USB — Universal Skill Bridge
Universal Skill Bridge v0.4.1
Plug & Play
MIT

One skill format. Every agent runtime.

Write once. Install anywhere. USB is the bridge: a single portable skill format with sha256-verified installers for 16 runtimes — Claude Code, Cursor, MCP, LangChain, local models, and more — backed by a 529-skill catalog, one npm install away.

One-Click Bridge

Pick Your Agent Platform

No telemetry by default
▼
Install Command● Live
npm install -g @peepsick/usb-cli usb install

Published on the npm registry as @peepsick/usb-cli — no raw curl | bash, auditable like any other package.

Auto-detect Bridge

Auto-detects the active agent runtime on your machine. LeoSIS folders are checked first, then Claude, Hermes, Cursor, LangChain, and finally falls back to generic markdown + JSON manifest when no known runtime is found.

Target Install Directory

$AI_SKILL_HOME or $HOME/.ai-skills

Privacy

The installer writes skill markdown, adapter manifest, cursor rule, and a local installed.json into ~/.ai-skills/<pack>/ plus your runtime-specific folder (e.g. ~/.claude/skills/, ~/.leosis/skills/, …). Nothing leaves your device unless you opt in with USB_TELEMETRY=on.

Demo

From catalog to running agent in 30 seconds.

USB demo: browse the catalog, try any skill live, install with one npm install command.

Step 1: Browse 529 skills, 65 domains, 14 categories, or 6 curated presets.  Step 2: Try any skill live — inspect the prompt template, inputs, outputs and examples before you install.  Step 3: One npm install — auto-detects your runtime and drops the right files into ~/.leosis/skills/ (or ~/.claude/, ~/.hermes/, …). Prefer raw bash? A curl-and-verify path is one click away.

Modular Skills

529

Seeded active agent capabilities

Agent Adapters

16

Different runtimes & platforms

Live Endpoints

8

Skills, Install, Audit, Version, SHA-256, Health

Database

PostgreSQL

Fully typed via Drizzle ORM

Architecture

Plugin-Like Modular Bridge

This system stores agent capabilities database-side, independent of model or runtime. A single-line bash script auto-detects your orchestrator (Claude, Hermes, Cursor, LangChain, etc.) and writes the correct configuration files — no manual setup required.

1

PostgreSQL Database

Skill bundles and installation records are stored in relational tables with typed JSONB fields via Drizzle ORM.

2

Dynamic Manifest

`/api/skills` compiles the contract for all 529 capabilities into a portable JSON bundle targeted at your platform.

3

Terminal Installer

`/api/install` analyses your environment and writes the correct markdown, manifest, and rule files to the appropriate folders.

4

Instant Activation

Your AI agent automatically discovers and executes the new capabilities without any reconfiguration.

flowchart LR
    U(["Developer or AI Agent"]) -->|picks skill or filter| A["USB Catalog API<br/>/api/skills?slug=..."]
    A -->|applyFilter| F["Filter Engine<br/>529 → 1-N skills"]
    F -->|renderInstallScript| S["Bash Installer<br/>/api/install"]
    S -->|"curl ... | bash"| I["Agent Skill Dir<br/>~/.leosis/skills/"]
    I -->|discovered| M["AI Model<br/>Claude, Hermes, Cursor, ..."]
    classDef user fill:#0f172a,stroke:#22d3ee,stroke-width:2px,color:#fff;
    classDef api fill:#1e293b,stroke:#a855f7,stroke-width:2px,color:#fff;
    classDef agent fill:#1e293b,stroke:#f472b6,stroke-width:2px,color:#fff;
    class U user;
    class A,F,S api;
    class I,M agent;

Skill Catalog

Universal Skill Bridge Catalog

A fully original, from-scratch catalog across 16 provider targets: 65 hand-researched engineering domains systematically expanded across 8 workflows (Audit, Plan, Build, Script, Diagnose, Harden, Explain, Tune) into 529 skills, plus 9 hand-written core orchestration skills. Every skill has a distinct trigger phrase, protocol prompt, input/output contract and examples — zero external dependencies.

GitHub: Universal Skill Bridge
Total 529 skillsFiltered 529Showing 96

Audit

A/B Testing Framework: Audit

low

[A/B Testing Framework] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets experiment spec / variant assignment / metric definition / statistical analysis script. Known failure pattern: Running A/B tests with sample sizes too small to reach statistical significance, leading to decisions based on noise.. Best practice: Use an online sample size calculator before starting the test. Define the minimum detectable effect and ensure the test runs for at least one full business cycle..

Trigger

You need to examine the current "A/B Testing Framework" setup without making changes. Look for the specific failure pattern: "Running A/B tests with sample sizes too small to reach statistical significance, leading to decisions based on noise.". Call this when you want a structured inventory before deciding what to modify.

target:a-b-testing-frameworkworkflow:auditauditab-testingexperimentsproduct

Audit

Accessibility ARIA Patterns: Audit

low

[Accessibility ARIA Patterns] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets ARIA attribute refactor / keyboard navigation / focus management / screen reader test script. Known failure pattern: Adding ARIA attributes that conflict with native HTML semantics (e.g., role='button' on a <button> element), confusing screen readers.. Best practice: Use native HTML elements whenever possible. Only use ARIA to supplement missing semantics, never to override existing ones. Test with a real screen reader..

Trigger

You need to examine the current "Accessibility ARIA Patterns" setup without making changes. Look for the specific failure pattern: "Adding ARIA attributes that conflict with native HTML semantics (e.g., role='button' on a <button> element), confusing screen readers.". Call this when you want a structured inventory before deciding what to modify.

target:a11y-aria-patternsworkflow:auditauditaccessibilityariatesting

Audit

Agent Tool Binding & Dispatch: Audit

low

[Agent Tool Binding & Dispatch] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets router tool / domain group / dynamic tool injection / tool usage statistics. Known failure pattern: Giving the agent too many tools at once, causing it to spend more time choosing than executing, and increasing token usage significantly.. Best practice: Group tools by domain and offer a 'router' tool first. The agent picks a domain, then that domain's tools are injected. This reduces the tool set per step..

Trigger

You need to examine the current "Agent Tool Binding & Dispatch" setup without making changes. Look for the specific failure pattern: "Giving the agent too many tools at once, causing it to spend more time choosing than executing, and increasing token usage significantly.". Call this when you want a structured inventory before deciding what to modify.

target:agent-tool-bindingworkflow:auditauditagentstool-bindingorchestration

Audit

Analytics Metric Definitions: Audit

low

[Analytics Metric Definitions] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets metric definition / dbt model / SQL logic / dashboard tile / documentation. Known failure pattern: Different teams computing the same metric (e.g., 'daily active users') with different SQL logic, producing conflicting numbers.. Best practice: Define every metric in a central repository as a dbt model or LookML view with a single source of truth, and document its logic explicitly..

Trigger

You need to examine the current "Analytics Metric Definitions" setup without making changes. Look for the specific failure pattern: "Different teams computing the same metric (e.g., 'daily active users') with different SQL logic, producing conflicting numbers.". Call this when you want a structured inventory before deciding what to modify.

target:analytics-metric-definitionworkflow:auditauditanalyticsmetricsdata

Audit

Architecture Decision Records: Audit

low

[Architecture Decision Records] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets ADR document / decision log / template / review workflow. Known failure pattern: Making important architectural decisions without documenting the context, alternatives, and rationale, leaving future team members confused about why something was done.. Best practice: Write an ADR for every non-trivial decision. Include the context, considered alternatives (with pros/cons of each), the chosen option, and the consequences..

Trigger

You need to examine the current "Architecture Decision Records" setup without making changes. Look for the specific failure pattern: "Making important architectural decisions without documenting the context, alternatives, and rationale, leaving future team members confused about why something was done.". Call this when you want a structured inventory before deciding what to modify.

target:adr-documentationworkflow:auditauditdocumentationadrarchitecture

Audit

AWS Lambda Cold Starts: Audit

low

[AWS Lambda Cold Starts] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets handler refactor / SnapStart config / Provisioned Concurrency / warmer function. Known failure pattern: Cold starts lasting multiple seconds because the function loads heavy dependencies or initialises database connections outside the handler.. Best practice: Move initialisation (DB connections, config loading) outside the handler. Use Lambda SnapStart for Java or .NET. Consider Provisioned Concurrency for latency-sensitive functions..

Trigger

You need to examine the current "AWS Lambda Cold Starts" setup without making changes. Look for the specific failure pattern: "Cold starts lasting multiple seconds because the function loads heavy dependencies or initialises database connections outside the handler.". Call this when you want a structured inventory before deciding what to modify.

target:aws-lambda-cold-startworkflow:auditauditawslambdaperformance

Audit

Azure Bicep Infrastructure: Audit

low

[Azure Bicep Infrastructure] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets main.bicep / module / parameter file / azd template. Known failure pattern: Manually creating resources in the portal without infrastructure-as-code, making environments inconsistent and hard to reproduce.. Best practice: Always define Azure resources in Bicep or Terraform. Use parameters and modules to keep the code DRY and environment-agnostic..

Trigger

You need to examine the current "Azure Bicep Infrastructure" setup without making changes. Look for the specific failure pattern: "Manually creating resources in the portal without infrastructure-as-code, making environments inconsistent and hard to reproduce.". Call this when you want a structured inventory before deciding what to modify.

target:azure-bicepworkflow:auditauditazurebicepiac

Audit

Browser DevTools & Debugging: Audit

low

[Browser DevTools & Debugging] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets debugging workflow / breakpoint guide / performance recording / memory snapshot. Known failure pattern: Trying to debug frontend issues by guessing instead of using the Elements, Console, Network, and Sources panels systematically.. Best practice: Start with the Network panel to confirm the request/response are correct, then use Sources to set breakpoints, then Elements to inspect the DOM..

