}
}

View file

@ -0,0 +1,53 @@
{
"file": "/home/user/claude-skills/engineering-team/skills/code-reviewer/assets/sample_java_clean.java",
"language": "java",
"metrics": {
"lines": {
"total": 56,
"code": 33,
"blank": 9,
"comment": 14
},
"functions": 3,
"classes": 1,
"avg_complexity": 2.0
},
"quality_score": 100,
"grade": "A",
"smells": [
{
"type": "magic_number",
"severity": "low",
"message": "Magic number 1000 should be a named constant",
"location": "line 49"
}
],
"solid_violations": [],
"function_details": [
{
"name": "UserService",
"parameters": 1,
"lines": 5,
"complexity": 1
},
{
"name": "getName",
"parameters": 2,
"lines": 17,
"complexity": 3
},
{
"name": "process",
"parameters": 0,
"lines": 10,
"complexity": 2
}
],
"class_details": [
{
"name": "UserService",
"methods": 3,
"lines": 38
}
]
}

View file

@ -0,0 +1,83 @@
{
"file": "/home/user/claude-skills/engineering-team/skills/code-reviewer/assets/sample_java_smells.java",
"language": "java",
"metrics": {
"lines": {
"total": 57,
"code": 29,
"blank": 10,
"comment": 18
},
"functions": 3,
"classes": 1,
"avg_complexity": 2.0
},
"quality_score": 68,
"grade": "D",
"smells": [
{
"type": "magic_number",
"severity": "low",
"message": "Magic number 1000 should be a named constant",
"location": "line 44"
},
{
"type": "java_empty_catch",
"severity": "high",
"message": "Empty catch block swallows exceptions silently",
"location": "offset 684"
},
{
"type": "java_print_stack_trace",
"severity": "medium",
"message": "'printStackTrace()' is not real error handling \u2014 log via a proper logger or rethrow with context",
"location": "offset 913"
},
{
"type": "java_swallowed_interrupt",
"severity": "high",
"message": "InterruptedException caught without 'Thread.currentThread().interrupt()' \u2014 breaks cooperative cancellation",
"location": "offset 841"
},
{
"type": "java_unclosed_resource",
"severity": "medium",
"message": "'FileInputStream' looks like an AutoCloseable but is not in a try-with-resources statement",
"location": "offset 366"
},
{
"type": "java_per_use_heavy_object",
"severity": "medium",
"message": "'new ObjectMapper()' is expensive \u2014 share a singleton instance instead of constructing per call",
"location": "offset 451"
}
],
"solid_violations": [],
"function_details": [
{
"name": "getName",
"parameters": 2,
"lines": 18,
"complexity": 3
},
{
"name": "process",
"parameters": 0,
"lines": 11,
"complexity": 2
},
{
"name": "log",
"parameters": 1,
"lines": 6,
"complexity": 1
}
],
"class_details": [
{
"name": "UserService",
"methods": 3,
"lines": 40
}
]
}

View file

@ -0,0 +1,97 @@
---
language: csharp
extensions: [".cs", ".csx", ".razor", ".cshtml"]
---
# C# / .NET — Language-Specific Review Notes
Load this file alongside `rules/universal.md`. Universal rules are not repeated here — only C#-specific rules and idioms.
---
## PR Analyzer — C# Risk Signals
- `#pragma warning disable` and `[SuppressMessage]` — verify they are justified
- `unsafe { }` blocks — require explicit sign-off
- Null-forgiving operator (`!`) used broadly without justification
- `dynamic` used outside of interop scenarios
- Hardcoded connection strings in source files
---
## Code Quality — C# Checks
- `async void` methods (except event handlers)
- `Task` returned but not awaited
- `IDisposable` objects not in `using` / `using var`
- Bare `catch { }` or `catch (Exception e) { }` swallowing silently
- Nullable reference types feature disabled at project level
---
## Security
- Flag raw string interpolation in SQL queries — require parameterized queries (`SqlCommand`) or EF Core
- Flag missing `[ValidateAntiForgeryToken]` on state-changing controller actions
- Flag user-controlled data passed to `Process.Start()` or `File` APIs without validation
- Flag hardcoded connection strings — require `appsettings.json` + secrets management
- Flag `[AllowAnonymous]` on endpoints that should be protected
---
## Async / Await
- Flag `async void` methods outside of event handlers — cannot be awaited and swallow exceptions
- Flag `.Result`, `.Wait()`, or `.GetAwaiter().GetResult()` on `Task` — causes deadlocks in ASP.NET contexts
- Flag missing `ConfigureAwait(false)` in library (non-application) code
- Flag `Task.Run()` wrapping synchronous code inside ASP.NET request handlers unnecessarily
- Flag `CancellationToken` not threaded through to downstream async calls
---
## Resource Management
- Flag `IDisposable` objects (`SqlConnection`, `HttpClient`, `FileStream`, etc.) not wrapped in `using` / `using var`
- Flag `HttpClient` instantiated with `new` inside a method — use `IHttpClientFactory` or a shared static instance to avoid socket exhaustion
- Flag `DbContext` registered as a singleton in DI — it must be scoped
- Flag `MemoryStream` / `MemoryCache` growing unboundedly without eviction policy
---
## Exception Handling
- Flag `catch { }` or `catch (Exception) { }` with no logging or re-throw — silent swallow
- Flag `catch (Exception e) { throw e; }` — resets the stack trace; use `throw;` instead
- Flag catching `Exception` when a specific type (`IOException`, `HttpRequestException`) is appropriate
- Flag exception filters (`when`) used for side effects that suppress the exception
- Flag exceptions used for control flow in hot paths — use `Try*` pattern methods instead
---
## Performance
- Flag `.ToList()` / `.ToArray()` on `IQueryable` before filtering — forces all rows into memory; filter server-side first
- Flag `string` concatenation in loops — use `StringBuilder`
- Flag `Enumerable.Count()` on `IQueryable` when only an existence check is needed — use `Any()`
- Flag `await` in a loop where `Task.WhenAll()` would parallelize the work
- Flag synchronous file or network I/O in an `async` method — use the async overload
---
## Idioms and Best Practices
### Null Safety
- Ensure `<Nullable>enable</Nullable>` is set in the project file
- Flag excessive use of `!` (null-forgiving) without a comment explaining why
- Prefer `is null` / `is not null` over `== null` for null checks
### LINQ
- Flag `First()` where `FirstOrDefault()` is safer
- Flag complex LINQ chains that would be clearer as explicit loops
### Modern C# (10+)
- Prefer `record` types for immutable data carriers
- Prefer `switch` expressions over `switch` statements where a value is returned
- Prefer primary constructors (C# 12) for simple dependency injection
- Prefer file-scoped namespaces (`namespace Foo;`) over block-scoped
- Prefer `is` pattern matching over explicit casts

View file

@ -0,0 +1,92 @@
---
language: go
extensions: [".go"]
---
# Go — Language-Specific Review Notes
Load this file alongside `rules/universal.md`. Universal rules are not repeated here — only Go-specific rules and idioms.
---
## PR Analyzer — Go Risk Signals
- `fmt.Println` / `log.Println` debug statements left in production code
- `//nolint` comments — verify they are justified
- `unsafe` package imports — require explicit sign-off
- Hardcoded credentials or tokens in source
---
## Code Quality — Go Checks
- Errors returned but not checked (`_ = someFunc()`)
- `panic()` used outside of package initialization
- Goroutines started without a clear lifetime or cancellation path
- `interface{}` / `any` used where a concrete type or typed interface would work
- Missing context propagation (`context.Context` not threaded through call chains)
---
## Security
- Flag `database/sql` queries built with `fmt.Sprintf` — require `?` / `$N` placeholders
- Flag `os/exec` calls with user-controlled arguments without sanitization
- Flag `html/template` bypassed in favor of `text/template` for HTML output
- Flag `http.ListenAndServeTLS` with `InsecureSkipVerify: true`
---
## Async / Concurrency
- Flag goroutines started with no clear lifetime or cancellation path — always pass `context.Context`
- Flag goroutines that write to a channel with no receiver and no `select` default — causes a leak
- Flag `time.Sleep()` used inside a goroutine as a synchronization mechanism
- Flag `sync.WaitGroup.Add()` called inside the goroutine it tracks — race condition
- Flag `sync.Mutex` copied by value — must always be used as a pointer or embedded in a struct
---
## Resource Management
- Flag `http.Response.Body` not closed after reading — even on error paths (`defer resp.Body.Close()`)
- Flag `os.File` not closed — use `defer f.Close()` immediately after opening
- Flag `rows.Close()` missing after `sql.Query()` — leaks the DB connection
- Flag `context.WithCancel` / `context.WithTimeout` cancel function not called — context and resources leak
---
## Exception Handling
- Flag errors assigned to `_` without a comment explaining why it is safe to ignore
- Flag errors not wrapped with `fmt.Errorf("...: %w", err)` — loses stack context
- Flag `errors.New` / `fmt.Errorf` strings starting with a capital letter or ending in punctuation — violates Go conventions
- Flag `panic()` used for expected runtime errors — reserve for programming errors and unrecoverable states
- Flag `recover()` used to silently swallow panics without logging
---
## Performance
- Flag `fmt.Sprintf` used for simple string concatenation — use `strings.Builder` or `+` for small cases
- Flag `append()` in a tight loop without pre-allocating slice capacity — use `make([]T, 0, n)`
- Flag `json.Marshal` / `json.Unmarshal` on large structs in hot paths — consider `json.Encoder` / streaming
- Flag goroutines spawned per-request without a worker pool for CPU-bound tasks
---
## Idioms and Best Practices
### Error Handling
- All returned errors must be checked — never assign to `_` without a comment
- Prefer wrapping with `fmt.Errorf("...: %w", err)` for stack context
- Use `errors.Is` / `errors.As` for error inspection — never string comparison
### Concurrency
- Every goroutine must have an owner responsible for its lifetime
- Always pass `context.Context` as the first argument to functions that do I/O or block
- Prefer `sync.WaitGroup` or `errgroup` over ad-hoc channel coordination
### Modern Go (1.18+)
- Prefer generics over `interface{}` for container types and utility functions
- Use `any` (alias for `interface{}`) in new code for readability

View file

@ -0,0 +1,103 @@
---
language: java
extensions: [".java"]
---
# Java — Language-Specific Review Notes
Load this file alongside `rules/universal.md`. Universal rules are not repeated here — only Java-specific rules and idioms.
---
## PR Analyzer — Java Risk Signals
- `System.out.println` / `e.printStackTrace()` left in production code
- `@SuppressWarnings` annotations — verify they are justified
- Hardcoded JDBC URLs or credentials in source
- Raw type usage (`List`, `Map` without generics)
---
## Code Quality — Java Checks
- Empty `catch` blocks swallowing exceptions silently
- Checked exceptions caught and not re-thrown with context
- `Closeable` / `AutoCloseable` resources not in try-with-resources
- Raw type usage — defeats generics type safety
- Missing `@Override` on overriding methods
- `InterruptedException` caught without calling `Thread.currentThread().interrupt()`
---
## Security
- Flag JPQL / HQL or native SQL string concatenation — require named parameters or `CriteriaBuilder`
- Flag `@RequestMapping` without explicit HTTP method restriction on state-changing endpoints
- Flag user-controlled input passed to `Runtime.exec()` or `ProcessBuilder` without validation
- Flag `ObjectInputStream.readObject()` on untrusted data — unsafe deserialization
- Flag hardcoded JDBC URLs or credentials — require environment variables or a vault
---
## Async / Concurrency
- Flag `ExecutorService.submit()` return value ignored — exceptions are swallowed
- Flag `Thread.sleep()` used as a synchronization mechanism — use `CountDownLatch`, `CompletableFuture`, or `await()`
- Flag `CompletableFuture` chains with no `.exceptionally()` or `.handle()` terminal handler
- Flag `InterruptedException` caught without calling `Thread.currentThread().interrupt()`
- Flag `synchronized` on a non-final field — the lock object can be replaced
- Flag `HashMap` used in multi-threaded context — use `ConcurrentHashMap`
---
## Resource Management
- Flag `InputStream`, `OutputStream`, `Connection`, `ResultSet`, `PreparedStatement` not wrapped in try-with-resources
- Flag manual `finally { resource.close() }` — replace with try-with-resources
- Flag `HttpURLConnection` not disconnected after use
- Flag JDBC `Connection` obtained from a pool and not returned (missing `close()`) on all paths
- Flag `static` `HttpClient` or `Connection` fields shared across threads without connection pool management
---
## Exception Handling
- Flag empty `catch` blocks — `catch (Exception e) {}`
- Flag `InterruptedException` caught without `Thread.currentThread().interrupt()` — breaks cooperative cancellation
- Flag checked exceptions swallowed in a `catch` and not re-thrown or logged with context
- Flag `throw new RuntimeException(e)` without a descriptive message — loses context
- Flag `printStackTrace()` as the sole error handling — use a proper logger
---
## Performance
- Flag `String` concatenation in loops — use `StringBuilder`
- Flag `List.contains()` / `Map.get()` in a loop on large collections — review data structure choice
- Flag N+1 JPA / Hibernate queries — use `JOIN FETCH` or `@BatchSize`
- Flag `new ObjectMapper()` / `new Gson()` instantiated per-request — share a singleton
- Flag `ResultSet` fully iterated when only the first result is needed — use `LIMIT 1` in the query
---
## Idioms and Best Practices
### Null Safety
- Prefer returning `Optional<T>` over `null` from methods
- Flag unchecked dereferences without a prior null guard
- Do not catch `NullPointerException` — fix the root cause instead
### Collections and Streams
- Flag `==` used to compare `String` or boxed types — use `.equals()`
- Flag `.collect(Collectors.toList())` where `.toList()` (Java 16+) suffices
- Flag premature `.stream().collect()` round-trips that could be a single-pass operation
### Generics
- Flag raw types in any new code — always parameterize (`List<String>`, not `List`)
- Flag unchecked cast warnings suppressed without explanation
### Modern Java (11+)
- Prefer `var` for local variables where the type is obvious from the right-hand side
- Prefer records for pure data carriers over manual POJOs with getters/setters
- Prefer `instanceof` pattern matching (`if (obj instanceof String s)`) over explicit casts
- Prefer `switch` expressions over `switch` statements where a value is returned

