all publishers

nickgallick

@nickgallick source repo

731 published skills · page 5 of 8

  1. ▌
    Content Repurposing Engine · nickgallick bundle
    Turn one piece of content into 8-10 platform-specific versions. Use when repurposing a blog post, battle result, product update, or any content event into Twitter threads, Reddit posts, TikTok scripts, YouTube shorts, LinkedIn articles, Discord announcements, email newsletters, and Dev.to posts. The "create once, distribute everywhere" system for developer products.
    0 repo stars
  2. ▌
    Referral Program Execution · nickgallick
    Design and run the Bouts referral program with tiered mechanics, shareable assets, referral copy, and milestone rewards. Use when building or optimizing the Bouts invite system to turn existing competitors into recruiters.
    0 repo stars
  3. ▌
    Weekly Intelligence Report · nickgallick
    Build the Bouts AI Agent Index weekly report — the flagship content asset that anchors all downstream content distribution across blog, email, social, and Reddit/HN. Use every Tuesday to produce and publish the structured weekly report from the Monday data pull.
    0 repo stars
  4. ▌
    Video And Media Integration · nickgallick
    Video backgrounds, HLS streaming, overlays, image optimization. Complete React implementations. Use when integrating video backgrounds, HLS streaming, video fades, responsive video, or media-heavy designs.
    0 repo stars
  5. ▌
    Advanced Typescript Patterns · nickgallick
    Type-level programming — discriminated unions, generics mastery, branded types, utility types, end-to-end type safety patterns for Next.js + Supabase.
    0 repo stars
  6. ▌
    Expert Information Hierarchy · nickgallick
    How to make dense evaluation output readable fast — the 3-second rule, progressive disclosure architecture, scan-first layout, expandable evidence panels, and concrete before/after redesign for Bouts result pages.
    0 repo stars
  7. ▌
    Observability And Monitoring · nickgallick
    The three pillars of observability — structured logging, metrics, traces. Alerting without fatigue, incident response, and runbook-driven operations.
    0 repo stars
  8. ▌
    Secure Architecture Patterns · nickgallick bundle
    Architecture patterns that make entire categories of vulnerabilities impossible by design. Use when designing system architecture, reviewing architecture specs, deciding on data flow patterns, choosing auth/authz models, or evaluating if a design is secure by construction vs requiring runtime enforcement. Covers zero-trust architecture, defense in depth, blast radius containment, secure-by-default patterns, the principle of least privilege applied to system design, and specific Next.js + Supabase + Vercel architectural decisions that determine the security ceiling of everything built on top.
    0 repo stars
  9. ▌
    Solidity And Smart Contracts · nickgallick
    Solidity development — language fundamentals, security vulnerabilities (reentrancy, overflow, access control, front-running, DoS), gas optimization, testing, upgradability.
    0 repo stars
  10. ▌
    Content Calendar Autonomous · nickgallick
    The autonomous weekly content rhythm for Bouts that runs Monday through Friday with specific content actions per day, daily automated monitoring tasks, and quarterly planning cycles. Use when planning the weekly content operation or executing without additional instruction.
    0 repo stars
  11. ▌
    Developer Community Seeding · nickgallick
    Build Bouts presence in existing developer communities on Reddit, Discord, and GitHub through value-first participation, specific subreddit strategies, and community engagement rules. Use when planning community outreach, writing Reddit posts, seeding developer Discord servers, or creating GitHub presence for Bouts.
    0 repo stars
  12. ▌
    Developer Persona Deep Dive · nickgallick
    Four detailed builder/buyer personas for Bouts including indie agent builder, AI startup CTO, AI lab researcher, and enterprise evaluator. Use when deciding what content to create, how to pitch Bouts to a specific person, or personalizing DMs, outreach, and onboarding messaging.
    0 repo stars
  13. ▌
    Developer Relations Content · nickgallick
    Technical content strategy for Bouts' developer relations program including architecture deep-dives, builder guides, data analysis posts, and open-source contribution plans. Use when planning or writing content that builds trust with the agent builder audience through technical depth and genuine usefulness.
    0 repo stars
  14. ▌
    Launch Operating Principles · nickgallick
    The 15 permanent operating principles Launch follows across all content creation, growth execution, and enterprise pipeline work for Bouts — covering content, growth, and coordination standards.
    0 repo stars
  15. ▌
    Marketing Budget Management · nickgallick
    Allocate and review Agent Arena marketing budget by phase, channel, and experiment with Arena-specific spending logic for launch, validation, and growth. Use when deciding where Arena should spend or avoid spending, how much to test on each channel, and how to run monthly marketing reviews tied to activation and challenge participation instead of vanity traffic.
    0 repo stars
  16. ▌
    Pr And Media Outreach Bouts · nickgallick
    Bouts PR and media strategy including tiered media targets, pitchable stories, journalist relationship building, conference presence, and exclusive data outreach. Use when preparing press pitches, writing media outreach copy, or planning coverage for Bouts launches and monthly data reports.
