← all publishers

afu-it

@afu-it source repo

41 published skills

  1. Prpm Dbp · afu-it bundle
    Sahkan ejaan Bahasa Melayu dan Jawi terhadap PRPM Dewan Bahasa dan Pustaka sebelum menghantar output. Guna apabila menulis, menyemak, atau mentransliterasi teks BM/Jawi, terutama bahan pendidikan, RPH, nota, atau apa-apa yang perlu ikut ejaan rasmi DBP. Trigger: jawi, kamus dewan, ejaan rasmi, DBP, PRPM, transliterasi, bahasa melayu baku.
    0
    installs
  2. UI Redesign Director · afu-it
    redesign existing user interfaces, screenshots, dashboard cards, app screens, and product components into polished modern visuals. use when the user asks to redesign, improve, modernize, premiumize, clean up, or generate a better version of an existing ui. especially useful for saas dashboards, mobile app screens, widgets, progress cards, onboarding flows, settings pages, and components where layout, hierarchy, spacing, and visual quality need improvement.
    0
    installs
  3. Imagegen · afu-it bundle
    Use when the user asks to generate or edit images (e.g., generate image, edit/inpaint/mask, background removal, transparent background, product shots, concept art, covers, or batch variants). Runs built-in image_generation_call first, then falls back to custom endpoint via auth.json.
    0
    installs
  4. Create Image Codex · afu-it
    Create images on Codex, especially with 9Router (e.g., generate image, edit/inpaint/mask, background removal, transparent background, product shots, concept art, covers, or batch variants). Auto-patches ~/.codex/config.toml if needed. Uses built-in image generation first, then falls back to provider endpoint via config.toml + auth.json.
    0
    installs
  5. Safe Code · afu-it bundle
    Use when asked to run a full repo hygiene pass, full cleanup, or to maintain a repo in one go — and whenever the user invokes /safe-code or any wrapper of it (/skill:safe-code, /skills safe-code, $safe-code, @safe-code, or bare safe-code), including --continue to resume saved work and --save to finalize docs and commit. Also use for first-time project setup, restoring project context or session memory, dead-code audits, or agent-config trust checks.
    0
    installs
  6. Senior Dev · afu-it
    Senior engineer discipline layer for any coding task. Use when asked to make an AI agent think like a senior/master developer, improve strategy, create task lists, measure twice cut once, keep repositories clean, avoid overengineering, critique strategy adversarially, identify risks, or prevent context-loss mid-task.
    0
    installs
  7. Build Graph · afu-it
    Build or update the code review knowledge graph. Use before safe-code audits, refactors, reviews, debugging, or when the graph may be stale.
    0
    installs
  8. Debug Issue · afu-it
    Systematically debug a symptom with a red-capable feedback loop, a minimised repro, ranked falsifiable hypotheses, tagged probes, and a regression test at the correct seam. Graph tools accelerate the search when present; they are never required.
    0
    installs
  9. Review Changes · afu-it
    Review working-tree, branch, or PR changes on two separate axes — Standards (repo conventions + a smell baseline) and Spec (does it do what the active feature spec asked) — with blast-radius and test-coverage checks. Graph tools accelerate when present; never required.
    0
    installs
  10. Codebase Pruner · afu-it
    Scan an entire codebase to detect and safely remove dead code such as unused functions, orphaned modules, unreferenced exports, stale configs, dead routes, and leftover workflow artifacts. Use when asked to clean up dead code, remove unused code, prune stale files, find orphaned modules, audit codebase bloat, or delete code left behind after a workflow or architecture change.
    0
    installs
  11. Explore Codebase · afu-it
    Navigate and understand codebase structure using the code-review graph. Use for repo orientation, AGENTS.md authoring, architecture mapping, or finding relevant code.
    0
    installs
  12. Safe Refactor Code · afu-it
    Refactor code safely in small verified slices while keeping repo continuity docs in sync. Uses code-review graph tools for rename previews, impact radius, affected flows, and post-change review when available. Use when an agent is asked to refactor, restructure, clean up, remove or replace code, modernize modules, or do follow-up hygiene in a repo.