View file

@ -0,0 +1,88 @@
---
language: kotlin
extensions: [".kt", ".kts"]
---
# Kotlin — Language-Specific Review Notes
Load this file alongside `rules/universal.md`. Universal rules are not repeated here — only Kotlin-specific rules and idioms.
---
## PR Analyzer — Kotlin Risk Signals
- `println()` statements left in production code
- `@Suppress` annotations — verify they are justified
- `!!` (not-null assertion) used broadly without justification
- Hardcoded credentials or API keys in source
---
## Code Quality — Kotlin Checks
- `!!` used broadly — prefer `?.let`, `?:`, or `requireNotNull()`
- `lateinit var` accessed before initialization
- Coroutines launched with `GlobalScope` — prefer scoped coroutines
- `runBlocking` used outside of tests or top-level entry points
---
## Security
- Flag Room / SQLite queries built with string concatenation — require parameterized queries
- Flag `WebView.loadUrl()` with user-controlled input without validation
- Flag credentials stored in `SharedPreferences` — require `EncryptedSharedPreferences` or Keychain
---
## Async / Coroutines
- Flag `GlobalScope.launch` / `GlobalScope.async` in production code — use a structured scope
- Flag `runBlocking` outside of tests or top-level main functions
- Flag `launch` / `async` without a `CoroutineExceptionHandler` or `supervisorScope` where individual failures should not cancel siblings
- Flag `Dispatchers.Main` used for CPU-bound work — use `Dispatchers.Default`
- Flag coroutine cancellation not respected — long loops should check `isActive` or call `yield()`
---
## Resource Management
- Flag `Closeable` / `AutoCloseable` not wrapped in `.use { }` (Kotlin's try-with-resources equivalent)
- Flag `OkHttpClient` / `Retrofit` instantiated per-request — share a singleton
- Flag `BroadcastReceiver` registered without a corresponding `unregisterReceiver` — memory / battery leak
- Flag coroutines that hold a resource across a `suspend` point without structured cleanup in `finally`
---
## Exception Handling
- Flag `runCatching { }.getOrNull()` used broadly — silently swallows all exceptions
- Flag `catch (e: Exception)` in coroutines without re-throwing `CancellationException` — breaks structured concurrency
- Flag empty `catch` blocks
- Flag `throw RuntimeException(e)` without a descriptive message
- Prefer typed `sealed class` error hierarchies over raw exceptions for domain errors in coroutine flows
---
## Performance
- Flag `buildString` / `StringBuilder` not used for multi-step string construction in loops
- Flag `List` used for frequent `contains` checks — prefer `Set`
- Flag `flow.collect {}` re-subscribing on every recomposition in Jetpack Compose — use `collectAsStateWithLifecycle`
- Flag `Dispatchers.IO` used for CPU-bound work — use `Dispatchers.Default`
- Flag `suspend` functions calling non-suspend blocking APIs directly — wrap with `withContext(Dispatchers.IO)`
---
## Idioms and Best Practices
### Null Safety
- Prefer safe call (`?.`) and Elvis operator (`?:`) over `!!`
- Use `requireNotNull()` / `checkNotNull()` with a descriptive message when null means a programming error
- Prefer `val` over `var` — immutability by default
### Modern Kotlin
- Prefer `data class` for value carriers
- Prefer `sealed class` / `sealed interface` for exhaustive `when` expressions
- Prefer extension functions over utility classes
- Prefer `object` declarations for singletons

View file

@ -0,0 +1,94 @@
---
language: python
extensions: [".py"]
---
# Python — Language-Specific Review Notes
Load this file alongside `rules/universal.md`. Universal rules are not repeated here — only Python-specific rules and idioms.
---
## PR Analyzer — Python Risk Signals
- `print()` statements left in production code
- `# noqa` and `# type: ignore` comments — verify they are justified
- `eval()` / `exec()` with any user-controlled input
- `pickle` used to deserialize untrusted data
- Hardcoded credentials or tokens in source
---
## Code Quality — Python Checks
- Bare `except:` or `except Exception:` swallowing silently
- Mutable default arguments (`def foo(items=[])`) — shared across calls
- `import *` — pollutes namespace and hides dependencies
- Missing type hints on public functions and methods
- `assert` used for runtime validation — stripped by `-O` flag
---
## Security
- Flag `eval()` / `exec()` with any user-controlled input
- Flag `pickle.loads()` on untrusted data — use `json` or `msgpack`
- Flag `subprocess` calls with `shell=True` and user input
- Flag `flask.render_template_string()` with user data (SSTI)
- Flag `SECRET_KEY` / `DEBUG = True` committed to source
---
## Async
- Flag `asyncio.get_event_loop().run_until_complete()` inside an already-running loop
- Flag mixing `threading` and `asyncio` without a clear bridge (`run_in_executor`)
- Flag CPU-bound work inside an `async def` without offloading to `ProcessPoolExecutor`
- Flag `time.sleep()` inside async functions — use `await asyncio.sleep()`
---
## Resource Management
- Flag `open()` not used as a context manager (`with open(...) as f`)
- Flag `requests.Session` created per-request instead of shared/reused
- Flag database connections not closed or returned to a pool on all paths
- Flag large files read entirely into memory with `.read()` — prefer streaming / chunked reads
---
## Exception Handling
- Flag bare `except:` — catches `BaseException` including `KeyboardInterrupt` and `SystemExit`
- Flag `except Exception: pass` — silently swallows errors
- Flag re-raising with `raise e` instead of `raise` — loses the original traceback
- Flag `except` clause too broad when the `try` block covers multiple operations with different failure modes — split them
---
## Performance
- Flag `+` string concatenation in loops — use `"".join()`
- Flag repeated `re.compile()` inside a loop — compile once at module level
- Flag `list.append()` in a loop where a list comprehension would be more efficient
- Flag `in` membership tests on `list` where the collection is large — use `set`
- Flag loading entire large files into memory — prefer streaming or chunked reads
---
## Idioms and Best Practices
### Type Safety
- All public functions and methods should have type annotations
- Prefer `X | None` (Python 3.10+) over `Optional[X]`
- Use `TypedDict` or `dataclass` over plain `dict` for structured data
### Modern Python (3.10+)
- Prefer `match` statements over long `if/elif` chains
- Prefer `dataclass` or `NamedTuple` over plain classes for data carriers
- Prefer `pathlib.Path` over `os.path` for file operations
- Prefer f-strings over `.format()` or `%` formatting
### None Safety
- Prefer explicit `if x is None` over falsy checks when `0` or `""` are valid values
- Flag functions returning `None` implicitly — make it explicit or raise

View file

@ -0,0 +1,88 @@
---
language: swift
extensions: [".swift"]
---
# Swift — Language-Specific Review Notes
Load this file alongside `rules/universal.md`. Universal rules are not repeated here — only Swift-specific rules and idioms.
---
## PR Analyzer — Swift Risk Signals
- `print()` statements left in production code
- Force unwrap (`!`) on optionals outside of tests or justified init
- Force cast (`as!`) without a safe fallback
- Hardcoded credentials or API keys in source
---
## Code Quality — Swift Checks
- Force unwrap (`!`) used broadly — prefer `guard let` or `if let`
- `try!` used outside of guaranteed-safe contexts
- Retain cycles in closures — missing `[weak self]` or `[unowned self]`
- `@objc` / `dynamic` used without an Objective-C interop reason
---
## Security
- Flag credentials stored in `UserDefaults` — require Keychain
- Flag `URLSession` requests over plain HTTP in production
- Flag `WKWebView` loading arbitrary user-supplied URLs without validation
---
## Async / Concurrency
- Flag `DispatchQueue.main.sync` called from the main thread — deadlock
- Flag `@escaping` closures capturing `self` strongly in reference cycles — use `[weak self]`
- Flag mixing `async/await` and `DispatchQueue` for the same operation without clear reasoning
- Flag `Task { }` (unstructured) where a structured `async let` or `TaskGroup` would maintain structure
- Flag data races — shared mutable state accessed from multiple tasks without an actor
---
## Resource Management
- Flag `URLSessionDataTask` started with no cancellation handle stored — cannot be cancelled if the view disappears
- Flag `NotificationCenter` observers added without a corresponding `removeObserver` — memory leak
- Flag `CLLocationManager` / `AVCaptureSession` not stopped when the owning view controller is dismissed
---
## Exception Handling
- Flag `try!` outside of guaranteed-safe contexts (test fixtures, constants) — crashes on failure
- Flag `try?` discarding errors where the failure mode matters to the caller
- Flag error types conforming to `Error` with no associated values or message — makes debugging hard
- Flag throwing functions calling `fatalError()` as a fallback — choose one error strategy
---
## Performance
- Flag `UIImage(named:)` called repeatedly for the same asset without caching
- Flag synchronous network calls on the main thread
- Flag `Array` used for frequent membership tests — prefer `Set`
- Flag `String` interpolation inside tight loops where a pre-built string would avoid allocations
---
## Idioms and Best Practices
### Optionals
- Prefer `guard let` for early exit; `if let` for local scope
- Prefer optional chaining (`?.`) over force unwrap
- Flag implicitly unwrapped optionals (`var x: String!`) outside of `@IBOutlet`
### Memory Management
- Flag closures capturing `self` strongly in reference cycles — use `[weak self]`
- Prefer `struct` over `class` for value semantics unless identity or inheritance is needed
- Use `unowned` only when the lifetime is guaranteed — otherwise `weak`
### Concurrency (Swift 5.5+)
- Prefer `async/await` over completion handlers in new code
- Flag `DispatchQueue.main.async` where `@MainActor` or `await MainActor.run` is more appropriate

View file

@ -0,0 +1,97 @@
---
language: typescript
extensions: [".ts", ".tsx", ".js", ".jsx", ".mjs"]
---
# TypeScript / JavaScript — Language-Specific Review Notes
Load this file alongside `rules/universal.md`. Universal rules are not repeated here — only TypeScript/JavaScript-specific rules and idioms.
---
## PR Analyzer — TypeScript / JavaScript Risk Signals
- `console.log` / `debugger` statements left in production code
- `// eslint-disable` comments — verify they are justified
- `any` type annotations — require explicit justification
- `@ts-ignore` / `@ts-expect-error` — verify they are justified
- `eval()` with any dynamic or user-controlled input
- Hardcoded API keys or tokens in source
---
## Code Quality — TypeScript / JavaScript Checks
- `any` used broadly instead of proper typing
- Non-null assertion (`!`) used without justification
- `var` declarations — prefer `const` / `let`
- Missing `await` on async function calls
- Floating promises (no `.catch()` and no `await`)
- `==` used instead of `===`
---
## Security
- Flag `innerHTML`, `outerHTML`, `document.write()` with user-controlled data — use `textContent` or a sanitizer
- Flag `dangerouslySetInnerHTML` in React without a sanitizer
- Flag `eval()` / `new Function()` with dynamic input
- Flag JWT decoded without signature verification
- Flag missing `httpOnly` / `secure` flags on cookies
---
## Async / Promises
- Flag floating promises — async calls not `await`-ed and without `.catch()`
- Flag `Promise.all()` where `Promise.allSettled()` is safer (one failure should not cancel siblings)
- Flag `async` functions inside `forEach` — `forEach` does not await; use `for...of` or `Promise.all()`
- Flag unhandled promise rejection (no global `unhandledRejection` handler in Node.js services)
---
## Resource Management
- Flag `fs.createReadStream` / `fs.createWriteStream` with no `close` or `destroy` on error
- Flag `EventEmitter` listeners added in a loop without removal — memory leak
- Flag `setInterval` / `setTimeout` handles not cleared when the owning component unmounts or exits
- Flag database clients / pools not released after use in Node.js
---
## Exception Handling
- Flag `catch (e) {}` (empty catch) — swallowed error
- Flag `catch (e)` where `e` is used as `any` without narrowing — type the error properly
- Flag `Promise` rejection not handled — `.catch()` or `try/await/catch` required
- Flag re-throwing a new `Error` without wrapping the original — loses stack context
- Use `Error` subclasses for domain errors rather than plain strings or object literals
---
## Performance
- Flag `Array.prototype.find` / `filter` / `map` chained multiple times over the same array — combine into one pass
- Flag DOM queries (`document.querySelector`) inside loops — cache the result
- Flag `JSON.parse` / `JSON.stringify` in a hot path on large objects — consider streaming or partial parsing
- Flag `async` functions called sequentially in a loop where `Promise.all()` would parallelize them
---
## Idioms and Best Practices
### Type Safety (TypeScript)
- Prefer `unknown` over `any` for truly unknown values — forces a type guard before use
- Prefer type narrowing (`typeof`, `instanceof`, discriminated unions) over casting
- Enable `strict` mode in `tsconfig.json`
- Prefer `interface` for object shapes that may be extended; `type` for unions and aliases
### Modern JavaScript / TypeScript
- Prefer `const` by default; `let` only when reassignment is needed
- Prefer optional chaining (`?.`) and nullish coalescing (`??`) over manual null guards
- Prefer `structuredClone()` over manual deep-copy patterns
- Prefer named exports over default exports for better refactoring support
### Null / Undefined Safety
- Distinguish between `null` (intentional absence) and `undefined` (not set) — be consistent
- Flag `== null` checks that accidentally include `undefined` when only one is intended