    0 repo stars
  17. ▌
    Error Handling Infodisclosure · nickgallick
    Detection of information disclosure through error handling, stack traces, verbose error messages, debug endpoints, and response metadata leakage. Use when reviewing error handling patterns, API error response shapes, Next.js error boundaries, Supabase error forwarding, logging configuration, and any code that catches and returns errors to clients. Information disclosure is Step 1 in nearly every exploit chain — it provides the reconnaissance data attackers need to construct targeted attacks.
    0 repo stars
  18. ▌
    Evaluation Analytics Pipeline · nickgallick
    Design and implement the analytics pipeline powering lane score distributions, repeated weakness patterns, agent progress over time, and challenge-level learning analytics — using materialized views, pg_cron refresh, and a clean separation between operational and analytical tables.
    0 repo stars
  19. ▌
    Feedback Actionability Design · nickgallick
    Turning Bouts evaluation breakdowns into coaching items that are concrete enough to act on — specificity ladder, failure code → next step derivation, deduplication across submissions, and a priority-ordered TSX coaching display component.
    0 repo stars
  20. ▌
    Replay Timeline System Design · nickgallick
    Full system design for Bouts evaluation replay — event model, SQL schema, TypeScript discriminated union, phase grouping, evidence ref linking, legacy record handling, and a virtualized TSX timeline component for 500+ events.
    0 repo stars
  21. ▌
    Web3 Frontend And Integration · nickgallick
    Web3 frontend development — wagmi hooks, viem client, wallet connection, contract interaction, The Graph, IPFS, account abstraction, hybrid Web2+Web3 architecture.
    0 repo stars
  22. ▌
    Conversion Rate Optimization · nickgallick
    Optimize Agent Arena conversion from landing page through signup, onboarding, first challenge, repeat challenge, and paid conversion using Arena-specific target rates, tests, and experiment designs. Use when auditing Arena’s landing page, GitHub auth flow, connector install path, challenge onboarding, or launch conversion bottlenecks.
    0 repo stars
  23. ▌
    Growth Metrics And Reporting · nickgallick
    Create Agent Arena weekly CEO reports, growth dashboards, and north-star reviews with Arena-specific KPIs such as weekly challenges completed, activation rate, repeat challenge rate, spectator return rate, and channel efficiency. Use when reporting performance to Nick, diagnosing growth, or creating the recurring operating report for Arena.
    0 repo stars
  24. ▌
    Social Media Execution Bouts · nickgallick
    Platform-specific Bouts social media posting strategies, cadence rules, proven tweet formats, LinkedIn post structure, Reddit/HN rules, and Discord community management for the Bouts AI Agent competition platform. Use when planning weekly social output, drafting posts from data, or managing community engagement across any channel.
    0 repo stars
  25. ▌
    Agent Prompt Injection Defense · nickgallick bundle
    Hardening patterns and detection techniques for indirect prompt injection (IDPI) and cross-domain prompt injection (XPIA) attacks against AI agents, specifically OpenClaw. Use when designing agent workflows that consume external content, reviewing agent configurations for injection risk, auditing skills/tools that fetch web content, responding to injection incidents, or building defenses into multi-agent pipelines. Covers the PromptArmor link-preview exfiltration technique, ClawJacked WebSocket hijacking, log poisoning injection, malicious ClawHub skills, 22 real-world IDPI payload techniques documented by Palo Alto Unit42, and CNCERT advisory on OpenClaw deployments.
    0 repo stars
  26. ▌
    Comparative Insight Generation · nickgallick
    Generate insights comparing an agent's performance to top performers, peers, and their own history — only from real data with minimum sample guards, including percentile comparisons, counterfactual rank calculation, and "surprisingly strong" lane detection.
    0 repo stars
  27. ▌
    Competitive Data Visualization · nickgallick
    Evaluation-specific visualization patterns for Bouts — radar charts, multi-judge comparison bars, rank distribution dots, confidence overlays, and percentile bands using Recharts with full accessibility and missing-data handling.
    0 repo stars
  28. ▌
    Competitive Platform Integrity · nickgallick bundle
    Anti-cheat, ELO manipulation prevention, Sybil defense, virtual currency compliance, and community moderation for competitive AI platforms. The integrity bible for Agent Arena. Cover ELO system design, anti-sandbagging, multi-account detection, submission integrity, judge integrity, economy abuse prevention, spectator privacy, replay integrity. Includes Supabase/Postgres patterns (RLS, functions, triggers).
    0 repo stars
  29. ▌
    Competitive Product Psychology · nickgallick
    What users actually need after losing or winning a competitive AI evaluation — emotional state design for winners, close misses, and clear losses, with TSX layout and copy patterns that make feedback feel fair rather than algorithmic.
    0 repo stars
  30. ▌
    Migration And Schema Evolution · nickgallick
    Safe database migration patterns — adding/removing/renaming columns, index creation, foreign keys, and Supabase-specific migration workflow.
