Web & Frontend
Web development agent skills handle frontend and full-stack work: component patterns, CSS and accessibility fixes, performance budgets, and framework conventions. Install a skill once and your AI agent follows the same playbook in every project, from quick prototypes to production apps.
-
pixartseu Bundle Shopify ThemesSviluppo di temi Shopify in Liquid — architettura Online Store 2.0, sezioni, blocchi, template JSON, theme editor, performance e accessibilità. ATTIVARE SEMPRE quando l'utente menziona "tema Shopify", "Liquid", "Dawn", "Online Store 2.0", "OS 2.0", "sezioni", "sections", "blocchi", "theme blocks", "app blocks", "schema", "settings_schema", "template JSON", "snippet", "section group", "theme editor", "shopify theme dev", "shopify theme push", "theme check", "Theme Inspector", "Lighthouse CI Shopify", "Theme Store", "theme app extension", "metafield in Liquid", "personalizzare un tema", "modificare il tema". Attivare anche quando la richiesta lo implica senza dirlo - "il cliente vuole cambiare la homepage da solo", "aggiungere una sezione al sito Shopify", "il sito Shopify è lento", "migrare un tema vecchio", "il tema si rompe quando lo aggiorno". NON è la skill per vetrine React headless - quella è shopify-storefront.
-
pixartseu Skill Background JobsBackground job processing with BullMQ, Inngest, Trigger.dev, Upstash QStash. Use when implementing async tasks, scheduled jobs, event-driven workflows, retries, or dead letter queues in Next.js.
-
pixartseu Bundle Pixarts WorkflowPixarts complete workflow - intake, CMS setup, scaffold, build, deploy, QA. Use when implementing full client site projects, managing multi-phase delivery, or coordinating CMS and frontend setup.
-
pixartseu Bundle CSS 3d TransformsCSS 3D Transforms
-
pixartseu Skill Monitoring NextjsMonitoring and observability for Next.js — Sentry error tracking, structured logging with Pino, OpenTelemetry tracing, health checks, uptime monitoring, alerting. Use when adding error tracking, logging, performance monitoring, or alerting to a Next.js project.
-
pixartseu Bundle React Three FiberReact Three Fiber (R3F) knowledge base — Canvas, JSX scene graph, useFrame, useThree, useLoader, Suspense, @react-three/drei helpers, event system, SSR-safe Next.js integration. Use when building 3D scenes in React/Next.js, integrating drei components (OrbitControls, Environment, useGLTF), or debugging R3F lifecycle issues.
-
pixartseu Bundle Supabase Auth SsrSupabase Auth + @supabase/ssr for Next.js 15 App Router — server/browser/middleware clients, cookie-based session, RLS-aware queries, magic link / OAuth / password flows, password reset, session refresh, route protection, server actions. Use when setting up Supabase Auth in a Next.js project, debugging "Auth session missing" errors, implementing protected routes, or adding RLS-aware data fetching.
-
pixartseu Bundle R3f PostprocessingPost-processing in React Three Fiber via @react-three/postprocessing (pmndrs) — EffectComposer, Bloom, DepthOfField, ChromaticAberration, Vignette, Noise, SSAO, ToneMapping, custom effects. Use when adding cinematic visuals (bloom, DOF, color grading) to an R3F scene, debugging post-FX performance, or porting a Three.js EffectComposer setup to declarative R3F syntax.
-
pixartseu Bundle Resend React EmailResend (resend.com) HTTP API + React Email components for transactional and broadcast email in Next.js — domain verification, DKIM, send/batch/schedule, attachments, idempotency, React-templated emails, audience+broadcast, webhooks (delivered, bounce, complaint), reply-to, preview via React Email Studio. Use when sending transactional email with React templates, setting up Resend in a new project, debugging "domain not verified", or switching from Nodemailer to a hosted API.
-
pixartseu Bundle Shopify StorefrontSviluppo di vetrine headless Shopify con Hydrogen (React Router/Remix) e deploy su Oxygen. ATTIVARE SEMPRE quando l'utente menziona "Hydrogen", "Oxygen", "storefront headless", "Shopify headless", "Storefront API", "Customer Account API", "shopify hydrogen dev", "h2 dev", "mock.shop", "CartForm", "createHydrogenContext", "storefront.query", "CacheLong", "CacheShort", "subrequest profiler", "hydrogen deploy", "hydrogen link", "hydrogen codegen", "storefrontapi.generated", "@shopify/hydrogen", "@shopify/remix-oxygen", "mini-oxygen", "e-commerce React Router", "PDP/PLP Shopify custom". Attivare anche quando l'utente descrive il problema senza nominare Hydrogen — "voglio un e-commerce Shopify ma con frontend mio", "il checkout Shopify ma la vetrina in React", "migrare da Liquid a React", "cache che non si invalida sul prodotto", "dati cliente che finiscono nella cache", "il worker supera i 10MB", "deploy Shopify edge". In caso di dubbio su un progetto e-commerce Shopify custom, attivare.