Trigger

You need to examine the current "Browser DevTools & Debugging" setup without making changes. Look for the specific failure pattern: "Trying to debug frontend issues by guessing instead of using the Elements, Console, Network, and Sources panels systematically.". Call this when you want a structured inventory before deciding what to modify.

target:browser-devtoolsworkflow:auditauditbrowserdebuggingdevtools

Audit

CLI Tool Design Patterns: Audit

low

[CLI Tool Design Patterns] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets CLI scaffolding / argument parser / exit code handler / --json output mode. Known failure pattern: Building CLI tools that print output without usable exit codes (always exits 0) or swallow error messages, making them impossible to script with.. Best practice: Always exit 0 on success, non-zero on failure. Print errors to stderr, output to stdout. Support --json flag for machine-readable output..

Trigger

You need to examine the current "CLI Tool Design Patterns" setup without making changes. Look for the specific failure pattern: "Building CLI tools that print output without usable exit codes (always exits 0) or swallow error messages, making them impossible to script with.". Call this when you want a structured inventory before deciding what to modify.

target:cli-tool-designworkflow:auditauditclidevtoolsscripting

Audit

Cloud Cost Optimisation: Audit

low

[Cloud Cost Optimisation] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets right-sizing recommendation / auto-stop schedule / reserved instance plan / unused resource report. Known failure pattern: Running oversized instances 'just in case', or leaving development/staging resources running 24/7 when they are only needed during working hours.. Best practice: Right-size instances based on actual usage metrics (not peak theoretical load). Use auto-stop schedules for non-production environments..

Trigger

You need to examine the current "Cloud Cost Optimisation" setup without making changes. Look for the specific failure pattern: "Running oversized instances 'just in case', or leaving development/staging resources running 24/7 when they are only needed during working hours.". Call this when you want a structured inventory before deciding what to modify.

target:cloud-cost-optimizationworkflow:auditauditcloudcostoptimization

Audit

Code Review Checklist: Audit

low

[Code Review Checklist] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets review checklist / automated review comment / risk classification / diff summary. Known failure pattern: Reviewers focusing only on code style and missing architectural issues like missing error handling, security vulnerabilities, or performance regressions.. Best practice: Use a structured review checklist: correctness, security, performance, test coverage, error handling, and code style — in that order..

Trigger

You need to examine the current "Code Review Checklist" setup without making changes. Look for the specific failure pattern: "Reviewers focusing only on code style and missing architectural issues like missing error handling, security vulnerabilities, or performance regressions.". Call this when you want a structured inventory before deciding what to modify.

target:code-review-checklistworkflow:auditauditcode-reviewqualitychecklist

Audit

Convex Functions & Mutations: Audit

low

[Convex Functions & Mutations] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets mutation / query / action / component / scheduler job. Known failure pattern: Accidentally creating OCC (Optimistic Concurrency Control) conflicts by reading and writing the same document in rapid succession from multiple clients.. Best practice: Use patch() for partial updates and batch mutations for atomic multi-document writes. Avoid reading a document before immediately writing it back..

Trigger

You need to examine the current "Convex Functions & Mutations" setup without making changes. Look for the specific failure pattern: "Accidentally creating OCC (Optimistic Concurrency Control) conflicts by reading and writing the same document in rapid succession from multiple clients.". Call this when you want a structured inventory before deciding what to modify.

target:convex-functionsworkflow:auditauditconvexrealtimebackend

Audit

Cron Job & Scheduled Task Reliability: Audit

low

[Cron Job & Scheduled Task Reliability] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets crontab entry / log rotation / idempotency guard / failure alert integration. Known failure pattern: Cron jobs failing silently because output is not logged, or running the same job multiple times when the system is down at the scheduled time.. Best practice: Redirect cron output to a log file with timestamp. Use || to send failure alerts. Implement job idempotency so running it multiple times has no side effects..

Trigger

You need to examine the current "Cron Job & Scheduled Task Reliability" setup without making changes. Look for the specific failure pattern: "Cron jobs failing silently because output is not logged, or running the same job multiple times when the system is down at the scheduled time.". Call this when you want a structured inventory before deciding what to modify.

target:cron-job-reliabilityworkflow:auditauditcronschedulingreliability

Audit

CSS Layout & Responsiveness: Audit

low

[CSS Layout & Responsiveness] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets CSS layout refactor / responsive grid / container query implementation. Known failure pattern: Over-reliance on media queries when container queries or flex/grid intrinsic sizing would be simpler and more maintainable.. Best practice: Design for the content, not the viewport. Use clamp(), minmax(), and auto-fit/auto-fill before reaching for breakpoints..

Trigger

You need to examine the current "CSS Layout & Responsiveness" setup without making changes. Look for the specific failure pattern: "Over-reliance on media queries when container queries or flex/grid intrinsic sizing would be simpler and more maintainable.". Call this when you want a structured inventory before deciding what to modify.

target:css-layoutworkflow:auditauditcsslayoutfrontend

Audit

CSV Data Cleaning Pipeline: Audit

low

[CSV Data Cleaning Pipeline] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets CSV parser / row validator / column type mapper / error report / cleaned output. Known failure pattern: Assuming CSV values are clean and consistent, then hitting parsing errors or silent data corruption when encountering commas inside quoted fields, missing headers, or inconsistent newlines.. Best practice: Always use a proper CSV parser (Python's csv module, Papa Parse in JS) instead of splitting on commas. Validate column count and types for every row..

Trigger

You need to examine the current "CSV Data Cleaning Pipeline" setup without making changes. Look for the specific failure pattern: "Assuming CSV values are clean and consistent, then hitting parsing errors or silent data corruption when encountering commas inside quoted fields, missing headers, or inconsistent newlines.". Call this when you want a structured inventory before deciding what to modify.

target:csv-data-cleaningworkflow:auditauditdatacsvpipeline

Audit

Database Migration Safety: Audit

low

[Database Migration Safety] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets batch migration / expand-contract pattern / zero-downtime migration / rollback plan. Known failure pattern: Running a long-running migration (e.g., adding a column with a default value) that locks the table and causes downtime for active users.. Best practice: Use PostgreSQL's ADD COLUMN DEFAULT (no-rewrite in recent versions) or break the migration into steps: add column without default, backfill in batches, then add default..

Trigger

You need to examine the current "Database Migration Safety" setup without making changes. Look for the specific failure pattern: "Running a long-running migration (e.g., adding a column with a default value) that locks the table and causes downtime for active users.". Call this when you want a structured inventory before deciding what to modify.

target:database-migration-safetyworkflow:auditauditdatabasemigrationsafety

Audit

Data Warehouse Schema Design: Audit

low

[Data Warehouse Schema Design] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets star schema / fact table / dimension table / ETL pipeline spec. Known failure pattern: Using a highly normalised OLTP schema (3NF) directly in a data warehouse, causing complex JOINs and slow analytical queries.. Best practice: Use a star schema (one fact table, multiple dimension tables) or a wide-column denormalised table for analytical queries. Pre-join at loading time..

Trigger

You need to examine the current "Data Warehouse Schema Design" setup without making changes. Look for the specific failure pattern: "Using a highly normalised OLTP schema (3NF) directly in a data warehouse, causing complex JOINs and slow analytical queries.". Call this when you want a structured inventory before deciding what to modify.

target:data-warehouse-schemaworkflow:auditauditdatawarehouseschema

Audit

Design Token Systems: Audit

low

[Design Token Systems] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets token JSON / CSS custom properties / theme switcher / token documentation. Known failure pattern: Hardcoding colors, spacing, or typography values in components instead of referencing design tokens, making theming impossible without changing every file.. Best practice: Define all visual primitives as CSS custom properties or JSON tokens. Reference them in components via token names, not literal values..

Trigger

You need to examine the current "Design Token Systems" setup without making changes. Look for the specific failure pattern: "Hardcoding colors, spacing, or typography values in components instead of referencing design tokens, making theming impossible without changing every file.". Call this when you want a structured inventory before deciding what to modify.

target:design-token-systemworkflow:auditauditdesigntokenscomponents

Audit

Docker Compose Networking: Audit

low

[Docker Compose Networking] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets docker-compose.yml / network config / healthcheck / depends_on condition. Known failure pattern: Services unable to reach each other because they are on different Docker networks, or using 'localhost' instead of the service name.. Best practice: All services in the same docker-compose.yml are on a shared network by default. Reference other services by their service name, not 'localhost'..

Trigger

You need to examine the current "Docker Compose Networking" setup without making changes. Look for the specific failure pattern: "Services unable to reach each other because they are on different Docker networks, or using 'localhost' instead of the service name.". Call this when you want a structured inventory before deciding what to modify.

target:docker-compose-networkingworkflow:auditauditdockernetworkingdevops

Audit

Docker Multi-Stage Builds: Audit

low

[Docker Multi-Stage Builds] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets multi-stage Dockerfile / .dockerignore / slim base image switch. Known failure pattern: Including the entire node_modules and build toolchain in the final production image, making it unnecessarily large and insecure.. Best practice: Use at least two stages: one for installing dev dependencies and building, another for copying only the production artefacts and running the app..

Trigger

You need to examine the current "Docker Multi-Stage Builds" setup without making changes. Look for the specific failure pattern: "Including the entire node_modules and build toolchain in the final production image, making it unnecessarily large and insecure.". Call this when you want a structured inventory before deciding what to modify.

target:docker-multistageworkflow:auditauditdockerbuilddevops

Audit

Drizzle Schema Design: Audit

low

[Drizzle Schema Design] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets schema.ts / relation map / migration SQL / Drizzle query builder. Known failure pattern: Over-using relations() when simple foreign key columns with manual joins would be clearer and faster.. Best practice: Define relations only for eagerly loaded nested data. For simple lookups, just reference the foreign key column directly..

Trigger

You need to examine the current "Drizzle Schema Design" setup without making changes. Look for the specific failure pattern: "Over-using relations() when simple foreign key columns with manual joins would be clearer and faster.". Call this when you want a structured inventory before deciding what to modify.

target:drizzle-schema-designworkflow:auditauditdrizzleschemadatabase

Audit

Error Monitoring & Alerting Setup: Audit

low

[Error Monitoring & Alerting Setup] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets Sentry project config / alert rule / error grouping / source map upload / performance monitoring. Known failure pattern: Setting up error monitoring (Sentry, Datadog) but configuring no alerts, so errors accumulate silently until a user complains.. Best practice: Configure at least two alerts: one for new errors (errors appearing for the first time) and one for error spikes (error count exceeding a threshold)..