View file

@ -1,270 +0,0 @@
# Code Review Checklist
Structured checklists for systematic code review across different aspects.
---
## Table of Contents
- [Pre-Review Checks](#pre-review-checks)
- [Correctness](#correctness)
- [Security](#security)
- [Performance](#performance)
- [Maintainability](#maintainability)
- [Testing](#testing)
- [Documentation](#documentation)
- [Language-Specific Checks](#language-specific-checks)
---
## Pre-Review Checks
Before diving into code, verify these basics:
### Build and Tests
- [ ] Code compiles without errors
- [ ] All existing tests pass
- [ ] New tests are included for new functionality
- [ ] No unintended files included (build artifacts, IDE configs)
### PR Hygiene
- [ ] PR has clear title and description
- [ ] Changes are scoped appropriately (not too large)
- [ ] Commits follow conventional commit format
- [ ] Branch is up to date with base branch
### Scope Verification
- [ ] Changes match the stated purpose
- [ ] No unrelated changes bundled in
- [ ] Breaking changes are documented
- [ ] Migration path provided if needed
---
## Correctness
### Logic
- [ ] Algorithm implements requirements correctly
- [ ] Edge cases handled (null, empty, boundary values)
- [ ] Off-by-one errors checked
- [ ] Correct operators used (== vs ===, & vs &&)
- [ ] Loop termination conditions correct
- [ ] Recursion has proper base cases
### Data Handling
- [ ] Data types appropriate for the use case
- [ ] Numeric overflow/underflow considered
- [ ] Date/time handling accounts for timezones
- [ ] Unicode and internationalization handled
- [ ] Data validation at entry points
### State Management
- [ ] State transitions are valid
- [ ] Race conditions addressed
- [ ] Concurrent access handled correctly
- [ ] State cleanup on errors/exit
### Error Handling
- [ ] Errors caught at appropriate levels
- [ ] Error messages are actionable
- [ ] Errors don't expose sensitive information
- [ ] Recovery or graceful degradation implemented
- [ ] Resources cleaned up in error paths
---
## Security
### Input Validation
- [ ] All user input validated and sanitized
- [ ] Input length limits enforced
- [ ] File uploads validated (type, size, content)
- [ ] URL parameters validated
### Injection Prevention
- [ ] SQL queries parameterized
- [ ] Command execution uses safe APIs
- [ ] HTML output escaped to prevent XSS
- [ ] LDAP queries properly escaped
- [ ] XML parsing disables external entities
### Authentication & Authorization
- [ ] Authentication required for protected resources
- [ ] Authorization checked before operations
- [ ] Session management secure
- [ ] Password handling follows best practices
- [ ] Token expiration implemented
### Data Protection
- [ ] Sensitive data encrypted at rest
- [ ] Sensitive data encrypted in transit
- [ ] PII handled according to policy
- [ ] Secrets not hardcoded
- [ ] Logs don't contain sensitive data
### API Security
- [ ] Rate limiting implemented
- [ ] CORS configured correctly
- [ ] CSRF protection in place
- [ ] API keys/tokens secured
- [ ] Endpoints use HTTPS
---
## Performance
### Efficiency
- [ ] Appropriate data structures used
- [ ] Algorithms have acceptable complexity
- [ ] Database queries are optimized
- [ ] N+1 query problems avoided
- [ ] Indexes used where beneficial
### Resource Usage
- [ ] Memory usage bounded
- [ ] No memory leaks
- [ ] File handles properly closed
- [ ] Database connections pooled
- [ ] Network calls minimized
### Caching
- [ ] Appropriate caching strategy
- [ ] Cache invalidation handled
- [ ] Cache keys are unique and predictable
- [ ] TTL values appropriate
### Scalability
- [ ] Horizontal scaling considered
- [ ] Bottlenecks identified
- [ ] Async processing for long operations
- [ ] Batch operations where appropriate
---
## Maintainability
### Code Quality
- [ ] Functions/methods have single responsibility
- [ ] Classes follow SOLID principles
- [ ] Code is DRY (Don't Repeat Yourself)
- [ ] No dead code or commented-out code
- [ ] Magic numbers replaced with constants
### Naming
- [ ] Names are descriptive and consistent
- [ ] Naming follows project conventions
- [ ] No abbreviations that obscure meaning
- [ ] Boolean variables/functions have is/has/can prefix
### Structure
- [ ] Functions are appropriately sized (<50 lines preferred)
- [ ] Nesting depth is reasonable (<4 levels)
- [ ] Related code is grouped together
- [ ] Dependencies are minimal and explicit
### Readability
- [ ] Code is self-documenting where possible
- [ ] Complex logic has explanatory comments
- [ ] Formatting is consistent
- [ ] No overly clever or obscure code
---
## Testing
### Coverage
- [ ] New code has unit tests
- [ ] Critical paths have integration tests
- [ ] Edge cases are tested
- [ ] Error conditions are tested
### Quality
- [ ] Tests are independent
- [ ] Tests have clear assertions
- [ ] Test names describe what is tested
- [ ] Tests don't depend on external state
### Mocking
- [ ] External dependencies are mocked
- [ ] Mocks are realistic
- [ ] Mock setup is not excessive
---
## Documentation
### Code Documentation
- [ ] Public APIs are documented
- [ ] Complex algorithms explained
- [ ] Non-obvious decisions documented
- [ ] TODO/FIXME comments have context
### External Documentation
- [ ] README updated if needed
- [ ] API documentation updated
- [ ] Changelog updated
- [ ] Migration guides provided
---
## Language-Specific Checks
### TypeScript/JavaScript
- [ ] Types are explicit (avoid `any`)
- [ ] Null checks present (`?.`, `??`)
- [ ] Async/await errors handled
- [ ] No floating promises
- [ ] Memory leaks from closures checked
### Python
- [ ] Type hints used for public APIs
- [ ] Context managers for resources (`with` statements)
- [ ] Exception handling is specific (not bare `except`)
- [ ] No mutable default arguments
- [ ] List comprehensions used appropriately
### Go
- [ ] Errors checked and handled
- [ ] Goroutine leaks prevented
- [ ] Context propagation correct
- [ ] Defer statements in right order
- [ ] Interfaces minimal
### Swift
- [ ] Optionals handled safely
- [ ] Memory management correct (weak/unowned)
- [ ] Error handling uses Result or throws
- [ ] Access control appropriate
- [ ] Codable implementation correct
### Kotlin
- [ ] Null safety leveraged
- [ ] Coroutine cancellation handled
- [ ] Data classes used appropriately
- [ ] Extension functions don't obscure behavior
- [ ] Sealed classes for state
---
## Review Process Tips
### Before Approving
1. Verify all critical checks passed
2. Confirm tests are adequate
3. Consider deployment impact
4. Check for any security concerns
5. Ensure documentation is updated
### Providing Feedback
- Be specific about issues
- Explain why something is problematic
- Suggest alternatives when possible
- Distinguish blockers from suggestions
- Acknowledge good patterns
### When to Block
- Security vulnerabilities present
- Critical logic errors
- No tests for risky changes
- Breaking changes without migration
- Significant performance regressions