    0
    installs
  13. Setup Billplz · afu-it bundle
    Set up, build, debug, review, and explain Billplz payment integrations using Billplz API docs, help center, GitHub plugins, status pages, payment collections, payment forms, Payment Order payouts, X Signature callbacks/redirects, V5 checksums, sandbox/live setup, API Secret Key, Collection ID, and X Signature Key.
    0
    installs
  14. Setup Bayarcash · afu-it bundle
    Set up, build, debug, and explain Bayarcash payment integrations using Bayarcash API docs, Web Impian API docs, Bayarcash PHP SDK, WordPress plugins, Boost.space integration links, and Bayarcash MCP server references. Use when working with Bayarcash API v2/v3, payment intents, FPX banks, DuitNow banks or wallets, portals, payment channels, callbacks/webhooks, checksums, transaction lookups, direct debit/e-Mandate flows, enterprise partner merchant/payout APIs, Laravel/PHP SDK usage, WordPress Bayarcash integrations, or Bayarcash MCP tooling.
    0
    installs
  15. Setup Senangpay · afu-it bundle
    Set up, build, debug, review, and explain senangPay payment integrations using official senangPay guide pages, Manual Integration API, Direct API, callbacks, return URLs, query status APIs, refund API, sandbox/live setup, Merchant ID, Secret Key, Hash Type, shopping cart plugins, e-commerce integrations, recurring payments, payout API, tokenisation, split settlements, and DOKU migration references. Use when working with senangPay hosted checkout, payment forms, callbacks, SHA256/MD5 hash verification, Direct API client sessions, JavaScript Web SDK, FPX bank lists, refunds, package capabilities, sandbox testing, or senangPay dashboard setup.
    0
    installs
  16. Setup Toyyibpay · afu-it bundle
    Set up, build, debug, review, and explain toyyibPay payment integrations using official toyyibPay API references, onboarding manuals, DuitNow QR notes, pricing/support pages, WooCommerce plugin notes, and WorkDo setup docs. Use when working with toyyibPay categories, bills, payment links, FPX, cards, DuitNow QR, callbacks, return URLs, MD5 callback verification, transaction lookups, inactive bills, sandbox/live setup, secret keys, category codes, WooCommerce setup, or ToyyibPay settlement checks.
    0
    installs
  17. Setup Stripe Malaysia · afu-it bundle
    Set up, build, debug, review, and explain Stripe payment gateway integrations for Malaysia. Use when working with Stripe Checkout Sessions, Payment Intents, Payment Links, Elements, webhooks, Stripe.js, Stripe CLI, refunds, sandbox/live setup, MYR payments, cards, FPX, GrabPay, and production readiness.
    0
    installs
  18. Malaysia Payment Gateway · afu-it bundle
    Build, debug, review, and explain Malaysia payment gateway integrations. Use when implementing checkout, payment links, hosted payment pages, redirects, callbacks, webhooks, HMAC/signature verification, idempotent settlement, paid-access unlocking, refunds, reconciliation, sandbox/live setup, or provider switching for Malaysian gateways such as CHIP Collect, Curlec/Razorpay, Xendit Malaysia, Bayarcash, BCL Pay, toyyibPay, Billplz, FPX, DuitNow QR, cards, or e-wallets.
    0
    installs
  19. Setup Bcl · afu-it bundle
    Set up, build, debug, review, and explain BCL payment gateway, BCL Pay, BCL Payment Link, BCL QR Terminal, BCL Forms, Bayarcash-linked setup, portal keys, transactions, webhooks, direct debit forms, client info, payment redirects, and BCL operating procedures using BCL docs.
    0
    installs
  20. Setup Chip · afu-it bundle
    Set up, build, debug, and explain CHIP Collect payment integrations using the official CHIP Collect API documentation. Use when working with CHIP Collect purchases, checkout URLs, payment links, direct post, FPX, DuitNow QR, cards, e-wallets, callbacks, webhooks, signature verification, clients, recurring tokens, subscriptions, pre-authorization, refunds, captures, releases, payment methods, statements, account balance, account turnover, API keys, Brand ID, or CHIP Collect endpoint schemas.