Trigger

You need to examine the current "Error Monitoring & Alerting Setup" setup without making changes. Look for the specific failure pattern: "Setting up error monitoring (Sentry, Datadog) but configuring no alerts, so errors accumulate silently until a user complains.". Call this when you want a structured inventory before deciding what to modify.

target:error-monitoring-setupworkflow:auditauditmonitoringerrorsalerts

Audit

FastAPI Dependency Injection: Audit

low

[FastAPI Dependency Injection] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets dependency / lifespan handler / override for testing. Known failure pattern: Re-initialising the same database connection or HTTP client inside every route instead of using FastAPI's dependency injection.. Best practice: Define shared resources (DB pool, HTTP client) as lifespan-managed dependencies and inject them via Depends()..

Trigger

You need to examine the current "FastAPI Dependency Injection" setup without making changes. Look for the specific failure pattern: "Re-initialising the same database connection or HTTP client inside every route instead of using FastAPI's dependency injection.". Call this when you want a structured inventory before deciding what to modify.

target:fastapi-dependenciesworkflow:auditauditfastapidependenciesapi

Audit

Feature Flags & Gradual Rollouts: Audit

low

[Feature Flags & Gradual Rollouts] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets flag provider config / gradual rollout target / flag cleanup plan / A/B test flag. Known failure pattern: Leaving feature flag code in the codebase permanently, making the codebase harder to read and maintain, and never removing old flags.. Best practice: Treat feature flags as temporary. After a flag has been fully rolled out and stable for one release cycle, remove the flag code and the flag condition entirely..

Trigger

You need to examine the current "Feature Flags & Gradual Rollouts" setup without making changes. Look for the specific failure pattern: "Leaving feature flag code in the codebase permanently, making the codebase harder to read and maintain, and never removing old flags.". Call this when you want a structured inventory before deciding what to modify.

target:feature-flagsworkflow:auditauditfeature-flagsrolloutdevops

Audit

Git Conflict Resolution: Audit

low

[Git Conflict Resolution] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets conflict resolution plan / cherry-pick strategy / rebase workflow / merge commit message. Known failure pattern: Resolving merge conflicts by blindly accepting one side without understanding why the change was made, potentially reintroducing bugs.. Best practice: For each conflicted section, trace the origin of both changes using 'git log --oneline' on the file. Understand the intent before picking a resolution..

Trigger

You need to examine the current "Git Conflict Resolution" setup without making changes. Look for the specific failure pattern: "Resolving merge conflicts by blindly accepting one side without understanding why the change was made, potentially reintroducing bugs.". Call this when you want a structured inventory before deciding what to modify.

target:git-conflict-resolutionworkflow:auditauditgitconflictsworkflow

Audit

GitHub Actions Pipeline Optimisation: Audit

low

[GitHub Actions Pipeline Optimisation] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets workflow YAML / cache config / matrix build / conditional job execution. Known failure pattern: Long CI times caused by not caching dependencies between runs, or running the full test suite on every push regardless of change scope.. Best practice: Cache node_modules (or other dependency folders) using actions/cache with a hash of the lock file. Use paths filter to run only relevant jobs..

Trigger

You need to examine the current "GitHub Actions Pipeline Optimisation" setup without making changes. Look for the specific failure pattern: "Long CI times caused by not caching dependencies between runs, or running the full test suite on every push regardless of change scope.". Call this when you want a structured inventory before deciding what to modify.

target:github-actions-pipelineworkflow:auditauditgithub-actionscidevops

Audit

GraphQL N+1 Query Prevention: Audit

low

[GraphQL N+1 Query Prevention] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets DataLoader instance / batch load function / resolver refactor / query complexity analysis. Known failure pattern: A resolver that fetches a parent entity, then for each child calls a separate database query, resulting in N+1 queries for N children.. Best practice: Use DataLoader to batch and cache child-loading queries. DataLoader groups all child-loading calls into a single IN query per request cycle..

Trigger

You need to examine the current "GraphQL N+1 Query Prevention" setup without making changes. Look for the specific failure pattern: "A resolver that fetches a parent entity, then for each child calls a separate database query, resulting in N+1 queries for N children.". Call this when you want a structured inventory before deciding what to modify.

target:graphql-n-plus-oneworkflow:auditauditgraphqln-plus-oneperformance

Audit

Jest Test Optimisation: Audit

low

[Jest Test Optimisation] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets jest config optimisation / --changedSince / --onlyChanged / test sharding / module mocking. Known failure pattern: Running the entire test suite on every change, taking minutes even for small incremental code changes.. Best practice: Use jest --changedSince to run only tests related to changed files. Use jest --onlyChanged during development to get instant feedback..

Trigger

You need to examine the current "Jest Test Optimisation" setup without making changes. Look for the specific failure pattern: "Running the entire test suite on every change, taking minutes even for small incremental code changes.". Call this when you want a structured inventory before deciding what to modify.

target:jest-test-optimizationworkflow:auditauditjesttestingoptimisation

Audit

JSON Schema Validation: Audit

low

[JSON Schema Validation] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets JSON Schema / validator middleware / type guard / error message / response parser. Known failure pattern: Trusting external API responses without validating their structure, causing runtime errors when the API changes the response format unexpectedly.. Best practice: Always validate external JSON responses against a JSON Schema before accessing properties. Use AJV (JavaScript) or jsonschema (Python) for fast validation..

Trigger

You need to examine the current "JSON Schema Validation" setup without making changes. Look for the specific failure pattern: "Trusting external API responses without validating their structure, causing runtime errors when the API changes the response format unexpectedly.". Call this when you want a structured inventory before deciding what to modify.

target:json-schema-validationworkflow:auditauditjsonvalidationapi

Audit

Kubernetes Horizontal Pod Autoscaling: Audit

low

[Kubernetes Horizontal Pod Autoscaling] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets HPA manifest / custom metric / vertical pod autoscaler / cluster autoscaler config. Known failure pattern: HPA not scaling because metrics-server is not installed, or because resource requests/limits are not set on the target deployment.. Best practice: Always set CPU/memory requests on every container. HPA cannot scale based on resource metrics without requests defined..

Trigger

You need to examine the current "Kubernetes Horizontal Pod Autoscaling" setup without making changes. Look for the specific failure pattern: "HPA not scaling because metrics-server is not installed, or because resource requests/limits are not set on the target deployment.". Call this when you want a structured inventory before deciding what to modify.

target:kubernetes-hpaworkflow:auditauditkubernetesautoscalingdevops

Audit

Kubernetes Pod Lifecycle: Audit

low

[Kubernetes Pod Lifecycle] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets deployment.yaml / startup probe / readiness probe / liveness probe / init container. Known failure pattern: Pods stuck in CrashLoopBackOff because the application exits when a dependency (database, cache) is not yet ready.. Best practice: Implement a startup probe with a longer initial delay and a readiness probe that checks actual dependency health, not just TCP connectivity..

Trigger

You need to examine the current "Kubernetes Pod Lifecycle" setup without making changes. Look for the specific failure pattern: "Pods stuck in CrashLoopBackOff because the application exits when a dependency (database, cache) is not yet ready.". Call this when you want a structured inventory before deciding what to modify.

target:kubernetes-pod-lifecycleworkflow:auditauditkubernetespodsdevops

Audit

LLM Context Window Budget Management: Audit

low

[LLM Context Window Budget Management] Audit the current setup; do NOT modify files; produce a structured inventory and a risk-ranked list of findings Targets trimmed context array / token budget report / sliding window snapshot / semantic retrieval hit list / cache hit dashboard. Known failure pattern: Dumping the entire conversation history plus all file contents into the LLM context window on every turn, causing immediate overflow on multi-hour sessions and burning tens of thousands of tokens on redundant content. Worse: re-reading the same 10MB file 50 times because each tool call rebuilds context from scratch without cache awareness.. Best practice: Use sliding window summarization: keep system prompt + last 5 turns verbatim, compress older turns into a 200-token lossless summary. Aggressively cache stable prefixes (system prompt, tool schemas, file headers). Strip redundant tool outputs after they're acted on. Use semantic search to inject only relevant code chunks, never whole files. Always log token usage per turn so budget overruns are visible..

Trigger

You need to examine the current "LLM Context Window Budget Management" setup without making changes. Look for the specific failure pattern: "Dumping the entire conversation history plus all file contents into the LLM context window on every turn, causing immediate overflow on multi-hour sessions and burning tens of thousands of tokens on redundant content. Worse: re-reading the same 10MB file 50 times because each tool call rebuilds context from scratch without cache awareness.". Call this when you want a structured inventory before deciding what to modify.

target:context-window-budgetworkflow:auditauditcontexttokensllm

Audit

MCP Tool Design & Best Practices: Audit

low

[MCP Tool Design & Best Practices] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets MCP tool descriptor / resource definition / prompt template / server metadata. Known failure pattern: Designing MCP tool names that are too generic ('search', 'get_data') causing ambiguity when multiple tools are available to the agent.. Best practice: Prefix tool names with a namespace that reflects their domain (e.g., 'github_search_repos', 'jira_get_issue'). Always provide a detailed description of when to use each tool..

Trigger

You need to examine the current "MCP Tool Design & Best Practices" setup without making changes. Look for the specific failure pattern: "Designing MCP tool names that are too generic ('search', 'get_data') causing ambiguity when multiple tools are available to the agent.". Call this when you want a structured inventory before deciding what to modify.

target:mcp-tool-designworkflow:auditauditmcptoolsagents

Audit

Message Queues & Background Jobs: Audit

low

[Message Queues & Background Jobs] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets queue producer / worker / dead-letter handler / retry policy. Known failure pattern: Losing messages when a worker crashes before acknowledging completion, because auto-ack is enabled.. Best practice: Disable auto-ack. Acknowledge only after the job has been fully processed and its result has been persisted..