-
pixartseu Bundle Turborepo MonorepoTurborepo + pnpm workspaces monorepo for Next.js apps and shared packages — workspace layout, turbo.json pipeline, task caching (local + remote), shared UI/config/utils packages, internal package imports, env vars per task, CI integration, Vercel deploys, transpilePackages, debugging cache misses. Use when migrating multiple Next.js projects into a monorepo, sharing components/configs across apps, speeding up CI with caching, or setting up internal pkgs.
-
pixartseu Bundle Claude API PatternsAnthropic Claude API patterns with the official `@anthropic-ai/sdk` — model selection (Opus 4.7 / Sonnet 4.6 / Haiku 4.5), streaming, prompt caching, tool use, structured output, vision, batch API, retry/backoff, cost control, Next.js Route Handler and Server Action wiring. Use when building features that call Claude (chat, summarization, agents, classifications), debugging tool-use loops, optimizing token cost via caching, or migrating between Claude model versions.
-
pixartseu Bundle Gltf Asset PipelineglTF/GLB asset preparation pipeline — Blender export, gltfpack (Meshopt) and gltf-transform optimization, Draco geometry compression, KTX2 + Basis Universal textures, gltfjsx code generation, hosting & cache headers. Use when a 3D model is too heavy, you need to bake/export from Blender, optimize for production, generate React Three Fiber components from a model, or set up CDN headers for .glb files.
-
pixartseu Bundle Pixarts Client SitePixarts client site stack - Next.js, Payload CMS, shadcn/ui, i18n, Tailwind. Use when building frontend for Pixarts client projects, setting up standard stack, or implementing multi-tenant architecture.
-
pixartseu Bundle Threejs FundamentalsThree.js core knowledge base — scene, camera, renderer, geometries, materials, lights, GLTF loader, OrbitControls, raycaster, render loop, resize handling. Use when starting a vanilla Three.js scene, debugging WebGL context, integrating Three.js without React, or learning the engine before moving to React Three Fiber.
-
pixartseu Bundle Rhf Zod Server ActionsCanonical Next.js 15 form stack — react-hook-form + Zod resolver + Server Actions + useActionState + Progressive Enhancement + revalidation. Use when building forms (contact, login, signup, multi-step, file upload), debugging duplicate validation logic between client and server, adding optimistic updates, or handling field/global errors and pending states without losing PE.
-
pixartseu Bundle Vitest Next ConventionsVitest in Next.js 15 App Router — vite.config setup, jsdom vs node environments, testing Server Components/Server Actions, mocking next/navigation/headers/cookies, React Testing Library integration, fixtures, MSW for network, coverage with v8, watch mode, parallelization, CI in GitHub Actions. Use when setting up Vitest, fixing test failures around RSC or async hooks, mocking Next.js APIs, or speeding up the test suite.
-
pixartseu Bundle Nodemailer TransactionalNodemailer + SMTP for transactional emails in Next.js — singleton transporter, HTML+plaintext templates, attachments, SPF/DKIM/DMARC deliverability, retry/queue strategies, Server Action integration, common providers (Postmark, SendGrid, Mailgun, generic SMTP, Gmail). Use when sending contact form submissions, password reset, order confirmations, notifications, or debugging emails landing in spam.
-
pixartseu Bundle Tanstack Query Next ActionsTanStack Query v5 in Next.js 15 App Router — QueryClient + QueryClientProvider setup, prefetch in RSC + HydrationBoundary, mutations with optimistic updates, Server Actions interop, invalidation patterns, infinite queries, suspense queries, devtools. Use when you need rich client-side caching for server data, interactive lists with optimistic updates, infinite scroll, or when Server Components alone can't handle your interaction patterns.
-
pixartseu Bundle Pixarts Template ArchitectureStandard Next.js project architecture for Pixarts client sites - folder structure, root layout, block renderer, env config. Use when scaffolding a new client project, setting up the standard folder structure, or configuring root layout/config files.
-
pixartseu Bundle Stripe Subscriptions WebhooksStripe for SaaS in Next.js — Checkout Sessions (subscription mode), Customer Portal, webhook signature verification, idempotency, subscription lifecycle events, multi-currency, Stripe Tax, metered billing, prorations, trial logic, sync to your DB. Use when adding paid plans, integrating Stripe Checkout, handling webhook events, debugging signature errors, syncing subscriptions, or building a self-serve billing UI.
-
neuralblitz Skill MobileExpert guidance on mobile app development for iOS and Android. Use for: native app development with Swift/SwiftUI and Kotlin/Jetpack Compose, cross-platform development with React Native and Flutter, mobile UI/UX design, device APIs, push notifications, offline-first architecture, app store submission, and mobile performance optimization.