    0
    installs
  21. Setup Fiuu · afu-it bundle
    Set up, build, debug, review, and explain Fiuu payment integrations using official Fiuu API specs, Seamless Integration, Inpage Checkout, Mobile XDK, SDKs, and shopping cart plugin references. Use when working with Fiuu hosted payment pages, payment requests, vcode/skey verification, Return URL, Notify/Notification URL, Callback URL, IPN ACK/retry behavior, payment status requery, refunds, captures, recurring/token payments, channel status, mobile Flutter/Android/iOS/React Native XDK, JavaScript Seamless Integration, Inpage Checkout, WooCommerce, Magento, OpenCart, WHMCS, Shopify, or Fiuu account/dashboard setup.
    0
    installs
  22. Setup Curlec · afu-it bundle
    Set up, build, debug, review, and explain Razorpay Curlec payment gateway integrations using Curlec and shared Razorpay documentation. Use when working with Curlec/Razorpay Standard Checkout, FPX or redirect payment methods, Orders API, Payments API, Refunds API, Payment Links, Basic Auth API keys, checkout.js options, callback_url, payment signature verification, webhook setup, webhook HMAC validation, sandbox/test mode, payment capture, payment status reconciliation, or Malaysia payment gateway go-live checks.
    0
    installs
  23. Setup Hitpay · afu-it bundle
    Set up, build, debug, review, and explain HitPay payment integrations using official HitPay docs, Payment Request API, hosted checkout, Drop-In UI, webhooks, HMAC-SHA256 signatures, sandbox/live setup, API keys, webhook salt, payment methods, plugins, refunds, recurring billing, payouts, platform APIs, and status page checks. Use when working with HitPay Malaysia, FPX, DuitNow, Touch 'n Go, cards, e-wallets, QR payments, Payment Links, API checkout, webhook settlement, refunds, or production readiness.
    0
    installs
  24. Setup Xendit · afu-it bundle
    Set up, build, debug, and explain Xendit payment gateway integrations, including Payments API v3, payment requests, payment tokens, webhooks, refunds, and xenPlatform sub-account routing. Use when implementing checkout, server-side payment collection, saved payment methods, webhook handling, payment status reconciliation, or platform marketplace flows with Xendit.
    0
    installs
  25. Secure Ship · afu-it
    Security for vibe coders. Full PDPA 2024 + OWASP Top 10 compliance for any codebase. Covers enterprise-grade access control, SSRF prevention, SQL injection, input validation, secrets management, auth hardening, security headers, CORS, data encryption, error handling, audit logging, webhook security, CI/CD gates, rate limiting, and dependency auditing. Based on real Malaysian court cases where developers were fined RM1,000,000. Use when asked to secure a project, check PDPA compliance, run OWASP audit, add security to CI, or before go-live.
    0
    installs
  26. Rate Limiting · afu-it
    Add per-user and per-IP rate limiting to API endpoints. Covers Cloudflare Workers (KV-based sliding window), Express.js, Next.js, and generic patterns. Prevents abuse, brute-force attacks, and resource exhaustion. Use when adding rate limits, preventing API abuse, or fixing OWASP A04/A07 findings.
    0
    installs
  27. Auth Hardening · afu-it
    Harden authentication systems against session fixation, brute-force attacks, and weak password storage. Covers bcrypt/argon2 hashing, JWT best practices, session management, and account lockout. Use when implementing login, fixing auth vulnerabilities, or reviewing authentication code.
    0
    installs
  28. Data Encryption · afu-it
    Encrypt personal data at rest and in transit to comply with PDPA 2024. Covers field-level encryption for PII, AES-256-GCM patterns, key management, and database column encryption for Node.js, Python, Laravel, and Cloudflare Workers. Use when storing sensitive user data, implementing encryption, or responding to PDPA compliance requirements.
    0
    installs
  29. Ssrf Prevention · afu-it
    Enterprise-grade Server-Side Request Forgery (SSRF) prevention for APIs, webhooks, URL previewers, importers, and fetch-by-URL features. Covers strict allowlists, DNS rebinding defense, private IP blocking, cloud metadata protection, redirect validation, egress controls, and safe fetch wrappers for Node.js, Cloudflare Workers, Python, and Laravel. Use when code fetches user-provided URLs or calls external services.