Trigger

You need to examine the current "Message Queues & Background Jobs" setup without making changes. Look for the specific failure pattern: "Losing messages when a worker crashes before acknowledging completion, because auto-ack is enabled.". Call this when you want a structured inventory before deciding what to modify.

target:message-queuesworkflow:auditauditqueuebackground-jobsbackend

Audit

Multi-Tenant Data Isolation: Audit

low

[Multi-Tenant Data Isolation] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets RLS policy / tenant context middleware / session variable injection / tenant-aware query builder. Known failure pattern: Using a single database with a tenant_id column but forgetting to filter by tenant_id in every query, accidentally mixing tenant data.. Best practice: Use PostgreSQL Row-Level Security with tenant_id automatically set via session variable. This guarantees isolation even if a query misses the WHERE clause..

Trigger

You need to examine the current "Multi-Tenant Data Isolation" setup without making changes. Look for the specific failure pattern: "Using a single database with a tenant_id column but forgetting to filter by tenant_id in every query, accidentally mixing tenant data.". Call this when you want a structured inventory before deciding what to modify.

target:multi-tenant-isolationworkflow:auditauditmulti-tenantsaasdatabase

Audit

Next.js API Routes & Route Handlers: Audit

low

[Next.js API Routes & Route Handlers] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets route.ts handler / server action / API client wrapper / error boundary. Known failure pattern: Exposing server-side secrets to the client by accidentally importing environment variables in a 'use client' component.. Best practice: All sensitive operations (DB queries, external API calls with keys) belong in API routes or server actions, never in client components..

Trigger

You need to examine the current "Next.js API Routes & Route Handlers" setup without making changes. Look for the specific failure pattern: "Exposing server-side secrets to the client by accidentally importing environment variables in a 'use client' component.". Call this when you want a structured inventory before deciding what to modify.

target:nextjs-api-routesworkflow:auditauditnextjsapibackend

Audit

Next.js Data Fetching Patterns: Audit

low

[Next.js Data Fetching Patterns] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets server fetch / React cache wrapper / streaming suspense boundary. Known failure pattern: Fetching the same data in multiple server components or mixing server fetch with client fetch leading to duplicate network requests.. Best practice: Use server components for initial data fetch and pass down as props. Use React.cache() to deduplicate fetches across parallel routes..

Trigger

You need to examine the current "Next.js Data Fetching Patterns" setup without making changes. Look for the specific failure pattern: "Fetching the same data in multiple server components or mixing server fetch with client fetch leading to duplicate network requests.". Call this when you want a structured inventory before deciding what to modify.

target:nextjs-data-fetchingworkflow:auditauditnextjsdata-fetchingfullstack

Audit

Next.js Middleware & Edge Runtime: Audit

low

[Next.js Middleware & Edge Runtime] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets middleware.ts / rewrite rule / cookie-based redirect / geolocation routing. Known failure pattern: Using Node.js APIs (fs, crypto, database drivers) inside Edge Middleware, causing runtime crashes.. Best practice: Keep middleware stateless and light. Use it only for redirects, rewrites, header manipulation, and basic auth checks..

Trigger

You need to examine the current "Next.js Middleware & Edge Runtime" setup without making changes. Look for the specific failure pattern: "Using Node.js APIs (fs, crypto, database drivers) inside Edge Middleware, causing runtime crashes.". Call this when you want a structured inventory before deciding what to modify.

target:nextjs-middlewareworkflow:auditauditnextjsmiddlewareedge

Audit

Node.js Error Handling & Resilience: Audit

low

[Node.js Error Handling & Resilience] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets global error handler / async wrapper / structured error response / retry logic. Known failure pattern: Unhandled promise rejections crashing the process, or try-catch blocks that swallow errors without logging context.. Best practice: Use a global error handler for uncaught exceptions and unhandled rejections. Wrap every async route handler in a higher-order catch function..

Trigger

You need to examine the current "Node.js Error Handling & Resilience" setup without making changes. Look for the specific failure pattern: "Unhandled promise rejections crashing the process, or try-catch blocks that swallow errors without logging context.". Call this when you want a structured inventory before deciding what to modify.

target:node-error-handlingworkflow:auditauditnodeerror-handlingbackend

Audit

Node.js Streams & Backpressure: Audit

low

[Node.js Streams & Backpressure] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets Readable/Writable stream / Transform / pipeline() refactor. Known failure pattern: Reading entire files into memory instead of streaming, or ignoring backpressure signals from writable streams.. Best practice: Use pipeline() instead of pipe() because pipeline automatically handles backpressure and destroys streams on error..

Trigger

You need to examine the current "Node.js Streams & Backpressure" setup without making changes. Look for the specific failure pattern: "Reading entire files into memory instead of streaming, or ignoring backpressure signals from writable streams.". Call this when you want a structured inventory before deciding what to modify.

target:node-streamsworkflow:auditauditnodestreamsperformance

Audit

OAuth 2.0 Flows & Token Management: Audit

low

[OAuth 2.0 Flows & Token Management] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets OAuth callback / token refresh / PKCE flow / httpOnly cookie handler. Known failure pattern: Storing access tokens in localStorage, making them accessible to XSS attacks, and not implementing refresh token rotation.. Best practice: Store tokens in an httpOnly cookie set by the server, not in client-side storage. Implement refresh token rotation and revoke old refresh tokens after use..

Trigger

You need to examine the current "OAuth 2.0 Flows & Token Management" setup without making changes. Look for the specific failure pattern: "Storing access tokens in localStorage, making them accessible to XSS attacks, and not implementing refresh token rotation.". Call this when you want a structured inventory before deciding what to modify.

target:oauth-flowsworkflow:auditauditoauthauthsecurity

Audit

OpenAPI Specification & Validation: Audit

low

[OpenAPI Specification & Validation] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets openapi.yaml / code-first generator / request/response validation middleware. Known failure pattern: Generating an OpenAPI spec that is out of sync with the actual implementation because the spec is maintained manually instead of generated from code.. Best practice: Use code-first OpenAPI generation (FastAPI, NestJS swagger, or express-openapi) so the spec always reflects the actual routes..

Trigger

You need to examine the current "OpenAPI Specification & Validation" setup without making changes. Look for the specific failure pattern: "Generating an OpenAPI spec that is out of sync with the actual implementation because the spec is maintained manually instead of generated from code.". Call this when you want a structured inventory before deciding what to modify.

target:openapi-specworkflow:auditauditopenapiapicontract

Audit

Playwright Selectors & Locators: Audit

low

[Playwright Selectors & Locators] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets locator refactor / test fixture / POM (Page Object Model) / custom fixture. Known failure pattern: Using fragile CSS selectors (nth-child, class names that change) that break on every UI update.. Best practice: Use getByRole, getByText, or getByTestId with semantic naming. These are resilient to CSS and DOM structure changes..

Trigger

You need to examine the current "Playwright Selectors & Locators" setup without making changes. Look for the specific failure pattern: "Using fragile CSS selectors (nth-child, class names that change) that break on every UI update.". Call this when you want a structured inventory before deciding what to modify.

target:playwright-selectorsworkflow:auditauditplaywrighttestinge2e

Audit

Prompt Injection Defense: Audit

low

[Prompt Injection Defense] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets defensive system prompt / input sanitizer / instruction guardrail / output validator. Known failure pattern: Building a system prompt that includes user input directly without isolation, allowing users to override instructions by saying 'ignore previous instructions'.. Best practice: Isolate user input in a delimited section, use a separate 'input' variable, and add explicit guardrails that reject instruction override attempts..

Trigger

You need to examine the current "Prompt Injection Defense" setup without making changes. Look for the specific failure pattern: "Building a system prompt that includes user input directly without isolation, allowing users to override instructions by saying 'ignore previous instructions'.". Call this when you want a structured inventory before deciding what to modify.

target:prompt-injection-defenseworkflow:auditauditpromptsecurityllm

Audit

Python Async/Await Patterns: Audit

low

[Python Async/Await Patterns] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets async/await refactor / asyncio.gather / async context manager. Known failure pattern: Blocking the event loop by using synchronous requests or time.sleep inside async functions.. Best practice: Use httpx.AsyncClient for HTTP calls and asyncio.sleep for delays inside async functions. Never mix sync and async I/O in the same function..

Trigger

You need to examine the current "Python Async/Await Patterns" setup without making changes. Look for the specific failure pattern: "Blocking the event loop by using synchronous requests or time.sleep inside async functions.". Call this when you want a structured inventory before deciding what to modify.

target:python-asyncworkflow:auditauditpythonasyncperformance

Audit

Python File I/O & Encoding: Audit

low

[Python File I/O & Encoding] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets pathlib refactor / encoding-safe file reader / batch file processor. Known failure pattern: Opening binary files in text mode or assuming UTF-8 encoding, leading to UnicodeDecodeError on non-ASCII content.. Best practice: Always specify encoding explicitly when opening text files. Use pathlib.Path.read_text/write_bytes for cleaner code..

Trigger

You need to examine the current "Python File I/O & Encoding" setup without making changes. Look for the specific failure pattern: "Opening binary files in text mode or assuming UTF-8 encoding, leading to UnicodeDecodeError on non-ASCII content.". Call this when you want a structured inventory before deciding what to modify.

target:python-file-ioworkflow:auditauditpythonfile-ioscripting

Audit

RAG Chunking Strategies: Audit

low

[RAG Chunking Strategies] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets semantic chunker / chunk overlap config / hybrid retriever / chunk metadata enrichment. Known failure pattern: Using fixed-size chunking (500 characters) that splits sentences or code blocks in half, reducing retrieval quality.. Best practice: Use semantic chunking: split on paragraph boundaries, markdown headings, or code function boundaries. Overlap adjacent chunks by 10-20% to avoid missing context near boundaries..

Trigger

You need to examine the current "RAG Chunking Strategies" setup without making changes. Look for the specific failure pattern: "Using fixed-size chunking (500 characters) that splits sentences or code blocks in half, reducing retrieval quality.". Call this when you want a structured inventory before deciding what to modify.

target:rag-chunkingworkflow:auditauditragchunkingretrieval

Audit

Rate Limiting & API Gateway Proxy: Audit

low

[Rate Limiting & API Gateway Proxy] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets NGINX rate limit config / Cloudflare WAF rule / API Gateway usage plan / token bucket implementation. Known failure pattern: Applying rate limiting at the application level without a proxy layer, so rate-limited requests still consume application server resources.. Best practice: Enforce rate limits at the reverse proxy level (NGINX, Cloudflare, API Gateway) before the request reaches your application server..