View file

@ -1,793 +0,0 @@
# Coding Standards
Language-specific coding standards and conventions for code review.
---
## Table of Contents
- [Universal Principles](#universal-principles)
- [TypeScript Standards](#typescript-standards)
- [JavaScript Standards](#javascript-standards)
- [Python Standards](#python-standards)
- [Go Standards](#go-standards)
- [Swift Standards](#swift-standards)
- [Kotlin Standards](#kotlin-standards)
- [C# / .NET Standards](#c--net-standards)
---
## Universal Principles
These apply across all languages.
### Naming Conventions
| Element | Convention | Example |
|---------|------------|---------|
| Variables | camelCase (JS/TS), snake_case (Python/Go) | `userName`, `user_name` |
| Constants | SCREAMING_SNAKE_CASE | `MAX_RETRY_COUNT` |
| Functions | camelCase (JS/TS), snake_case (Python) | `getUserById`, `get_user_by_id` |
| Classes | PascalCase | `UserRepository` |
| Interfaces | PascalCase, optionally prefixed | `IUserService` or `UserService` |
| Private members | Prefix with underscore or use access modifiers | `_internalState` |
### Function Design
```
Good functions:
- Do one thing well
- Have descriptive names (verb + noun)
- Take 3 or fewer parameters
- Return early for error cases
- Stay under 50 lines
```
### Error Handling
```
Good error handling:
- Catch specific errors, not generic exceptions
- Log with context (what, where, why)
- Clean up resources in error paths
- Don't swallow errors silently
- Provide actionable error messages
```
---
## TypeScript Standards
### Type Annotations
```typescript
// Avoid 'any' - use unknown for truly unknown types
function processData(data: unknown): ProcessedResult {
if (isValidData(data)) {
return transform(data);
}
throw new Error('Invalid data format');
}
// Use explicit return types for public APIs
export function calculateTotal(items: CartItem[]): number {
return items.reduce((sum, item) => sum + item.price, 0);
}
// Use type guards for runtime checks
function isUser(obj: unknown): obj is User {
return (
typeof obj === 'object' &&
obj !== null &&
'id' in obj &&
'email' in obj
);
}
```
### Null Safety
```typescript
// Use optional chaining and nullish coalescing
const userName = user?.profile?.name ?? 'Anonymous';
// Be explicit about nullable types
interface Config {
timeout: number;
retries?: number; // Optional
fallbackUrl: string | null; // Explicitly nullable
}
// Use assertion functions for validation
function assertDefined<T>(value: T | null | undefined): asserts value is T {
if (value === null || value === undefined) {
throw new Error('Value is not defined');
}
}
```
### Async/Await
```typescript
// Always handle errors in async functions
async function fetchUser(id: string): Promise<User> {
try {
const response = await api.get(`/users/${id}`);
return response.data;
} catch (error) {
logger.error('Failed to fetch user', { id, error });
throw new UserFetchError(id, error);
}
}
// Use Promise.all for parallel operations
async function loadDashboard(userId: string): Promise<Dashboard> {
const [profile, stats, notifications] = await Promise.all([
fetchProfile(userId),
fetchStats(userId),
fetchNotifications(userId)
]);
return { profile, stats, notifications };
}
```
### React/Component Standards
```typescript
// Use explicit prop types
interface ButtonProps {
label: string;
onClick: () => void;
variant?: 'primary' | 'secondary';
disabled?: boolean;
}
// Prefer functional components with hooks
function Button({ label, onClick, variant = 'primary', disabled = false }: ButtonProps) {
return (
<button
className={`btn btn-${variant}`}
onClick={onClick}
disabled={disabled}
>
{label}
</button>
);
}
// Use custom hooks for reusable logic
function useDebounce<T>(value: T, delay: number): T {
const [debouncedValue, setDebouncedValue] = useState(value);
useEffect(() => {
const timer = setTimeout(() => setDebouncedValue(value), delay);
return () => clearTimeout(timer);
}, [value, delay]);
return debouncedValue;
}
```
---
## JavaScript Standards
### Variable Declarations
```javascript
// Use const by default, let when reassignment needed
const MAX_ITEMS = 100;
let currentCount = 0;
// Never use var
// var is function-scoped and hoisted, leading to bugs
```
### Object and Array Patterns
```javascript
// Use object destructuring
const { name, email, role = 'user' } = user;
// Use spread for immutable updates
const updatedUser = { ...user, lastLogin: new Date() };
const updatedList = [...items, newItem];
// Use array methods over loops
const activeUsers = users.filter(u => u.isActive);
const emails = users.map(u => u.email);
const total = orders.reduce((sum, o) => sum + o.amount, 0);
```
### Module Patterns
```javascript
// Use named exports for utilities
export function formatDate(date) { ... }
export function parseDate(str) { ... }
// Use default export for main component/class
export default class UserService { ... }
// Group related exports
export { formatDate, parseDate, isValidDate } from './dateUtils';
```
---
## Python Standards
### Type Hints (PEP 484)
```python
from typing import Optional, List, Dict, Union
def get_user(user_id: int) -> Optional[User]:
"""Fetch user by ID, returns None if not found."""
return db.query(User).filter(User.id == user_id).first()
def process_items(items: List[str]) -> Dict[str, int]:
"""Count occurrences of each item."""
return {item: items.count(item) for item in set(items)}
def send_notification(
user: User,
message: str,
*,
priority: str = "normal",
channels: List[str] = None
) -> bool:
"""Send notification to user via specified channels."""
channels = channels or ["email"]
# Implementation
```
### Exception Handling
```python
# Catch specific exceptions
try:
result = api_client.fetch_data(endpoint)
except ConnectionError as e:
logger.warning(f"Connection failed: {e}")
return cached_data
except TimeoutError as e:
logger.error(f"Request timed out: {e}")
raise ServiceUnavailableError() from e
# Use context managers for resources
with open(filepath, 'r') as f:
data = json.load(f)
# Custom exceptions should be informative
class ValidationError(Exception):
def __init__(self, field: str, message: str):
self.field = field
self.message = message
super().__init__(f"{field}: {message}")
```
### Class Design
```python
from dataclasses import dataclass
from abc import ABC, abstractmethod
# Use dataclasses for data containers
@dataclass
class UserDTO:
id: int
email: str
name: str
is_active: bool = True
# Use ABC for interfaces
class Repository(ABC):
@abstractmethod
def find_by_id(self, id: int) -> Optional[Entity]:
pass
@abstractmethod
def save(self, entity: Entity) -> Entity:
pass
# Use properties for computed attributes
class Order:
def __init__(self, items: List[OrderItem]):
self._items = items
@property
def total(self) -> Decimal:
return sum(item.price * item.quantity for item in self._items)
```
---
## Go Standards
### Error Handling
```go
// Always check errors
file, err := os.Open(filename)
if err != nil {
return fmt.Errorf("failed to open %s: %w", filename, err)
}
defer file.Close()
// Use custom error types for specific cases
type ValidationError struct {
Field string
Message string
}
func (e *ValidationError) Error() string {
return fmt.Sprintf("%s: %s", e.Field, e.Message)
}
// Wrap errors with context
if err := db.Query(query); err != nil {
return fmt.Errorf("query failed for user %d: %w", userID, err)
}
```
### Struct Design
```go
// Use unexported fields with exported methods
type UserService struct {
repo UserRepository
cache Cache
logger Logger
}
// Constructor functions for initialization
func NewUserService(repo UserRepository, cache Cache, logger Logger) *UserService {
return &UserService{
repo: repo,
cache: cache,
logger: logger,
}
}
// Keep interfaces small
type Reader interface {
Read(p []byte) (n int, err error)
}
type Writer interface {
Write(p []byte) (n int, err error)
}
```
### Concurrency
```go
// Use context for cancellation
func fetchData(ctx context.Context, url string) ([]byte, error) {
req, err := http.NewRequestWithContext(ctx, "GET", url, nil)
if err != nil {
return nil, err
}
// ...
}
// Use channels for communication
func worker(jobs <-chan Job, results chan<- Result) {
for job := range jobs {
result := process(job)
results <- result
}
}
// Use sync.WaitGroup for coordination
var wg sync.WaitGroup
for _, item := range items {
wg.Add(1)
go func(i Item) {
defer wg.Done()
processItem(i)
}(item)
}
wg.Wait()
```
---
## Swift Standards
### Optionals
```swift
// Use optional binding
if let user = fetchUser(id: userId) {
displayProfile(user)
}
// Use guard for early exit
guard let data = response.data else {
throw NetworkError.noData
}
// Use nil coalescing for defaults
let displayName = user.nickname ?? user.email
// Avoid force unwrapping except in tests
// BAD: let name = user.name!
// GOOD: guard let name = user.name else { return }
```
### Protocol-Oriented Design
```swift
// Define protocols with minimal requirements
protocol Identifiable {
var id: String { get }
}
protocol Persistable: Identifiable {
func save() throws
static func find(by id: String) -> Self?
}
// Use protocol extensions for default implementations
extension Persistable {
func save() throws {
try Storage.shared.save(self)
}
}
// Prefer composition over inheritance
struct User: Identifiable, Codable {
let id: String
var name: String
var email: String
}
```
### Error Handling
```swift
// Define domain-specific errors
enum AuthError: Error {
case invalidCredentials
case tokenExpired
case networkFailure(underlying: Error)
}
// Use Result type for async operations
func authenticate(
email: String,
password: String,
completion: @escaping (Result<User, AuthError>) -> Void
)
// Use throws for synchronous operations
func validate(_ input: String) throws -> ValidatedInput {
guard !input.isEmpty else {
throw ValidationError.emptyInput
}
return ValidatedInput(value: input)
}
```
---
## Kotlin Standards
### Null Safety
```kotlin
// Use nullable types explicitly
fun findUser(id: Int): User? {
return userRepository.find(id)
}
// Use safe calls and elvis operator
val name = user?.profile?.name ?: "Unknown"
// Use let for null checks with side effects
user?.let { activeUser ->
sendWelcomeEmail(activeUser.email)
logActivity(activeUser.id)
}
// Use require/check for validation
fun processPayment(amount: Double) {
require(amount > 0) { "Amount must be positive: $amount" }
// Process
}
```
### Data Classes and Sealed Classes
```kotlin
// Use data classes for DTOs
data class UserDTO(
val id: Int,
val email: String,
val name: String,
val isActive: Boolean = true
)
// Use sealed classes for state
sealed class Result<out T> {
data class Success<T>(val data: T) : Result<T>()
data class Error(val message: String, val cause: Throwable? = null) : Result<Nothing>()
object Loading : Result<Nothing>()
}
// Pattern matching with when
fun handleResult(result: Result<User>) = when (result) {
is Result.Success -> showUser(result.data)
is Result.Error -> showError(result.message)
Result.Loading -> showLoading()
}
```
### Coroutines
```kotlin
// Use structured concurrency
suspend fun loadDashboard(): Dashboard = coroutineScope {
val profile = async { fetchProfile() }
val stats = async { fetchStats() }
val notifications = async { fetchNotifications() }
Dashboard(
profile = profile.await(),
stats = stats.await(),
notifications = notifications.await()
)
}
// Handle cancellation
suspend fun fetchWithRetry(url: String): Response {
repeat(3) { attempt ->
try {
return httpClient.get(url)
} catch (e: IOException) {
if (attempt == 2) throw e
delay(1000L * (attempt + 1))
}
}
throw IllegalStateException("Unreachable")
}
```
---
## C# / .NET Standards
### Nullable Reference Types
```csharp
// Enable nullable reference types at the project level
// <PropertyGroup>
// <Nullable>enable</Nullable>
// <TreatWarningsAsErrors>true</TreatWarningsAsErrors>
// </PropertyGroup>
// Be explicit about nullability
public string Name { get; set; } = ""; // non-nullable, requires init
public string? Nickname { get; set; } // nullable
public User? FindUser(int id) // may return null
{
return _repo.Get(id);
}
// Avoid the null-forgiving operator (!) — it tells the compiler
// "trust me, this is not null" and silently disables the safety net.
// BAD: return user!.Name;
// GOOD: return user?.Name ?? throw new InvalidOperationException(nameof(user));
// Use the null-conditional and null-coalescing operators
var displayName = user?.Profile?.Name ?? "Anonymous";
// Pattern matching for null checks
if (user is { Profile.Name: { } name })
{
Log(name);
}
```
### Async / Await
```csharp
// Return Task (or Task<T>), never `void`, except for event handlers.
// `async void` cannot be awaited and exceptions cannot be caught by callers.
public async Task SaveAsync(User user)
{
await _db.SaveChangesAsync();
}
// Never block on async with .Result, .Wait(), or .GetAwaiter().GetResult()
// in code that runs on a synchronization context (ASP.NET Classic, WinForms, WPF)
// — it causes deadlocks.
// BAD: var data = FetchAsync().Result;
// GOOD: var data = await FetchAsync();
// In library code, use ConfigureAwait(false) to avoid forcing the caller's
// context back onto the continuation.
public async Task<User> LoadAsync(int id)
{
var row = await _db.Users.FindAsync(id).ConfigureAwait(false);
return Map(row);
}
// Parallelize independent awaitables
var (profile, stats, notifications) = (
await Task.WhenAll(
FetchProfileAsync(id),
FetchStatsAsync(id),
FetchNotificationsAsync(id)
)
);
```
### Exception Handling
```csharp
// Catch the most specific exception, not `Exception`
try
{
await client.GetAsync(url);
}
catch (HttpRequestException ex) when (ex.StatusCode == HttpStatusCode.NotFound)
{
return null;
}
catch (TaskCanceledException)
{
_logger.LogWarning("Request to {Url} timed out", url);
throw;
}
// Never swallow exceptions
// BAD:
// try { ... } catch (Exception) { }
//
// GOOD: log with context, then rethrow or convert to a domain error.
try
{
await Process(order);
}
catch (DomainException ex)
{
_logger.LogError(ex, "Order {OrderId} failed", order.Id);
throw;
}
// Use `throw;` (not `throw ex;`) to preserve the original stack trace
```
### Resource Management (IDisposable)
```csharp
// Always wrap IDisposable resources in `using` / `using var`
using var connection = new SqlConnection(connectionString);
using var command = new SqlCommand(query, connection);
// HttpClient is the exception — it's IDisposable but designed to be
// long-lived. Use IHttpClientFactory in DI rather than `new HttpClient()`
// in a method body.
public class Foo
{
private readonly HttpClient _client;
public Foo(IHttpClientFactory factory)
{
_client = factory.CreateClient("api");
}
}
// For `DbContext`, register as scoped — never instantiate per-request inside a method.
services.AddDbContext<AppDbContext>(opts => opts.UseSqlServer(connStr));
```
### LINQ
```csharp
// Defer execution until you actually need the results
var activeUsers = _db.Users
.Where(u => u.IsActive)
.Select(u => new UserDto(u.Id, u.Email)); // still an IQueryable
// Prefer FirstOrDefault / SingleOrDefault to First / Single
// when "no match" is a valid outcome
var user = await _db.Users.FirstOrDefaultAsync(u => u.Email == email);
if (user is null) return NotFound();
// Avoid premature materialization
// BAD: _db.Users.ToList().Where(u => u.IsActive) // pulls the entire table
// GOOD: _db.Users.Where(u => u.IsActive).ToList() // SQL WHERE clause
// Don't fight LINQ — if the chain is hard to read, drop to a for loop
```
### Dependency Injection
```csharp
// Constructor injection — required dependencies as ctor params
public class OrderService
{
private readonly IOrderRepository _repo;
private readonly IPaymentGateway _payments;
private readonly ILogger<OrderService> _logger;
public OrderService(
IOrderRepository repo,
IPaymentGateway payments,
ILogger<OrderService> logger)
{
_repo = repo;
_payments = payments;
_logger = logger;
}
}
// Pick lifetimes deliberately
services.AddSingleton<IClock, SystemClock>(); // stateless, thread-safe
services.AddScoped<AppDbContext>(); // per-request state
services.AddTransient<IEmailSender, SmtpEmailSender>(); // light, no state
// Don't pass IServiceProvider into business code — it's the service locator
// anti-pattern. If you need many services, group them or inject what you need.
```
### Records and Pattern Matching
```csharp
// Use records for immutable value types (DTOs, value objects, events)
public record UserDto(int Id, string Email, string Name);
// `with` expressions for non-destructive updates
var updated = user with { Name = "New Name" };
// Use pattern matching to flatten nested logic
public decimal CalculateFee(Order order) => order switch
{
{ Customer.Tier: "Gold", Total: > 1000m } => 0m,
{ Customer.Tier: "Gold" } => order.Total * 0.01m,
{ Total: > 500m } => order.Total * 0.02m,
_ => order.Total * 0.03m,
};
// Property patterns for clean guards
if (response is { IsSuccess: true, Data: var data })
{
Process(data);
}
```
### Security (ASP.NET Core)
```csharp
// Parameterized queries — never interpolate user input into SQL
// BAD: _db.Users.FromSqlRaw($"SELECT * FROM Users WHERE Id = {id}")
// GOOD:
var users = await _db.Users
.FromSqlInterpolated($"SELECT * FROM Users WHERE Id = {id}") // EF Core handles parameters
.ToListAsync();
// Or explicitly:
var users = await _db.Users
.FromSqlRaw("SELECT * FROM Users WHERE Id = @id",
new SqlParameter("@id", id))
.ToListAsync();
// Anti-forgery on state-changing actions
[HttpPost]
[ValidateAntiForgeryToken]
public async Task<IActionResult> Update(UpdateUserDto dto) { ... }
// Never bind sensitive properties from the request body
public record CreateUserDto(string Email, string Name); // no Role, no IsAdmin
public IActionResult Create([FromBody] CreateUserDto dto) { ... }
// Use IOptions and the secrets store, not appsettings.json, for secrets
// dotnet user-secrets set ConnectionStrings:Default "Server=...;Password=..."
public class DbOptions { public string ConnectionString { get; init; } = ""; }
services.Configure<DbOptions>(config.GetSection("Db"));
```