    0
    installs
  30. Input Validation · afu-it
    Validate and sanitize all user input to prevent XSS, path traversal, command injection, and malformed data. Covers Zod, Joi, class-validator, Laravel validation, and Python Pydantic. Use when building forms, API endpoints, file uploads, or fixing injection vulnerabilities beyond SQL.
    0
    installs
  31. Security Headers · afu-it
    Add security headers (CSP, HSTS, X-Frame-Options, Permissions-Policy) to prevent clickjacking, XSS, and data leaks. Provides copy-paste middleware for Express, Next.js, Cloudflare Workers, and Laravel. Use when hardening HTTP responses, fixing security scanner findings, or setting up a new project.
    0
    installs
  32. Webhook Security · afu-it
    Fix race conditions, add idempotency guards, and implement timing-safe token comparisons for payment webhooks. Covers Xendit, Stripe, Paddle, and generic webhook patterns. Prevents double-crediting, replay attacks, and timing attacks. Use when building payment webhooks, fixing race conditions, or securing callback endpoints.
    0
    installs
  33. CI Security Gates · afu-it
    Add CodeQL SAST, Gitleaks secret scanning, and dependency audit to any CI/CD pipeline. Blocks deployment if vulnerabilities or secrets are detected. Covers GitHub Actions, GitLab CI, and generic pipelines. Use when setting up CI security, adding SAST, preventing secret leaks, or hardening deployment pipelines.
    0
    installs
  34. Cors Configuration · afu-it
    Configure CORS correctly to prevent credential leaks and unauthorized cross-origin access. Covers Express, Next.js, Cloudflare Workers, Laravel, and FastAPI. Use when setting up CORS, fixing preflight errors, or auditing cross-origin policies.
    0
    installs
  35. Secrets Management · afu-it
    Prevent hardcoded secrets in source code. Covers .env setup, .gitignore patterns, secret scanning, runtime secret injection, and rotation strategies for Node.js, Python, Laravel, and Cloudflare Workers. Use when setting up environment variables, fixing exposed secrets, or implementing secret rotation.
    0
    installs
  36. Pdpa Security Audit · afu-it
    Full PDPA 2024 + OWASP Top 10 security audit for any codebase. Checks all 8 forensic findings from Malaysian court cases plus enterprise controls for access control, SSRF, secrets, encryption, CORS, auth hardening, and error handling. Produces a compliance scorecard and actionable fix list. Use when asked to audit security, check PDPA compliance, run OWASP assessment, or before go-live.
    0
    installs
  37. Audit Logging Workers · afu-it
    Add structured audit logging with immutable R2 storage to Cloudflare Workers. Creates a typed audit utility, instruments all API routes, deploys a tail worker for persistent log storage, and configures R2 bucket lock for tamper-resistance. Use when adding logging, audit trails, or PDPA compliance to a Cloudflare Workers project.
    0
    installs
  38. Access Control Patterns · afu-it
    Enterprise-grade access control patterns to prevent broken access control, IDOR, tenant data leaks, privilege escalation, and admin route exposure. Covers RBAC, ABAC, ownership checks, multi-tenant scoping, policy middleware, row-level security, and audit logging for Node.js, Cloudflare Workers, Laravel, and Python. Use when protecting routes, implementing roles, reviewing authorization, or fixing OWASP A01 findings.
    0
    installs
  39. Error Handling Security · afu-it
    Prevent information leakage through error messages. Covers sanitized error responses, structured error handling, no stack traces in production, and safe logging patterns for Express, Next.js, Cloudflare Workers, Laravel, and FastAPI. Use when fixing verbose errors, implementing error handlers, or preventing stack trace leaks.
    0
    installs
  40. SQL Injection Prevention · afu-it
    Detect and fix SQL injection vulnerabilities in any framework. Covers Laravel (DB::raw, whereRaw), Node.js (template literals in queries), Python (f-strings in SQL), and Cloudflare D1. Enforces parameterized bindings everywhere. Use when writing database queries, reviewing code for injection, or fixing SQL injection findings.
    0
    installs
  41. Dependency Lockfile Audit · afu-it
    Detect typosquatting, malicious packages, and lockfile tampering in npm, pip, and composer dependencies. Covers lockfile integrity verification, known-malicious package detection, and supply chain attack prevention. Use when auditing dependencies, investigating suspicious packages, or hardening the supply chain.
    0
    installs