Trigger

You need to examine the current "Rate Limiting & API Gateway Proxy" setup without making changes. Look for the specific failure pattern: "Applying rate limiting at the application level without a proxy layer, so rate-limited requests still consume application server resources.". Call this when you want a structured inventory before deciding what to modify.

target:rate-limiting-proxyworkflow:auditauditrate-limitingproxysecurity

Audit

React Server Components: Audit

low

[React Server Components] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets server component / client boundary refactor / streaming fallback. Known failure pattern: Accidentally making a server component a client component by using hooks or event handlers in the wrong file.. Best practice: Keep data fetching and heavy logic in server components; pass results as props to client islands..

Trigger

You need to examine the current "React Server Components" setup without making changes. Look for the specific failure pattern: "Accidentally making a server component a client component by using hooks or event handlers in the wrong file.". Call this when you want a structured inventory before deciding what to modify.

target:react-server-componentsworkflow:auditauditreactrscfrontend

Audit

React State Management: Audit

low

[React State Management] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets useState / useReducer / useContext hook refactor, zustand or jotai store slice. Known failure pattern: Stale closures or unnecessary re-renders caused by missing dependency arrays or incorrect state initialisation.. Best practice: Co-locate state as close to the consuming component as possible. Lift state only when two or more siblings need to share it..

Trigger

You need to examine the current "React State Management" setup without making changes. Look for the specific failure pattern: "Stale closures or unnecessary re-renders caused by missing dependency arrays or incorrect state initialisation.". Call this when you want a structured inventory before deciding what to modify.

target:react-stateworkflow:auditauditreactstatefrontend

Audit

Redis Caching Strategies: Audit

low

[Redis Caching Strategies] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets cache wrapper / mutex lock / stale-while-revalidate / TTL policy. Known failure pattern: Cache stampede: multiple requests simultaneously recomputing an expired cache entry because they all detected expiry at the same time.. Best practice: Use a mutex lock around cache regeneration, or stale-while-revalidate pattern to serve stale data while the new value is being computed..

Trigger

You need to examine the current "Redis Caching Strategies" setup without making changes. Look for the specific failure pattern: "Cache stampede: multiple requests simultaneously recomputing an expired cache entry because they all detected expiry at the same time.". Call this when you want a structured inventory before deciding what to modify.

target:redis-cachingworkflow:auditauditrediscachingperformance

Audit

REST Pagination Design: Audit

low

[REST Pagination Design] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets cursor pagination / offset pagination fallback / total count optimisation / response envelope. Known failure pattern: Using offset-based pagination with large offsets ('?offset=10000') that causes slow database queries because the DB has to scan and skip many rows.. Best practice: Use cursor-based pagination (keyset pagination) for large datasets. The cursor is an opaque token that points to the last item, and the DB query uses WHERE > cursor_value..

Trigger

You need to examine the current "REST Pagination Design" setup without making changes. Look for the specific failure pattern: "Using offset-based pagination with large offsets ('?offset=10000') that causes slow database queries because the DB has to scan and skip many rows.". Call this when you want a structured inventory before deciding what to modify.

target:rest-paginationworkflow:auditauditrestpaginationapi

Audit

Secrets Rotation Policy: Audit

low

[Secrets Rotation Policy] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets rotation script / vault integration / lease management / incident response plan. Known failure pattern: Using long-lived API keys and secrets that never expire, increasing the blast radius if they leak.. Best practice: Automate secret rotation with a scheduled job. Use short-lived tokens (e.g., 90 days) and rotate them before expiry. Store secrets in a vault, not in env files..

Trigger

You need to examine the current "Secrets Rotation Policy" setup without making changes. Look for the specific failure pattern: "Using long-lived API keys and secrets that never expire, increasing the blast radius if they leak.". Call this when you want a structured inventory before deciding what to modify.

target:secrets-rotationworkflow:auditauditsecretssecurityrotation

Audit

Shell Script Robustness & Safety: Audit

low

[Shell Script Robustness & Safety] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets set -euo pipefail script / confirmation prompt / shellcheck-passing script / rollback function. Known failure pattern: Shell scripts that fail silently midway because 'set -e' is not set, or that modify files without confirmation, causing irreversible damage.. Best practice: Always start scripts with 'set -euo pipefail'. Add confirmation prompts before destructive operations. Use shellcheck to lint the script..

Trigger

You need to examine the current "Shell Script Robustness & Safety" setup without making changes. Look for the specific failure pattern: "Shell scripts that fail silently midway because 'set -e' is not set, or that modify files without confirmation, causing irreversible damage.". Call this when you want a structured inventory before deciding what to modify.

target:shell-script-robustnessworkflow:auditauditshellscriptingsafety

Audit

SQL Query Optimisation: Audit

low

[SQL Query Optimisation] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets indexed query / composite index / EXPLAIN ANALYSE plan / partial index. Known failure pattern: Using SELECT * in production queries and missing indexes on foreign key columns used in JOINs.. Best practice: Always select only the columns you need. Add composite indexes that match your WHERE + ORDER BY clauses exactly..

Trigger

You need to examine the current "SQL Query Optimisation" setup without making changes. Look for the specific failure pattern: "Using SELECT * in production queries and missing indexes on foreign key columns used in JOINs.". Call this when you want a structured inventory before deciding what to modify.

target:sql-query-optimizationworkflow:auditauditsqloptimizationdatabase

Audit

Stealth Web Research & Harvesting: Audit

low

[Stealth Web Research & Harvesting] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets clean markdown corpus / structured JSON metadata / per-page extraction report / sitemap of crawled pages. Known failure pattern: Web scrapers getting blocked by Cloudflare, Akamai, or DataDome bot detection because they send no user-agent, use headless Chromium without stealth plugins, or hammer endpoints with zero delays between requests.. Best practice: Use stealth-augmented browser automation (playwright-extra + stealth or puppeteer-extra + stealth plugin). Rotate realistic user agents with referrer headers. Add 1.5-3 second random delays between navigations. Respect robots.txt and rate-limit headers..

Trigger

You need to examine the current "Stealth Web Research & Harvesting" setup without making changes. Look for the specific failure pattern: "Web scrapers getting blocked by Cloudflare, Akamai, or DataDome bot detection because they send no user-agent, use headless Chromium without stealth plugins, or hammer endpoints with zero delays between requests.". Call this when you want a structured inventory before deciding what to modify.

target:stealth-web-researchworkflow:auditauditstealthscrapingresearch

Audit

Stripe Webhook Idempotency: Audit

low

[Stripe Webhook Idempotency] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets Webhook handler / idempotency key check / event deduplication / failed payment recovery. Known failure pattern: Processing the same Stripe webhook event twice because Stripe sends at-least-once delivery, causing duplicate charges or duplicate subscription activations.. Best practice: Use the Stripe-Idempotency-Key or the event ID as a unique constraint in your database to skip already-processed events..

Trigger

You need to examine the current "Stripe Webhook Idempotency" setup without making changes. Look for the specific failure pattern: "Processing the same Stripe webhook event twice because Stripe sends at-least-once delivery, causing duplicate charges or duplicate subscription activations.". Call this when you want a structured inventory before deciding what to modify.

target:stripe-webhook-idempotencyworkflow:auditauditstripewebhookpayments

Audit

Supabase Row-Level Security: Audit

low

[Supabase Row-Level Security] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets RLS policy / policy test / security definer function / admin bypass. Known failure pattern: RLS policies that are too permissive (using 'true' instead of 'auth.uid() = user_id') accidentally exposing other users' data.. Best practice: Always reference auth.uid() in RLS policies. Test policies with a non-admin user before deploying to production..

Trigger

You need to examine the current "Supabase Row-Level Security" setup without making changes. Look for the specific failure pattern: "RLS policies that are too permissive (using 'true' instead of 'auth.uid() = user_id') accidentally exposing other users' data.". Call this when you want a structured inventory before deciding what to modify.

target:supabase-rlsworkflow:auditauditsupabaserlssecurity

Audit

Terraform State Management: Audit

low

[Terraform State Management] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets backend config / state migration plan / state locking config / remote state datasource. Known failure pattern: Losing the .tfstate file (or it becoming corrupted), forcing manual reconstruction of the entire infrastructure.. Best practice: Always store state in a remote backend (S3, Azure Storage, Terraform Cloud) with state locking enabled via DynamoDB or equivalent..

Trigger

You need to examine the current "Terraform State Management" setup without making changes. Look for the specific failure pattern: "Losing the .tfstate file (or it becoming corrupted), forcing manual reconstruction of the entire infrastructure.". Call this when you want a structured inventory before deciding what to modify.

target:terraform-stateworkflow:auditauditterraformstateiac

Audit

TypeScript Generics & Advanced Types: Audit

low

[TypeScript Generics & Advanced Types] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets generic type / conditional type / mapped type / branded type. Known failure pattern: Generic constraints that are too loose (accepting anything) or too tight (requiring exact shapes when interfaces would suffice).. Best practice: Prefer generic constraints that describe the minimum required structure (extends) rather than listing every possible property..

Trigger

You need to examine the current "TypeScript Generics & Advanced Types" setup without making changes. Look for the specific failure pattern: "Generic constraints that are too loose (accepting anything) or too tight (requiring exact shapes when interfaces would suffice).". Call this when you want a structured inventory before deciding what to modify.

target:typescript-genericsworkflow:auditaudittypescriptgenericstype-system

Audit

User Onboarding Flow Design: Audit

low

[User Onboarding Flow Design] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets onboarding wizard / feature checklist / in-app guide / first-run experience spec. Known failure pattern: Showing the user a long tutorial or feature list on first login, overwhelming them and causing the majority to leave before experiencing core value.. Best practice: Use progressive disclosure: only introduce features when the user reaches the point where they need them. A 3-step wizard that gets them to the 'aha moment' in under 60 seconds is ideal..