View file

@ -1,991 +0,0 @@
# Common Antipatterns
Code antipatterns to identify during review, with examples and fixes.
---
## Table of Contents
- [Structural Antipatterns](#structural-antipatterns)
- [Logic Antipatterns](#logic-antipatterns)
- [Security Antipatterns](#security-antipatterns)
- [Performance Antipatterns](#performance-antipatterns)
- [Testing Antipatterns](#testing-antipatterns)
- [Async Antipatterns](#async-antipatterns)
- [C# / .NET Antipatterns](#c--net-antipatterns)
---
## Structural Antipatterns
### God Class
A class that does too much and knows too much.
```typescript
// BAD: God class handling everything
class UserManager {
createUser(data: UserData) { ... }
updateUser(id: string, data: UserData) { ... }
deleteUser(id: string) { ... }
sendEmail(userId: string, content: string) { ... }
generateReport(userId: string) { ... }
validatePassword(password: string) { ... }
hashPassword(password: string) { ... }
uploadAvatar(userId: string, file: File) { ... }
resizeImage(file: File) { ... }
logActivity(userId: string, action: string) { ... }
// 50 more methods...
}
// GOOD: Single responsibility classes
class UserRepository {
create(data: UserData): User { ... }
update(id: string, data: Partial<UserData>): User { ... }
delete(id: string): void { ... }
}
class EmailService {
send(to: string, content: string): void { ... }
}
class PasswordService {
validate(password: string): ValidationResult { ... }
hash(password: string): string { ... }
}
```
**Detection:** Class has >20 methods, >500 lines, or handles unrelated concerns.
---
### Long Method
Functions that do too much and are hard to understand.
```python
# BAD: Long method doing everything
def process_order(order_data):
# Validate order (20 lines)
if not order_data.get('items'):
raise ValueError('No items')
if not order_data.get('customer_id'):
raise ValueError('No customer')
# ... more validation
# Calculate totals (30 lines)
subtotal = 0
for item in order_data['items']:
price = get_product_price(item['product_id'])
subtotal += price * item['quantity']
# ... tax calculation, discounts
# Process payment (40 lines)
payment_result = payment_gateway.charge(...)
# ... handle payment errors
# Create order record (20 lines)
order = Order.create(...)
# Send notifications (20 lines)
send_order_confirmation(...)
notify_warehouse(...)
return order
# GOOD: Composed of focused functions
def process_order(order_data):
validate_order(order_data)
totals = calculate_order_totals(order_data)
payment = process_payment(order_data['customer_id'], totals)
order = create_order_record(order_data, totals, payment)
send_order_notifications(order)
return order
```
**Detection:** Function >50 lines or requires scrolling to read.
---
### Deep Nesting
Excessive indentation making code hard to follow.
```javascript
// BAD: Deep nesting
function processData(data) {
if (data) {
if (data.items) {
if (data.items.length > 0) {
for (const item of data.items) {
if (item.isValid) {
if (item.type === 'premium') {
if (item.price > 100) {
// Finally do something
processItem(item);
}
}
}
}
}
}
}
}
// GOOD: Early returns and guard clauses
function processData(data) {
if (!data?.items?.length) {
return;
}
const premiumItems = data.items.filter(
item => item.isValid && item.type === 'premium' && item.price > 100
);
premiumItems.forEach(processItem);
}
```
**Detection:** Indentation >4 levels deep.
---
### Magic Numbers and Strings
Hard-coded values without explanation.
```go
// BAD: Magic numbers
func calculateDiscount(total float64, userType int) float64 {
if userType == 1 {
return total * 0.15
} else if userType == 2 {
return total * 0.25
}
return total * 0.05
}
// GOOD: Named constants
const (
UserTypeRegular = 1
UserTypePremium = 2
DiscountRegular = 0.05
DiscountStandard = 0.15
DiscountPremium = 0.25
)
func calculateDiscount(total float64, userType int) float64 {
switch userType {
case UserTypePremium:
return total * DiscountPremium
case UserTypeRegular:
return total * DiscountStandard
default:
return total * DiscountRegular
}
}
```
**Detection:** Literal numbers (except 0, 1) or repeated string literals.
---
### Primitive Obsession
Using primitives instead of small objects.
```typescript
// BAD: Primitives everywhere
function createUser(
name: string,
email: string,
phone: string,
street: string,
city: string,
zipCode: string,
country: string
): User { ... }
// GOOD: Value objects
interface Address {
street: string;
city: string;
zipCode: string;
country: string;
}
interface ContactInfo {
email: string;
phone: string;
}
function createUser(
name: string,
contact: ContactInfo,
address: Address
): User { ... }
```
**Detection:** Functions with >4 parameters of same type, or related primitives always passed together.
---
## Logic Antipatterns
### Boolean Blindness
Passing booleans that make code unreadable at call sites.
```swift
// BAD: What do these booleans mean?
user.configure(true, false, true, false)
// GOOD: Named parameters or option objects
user.configure(
sendWelcomeEmail: true,
requireVerification: false,
enableNotifications: true,
isAdmin: false
)
// Or use an options struct
struct UserConfiguration {
var sendWelcomeEmail: Bool = true
var requireVerification: Bool = false
var enableNotifications: Bool = true
var isAdmin: Bool = false
}
user.configure(UserConfiguration())
```
**Detection:** Function calls with multiple boolean literals.
---
### Null Returns for Collections
Returning null instead of empty collections.
```kotlin
// BAD: Returning null
fun findUsersByRole(role: String): List<User>? {
val users = repository.findByRole(role)
return if (users.isEmpty()) null else users
}
// Caller must handle null
val users = findUsersByRole("admin")
if (users != null) {
users.forEach { ... }
}
// GOOD: Return empty collection
fun findUsersByRole(role: String): List<User> {
return repository.findByRole(role)
}
// Caller can iterate directly
findUsersByRole("admin").forEach { ... }
```
**Detection:** Functions returning nullable collections.
---
### Stringly Typed Code
Using strings where enums or types should be used.
```python
# BAD: String-based logic
def handle_event(event_type: str, data: dict):
if event_type == "user_created":
handle_user_created(data)
elif event_type == "user_updated":
handle_user_updated(data)
elif event_type == "user_dleted": # Typo won't be caught
handle_user_deleted(data)
# GOOD: Enum-based
from enum import Enum
class EventType(Enum):
USER_CREATED = "user_created"
USER_UPDATED = "user_updated"
USER_DELETED = "user_deleted"
def handle_event(event_type: EventType, data: dict):
handlers = {
EventType.USER_CREATED: handle_user_created,
EventType.USER_UPDATED: handle_user_updated,
EventType.USER_DELETED: handle_user_deleted,
}
handlers[event_type](data)
```
**Detection:** String comparisons for type/status/category values.
---
## Security Antipatterns
### SQL Injection
String concatenation in SQL queries.
```javascript
// BAD: String concatenation
const query = `SELECT * FROM users WHERE id = ${userId}`;
db.query(query);
// BAD: String templates still vulnerable
const query = `SELECT * FROM users WHERE name = '${userName}'`;
// GOOD: Parameterized queries
const query = 'SELECT * FROM users WHERE id = $1';
db.query(query, [userId]);
// GOOD: Using ORM safely
User.findOne({ where: { id: userId } });
```
**Detection:** String concatenation or template literals with SQL keywords.
---
### Hardcoded Credentials
Secrets in source code.
```python
# BAD: Hardcoded secrets
API_KEY = "sk-abc123xyz789"
DATABASE_URL = "postgresql://admin:password123@prod-db.internal:5432/app"
# GOOD: Environment variables
import os
API_KEY = os.environ["API_KEY"]
DATABASE_URL = os.environ["DATABASE_URL"]
# GOOD: Secrets manager
from aws_secretsmanager import get_secret
API_KEY = get_secret("api-key")
```
**Detection:** Variables named `password`, `secret`, `key`, `token` with string literals.
---
### Unsafe Deserialization
Deserializing untrusted data without validation.
```python
# BAD: Binary serialization from untrusted source can execute arbitrary code
# Examples: Python's binary serialization, yaml.load without SafeLoader
# GOOD: Use safe alternatives
import json
def load_data(file_path):
with open(file_path, 'r') as f:
return json.load(f)
# GOOD: Use SafeLoader for YAML
import yaml
with open('config.yaml') as f:
config = yaml.safe_load(f)
```
**Detection:** Binary deserialization functions, yaml.load without safe loader, dynamic code execution on external data.
---
### Missing Input Validation
Trusting user input without validation.
```typescript
// BAD: No validation
app.post('/user', (req, res) => {
const user = db.create({
name: req.body.name,
email: req.body.email,
role: req.body.role // User can set themselves as admin!
});
res.json(user);
});
// GOOD: Validate and sanitize
import { z } from 'zod';
const CreateUserSchema = z.object({
name: z.string().min(1).max(100),
email: z.string().email(),
// role is NOT accepted from input
});
app.post('/user', (req, res) => {
const validated = CreateUserSchema.parse(req.body);
const user = db.create({
...validated,
role: 'user' // Default role, not from input
});
res.json(user);
});
```
**Detection:** Request body/params used directly without validation schema.
---
## Performance Antipatterns
### N+1 Query Problem
Loading related data one record at a time.
```python
# BAD: N+1 queries
def get_orders_with_items():
orders = Order.query.all() # 1 query
for order in orders:
items = OrderItem.query.filter_by(order_id=order.id).all() # N queries
order.items = items
return orders
# GOOD: Eager loading
def get_orders_with_items():
return Order.query.options(
joinedload(Order.items)
).all() # 1 query with JOIN
# GOOD: Batch loading
def get_orders_with_items():
orders = Order.query.all()
order_ids = [o.id for o in orders]
items = OrderItem.query.filter(
OrderItem.order_id.in_(order_ids)
).all() # 2 queries total
# Group items by order_id...
```
**Detection:** Database queries inside loops.
---
### Unbounded Collections
Loading unlimited data into memory.
```go
// BAD: Load all records
func GetAllUsers() ([]User, error) {
return db.Find(&[]User{}) // Could be millions
}
// GOOD: Pagination
func GetUsers(page, pageSize int) ([]User, error) {
offset := (page - 1) * pageSize
return db.Limit(pageSize).Offset(offset).Find(&[]User{})
}
// GOOD: Streaming for large datasets
func ProcessAllUsers(handler func(User) error) error {
rows, err := db.Model(&User{}).Rows()
if err != nil {
return err
}
defer rows.Close()
for rows.Next() {
var user User
db.ScanRows(rows, &user)
if err := handler(user); err != nil {
return err
}
}
return nil
}
```
**Detection:** `findAll()`, `find({})`, or queries without `LIMIT`.
---
### Synchronous I/O in Hot Paths
Blocking operations in request handlers.
```javascript
// BAD: Sync file read on every request
app.get('/config', (req, res) => {
const config = fs.readFileSync('./config.json'); // Blocks event loop
res.json(JSON.parse(config));
});
// GOOD: Load once at startup
const config = JSON.parse(fs.readFileSync('./config.json'));
app.get('/config', (req, res) => {
res.json(config);
});
// GOOD: Async with caching
let configCache = null;
app.get('/config', async (req, res) => {
if (!configCache) {
configCache = JSON.parse(await fs.promises.readFile('./config.json'));
}
res.json(configCache);
});
```
**Detection:** `readFileSync`, `execSync`, or blocking calls in request handlers.
---
## Testing Antipatterns
### Test Code Duplication
Repeating setup in every test.
```typescript
// BAD: Duplicate setup
describe('UserService', () => {
it('should create user', async () => {
const db = await createTestDatabase();
const userRepo = new UserRepository(db);
const emailService = new MockEmailService();
const service = new UserService(userRepo, emailService);
const user = await service.create({ name: 'Test' });
expect(user.name).toBe('Test');
});
it('should update user', async () => {
const db = await createTestDatabase(); // Duplicated
const userRepo = new UserRepository(db); // Duplicated
const emailService = new MockEmailService(); // Duplicated
const service = new UserService(userRepo, emailService); // Duplicated
// ...
});
});
// GOOD: Shared setup
describe('UserService', () => {
let service: UserService;
let db: TestDatabase;
beforeEach(async () => {
db = await createTestDatabase();
const userRepo = new UserRepository(db);
const emailService = new MockEmailService();
service = new UserService(userRepo, emailService);
});
afterEach(async () => {
await db.cleanup();
});
it('should create user', async () => {
const user = await service.create({ name: 'Test' });
expect(user.name).toBe('Test');
});
});
```
---
### Testing Implementation Instead of Behavior
Tests coupled to internal implementation.
```python
# BAD: Testing implementation details
def test_add_item_to_cart():
cart = ShoppingCart()
cart.add_item(Product("Apple", 1.00))
# Testing internal structure
assert cart._items[0].name == "Apple"
assert cart._total == 1.00
# GOOD: Testing behavior
def test_add_item_to_cart():
cart = ShoppingCart()
cart.add_item(Product("Apple", 1.00))
# Testing public behavior
assert cart.item_count == 1
assert cart.total == 1.00
assert cart.contains("Apple")
```
---
## Async Antipatterns
### Floating Promises
Promises without await or catch.
```typescript
// BAD: Floating promise
async function saveUser(user: User) {
db.save(user); // Not awaited, errors lost
logger.info('User saved'); // Logs before save completes
}
// BAD: Fire and forget in loop
for (const item of items) {
processItem(item); // All run in parallel, no error handling
}
// GOOD: Await the promise
async function saveUser(user: User) {
await db.save(user);
logger.info('User saved');
}
// GOOD: Process with proper handling
await Promise.all(items.map(item => processItem(item)));
// Or sequentially
for (const item of items) {
await processItem(item);
}
```
**Detection:** Async function calls without `await` or `.then()`.
---
### Callback Hell
Deeply nested callbacks.
```javascript
// BAD: Callback hell
getUser(userId, (err, user) => {
if (err) return handleError(err);
getOrders(user.id, (err, orders) => {
if (err) return handleError(err);
getProducts(orders[0].productIds, (err, products) => {
if (err) return handleError(err);
renderPage(user, orders, products, (err) => {
if (err) return handleError(err);
console.log('Done');
});
});
});
});
// GOOD: Async/await
async function loadPage(userId) {
try {
const user = await getUser(userId);
const orders = await getOrders(user.id);
const products = await getProducts(orders[0].productIds);
await renderPage(user, orders, products);
console.log('Done');
} catch (err) {
handleError(err);
}
}
```
**Detection:** >2 levels of callback nesting.
---
### Async in Constructor
Async operations in constructors.
```typescript
// BAD: Async in constructor
class DatabaseConnection {
constructor(url: string) {
this.connect(url); // Fire-and-forget async
}
private async connect(url: string) {
this.client = await createClient(url);
}
}
// GOOD: Factory method
class DatabaseConnection {
private constructor(private client: Client) {}
static async create(url: string): Promise<DatabaseConnection> {
const client = await createClient(url);
return new DatabaseConnection(client);
}
}
// Usage
const db = await DatabaseConnection.create(url);
```
**Detection:** `async` calls or `.then()` in constructor.
---
## C# / .NET Antipatterns
### `async void`
`async void` cannot be awaited and exceptions cannot be caught by callers — they tear down the process. Only safe for event handlers.
```csharp
// BAD: async void in non-event-handler code
public async void SaveUser(User user)
{
await _db.SaveChangesAsync(); // exception here crashes the host
}
// GOOD: return Task so callers can await + observe exceptions
public async Task SaveUserAsync(User user)
{
await _db.SaveChangesAsync();
}
// EXCEPTION: real event handlers must be `async void` (delegate signature)
private async void OnClick(object sender, EventArgs e)
{
try { await DoWorkAsync(); }
catch (Exception ex) { _logger.LogError(ex, "Click handler failed"); }
}
```
**Detection:** `async\s+void\s+\w+` outside of event-handler signatures.
---
### Blocking on Async (`.Result`, `.Wait()`, `.GetAwaiter().GetResult()`)
Synchronously waiting on a Task from inside a synchronization context (ASP.NET Classic, WinForms, WPF) deadlocks: the continuation needs the context, which is blocked by the caller.
```csharp
// BAD: deadlock in ASP.NET Classic / WPF / WinForms
public IActionResult Index()
{
var data = FetchAsync().Result;
return View(data);
}
// BAD: same issue
public string Synchronous() => FetchAsync().GetAwaiter().GetResult();
// GOOD: be async all the way up
public async Task<IActionResult> Index()
{
var data = await FetchAsync();
return View(data);
}
```
**Detection:** `\.Result`, `\.Wait\(\)`, `\.GetAwaiter\(\)\.GetResult\(\)` on Task-returning calls.
---
### Swallowing `Exception`
Catching the base `Exception` and dropping it hides bugs.
```csharp
// BAD: silent failure
try
{
await _payments.ChargeAsync(order);
}
catch (Exception)
{
// ¯\_(ツ)_/¯
}
// GOOD: catch specific exceptions, log, rethrow or convert
try
{
await _payments.ChargeAsync(order);
}
catch (PaymentDeclinedException ex)
{
_logger.LogWarning(ex, "Payment declined for order {OrderId}", order.Id);
throw new OrderDeclinedException(order.Id, ex);
}
catch (HttpRequestException ex)
{
_logger.LogError(ex, "Payment gateway unreachable");
throw; // bubble up — caller decides retry policy
}
```
**Detection:** `catch (Exception)` with empty body, or no log/rethrow.
---
### Undisposed `IDisposable`
Forgetting `using` leaks file handles, database connections, sockets, etc.
```csharp
// BAD: connection never closed if an exception occurs
public string GetName(int id)
{
var conn = new SqlConnection(_connStr);
conn.Open();
var cmd = new SqlCommand("SELECT name FROM users WHERE id = @id", conn);
cmd.Parameters.AddWithValue("@id", id);
return (string)cmd.ExecuteScalar();
}
// GOOD: `using var` disposes on scope exit, even on exceptions
public string GetName(int id)
{
using var conn = new SqlConnection(_connStr);
using var cmd = new SqlCommand("SELECT name FROM users WHERE id = @id", conn);
cmd.Parameters.AddWithValue("@id", id);
conn.Open();
return (string)cmd.ExecuteScalar();
}
```
**Detection:** `new\s+\w+(?:Stream|Connection|Reader|Writer|Client|Context|Command)\s*\(` not preceded by `using`.
---
### `new HttpClient()` in a Method
Each `HttpClient` opens its own socket pool. Creating one per request exhausts sockets under load.
```csharp
// BAD: socket exhaustion
public async Task<string> FetchAsync(string url)
{
using var client = new HttpClient(); // even disposed, sockets linger
return await client.GetStringAsync(url);
}
// GOOD: IHttpClientFactory via DI
public class ApiClient
{
private readonly HttpClient _client;
public ApiClient(IHttpClientFactory factory) => _client = factory.CreateClient("api");
public Task<string> FetchAsync(string url) => _client.GetStringAsync(url);
}
```
**Detection:** `new\s+HttpClient\s*\(` inside a method body.
---
### Missing `ConfigureAwait(false)` in Library Code
Continuations on the captured synchronization context can deadlock callers blocking on `Result` / `Wait()`, and create unnecessary context switches on hot paths.
```csharp
// BAD (library code):
public async Task<User> LoadAsync(int id)
{
var row = await _db.Users.FindAsync(id); // recaptures context
return Map(row);
}
// GOOD: opt out of the capture in library code
public async Task<User> LoadAsync(int id)
{
var row = await _db.Users.FindAsync(id).ConfigureAwait(false);
return Map(row);
}
```
**Detection:** library projects (not the entry point) where every `await` recaptures context.
**Note:** ASP.NET Core has no synchronization context, so `ConfigureAwait(false)` is *not required* in ASP.NET Core application code — but it doesn't hurt and is mandatory for shared libraries.
---
### Mutable Public Setters on Domain Models
```csharp
// BAD: any caller can mutate state outside the entity's rules
public class Order
{
public OrderStatus Status { get; set; } // anyone can set Shipped
public decimal Total { get; set; }
}
// GOOD: invariants enforced by methods, state only mutable through them
public class Order
{
public OrderStatus Status { get; private set; } = OrderStatus.Pending;
public decimal Total { get; private set; }
public void MarkShipped(IShippingProvider shipper)
{
if (Status != OrderStatus.Paid)
throw new InvalidOperationException("Cannot ship unpaid order");
shipper.Ship(this);
Status = OrderStatus.Shipped;
}
}
// For DTOs, prefer records with init-only properties
public record OrderDto(int Id, string Status, decimal Total);
```
**Detection:** public domain entities with `{ get; set; }` on every property.
---
### Overuse of `dynamic`
`dynamic` opts out of type checking. Use only when you genuinely need late binding (COM interop, ExpandoObject for JSON-shaped data).
```csharp
// BAD: dynamic for ordinary code — typos surface only at runtime
public void Save(dynamic user)
{
_db.Insert(user.Emial); // typo, compiles fine, NullReferenceException at runtime
}
// GOOD: real type
public void Save(User user)
{
_db.Insert(user.Email);
}
```
**Detection:** `\bdynamic\s+\w+\s*[=;]` outside of obvious interop / DOM code.
---
### Suppressing Analyzer Warnings Without Justification
```csharp
// BAD: suppression with no rationale
#pragma warning disable CS8602
var name = user.Name;
#pragma warning restore CS8602
// GOOD: explain WHY the warning is wrong here
// CS8602 is incorrect here: `user` is non-null because we just
// validated it on line 42 inside the same method.
#pragma warning disable CS8602 // justified above
var name = user.Name;
#pragma warning restore CS8602
```
**Detection:** `#pragma warning disable` or `[SuppressMessage]` without an adjacent justification comment.