Audited 1 -
tony Bundle Tailwind Spacing AuditUse when Tailwind UI spacing, alignment, gaps, margins, padding, or toolbar and navbar rhythm looks inconsistent.
-
26zl Skill Offensive MobileMobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, universal links), insecure data storage (SharedPrefs, KeyStore misuse, NSUserDefaults, Keychain ACL bypass), IPC / Intent redirection, WebView vulnerabilities (JavaScriptInterface, file:// access), Firebase/AWS/Azure misconfiguration leakage, mobile API testing, biometric/Face ID/Touch ID bypass, app-cloning and runtime patching, and mobile malware/RAT analysis primitives. Use for mobile pentest, bug bounty mobile triage, or app-store reconnaissance. Use only for authorized security research, training, or assessment.
-
26zl Bundle Web2 Vuln ClassesComplete reference for 22 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI (ASI01-ASI10 agentic framework), API misconfig (mass assignment, JWT attacks, prototype pollution, CORS), ATO taxonomy (9 paths), SSTI (Jinja2/Twig/Freemarker/ERB/Spring), subdomain takeover, cloud/infra misconfigs, HTTP smuggling (CL.TE/TE.CL/H2.CL), cache poisoning, MFA bypass (7 patterns), SAML attacks (XSW/comment injection/signature stripping), error disclosure / debug endpoints (stack trace regex per framework, chain templates), CSS injection (attribute-selector exfiltration, opacity clickjacking, @import). Use when hunting a specific vuln class or studying what makes bugs pay.
Audited -
26zl Skill Offensive ReportingPenetration test and red team report writing methodology: executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title, severity, scope, narrative, reproduction, impact, remediation, references), CVSS v3.1/v4.0 scoring with vector justification, OWASP risk rating, evidence hygiene (redacting credentials, hashing client data, time-stamping actions), screenshot and PoC artifact management, finding chain narratives, scope/limitations/assumptions, retest and remediation tracking, deliverable formats (PDF, DOCX, HTML, JSON for SIEM), client-customer-deliverable separation, and common mistakes (over-CVSSing, undermining the triager, missing the 'so what'). Use at the end of an engagement when authoring a deliverable, restructuring a draft for executive readability, or building a reusable report template. Authorized security research, training, or assessment only.
Audited -
26zl Skill Offensive Waf BypassWAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests. Use only for authorized security research, training, or assessment.
Audited -
26zl Skill Offensive File UploadFile upload vulnerability checklist: MIME type bypass, extension bypass, magic byte manipulation, path traversal in filenames, stored XSS via SVG/HTML upload, server-side processing attacks, and race conditions. Use for assessing file upload endpoints in web app pentests or bug bounty. Use only for authorized security research, training, or assessment.
-
26zl Skill Offensive Parameter PollutionHTTP parameter pollution (HPP) checklist: duplicate parameter injection, backend vs frontend parsing differences, WAF bypass via HPP, server-side vs client-side HPP, and practical exploitation patterns. Use when testing web applications for parameter handling flaws. Use only for authorized security research, training, or assessment.
Audited -
tcuzzo Skill Root Cause FirstUse when facing a hard bug, a silent failure, a regression hunt, or a risky change that could quietly break a downstream consumer. No fixes without investigation — read the error, reproduce it on demand, check recent changes, instrument component boundaries, trace data flow backward to the source. Trigger words: debug, root cause, why is this failing, silent failure, regression, works in tests but fails live, systematic debugging.
Audited -
harzva Bundle Ieee Figure TableAudit and improve IEEE figures, tables, captions, result reporting, and visual consistency using compact component fragments.
-
harzva Bundle Elsevier Figure TableAudit and improve Elsevier figures, tables, captions, result reporting, and visual consistency using compact component fragments.
-
harzva Bundle Ieee FigureIEEE Figure: figures, panels, visual evidence, resolution/readability, accessibility, and text-reference order.
-
harzva Bundle Ieee Component RouterIeee Component Router: detect manuscript components such as table, figure, caption, related work, method, experiment, ablation, references, declarations, and route them to the correct component skills. Use for IEEE Transactions, Journals, Letters, and IEEE-style technical journal writing.
-
harzva Bundle Elsevier FigureElsevier Figure: figures, panels, visual evidence, resolution/readability, accessibility, and text-reference order.
-
harzva Bundle Ieee Ablation StudyIEEE Ablation Study: ablation design, component-level evidence, sensitivity analysis, and mechanism validation.
Frequently asked questions
What are Web & Frontend agent skills?
Web development agent skills handle frontend and full-stack work: component patterns, CSS and accessibility fixes, performance budgets, and framework conventions. Install a skill once and your AI agent follows the same playbook in every project, from quick prototypes to production apps.
Which Web & Frontend skills are most installed?
Popular Web & Frontend skills on SkillMD right now include offensive-reporting, ieee-ablation-study, shopify-themes. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Web & Frontend skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.