Trigger

You need to examine the current "User Onboarding Flow Design" setup without making changes. Look for the specific failure pattern: "Showing the user a long tutorial or feature list on first login, overwhelming them and causing the majority to leave before experiencing core value.". Call this when you want a structured inventory before deciding what to modify.

target:user-onboarding-flowworkflow:auditaudituxonboardingproduct

Audit

Vercel Environment Variables: Audit

low

[Vercel Environment Variables] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets vercel.json env group / preview env config / Edge Config / KV store. Known failure pattern: Accidentally exposing preview URLs or internal API keys by adding them as preview environment variables that get picked up by branch deployments.. Best practice: Use separate environment groups for production, preview, and development. Never mark sensitive keys as 'available to all branches'..

Trigger

You need to examine the current "Vercel Environment Variables" setup without making changes. Look for the specific failure pattern: "Accidentally exposing preview URLs or internal API keys by adding them as preview environment variables that get picked up by branch deployments.". Call this when you want a structured inventory before deciding what to modify.

target:vercel-env-varsworkflow:auditauditvercelenvdeployment

Audit

Web Scraping Ethics & Compliance: Audit

low

[Web Scraping Ethics & Compliance] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets robots.txt check / polite scraper / rate-limited crawler / cached scraper. Known failure pattern: Scraping a website that explicitly prohibits it in robots.txt or terms of service, leading to legal or IP blocking issues.. Best practice: Always check robots.txt and terms of service before scraping. Respect Crawl-Delay directives and set a reasonable User-Agent with contact information..

Trigger

You need to examine the current "Web Scraping Ethics & Compliance" setup without making changes. Look for the specific failure pattern: "Scraping a website that explicitly prohibits it in robots.txt or terms of service, leading to legal or IP blocking issues.". Call this when you want a structured inventory before deciding what to modify.

target:web-scraping-ethicsworkflow:auditauditscrapingethicsresearch

Audit

WebSocket Reconnection Strategies: Audit

low

[WebSocket Reconnection Strategies] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets WebSocket client / reconnection logic / heartbeat / connection status component. Known failure pattern: Losing real-time updates when the WebSocket disconnects temporarily, and not attempting to reconnect, leaving the UI in a stale state.. Best practice: Implement exponential backoff reconnection with a maximum delay of 30 seconds. Show a connection status indicator in the UI..

Trigger

You need to examine the current "WebSocket Reconnection Strategies" setup without making changes. Look for the specific failure pattern: "Losing real-time updates when the WebSocket disconnects temporarily, and not attempting to reconnect, leaving the UI in a stale state.". Call this when you want a structured inventory before deciding what to modify.

target:websocket-reconnectionworkflow:auditauditwebsocketrealtimefrontend

Audit

Web Vitals Optimisation (LCP/CLS/INP): Audit

low

[Web Vitals Optimisation (LCP/CLS/INP)] Inspect the current state without making changes. List files, configurations, dependencies, or outputs relevant to the goal. Produce a structured inventory with findings, risks, and recommendations — but do not modify anything. Targets image optimisation / font display swap / critical CSS / lazy load / bundle analysis. Known failure pattern: Large LCP caused by a hero image that is larger than needed and not optimised (WebP, lazy loading, proper dimensions).. Best practice: Serve images in WebP/AVIF format, specify width and height to reserve space (prevent CLS), and lazy-load below-the-fold images. Use next/image for automatic optimisation..

Trigger

You need to examine the current "Web Vitals Optimisation (LCP/CLS/INP)" setup without making changes. Look for the specific failure pattern: "Large LCP caused by a hero image that is larger than needed and not optimised (WebP, lazy loading, proper dimensions).". Call this when you want a structured inventory before deciding what to modify.

target:web-vitals-optimizationworkflow:auditauditperformanceweb-vitalsoptimisation

Automation

A/B Testing Framework: Script

medium

[A/B Testing Framework] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets experiment spec / variant assignment / metric definition / statistical analysis script. Known failure pattern: Running A/B tests with sample sizes too small to reach statistical significance, leading to decisions based on noise.. Best practice: Use an online sample size calculator before starting the test. Define the minimum detectable effect and ensure the test runs for at least one full business cycle..

Trigger

Create a reusable automation for "A/B Testing Framework". The task produces experiment spec / variant assignment / metric definition / statistical analysis script. Handle the failure pattern "Running A/B tests with sample sizes too small to reach statistical significance, leading to decisions based on noise.". Include a dry-run mode and test with statsmodels sample size calculation + Bayesian A/B test + sequential testing.

target:a-b-testing-frameworkworkflow:scriptautomationab-testingexperimentsproduct

Automation

Accessibility ARIA Patterns: Script

medium

[Accessibility ARIA Patterns] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets ARIA attribute refactor / keyboard navigation / focus management / screen reader test script. Known failure pattern: Adding ARIA attributes that conflict with native HTML semantics (e.g., role='button' on a <button> element), confusing screen readers.. Best practice: Use native HTML elements whenever possible. Only use ARIA to supplement missing semantics, never to override existing ones. Test with a real screen reader..

Trigger

Create a reusable automation for "Accessibility ARIA Patterns". The task produces ARIA attribute refactor / keyboard navigation / focus management / screen reader test script. Handle the failure pattern "Adding ARIA attributes that conflict with native HTML semantics (e.g., role='button' on a <button> element), confusing screen readers.". Include a dry-run mode and test with axe-core + WAVE tool + VoiceOver/NVDA manual test + keyboard-only audit.

target:a11y-aria-patternsworkflow:scriptautomationaccessibilityariatesting

Automation

Agent Tool Binding & Dispatch: Script

medium

[Agent Tool Binding & Dispatch] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets router tool / domain group / dynamic tool injection / tool usage statistics. Known failure pattern: Giving the agent too many tools at once, causing it to spend more time choosing than executing, and increasing token usage significantly.. Best practice: Group tools by domain and offer a 'router' tool first. The agent picks a domain, then that domain's tools are injected. This reduces the tool set per step..

Trigger

Create a reusable automation for "Agent Tool Binding & Dispatch". The task produces router tool / domain group / dynamic tool injection / tool usage statistics. Handle the failure pattern "Giving the agent too many tools at once, causing it to spend more time choosing than executing, and increasing token usage significantly.". Include a dry-run mode and test with agent trace log + tool invocation frequency analysis + token cost audit.

target:agent-tool-bindingworkflow:scriptautomationagentstool-bindingorchestration

Automation

Analytics Metric Definitions: Script

medium

[Analytics Metric Definitions] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets metric definition / dbt model / SQL logic / dashboard tile / documentation. Known failure pattern: Different teams computing the same metric (e.g., 'daily active users') with different SQL logic, producing conflicting numbers.. Best practice: Define every metric in a central repository as a dbt model or LookML view with a single source of truth, and document its logic explicitly..

Trigger

Create a reusable automation for "Analytics Metric Definitions". The task produces metric definition / dbt model / SQL logic / dashboard tile / documentation. Handle the failure pattern "Different teams computing the same metric (e.g., 'daily active users') with different SQL logic, producing conflicting numbers.". Include a dry-run mode and test with dbt docs generate + dbt test --select tag:metrics + metric comparison script.

target:analytics-metric-definitionworkflow:scriptautomationanalyticsmetricsdata

Automation

Architecture Decision Records: Script

medium

[Architecture Decision Records] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets ADR document / decision log / template / review workflow. Known failure pattern: Making important architectural decisions without documenting the context, alternatives, and rationale, leaving future team members confused about why something was done.. Best practice: Write an ADR for every non-trivial decision. Include the context, considered alternatives (with pros/cons of each), the chosen option, and the consequences..

Trigger

Create a reusable automation for "Architecture Decision Records". The task produces ADR document / decision log / template / review workflow. Handle the failure pattern "Making important architectural decisions without documenting the context, alternatives, and rationale, leaving future team members confused about why something was done.". Include a dry-run mode and test with adr-tools list + adr-tools generate + decision log index page.

target:adr-documentationworkflow:scriptautomationdocumentationadrarchitecture

Automation

AWS Lambda Cold Starts: Script

medium

[AWS Lambda Cold Starts] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets handler refactor / SnapStart config / Provisioned Concurrency / warmer function. Known failure pattern: Cold starts lasting multiple seconds because the function loads heavy dependencies or initialises database connections outside the handler.. Best practice: Move initialisation (DB connections, config loading) outside the handler. Use Lambda SnapStart for Java or .NET. Consider Provisioned Concurrency for latency-sensitive functions..

Trigger

Create a reusable automation for "AWS Lambda Cold Starts". The task produces handler refactor / SnapStart config / Provisioned Concurrency / warmer function. Handle the failure pattern "Cold starts lasting multiple seconds because the function loads heavy dependencies or initialises database connections outside the handler.". Include a dry-run mode and test with AWS X-Ray trace + Lambda Insights + cold start dashboard.

target:aws-lambda-cold-startworkflow:scriptautomationawslambdaperformance

Automation

Azure Bicep Infrastructure: Script

medium

[Azure Bicep Infrastructure] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets main.bicep / module / parameter file / azd template. Known failure pattern: Manually creating resources in the portal without infrastructure-as-code, making environments inconsistent and hard to reproduce.. Best practice: Always define Azure resources in Bicep or Terraform. Use parameters and modules to keep the code DRY and environment-agnostic..

Trigger

Create a reusable automation for "Azure Bicep Infrastructure". The task produces main.bicep / module / parameter file / azd template. Handle the failure pattern "Manually creating resources in the portal without infrastructure-as-code, making environments inconsistent and hard to reproduce.". Include a dry-run mode and test with az deployment group validate + az what-if + bicep build.

target:azure-bicepworkflow:scriptautomationazurebicepiac

Automation

Browser DevTools & Debugging: Script

medium

[Browser DevTools & Debugging] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets debugging workflow / breakpoint guide / performance recording / memory snapshot. Known failure pattern: Trying to debug frontend issues by guessing instead of using the Elements, Console, Network, and Sources panels systematically.. Best practice: Start with the Network panel to confirm the request/response are correct, then use Sources to set breakpoints, then Elements to inspect the DOM..