View file

@ -0,0 +1,49 @@
# Universal Rules — All Languages
These rules apply regardless of language. Load this file for every review, alongside the relevant `languages/*.md` file.
---
## Security
- Flag any string interpolation or concatenation used to build SQL, shell, or LDAP queries — require parameterized queries or a safe API
- Flag hardcoded credentials, API keys, tokens, or secrets anywhere in source — require environment variables or a secrets manager
- Flag user-controlled input passed to file system, process execution, or URL redirect APIs without validation
- Flag overly broad CORS or CSP policies
---
## Async / Concurrency
- Flag shared mutable state accessed from multiple threads/coroutines/tasks without synchronization
- Flag fire-and-forget async operations with no error handling path
- Flag timeouts missing on any network or I/O call
- Flag unbounded queues or thread pools with no backpressure mechanism
---
## Resource Management
- Flag any resource (file, socket, DB connection, HTTP connection) acquired without a guaranteed release path
- Flag connection pools not returned to the pool on all code paths (including exceptions)
- Flag unbounded collections that grow without eviction — potential memory leak
- Flag resources held open longer than the operation they serve
---
## Exception Handling
- Flag empty catch/except blocks — swallowed exceptions hide bugs silently
- Flag catching the broadest possible exception type (`Exception`, `Throwable`, `error`) where a specific type is appropriate
- Flag exceptions used for normal control flow (signaling "not found", etc.) — use return values or `Optional`
- Flag error context lost when re-throwing — always wrap with the original cause
---
## Performance
- Flag N+1 query patterns — loading a collection then querying for each item individually
- Flag unbounded queries or API calls with no pagination or limit
- Flag synchronous I/O on a thread or event loop that serves concurrent requests
- Flag large objects serialized/deserialized repeatedly when they could be cached
- Flag string concatenation in tight loops — use a builder or join

View file

@ -28,6 +28,7 @@ LANGUAGE_EXTENSIONS = {
"swift": [".swift"],
"kotlin": [".kt", ".kts"],
"csharp": [".cs", ".csx", ".razor", ".cshtml"],
"java": [".java"],
}
# Code smell thresholds
@ -135,6 +136,13 @@ def find_functions(content: str, language: str) -> List[Dict]:
r"override|sealed|abstract|partial|new|readonly|extern)\s+)+"
r"(?:[\w<>?,\s\[\]\.]+?\s+)?(\w+)\s*\(([^)]*)\)"
),
# Java: require at least one method modifier to distinguish
# declarations from invocations (mirrors the C# approach).
"java": (
r"(?:(?:public|private|protected|static|final|abstract|"
r"synchronized|native|default|strictfp)\s+)+"
r"(?:[\w<>?,\s\[\]\.]+?\s+)?(\w+)\s*\(([^)]*)\)"
),
}
pattern = patterns.get(language, patterns["python"])
@ -183,6 +191,7 @@ def find_classes(content: str, language: str) -> List[Dict]:
"swift": r"class\s+(\w+)",
"kotlin": r"class\s+(\w+)",
"csharp": r"(?:class|struct|record|interface)\s+(\w+)",
"java": r"(?:class|interface|enum|record)\s+(\w+)",
}
pattern = patterns.get(language, patterns["python"])
@ -213,6 +222,11 @@ def find_classes(content: str, language: str) -> List[Dict]:
r"override|sealed|abstract|partial)\s+)+"
r"(?:[\w<>?,\s\[\]\.]+?\s+)?\w+\s*\("
),
"java": (
r"(?:(?:public|private|protected|static|final|abstract|"
r"synchronized|native|default|strictfp)\s+)+"
r"(?:[\w<>?,\s\[\]\.]+?\s+)?\w+\s*\("
),
}
method_pattern = method_patterns.get(language, method_patterns["python"])
methods = len(re.findall(method_pattern, class_body))
@ -418,6 +432,88 @@ def check_csharp_specific_smells(content: str) -> List[Dict]:
return smells
def check_java_specific_smells(content: str) -> List[Dict]:
"""Java-specific code smells documented in languages/java.md."""
smells: List[Dict] = []
# Java comment syntax matches C#, so the same stripper applies.
content = _strip_csharp_comments(content)
# Empty catch block — swallows the exception silently.
for match in re.finditer(r"catch\s*\([^)]*\)\s*\{\s*\}", content):
smells.append({
"type": "java_empty_catch",
"severity": "high",
"message": "Empty catch block swallows exceptions silently",
"location": f"offset {match.start()}",
})
# printStackTrace() as error handling — use a logger instead.
for match in re.finditer(r"\.printStackTrace\s*\(\s*\)", content):
smells.append({
"type": "java_print_stack_trace",
"severity": "medium",
"message": (
"'printStackTrace()' is not real error handling — log via a "
"proper logger or rethrow with context"
),
"location": f"offset {match.start()}",
})
# InterruptedException caught without restoring the interrupt flag.
for match in re.finditer(
r"catch\s*\(\s*InterruptedException\s+(\w+)\s*\)\s*\{(.*?)\}",
content,
re.DOTALL,
):
if "interrupt()" not in match.group(2):
smells.append({
"type": "java_swallowed_interrupt",
"severity": "high",
"message": (
"InterruptedException caught without "
"'Thread.currentThread().interrupt()' — breaks cooperative "
"cancellation"
),
"location": f"offset {match.start()}",
})
# Closeable resource instantiated outside try-with-resources (leak heuristic).
resource_hint = re.compile(
r"^(?!\s*try\b)\s*(?:final\s+)?[\w<>\[\]]+\s+\w+\s*=\s*new\s+"
r"(\w*(?:InputStream|OutputStream|Reader|Writer|Stream|Connection))\s*\(",
re.MULTILINE,
)
for match in resource_hint.finditer(content):
smells.append({
"type": "java_unclosed_resource",
"severity": "medium",
"message": (
f"'{match.group(1)}' looks like an AutoCloseable but is not in a "
"try-with-resources statement"
),
"location": f"offset {match.start()}",
})
# Heavy object built per use instead of shared as a singleton.
# A `static` field assignment is the recommended singleton form — skip it.
heavy_object = re.compile(
r"^(?!.*\bstatic\b).*\bnew\s+(ObjectMapper|Gson)\s*\(\s*\)",
re.MULTILINE,
)
for match in heavy_object.finditer(content):
smells.append({
"type": "java_per_use_heavy_object",
"severity": "medium",
"message": (
f"'new {match.group(1)}()' is expensive — share a singleton "
"instance instead of constructing per call"
),
"location": f"offset {match.start()}",
})
return smells
def check_solid_violations(content: str) -> List[Dict]:
"""Check for potential SOLID principle violations."""
violations = []
@ -528,6 +624,8 @@ def analyze_file(filepath: Path) -> Dict:
smells = check_code_smells(content, functions, classes)
if language == "csharp":
smells.extend(check_csharp_specific_smells(content))
if language == "java":
smells.extend(check_java_specific_smells(content))
violations = check_solid_violations(content)
score = calculate_quality_score(line_metrics, functions, classes, smells, violations)

