nickgallick
- 731 skills
- 0 followers
- 2 weeks ago last updated
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Nick Product Strategist 2 · nickgallickStrategic product evaluation before building anything. Runs market gap analysis, competitor landscape, revenue model viability, and go/no-go recommendation. Use before committing to any new product, SaaS, or app idea. Prevents wasting time building things nobody will pay for.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Nick Project Orchestrator 2 · nickgallickTop-level orchestration skill that chains all of Nick's skills in the right order. From idea to live product in one flow. Routes through Strategy → Schema → Design → Build → Deploy → Verify. Use when Nick shares a new product idea or says "build this."
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Nick Fullstack 2 · nickgallickEnterprise-grade fullstack build standards for all projects. Covers code quality, Supabase patterns, error handling, security, SEO, accessibility, performance, and QA. Injected into every Claude Code build spec alongside the design system.
- ▌ Youtube Research 2 · nickgallickPull full YouTube video transcripts and analyze them for research intelligence. Uses TranscriptAPI.com.
- ▌
- ▌ Framework Source Code 2 · nickgallickIndex of cloned design framework repos and how to reference them.
- ▌ Competitive Intelligence 2 · nickgallickTrack Agent Arena competitors, substitutes, and category-adjacent products with a concrete monitoring checklist and response playbooks. Use when building Arena competitive briefs, preparing launch positioning, reacting to new entrants, or deciding how Arena should frame itself against Kaggle, local benchmarking, private eval harnesses, and benchmark leaderboards.
- ▌ Multi Tenancy Architecture · nickgallickMulti-tenancy patterns — shared schema with RLS, schema-per-tenant, tenant context propagation, team/role management, billing per tenant, and isolation testing.
- ▌ Prototype Pollution Chains · nickgallickDetection and exploitation understanding of JavaScript prototype pollution vulnerabilities, from source identification through gadget chains to RCE. Use when reviewing code that merges objects, parses JSON, uses lodash/underscore deep operations, processes GraphQL responses, handles deserialization (React Flight, devalue, flatted), or any code where user input flows into object property assignment. Covers CVE-2025-13465 (Lodash), CVE-2025-55182 (React2Shell via pollution), CVE-2026-30226 (Svelte devalue), CVE-2026-33228 (flatted), CVE-2026-12345 (Apollo Federation CRITICAL). Essential for Next.js + Supabase stack review.
- ▌ Analytics And Attribution · nickgallickDefine marketing and product analytics for Agent Arena including full acquisition-to-retention funnel tracking, UTM structure, Arena-specific events, dashboard specs, attribution rules, and weekly reporting. Use when instrumenting launch, measuring which channels drive signups and challenge entries, or diagnosing funnel drop-off and loop health for Arena.
- ▌ Content Localization Prep · nickgallickPrepare Bouts content for international reach starting with language-neutral English and defining the localization roadmap for Chinese, Japanese, Korean, German, and French markets by AI developer density. Use when writing English content to ensure it is globally accessible, or when planning future localization efforts.
- ▌ Email Marketing Execution · nickgallickRun Bouts email marketing including the weekly newsletter, agent onboarding sequence, win-back sequence, and Boss Fight announcements with full cadence and copy structure. Use when setting up or managing email programs for any of Bouts's four audience segments.
- ▌ Launch Execution Playbook · nickgallickRun Agent Arena launch operations from Day -14 through Day +7 with hour-by-hour channel execution, actual post copy, owner sequencing, and contingency plans. Use when preparing or executing Arena’s launch week and when a detailed launch runbook is needed instead of a vague GTM summary.
- ▌ Accessibility Smoke Testing · nickgallickRun automated WCAG 2.1 AA accessibility checks on every Arena page using axe-core via @axe-core/playwright. Identifies critical violations that block launch vs serious issues to fix soon. Integrated into Forge's E2E flow.
- ▌ Business Logic Exploitation · nickgallickDetection of business logic vulnerabilities — the bugs that scanners never find. Use when reviewing payment flows, subscription management, resource allocation, competitions/contests, coupon/discount systems, multi-step workflows, role/permission transitions, approval processes, or any feature where the correctness of behavior depends on business rules rather than technical implementation. Covers IDOR (Insecure Direct Object References), state machine violations, parameter tampering, price/quantity manipulation, privilege escalation via logic flaws, workflow bypass, and financial calculation errors. Relevant for Agent Arena, UberKiwi, and any product with money, permissions, or competitive mechanics.
- ▌ Compliance Security Finance · nickgallickSecurity compliance requirements for financial services applications — SOC 2, PCI DSS, GDPR/privacy, and financial data handling standards. Use when building payment products, financial SaaS, mortgage/lending tools, or any application handling financial data, PII, or payment card information. Covers what SOC 2 Type II requires from a technical security standpoint, PCI DSS scope reduction (so you don't have to become PCI compliant yourself), GDPR technical requirements, breach notification obligations, data retention rules, and the specific audit controls that map to our Next.js + Supabase architecture.
- ▌ Cryptography For Developers · nickgallickUsing crypto correctly — hashing, HMAC, encryption, JWT internals, and review flags for cryptographic anti-patterns.
- ▌ Data Structures In Practice · nickgallickPractical data structures for production code — Map for O(1) lookups, Set for membership, trees for hierarchies, queues for job scheduling. Not LeetCode — real patterns.
- ▌ Game Theory And Matchmaking · nickgallickELO deep dive, Glicko-2 rating system, matchmaking algorithms, tournament bracket generation, and anti-gaming detection for Agent Arena.
- ▌ Null Safe Results Rendering · nickgallickRender partial, legacy, missing, and evolving evaluation result data without crashes — covering every null/undefined edge case in Bouts lane scores, evidence refs, confidence fields, and partial judge results.
- ▌ Premium Replay Breakdown UX · nickgallickDesign the Bouts post-match breakdown page — information hierarchy, component architecture, partial result handling, loading states, mobile/desktop layout, and psychological flow that makes users feel the result is trustworthy and earned.
- ▌ Threat Modeling Methodology · nickgallick bundleSystematic threat modeling using STRIDE, attack trees, and data flow analysis — applied BEFORE code is written to catch security flaws at design time. Use when designing new features, reviewing architecture specs, evaluating system designs, creating security requirements for new projects, or performing pre-development security review. This is the proactive counterpart to reactive code review — find the vulnerability in the design before anyone writes a line of code. Covers STRIDE threat categorization, data flow diagramming, trust boundary identification, attack tree construction, risk scoring, and threat-to-mitigation mapping specific to our Next.js + Supabase + Vercel stack.