Trigger

Create a reusable automation for "Browser DevTools & Debugging". The task produces debugging workflow / breakpoint guide / performance recording / memory snapshot. Handle the failure pattern "Trying to debug frontend issues by guessing instead of using the Elements, Console, Network, and Sources panels systematically.". Include a dry-run mode and test with Chrome DevTools performance recording + memory heap snapshot + network throttle.

target:browser-devtoolsworkflow:scriptautomationbrowserdebuggingdevtools

Automation

CLI Tool Design Patterns: Script

medium

[CLI Tool Design Patterns] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets CLI scaffolding / argument parser / exit code handler / --json output mode. Known failure pattern: Building CLI tools that print output without usable exit codes (always exits 0) or swallow error messages, making them impossible to script with.. Best practice: Always exit 0 on success, non-zero on failure. Print errors to stderr, output to stdout. Support --json flag for machine-readable output..

Trigger

Create a reusable automation for "CLI Tool Design Patterns". The task produces CLI scaffolding / argument parser / exit code handler / --json output mode. Handle the failure pattern "Building CLI tools that print output without usable exit codes (always exits 0) or swallow error messages, making them impossible to script with.". Include a dry-run mode and test with echo $? after CLI run + stderr redirection test + --json output validation.

target:cli-tool-designworkflow:scriptautomationclidevtoolsscripting

Automation

Cloud Cost Optimisation: Script

medium

[Cloud Cost Optimisation] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets right-sizing recommendation / auto-stop schedule / reserved instance plan / unused resource report. Known failure pattern: Running oversized instances 'just in case', or leaving development/staging resources running 24/7 when they are only needed during working hours.. Best practice: Right-size instances based on actual usage metrics (not peak theoretical load). Use auto-stop schedules for non-production environments..

Trigger

Create a reusable automation for "Cloud Cost Optimisation". The task produces right-sizing recommendation / auto-stop schedule / reserved instance plan / unused resource report. Handle the failure pattern "Running oversized instances 'just in case', or leaving development/staging resources running 24/7 when they are only needed during working hours.". Include a dry-run mode and test with cloud cost explorer + instance utilisation report + auto-stop Lambda function test.

target:cloud-cost-optimizationworkflow:scriptautomationcloudcostoptimization

Automation

Code Review Checklist: Script

medium

[Code Review Checklist] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets review checklist / automated review comment / risk classification / diff summary. Known failure pattern: Reviewers focusing only on code style and missing architectural issues like missing error handling, security vulnerabilities, or performance regressions.. Best practice: Use a structured review checklist: correctness, security, performance, test coverage, error handling, and code style — in that order..

Trigger

Create a reusable automation for "Code Review Checklist". The task produces review checklist / automated review comment / risk classification / diff summary. Handle the failure pattern "Reviewers focusing only on code style and missing architectural issues like missing error handling, security vulnerabilities, or performance regressions.". Include a dry-run mode and test with git diff --stat + lint-staged + danger.js automated review + commitlint.

target:code-review-checklistworkflow:scriptautomationcode-reviewqualitychecklist

Automation

Convex Functions & Mutations: Script

medium

[Convex Functions & Mutations] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets mutation / query / action / component / scheduler job. Known failure pattern: Accidentally creating OCC (Optimistic Concurrency Control) conflicts by reading and writing the same document in rapid succession from multiple clients.. Best practice: Use patch() for partial updates and batch mutations for atomic multi-document writes. Avoid reading a document before immediately writing it back..

Trigger

Create a reusable automation for "Convex Functions & Mutations". The task produces mutation / query / action / component / scheduler job. Handle the failure pattern "Accidentally creating OCC (Optimistic Concurrency Control) conflicts by reading and writing the same document in rapid succession from multiple clients.". Include a dry-run mode and test with npx convex dev + dashboard OCC conflict log + custom retry logic.

target:convex-functionsworkflow:scriptautomationconvexrealtimebackend

Automation

Cron Job & Scheduled Task Reliability: Script

medium

[Cron Job & Scheduled Task Reliability] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets crontab entry / log rotation / idempotency guard / failure alert integration. Known failure pattern: Cron jobs failing silently because output is not logged, or running the same job multiple times when the system is down at the scheduled time.. Best practice: Redirect cron output to a log file with timestamp. Use || to send failure alerts. Implement job idempotency so running it multiple times has no side effects..

Trigger

Create a reusable automation for "Cron Job & Scheduled Task Reliability". The task produces crontab entry / log rotation / idempotency guard / failure alert integration. Handle the failure pattern "Cron jobs failing silently because output is not logged, or running the same job multiple times when the system is down at the scheduled time.". Include a dry-run mode and test with tail -f /var/log/cron + systemctl status cron + idempotency test script.

target:cron-job-reliabilityworkflow:scriptautomationcronschedulingreliability

Automation

CSS Layout & Responsiveness: Script

medium

[CSS Layout & Responsiveness] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets CSS layout refactor / responsive grid / container query implementation. Known failure pattern: Over-reliance on media queries when container queries or flex/grid intrinsic sizing would be simpler and more maintainable.. Best practice: Design for the content, not the viewport. Use clamp(), minmax(), and auto-fit/auto-fill before reaching for breakpoints..

Trigger

Create a reusable automation for "CSS Layout & Responsiveness". The task produces CSS layout refactor / responsive grid / container query implementation. Handle the failure pattern "Over-reliance on media queries when container queries or flex/grid intrinsic sizing would be simpler and more maintainable.". Include a dry-run mode and test with Lighthouse mobile emulation + browser DevTools responsive mode.

target:css-layoutworkflow:scriptautomationcsslayoutfrontend

Automation

CSV Data Cleaning Pipeline: Script

medium

[CSV Data Cleaning Pipeline] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets CSV parser / row validator / column type mapper / error report / cleaned output. Known failure pattern: Assuming CSV values are clean and consistent, then hitting parsing errors or silent data corruption when encountering commas inside quoted fields, missing headers, or inconsistent newlines.. Best practice: Always use a proper CSV parser (Python's csv module, Papa Parse in JS) instead of splitting on commas. Validate column count and types for every row..

Trigger

Create a reusable automation for "CSV Data Cleaning Pipeline". The task produces CSV parser / row validator / column type mapper / error report / cleaned output. Handle the failure pattern "Assuming CSV values are clean and consistent, then hitting parsing errors or silent data corruption when encountering commas inside quoted fields, missing headers, or inconsistent newlines.". Include a dry-run mode and test with python3 -c csv.DictReader + validation script + row count diff.

target:csv-data-cleaningworkflow:scriptautomationdatacsvpipeline

Automation

Database Migration Safety: Script

medium

[Database Migration Safety] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets batch migration / expand-contract pattern / zero-downtime migration / rollback plan. Known failure pattern: Running a long-running migration (e.g., adding a column with a default value) that locks the table and causes downtime for active users.. Best practice: Use PostgreSQL's ADD COLUMN DEFAULT (no-rewrite in recent versions) or break the migration into steps: add column without default, backfill in batches, then add default..

Trigger

Create a reusable automation for "Database Migration Safety". The task produces batch migration / expand-contract pattern / zero-downtime migration / rollback plan. Handle the failure pattern "Running a long-running migration (e.g., adding a column with a default value) that locks the table and causes downtime for active users.". Include a dry-run mode and test with pg_locks monitoring during migration + batch backfill script + rollback test.

target:database-migration-safetyworkflow:scriptautomationdatabasemigrationsafety

Automation

Data Warehouse Schema Design: Script

medium

[Data Warehouse Schema Design] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets star schema / fact table / dimension table / ETL pipeline spec. Known failure pattern: Using a highly normalised OLTP schema (3NF) directly in a data warehouse, causing complex JOINs and slow analytical queries.. Best practice: Use a star schema (one fact table, multiple dimension tables) or a wide-column denormalised table for analytical queries. Pre-join at loading time..

Trigger

Create a reusable automation for "Data Warehouse Schema Design". The task produces star schema / fact table / dimension table / ETL pipeline spec. Handle the failure pattern "Using a highly normalised OLTP schema (3NF) directly in a data warehouse, causing complex JOINs and slow analytical queries.". Include a dry-run mode and test with dbt run + dbt test + query profiling with warehouse-native tools.

target:data-warehouse-schemaworkflow:scriptautomationdatawarehouseschema

Automation

Design Token Systems: Script

medium

[Design Token Systems] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets token JSON / CSS custom properties / theme switcher / token documentation. Known failure pattern: Hardcoding colors, spacing, or typography values in components instead of referencing design tokens, making theming impossible without changing every file.. Best practice: Define all visual primitives as CSS custom properties or JSON tokens. Reference them in components via token names, not literal values..

Trigger

Create a reusable automation for "Design Token Systems". The task produces token JSON / CSS custom properties / theme switcher / token documentation. Handle the failure pattern "Hardcoding colors, spacing, or typography values in components instead of referencing design tokens, making theming impossible without changing every file.". Include a dry-run mode and test with style-dictionary build + Storybook token viewer + token value comparison.

target:design-token-systemworkflow:scriptautomationdesigntokenscomponents

Automation

Docker Compose Networking: Script

medium

[Docker Compose Networking] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets docker-compose.yml / network config / healthcheck / depends_on condition. Known failure pattern: Services unable to reach each other because they are on different Docker networks, or using 'localhost' instead of the service name.. Best practice: All services in the same docker-compose.yml are on a shared network by default. Reference other services by their service name, not 'localhost'..

Trigger

Create a reusable automation for "Docker Compose Networking". The task produces docker-compose.yml / network config / healthcheck / depends_on condition. Handle the failure pattern "Services unable to reach each other because they are on different Docker networks, or using 'localhost' instead of the service name.". Include a dry-run mode and test with docker compose up --wait + docker network inspect + container logs.

target:docker-compose-networkingworkflow:scriptautomationdockernetworkingdevops

Automation

Docker Multi-Stage Builds: Script

medium

[Docker Multi-Stage Builds] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets multi-stage Dockerfile / .dockerignore / slim base image switch. Known failure pattern: Including the entire node_modules and build toolchain in the final production image, making it unnecessarily large and insecure.. Best practice: Use at least two stages: one for installing dev dependencies and building, another for copying only the production artefacts and running the app..