View file

@ -72,9 +72,15 @@ RISK_PATTERNS = [
},
{
"name": "console_log",
"pattern": r"console\.(log|debug|info|warn|error)\(|\bDebug\.WriteLine\(",
"pattern": (
r"console\.(log|debug|info|warn|error)\(|\bDebug\.WriteLine\(|"
r"\bSystem\.out\.print(?:ln)?\(|\.printStackTrace\("
),
"severity": "medium",
"message": "Debug output statement found (console.* / Debug.WriteLine)"
"message": (
"Debug output statement found "
"(console.* / Debug.WriteLine / System.out / printStackTrace)"
)
},
{
"name": "debugger",
@ -84,9 +90,15 @@ RISK_PATTERNS = [
},
{
"name": "analyzer_disable",
"pattern": r"eslint-disable|#pragma\s+warning\s+disable|\[SuppressMessage",
"pattern": (
r"eslint-disable|#pragma\s+warning\s+disable|\[SuppressMessage|"
r"@SuppressWarnings"
),
"severity": "medium",
"message": "Static-analyzer rule disabled (ESLint / Roslyn / SuppressMessage)"
"message": (
"Static-analyzer rule disabled "
"(ESLint / Roslyn / SuppressMessage / @SuppressWarnings)"
)
},
{
"name": "loose_type",

View file

@ -1,7 +1,7 @@
---
name: "engineering-skills"
description: "23 engineering agent skills and plugins for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw, and 6 more tools. Architecture, frontend, backend, QA, DevOps, security, AI/ML, data engineering, Playwright, Stripe, AWS, MS365. 30+ Python tools (stdlib-only)."
version: 1.1.0
version: 2.9.0
author: Alireza Rezvani
license: MIT
tags:

View file

@ -191,6 +191,6 @@ jobs:
---
**Version:** 2.0.0
**Version:** 2.9.0
**Last Updated:** January 2026
**Tech Focus:** React 18+, Next.js 14+, Jest 29+, Playwright 1.40+

View file

@ -1,7 +1,7 @@
{
"name": "snowflake-development",
"description": "Snowflake SQL, data pipelines (Dynamic Tables, Streams+Tasks), Cortex AI functions, Snowpark Python, and dbt integration. Includes query helper script, 3 reference guides, and troubleshooting.",
"version": "2.1.4",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/snowflake-development",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "engineering-advanced-skills",
"description": "40 advanced engineering skills: agent designer, agent workflow designer, AgentHub, RAG architect, database designer, migration architect, observability designer, dependency auditor, release manager, API reviewer, CI/CD pipeline builder, MCP server builder, skill security auditor, performance profiler, Helm chart builder, Terraform patterns, focused-fix, browser-automation, spec-driven-workflow, secrets-vault-manager, sql-database-assistant, self-eval, llm-cost-optimizer, prompt-governance, llm-wiki (second brain for Obsidian + Claude Code, Karpathy pattern), tc-tracker (task context tracker with lifecycle and handoff format), feature-flags-architect, kubernetes-operator, chaos-engineering, ship-gate (pre-production 8-category audit with deploy-intent intercept), slo-architect (SLO designer, error-budget calculator with multi-window burn-rate alerts, SLO reviewer per Google SRE Workbook), and more. Agent skill and plugin for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw.",
"version": "2.4.4",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "agenthub",
"description": "Multi-agent collaboration plugin for Claude Code. Spawn N parallel subagents that compete on code optimization, content drafts, research approaches, or any problem that benefits from diverse solutions. Evaluate by metric or LLM judge, merge the winner. 7 slash commands, agent templates, git DAG orchestration, message board coordination.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/agenthub",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "autoresearch-agent",
"description": "Autonomous experiment loop that optimizes any file by a measurable metric. 5 slash commands, 8 evaluators, configurable loop intervals (10min to monthly).",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/autoresearch-agent",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "behuman",
"description": "Self-Mirror consciousness loop for human-like AI responses. Adds inner dialogue (Self → Mirror → Conscious Response) to make AI output feel authentic, not robotic. Zero dependencies — pure prompt technique.",
"version": "2.2.2",
"description": "Self-Mirror consciousness loop for human-like AI responses. Adds inner dialogue (Self \u2192 Mirror \u2192 Conscious Response) to make AI output feel authentic, not robotic. Zero dependencies \u2014 pure prompt technique.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/behuman",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "caveman",
"description": "Ultra-compressed communication mode. Cuts token usage ~75% by dropping filler, articles, and pleasantries while keeping full technical accuracy. Enhanced from Matt Pocock's MIT-licensed caveman skill (https://github.com/mattpocock/skills) with: (1) stdlib Python tools (text compressor, token-savings estimator, caveman-style linter), (2) 3 reference docs citing 5+ authoritative sources each (compression principles, technical communication patterns, when caveman backfires), (3) cs-caveman-mode persona agent + /cs:caveman slash command. Matt's voice and persistence rules preserved verbatim per MIT. Use when user says \"caveman mode\", \"talk like caveman\", \"use caveman\", \"less tokens\", \"be brief\", or invokes /caveman.",
"version": "1.0.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,7 +9,9 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/caveman",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills/caveman"],
"skills": [
"./skills/caveman"
],
"attribution": {
"derived_from": "https://github.com/mattpocock/skills/tree/main/skills/productivity/caveman",
"original_author": "Matt Pocock (@mattpocock)",

View file

@ -1,7 +1,7 @@
{
"name": "chaos-engineering",
"description": "End-to-end chaos engineering discipline: design experiments with hypothesis + steady-state metric + blast radius + abort criteria, calculate risk score against error budget, and generate blameless postmortems. 3 stdlib Python tools (experiment_designer, blast_radius_calculator, experiment_postmortem), 4 references on chaos principles + experiment design + 7-attack taxonomy + tooling landscape (Chaos Toolkit/Mesh/Litmus/Gremlin/AWS FIS/DIY), templates for plans + postmortems, and a /chaos-experiment slash command. Composes with feature-flags-architect (kill switches as abort triggers) and kubernetes-operator (chaos targets).",
"version": "2.4.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/chaos-engineering",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -2,7 +2,7 @@
name: chaos-engineering
description: Use when planning, running, or learning from chaos engineering experiments. Triggers on "chaos experiment", "fault injection", "gameday", "resilience test", "blast radius", "steady state", "abort criteria", "Chaos Toolkit", "Chaos Mesh", "Litmus", "Gremlin", "AWS FIS", or any deliberate failure-injection question. Ships experiment designer, blast-radius calculator, and postmortem generator (all stdlib Python), 4 references on chaos principles + experiment design + attack taxonomy + tooling landscape, and a /chaos-experiment slash command. Composes with feature-flags-architect (kill switches as abort triggers) and kubernetes-operator (common chaos targets).
context: fork
version: 2.4.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [chaos-engineering, resilience, fault-injection, gameday, sre, reliability, chaos-toolkit, chaos-mesh, litmus, gremlin, aws-fis]

View file

@ -1,7 +1,7 @@
{
"name": "claude-coach",
"description": "Personal Claude power-user coach. On first activation, delivers a personalized, ranked cheat-code glossary filtered to the user's use cases. On every subsequent turn, scans for missed power-user opportunities and surfaces at most ONE ⚡ tip when a tip would genuinely 10x the next attempt. Silence is the default. Ships SKILL.md, cheat-codes glossary, coaching-rules decision tree, and three stdlib Python tools (cheat-code filter, prompt rater, 5-gate tip classifier). Includes cs-claude-coach agent persona and /cs:claude-coach slash command.",
"version": "1.0.0",
"description": "Personal Claude power-user coach. On first activation, delivers a personalized, ranked cheat-code glossary filtered to the user's use cases. On every subsequent turn, scans for missed power-user opportunities and surfaces at most ONE \u26a1 tip when a tip would genuinely 10x the next attempt. Silence is the default. Ships SKILL.md, cheat-codes glossary, coaching-rules decision tree, and three stdlib Python tools (cheat-code filter, prompt rater, 5-gate tip classifier). Includes cs-claude-coach agent persona and /cs:claude-coach slash command.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/claude-coach",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills/claude-coach"]
"skills": [
"./skills/claude-coach"
]
}

View file

@ -7,7 +7,7 @@ Category: meta
Author: claude-skills
Dependencies: python3.11
Version: 1.0.0
version: 1.0.0
version: 2.9.0
license: MIT
---

View file

@ -1,7 +1,7 @@
{
"name": "code-tour",
"description": "Create CodeTour .tour files — persona-targeted, step-by-step walkthroughs that link to real files and line numbers. Supports 10 developer personas (vibecoder, new joiner, architect, security reviewer, etc.), all CodeTour step types, and SMIG description formula.",
"version": "2.2.2",
"description": "Create CodeTour .tour files \u2014 persona-targeted, step-by-step walkthroughs that link to real files and line numbers. Supports 10 developer personas (vibecoder, new joiner, architect, security reviewer, etc.), all CodeTour step types, and SMIG description formula.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/code-tour",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "data-quality-auditor",
"description": "Audit datasets for completeness, consistency, accuracy, and validity. 3 stdlib-only Python tools: data profiler with DQS scoring, missing value analyzer with MCAR/MAR/MNAR classification, and multi-method outlier detector.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/data-quality-auditor",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "demo-video",
"description": "Create polished demo videos from screenshots and scene descriptions. Orchestrates playwright, ffmpeg, and edge-tts to produce product walkthroughs, feature showcases, and marketing teasers with story structure, scene design system, and narration guidance.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/demo-video",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "docker-development",
"description": "Docker and container development agent skill and plugin for Dockerfile optimization, docker-compose orchestration, multi-stage builds, and container security hardening. Covers build performance, layer caching, and production-ready container patterns.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/docker-development",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "feature-flags-architect",
"description": "End-to-end feature-flag discipline: classify, ship, ramp, retire. Detects stale flags as debt, generates phased rollout plans (ring/linear/log/cohort), and audits every flag for a documented kill switch. 3 stdlib Python tools, 4 references on flag taxonomy + provider trade-offs (LaunchDarkly/GrowthBook/Statsig/Unleash/Flipt/DIY) + rollout strategies + lifecycle. /flag-cleanup slash command. Cross-tool compatible.",
"version": "2.4.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/feature-flags-architect",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -2,7 +2,7 @@
name: feature-flags-architect
description: Use when adding, retiring, or auditing feature flags. Triggers on "add a flag", "ship behind a flag", "rollout plan", "kill switch", "stale flags", "flag debt", "LaunchDarkly", "GrowthBook", "Statsig", "Unleash", "Flipt", or any progressive-delivery question. Ships flag debt scanner, rollout planner, and kill-switch auditor (all stdlib Python), 4 references on flag taxonomy + provider trade-offs + rollout strategies + lifecycle, plus a /flag-cleanup slash command.
context: fork
version: 2.4.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [feature-flags, progressive-delivery, rollout, kill-switch, launchdarkly, growthbook, statsig, unleash, flipt, release-engineering]

View file

@ -1,7 +1,7 @@
{
"name": "grill-me",
"description": "Relentless plan-and-design interrogator. Walks the decision tree of a plan one branch at a time, asking forcing questions sequentially with recommended answers. Explores codebase to resolve answers where possible. Enhanced from Matt Pocock's MIT-licensed grill-me skill (https://github.com/mattpocock/skills) with: (1) stdlib Python tools (decision-tree extractor, question generator, session-state tracker), (2) 3 reference docs citing 5+ authoritative sources each (forcing-question patterns, decision-tree completeness, when to stop grilling), (3) cs-grill-master persona agent + /cs:grill-me slash command. Matt's relentless one-at-a-time interview discipline preserved verbatim per MIT. Use when user wants to stress-test a plan, get grilled on their design, or says \"grill me\".",
"version": "1.0.0",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,7 +9,9 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/grill-me",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills/grill-me"],
"skills": [
"./skills/grill-me"
],
"attribution": {
"derived_from": "https://github.com/mattpocock/skills/tree/main/skills/productivity/grill-me",
"original_author": "Matt Pocock (@mattpocock)",

View file

@ -1,7 +1,7 @@
{
"name": "grill-with-docs",
"description": "Docs-anchored grilling session — interrogates a plan against the project's existing language (CONTEXT.md) and recorded decisions (docs/adr/), updating those files inline as terminology and decisions crystallise. Derived from Matt Pocock's MIT-licensed grill-with-docs skill (https://github.com/mattpocock/skills) with: (1) 3 stdlib Python tools (CONTEXT.md linter, ADR scanner, glossary-to-code consistency check), (2) 3 reference docs each citing 7+ authoritative sources on ubiquitous language, ADR practice, and CONTEXT.md as a living artifact, (3) cs-grill-with-docs persona agent + /cs:grill-with-docs slash command. Matt's interview discipline + domain-awareness rules + ADR-when-3-criteria-are-met gate preserved verbatim per MIT.",
"version": "1.0.0",
"description": "Docs-anchored grilling session \u2014 interrogates a plan against the project's existing language (CONTEXT.md) and recorded decisions (docs/adr/), updating those files inline as terminology and decisions crystallise. Derived from Matt Pocock's MIT-licensed grill-with-docs skill (https://github.com/mattpocock/skills) with: (1) 3 stdlib Python tools (CONTEXT.md linter, ADR scanner, glossary-to-code consistency check), (2) 3 reference docs each citing 7+ authoritative sources on ubiquitous language, ADR practice, and CONTEXT.md as a living artifact, (3) cs-grill-with-docs persona agent + /cs:grill-with-docs slash command. Matt's interview discipline + domain-awareness rules + ADR-when-3-criteria-are-met gate preserved verbatim per MIT.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,7 +9,9 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/grill-with-docs",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills/grill-with-docs"],
"skills": [
"./skills/grill-with-docs"
],
"attribution": {
"derived_from": "https://github.com/mattpocock/skills/tree/main/skills/engineering/grill-with-docs",
"original_author": "Matt Pocock (@mattpocock)",

View file

@ -1,7 +1,7 @@
{
"name": "handoff",
"description": "Conversation-handoff document generator. Compacts the current conversation into a markdown handoff so a fresh agent can continue. References existing artifacts (PRDs, plans, ADRs, issues, commits) by path/URL — does not duplicate them. Enhanced from Matt Pocock's MIT-licensed handoff skill (https://github.com/mattpocock/skills) with: (1) stdlib Python tools (template generator, artifact deduplicator, skill recommender), (2) 3 reference docs citing 5+ authoritative sources each (handoff structure, deduplication discipline, next-session skill matching), (3) cs-handoff-author persona agent + /cs:handoff slash command. Matt's no-duplication discipline preserved verbatim per MIT. Use when user wants to hand off the current conversation to a fresh agent or starts a new session that picks up prior work.",
"version": "1.0.0",
"description": "Conversation-handoff document generator. Compacts the current conversation into a markdown handoff so a fresh agent can continue. References existing artifacts (PRDs, plans, ADRs, issues, commits) by path/URL \u2014 does not duplicate them. Enhanced from Matt Pocock's MIT-licensed handoff skill (https://github.com/mattpocock/skills) with: (1) stdlib Python tools (template generator, artifact deduplicator, skill recommender), (2) 3 reference docs citing 5+ authoritative sources each (handoff structure, deduplication discipline, next-session skill matching), (3) cs-handoff-author persona agent + /cs:handoff slash command. Matt's no-duplication discipline preserved verbatim per MIT. Use when user wants to hand off the current conversation to a fresh agent or starts a new session that picks up prior work.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,7 +9,9 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/handoff",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills/handoff"],
"skills": [
"./skills/handoff"
],
"attribution": {
"derived_from": "https://github.com/mattpocock/skills/tree/main/skills/productivity/handoff",
"original_author": "Matt Pocock (@mattpocock)",

View file

@ -1,7 +1,7 @@
{
"name": "helm-chart-builder",
"description": "Helm chart development agent skill and plugin for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw — chart scaffolding, values design, template patterns, dependency management, security hardening, and chart testing.",
"version": "2.2.2",
"description": "Helm chart development agent skill and plugin for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw \u2014 chart scaffolding, values design, template patterns, dependency management, security hardening, and chart testing.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/helm-chart-builder",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "karpathy-coder",
"description": "Active coding discipline enforcer based on Karpathy's 4 principles: surface assumptions, keep it simple, make surgical changes, define verifiable goals. Ships 4 Python tools (complexity_checker, diff_surgeon, assumption_linter, goal_verifier), a review agent, /karpathy-check slash command, and a pre-commit hook. All tools stdlib-only.",
"version": "2.3.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/karpathy-coder",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -2,7 +2,7 @@
name: karpathy-coder
description: Use when writing, reviewing, or committing code to enforce Karpathy's 4 coding principles — surface assumptions before coding, keep it simple, make surgical changes, define verifiable goals. Triggers on "review my diff", "check complexity", "am I overcomplicating this", "karpathy check", "before I commit", or any code quality concern where the LLM might be overcoding.
context: fork
version: 2.3.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [code-quality, discipline, karpathy, simplicity, surgical-changes, anti-patterns, review]

View file

@ -1,7 +1,7 @@
{
"name": "kubernetes-operator",
"description": "End-to-end Kubernetes Operator discipline: CRD design, reconcile-loop patterns, and OperatorHub Capability Levels. Ships CRD validator, reconcile-loop linter, and capability auditor (3 stdlib Python tools), 4 references on the operator pattern + CRD design + reconcile patterns + framework comparison (controller-runtime/kubebuilder/operator-sdk/metacontroller/KOPF), CRD + Go controller skeletons, and /operator-audit slash command. NOT a generic k8s skill — specifically the Operator pattern.",
"version": "2.4.0",
"description": "End-to-end Kubernetes Operator discipline: CRD design, reconcile-loop patterns, and OperatorHub Capability Levels. Ships CRD validator, reconcile-loop linter, and capability auditor (3 stdlib Python tools), 4 references on the operator pattern + CRD design + reconcile patterns + framework comparison (controller-runtime/kubebuilder/operator-sdk/metacontroller/KOPF), CRD + Go controller skeletons, and /operator-audit slash command. NOT a generic k8s skill \u2014 specifically the Operator pattern.",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/kubernetes-operator",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -2,7 +2,7 @@
name: kubernetes-operator
description: Use when building a Kubernetes Operator — custom controllers that reconcile CRD state. Triggers on "build an operator", "CRD design", "reconcile loop", "controller-runtime", "kubebuilder", "operator-sdk", "metacontroller", "KOPF", "operator capability levels", or "custom resource". Ships CRD validator, reconcile-loop linter, and OperatorHub capability auditor (all stdlib Python), 4 references on the operator pattern + CRD design + reconcile patterns + tooling landscape, and a /operator-audit slash command. NOT a generic k8s skill — specifically the Operator pattern.
context: fork
version: 2.4.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [kubernetes, operator, crd, controller-runtime, kubebuilder, operator-sdk, metacontroller, kopf, reconcile, devops]

View file

@ -1,7 +1,7 @@
{
"name": "llm-cost-optimizer",
"description": "Use when you need to reduce LLM API spend, control token usage, route between models by cost/quality, implement prompt caching, or build cost observability for AI features. Triggers: 'my AI costs are ",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/llm-cost-optimizer",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "llm-wiki",
"description": "Turn Claude Code + Obsidian into a second brain. The LLM incrementally ingests sources into a persistent, interlinked markdown wiki — building entity/concept/source pages, flagging contradictions, maintaining an index and log. Knowledge compounds instead of being re-derived by RAG on every query. Inspired by Karpathy's LLM Wiki gist. Ships SKILL, 3 sub-agents, 5 slash commands, 8 Python tools (stdlib only), full vault templates, and cross-tool compatibility (Claude Code, Codex CLI, Cursor, Antigravity, OpenCode, Gemini CLI).",
"version": "2.3.2",
"description": "Turn Claude Code + Obsidian into a second brain. The LLM incrementally ingests sources into a persistent, interlinked markdown wiki \u2014 building entity/concept/source pages, flagging contradictions, maintaining an index and log. Knowledge compounds instead of being re-derived by RAG on every query. Inspired by Karpathy's LLM Wiki gist. Ships SKILL, 3 sub-agents, 5 slash commands, 8 Python tools (stdlib only), full vault templates, and cross-tool compatibility (Claude Code, Codex CLI, Cursor, Antigravity, OpenCode, Gemini CLI).",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/llm-wiki",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -2,7 +2,7 @@
name: llm-wiki
description: Use when building or maintaining a persistent personal knowledge base (second brain) in Obsidian where an LLM incrementally ingests sources, updates entity/concept pages, maintains cross-references, and keeps a synthesis current. Triggers include "second brain", "Obsidian wiki", "personal knowledge management", "ingest this paper/article/book", "build a research wiki", "compound knowledge", "Memex", or whenever the user wants knowledge to accumulate across sessions instead of being re-derived by RAG on every query.
context: fork
version: 1.0.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [knowledge-management, obsidian, second-brain, pkm, rag-alternative, wiki, karpathy, memex]

View file

@ -1,7 +1,7 @@
{
"name": "prompt-governance",
"description": "Use when managing prompts in production at scale: versioning prompts, running A/B tests on prompts, building prompt registries, preventing prompt regressions, or creating eval pipelines for production",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/prompt-governance",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -2,7 +2,7 @@
name: chaos-engineering
description: Use when planning, running, or learning from chaos engineering experiments. Triggers on "chaos experiment", "fault injection", "gameday", "resilience test", "blast radius", "steady state", "abort criteria", "Chaos Toolkit", "Chaos Mesh", "Litmus", "Gremlin", "AWS FIS", or any deliberate failure-injection question. Ships experiment designer, blast-radius calculator, and postmortem generator (all stdlib Python), 4 references on chaos principles + experiment design + attack taxonomy + tooling landscape, and a /chaos-experiment slash command. Composes with feature-flags-architect (kill switches as abort triggers) and kubernetes-operator (common chaos targets).
context: fork
version: 2.4.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [chaos-engineering, resilience, fault-injection, gameday, sre, reliability, chaos-toolkit, chaos-mesh, litmus, gremlin, aws-fis]

View file

@ -1,7 +1,7 @@
---
name: "engineering-advanced-skills"
description: "25 advanced engineering agent skills and plugins for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw. Agent design, RAG, MCP servers, CI/CD, database design, observability, security auditing, release management, platform ops."
version: 1.1.0
version: 2.9.0
author: Alireza Rezvani
license: MIT
tags:

View file

@ -2,7 +2,7 @@
name: feature-flags-architect
description: Use when adding, retiring, or auditing feature flags. Triggers on "add a flag", "ship behind a flag", "rollout plan", "kill switch", "stale flags", "flag debt", "LaunchDarkly", "GrowthBook", "Statsig", "Unleash", "Flipt", or any progressive-delivery question. Ships flag debt scanner, rollout planner, and kill-switch auditor (all stdlib Python), 4 references on flag taxonomy + provider trade-offs + rollout strategies + lifecycle, plus a /flag-cleanup slash command.
context: fork
version: 2.4.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [feature-flags, progressive-delivery, rollout, kill-switch, launchdarkly, growthbook, statsig, unleash, flipt, release-engineering]

View file

@ -2,7 +2,7 @@
name: kubernetes-operator
description: Use when building a Kubernetes Operator — custom controllers that reconcile CRD state. Triggers on "build an operator", "CRD design", "reconcile loop", "controller-runtime", "kubebuilder", "operator-sdk", "metacontroller", "KOPF", "operator capability levels", or "custom resource". Ships CRD validator, reconcile-loop linter, and OperatorHub capability auditor (all stdlib Python), 4 references on the operator pattern + CRD design + reconcile patterns + tooling landscape, and a /operator-audit slash command. NOT a generic k8s skill — specifically the Operator pattern.
context: fork
version: 2.4.0
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [kubernetes, operator, crd, controller-runtime, kubebuilder, operator-sdk, metacontroller, kopf, reconcile, devops]

View file

@ -2,7 +2,7 @@
name: slo-architect
description: Use when defining, reviewing, or operating SLOs/SLIs/error budgets. Triggers on "define an SLO", "what should our SLO be", "error budget", "burn rate", "SLI", "service level objective", "Google SRE workbook", "multi-window burn-rate alert", or any reliability-target question. Ships SLO designer, error-budget calculator with multi-window burn-rate thresholds, and SLO reviewer that catches the common bugs (target too aggressive, window too short, conflicting SLOs, no SLI definition). 4 references on SLO principles + SLI design + error budget math + composition with feature-flags-architect/chaos-engineering/kubernetes-operator. NOT a generic observability skill — specifically the SLO discipline.
context: fork
version: 2.4.4
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [slo, sli, sla, error-budget, burn-rate, sre, reliability, google-sre-workbook, observability]

View file

@ -1,7 +1,7 @@
{
"name": "slo-architect",
"description": "End-to-end SLO/SLI/error-budget discipline per Google SRE Workbook. Ships SLO designer (refuses to render without required fields), error-budget calculator with multi-window burn-rate alert thresholds (PromQL-shaped), and SLO reviewer that catches the 7 common bugs (target too high, window too short, no SLI definition, CPU-as-SLI, etc.). 4 references on principles + SLI design + error budget math + composition with feature-flags-architect/chaos-engineering/kubernetes-operator. Asset templates for SLO YAML and error budget policy. /slo-design slash command. NOT a generic observability skill.",
"version": "2.4.4",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/slo-architect",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -2,7 +2,7 @@
name: slo-architect
description: Use when defining, reviewing, or operating SLOs/SLIs/error budgets. Triggers on "define an SLO", "what should our SLO be", "error budget", "burn rate", "SLI", "service level objective", "Google SRE workbook", "multi-window burn-rate alert", or any reliability-target question. Ships SLO designer, error-budget calculator with multi-window burn-rate thresholds, and SLO reviewer that catches the common bugs (target too aggressive, window too short, conflicting SLOs, no SLI definition). 4 references on SLO principles + SLI design + error budget math + composition with feature-flags-architect/chaos-engineering/kubernetes-operator. NOT a generic observability skill — specifically the SLO discipline.
context: fork
version: 2.4.4
version: 2.9.0
author: claude-code-skills
license: MIT
tags: [slo, sli, sla, error-budget, burn-rate, sre, reliability, google-sre-workbook, observability]

View file

@ -1,7 +1,7 @@
{
"name": "statistical-analyst",
"description": "Hypothesis testing, A/B experiment analysis, sample size calculation, and confidence intervals. 3 stdlib-only Python tools with Z-test, t-test, chi-square, effect sizes, power analysis, and Wilson score intervals.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/statistical-analyst",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -1,7 +1,7 @@
{
"name": "terraform-patterns",
"description": "Terraform infrastructure-as-code agent skill and plugin for module design patterns, state management strategies, provider configuration, security hardening, and CI/CD plan/apply workflows. Covers mono-repo vs multi-repo, workspaces, policy-as-code, and drift detection.",
"version": "2.2.2",
"version": "2.9.0",
"author": {
"name": "Alireza Rezvani",
"url": "https://alirezarezvani.com"
@ -9,5 +9,7 @@
"homepage": "https://github.com/alirezarezvani/claude-skills/tree/main/engineering/terraform-patterns",
"repository": "https://github.com/alirezarezvani/claude-skills",
"license": "MIT",
"skills": ["./skills"]
"skills": [
"./skills"
]
}

View file

@ -603,7 +603,7 @@ jobs:
```yaml
# infracost.yml — policy file
version: 0.1
version: 2.9.0
policies:
- path: "*"
max_monthly_cost: "5000" # Fail PR if estimated cost exceeds $5,000/month

Some files were not shown because too many files have changed in this diff Show more