Trigger

Create a reusable automation for "Docker Multi-Stage Builds". The task produces multi-stage Dockerfile / .dockerignore / slim base image switch. Handle the failure pattern "Including the entire node_modules and build toolchain in the final production image, making it unnecessarily large and insecure.". Include a dry-run mode and test with docker build + docker scout + dive layer analysis.

target:docker-multistageworkflow:scriptautomationdockerbuilddevops

Automation

Drizzle Schema Design: Script

medium

[Drizzle Schema Design] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets schema.ts / relation map / migration SQL / Drizzle query builder. Known failure pattern: Over-using relations() when simple foreign key columns with manual joins would be clearer and faster.. Best practice: Define relations only for eagerly loaded nested data. For simple lookups, just reference the foreign key column directly..

Trigger

Create a reusable automation for "Drizzle Schema Design". The task produces schema.ts / relation map / migration SQL / Drizzle query builder. Handle the failure pattern "Over-using relations() when simple foreign key columns with manual joins would be clearer and faster.". Include a dry-run mode and test with drizzle-kit push + drizzle-kit studio + generated SQL audit.

target:drizzle-schema-designworkflow:scriptautomationdrizzleschemadatabase

Automation

Error Monitoring & Alerting Setup: Script

medium

[Error Monitoring & Alerting Setup] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets Sentry project config / alert rule / error grouping / source map upload / performance monitoring. Known failure pattern: Setting up error monitoring (Sentry, Datadog) but configuring no alerts, so errors accumulate silently until a user complains.. Best practice: Configure at least two alerts: one for new errors (errors appearing for the first time) and one for error spikes (error count exceeding a threshold)..

Trigger

Create a reusable automation for "Error Monitoring & Alerting Setup". The task produces Sentry project config / alert rule / error grouping / source map upload / performance monitoring. Handle the failure pattern "Setting up error monitoring (Sentry, Datadog) but configuring no alerts, so errors accumulate silently until a user complains.". Include a dry-run mode and test with Sentry API error list + alert rule test + source map validation.

target:error-monitoring-setupworkflow:scriptautomationmonitoringerrorsalerts

Automation

FastAPI Dependency Injection: Script

medium

[FastAPI Dependency Injection] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets dependency / lifespan handler / override for testing. Known failure pattern: Re-initialising the same database connection or HTTP client inside every route instead of using FastAPI's dependency injection.. Best practice: Define shared resources (DB pool, HTTP client) as lifespan-managed dependencies and inject them via Depends()..

Trigger

Create a reusable automation for "FastAPI Dependency Injection". The task produces dependency / lifespan handler / override for testing. Handle the failure pattern "Re-initialising the same database connection or HTTP client inside every route instead of using FastAPI's dependency injection.". Include a dry-run mode and test with uvicorn --reload + /docs interactive test + dependency graph visualisation.

target:fastapi-dependenciesworkflow:scriptautomationfastapidependenciesapi

Automation

Feature Flags & Gradual Rollouts: Script

medium

[Feature Flags & Gradual Rollouts] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets flag provider config / gradual rollout target / flag cleanup plan / A/B test flag. Known failure pattern: Leaving feature flag code in the codebase permanently, making the codebase harder to read and maintain, and never removing old flags.. Best practice: Treat feature flags as temporary. After a flag has been fully rolled out and stable for one release cycle, remove the flag code and the flag condition entirely..

Trigger

Create a reusable automation for "Feature Flags & Gradual Rollouts". The task produces flag provider config / gradual rollout target / flag cleanup plan / A/B test flag. Handle the failure pattern "Leaving feature flag code in the codebase permanently, making the codebase harder to read and maintain, and never removing old flags.". Include a dry-run mode and test with flag evaluation log + rollout percentage monitoring + unused flag scan.

target:feature-flagsworkflow:scriptautomationfeature-flagsrolloutdevops

Automation

Git Conflict Resolution: Script

medium

[Git Conflict Resolution] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets conflict resolution plan / cherry-pick strategy / rebase workflow / merge commit message. Known failure pattern: Resolving merge conflicts by blindly accepting one side without understanding why the change was made, potentially reintroducing bugs.. Best practice: For each conflicted section, trace the origin of both changes using 'git log --oneline' on the file. Understand the intent before picking a resolution..

Trigger

Create a reusable automation for "Git Conflict Resolution". The task produces conflict resolution plan / cherry-pick strategy / rebase workflow / merge commit message. Handle the failure pattern "Resolving merge conflicts by blindly accepting one side without understanding why the change was made, potentially reintroducing bugs.". Include a dry-run mode and test with git log --oneline -5 -- <file> + git diff HEAD...MERGE_HEAD + git rerere.

target:git-conflict-resolutionworkflow:scriptautomationgitconflictsworkflow

Automation

GitHub Actions Pipeline Optimisation: Script

medium

[GitHub Actions Pipeline Optimisation] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets workflow YAML / cache config / matrix build / conditional job execution. Known failure pattern: Long CI times caused by not caching dependencies between runs, or running the full test suite on every push regardless of change scope.. Best practice: Cache node_modules (or other dependency folders) using actions/cache with a hash of the lock file. Use paths filter to run only relevant jobs..

Trigger

Create a reusable automation for "GitHub Actions Pipeline Optimisation". The task produces workflow YAML / cache config / matrix build / conditional job execution. Handle the failure pattern "Long CI times caused by not caching dependencies between runs, or running the full test suite on every push regardless of change scope.". Include a dry-run mode and test with act --job test + cache hit/miss analysis + workflow graph visualisation.

target:github-actions-pipelineworkflow:scriptautomationgithub-actionscidevops

Automation

GraphQL N+1 Query Prevention: Script

medium

[GraphQL N+1 Query Prevention] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets DataLoader instance / batch load function / resolver refactor / query complexity analysis. Known failure pattern: A resolver that fetches a parent entity, then for each child calls a separate database query, resulting in N+1 queries for N children.. Best practice: Use DataLoader to batch and cache child-loading queries. DataLoader groups all child-loading calls into a single IN query per request cycle..

Trigger

Create a reusable automation for "GraphQL N+1 Query Prevention". The task produces DataLoader instance / batch load function / resolver refactor / query complexity analysis. Handle the failure pattern "A resolver that fetches a parent entity, then for each child calls a separate database query, resulting in N+1 queries for N children.". Include a dry-run mode and test with graphql query with tracing + DataLoader statistics + SQL log analysis.

target:graphql-n-plus-oneworkflow:scriptautomationgraphqln-plus-oneperformance

Automation

Jest Test Optimisation: Script

medium

[Jest Test Optimisation] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets jest config optimisation / --changedSince / --onlyChanged / test sharding / module mocking. Known failure pattern: Running the entire test suite on every change, taking minutes even for small incremental code changes.. Best practice: Use jest --changedSince to run only tests related to changed files. Use jest --onlyChanged during development to get instant feedback..

Trigger

Create a reusable automation for "Jest Test Optimisation". The task produces jest config optimisation / --changedSince / --onlyChanged / test sharding / module mocking. Handle the failure pattern "Running the entire test suite on every change, taking minutes even for small incremental code changes.". Include a dry-run mode and test with jest --changedSince=main --json + jest --onlyChanged + jest-coverage threshold check.

target:jest-test-optimizationworkflow:scriptautomationjesttestingoptimisation

Automation

JSON Schema Validation: Script

medium

[JSON Schema Validation] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets JSON Schema / validator middleware / type guard / error message / response parser. Known failure pattern: Trusting external API responses without validating their structure, causing runtime errors when the API changes the response format unexpectedly.. Best practice: Always validate external JSON responses against a JSON Schema before accessing properties. Use AJV (JavaScript) or jsonschema (Python) for fast validation..

Trigger

Create a reusable automation for "JSON Schema Validation". The task produces JSON Schema / validator middleware / type guard / error message / response parser. Handle the failure pattern "Trusting external API responses without validating their structure, causing runtime errors when the API changes the response format unexpectedly.". Include a dry-run mode and test with ajv validate + JSON Schema test suite + response mock test.

target:json-schema-validationworkflow:scriptautomationjsonvalidationapi

Automation

Kubernetes Horizontal Pod Autoscaling: Script

medium

[Kubernetes Horizontal Pod Autoscaling] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets HPA manifest / custom metric / vertical pod autoscaler / cluster autoscaler config. Known failure pattern: HPA not scaling because metrics-server is not installed, or because resource requests/limits are not set on the target deployment.. Best practice: Always set CPU/memory requests on every container. HPA cannot scale based on resource metrics without requests defined..

Trigger

Create a reusable automation for "Kubernetes Horizontal Pod Autoscaling". The task produces HPA manifest / custom metric / vertical pod autoscaler / cluster autoscaler config. Handle the failure pattern "HPA not scaling because metrics-server is not installed, or because resource requests/limits are not set on the target deployment.". Include a dry-run mode and test with kubectl get hpa --watch + kubectl top pods + metrics-server logs.

target:kubernetes-hpaworkflow:scriptautomationkubernetesautoscalingdevops

Automation

Kubernetes Pod Lifecycle: Script

medium

[Kubernetes Pod Lifecycle] Create a reusable automation: a shell script, CLI tool, scheduled job, or workflow definition. The automation must handle edge cases (missing input, network failures, permission errors) and include a dry-run or test mode. Targets deployment.yaml / startup probe / readiness probe / liveness probe / init container. Known failure pattern: Pods stuck in CrashLoopBackOff because the application exits when a dependency (database, cache) is not yet ready.. Best practice: Implement a startup probe with a longer initial delay and a readiness probe that checks actual dependency health, not just TCP connectivity..

Trigger

Create a reusable automation for "Kubernetes Pod Lifecycle". The task produces deployment.yaml / startup probe / readiness probe / liveness probe / init container. Handle the failure pattern "Pods stuck in CrashLoopBackOff because the application exits when a dependency (database, cache) is not yet ready.". Include a dry-run mode and test with kubectl describe pod + kubectl logs --previous + kubectl get events --sort-by='.lastTimestamp'.

target:kubernetes-pod-lifecycleworkflow:scriptautomationkubernetespodsdevops