    0 repo stars
  31. ▌
    Bouts Competitive Positioning · nickgallick
    Position Bouts against all AI benchmark competitors and alternatives with specific messaging for each comparison. Use when writing positioning copy, press pitches, investor materials, or any content where Bouts needs to be differentiated from SWE-bench, HumanEval, Aider, CodeClash, or generic evaluation approaches.
    0 repo stars
  32. ▌
    Competitive Response Playbook · nickgallick
    Respond to competitive moves, benchmark launches, methodology criticism, and market changes as Bouts' calm, data-rich voice in AI evaluation debates. Use when a competitor launches, a critic raises objections, an AI lab releases its own eval, or any situation requiring a public competitive response.
    0 repo stars
  33. ▌
    Content Multiplication Engine · nickgallick
    Turn one Bouts data insight into 7 ready-to-publish pieces of content across X, LinkedIn, blog, email, Reddit/HN, Discord, and lab reports. Use when transforming weekly platform data into a full week of cross-channel content without rewriting from scratch for each platform.
    0 repo stars
  34. ▌
    Content Repurposing For Bouts · nickgallick
    Turn every Bouts weekly intelligence report and technical blog post into 10+ channel-specific pieces for X, LinkedIn, email, Reddit, HN, Discord, and social sharing. Use when maximizing reach from existing Bouts content and enforcing the rule that nothing is created once for one channel.
    0 repo stars
  35. ▌
    Developer Community Marketing · nickgallick bundle
    GTM strategies for developer-facing products. Use when planning distribution for dev tools, AI products, SaaS targeting engineers/builders, or any product where the buyer is technical. Covers Reddit (r/artificial, r/machinelearning, r/LocalLLaMA, r/SideProject, r/webdev), Hacker News (Show HN), Twitter/X developer audience, Discord communities, YouTube technical demos, Dev.to/Hashnode blog posts, Product Hunt developer launches, developer trust signals, and cross-promotion from non-tech audiences (TikTok) to builder audiences. Use when generating launch copy, distribution plans, community engagement strategies, or developer marketing materials.
    0 repo stars
  36. ▌
    Anti Generic LLM Output Control · nickgallick
    Block filler, detect low-signal text, score specificity, and enforce evidence-anchored observations across all LLM-generated feedback in Bouts — with banned phrase detection, specificity scoring, retry-with-critique, and dimension name normalization.
    0 repo stars
  37. ▌
    Provisional Final Ranking Logic · nickgallick
    Open-window ranking, provisional placement, finalization triggers, edge case handling (ties, disqualifications, late submissions), rank history storage, and clear status communication for Bouts.
    0 repo stars
  38. ▌
    Unicode Steganography Detection · nickgallick bundle
    Detect hidden payloads concealed in source code via Unicode steganography — invisible characters from Tags block (U+E0000–E007F), Supplementary Private Use Areas (U+F0000–FFFFF, U+100000–10FFFF), zero-width characters (U+200B–200F, U+2060–2064, U+FEFF), variation selectors (U+FE00–FE0F, U+E0100–E01EF), and other non-printing ranges. Use when reviewing code, auditing dependencies, scanning repos before merge, installing third-party skills/packages, or conducting security reviews. Catches the GlassWorm, PhantomRaven, and CanisterWorm family of supply-chain attacks that hide exec/eval backdoors inside what appears to be legitimate sanitization or utility code.
    0 repo stars
  39. ▌
    Conference And Event Marketing · nickgallick
    Plan and execute Bouts conference presence at NeurIPS, ICML, AI Engineer Summit, and developer conferences with talk submissions, poster proposals, live competition events, and follow-up sequences. Use when planning conference strategy, writing talk abstracts, or maximizing the business value of any Bouts conference presence.
    0 repo stars
  40. ▌
    Conversion Funnel Optimization · nickgallick
    Optimize every stage of the Bouts conversion funnel from awareness to retention with specific targets, copy guidance, friction rules, and measurement approach. Use when diagnosing drop-off, writing onboarding copy, or improving the visit-to-active-competitor rate.
    0 repo stars
  41. ▌
    Monthly Bouts Index Production · nickgallick
    Produce the Bouts AI Agent Index monthly report including the full 5-section structure (leaderboard, model family, challenge family, failure archetypes, industry implications), production timeline, and distribution checklist. Use every month to create the flagship authority content piece that drives media coverage, lab outreach, and enterprise sales conversations.
    0 repo stars
  42. ▌
    Analytics And Attribution Bouts · nickgallick
    Track Bouts marketing performance weekly across growth, content, and revenue metrics with UTM attribution, a structured weekly analytics report, and decision rules for scaling or cutting channels. Use when reporting on Bouts marketing performance, diagnosing what is or is not working, or building the analytics infrastructure for the Bouts launch.
    0 repo stars
  43. ▌
    Tool Integration Specifications · nickgallick
    Specify the tools and API integrations Launch needs to operate autonomously including priority, approval workflows, rate limits, and auto-publish rules for X, email, blog, Discord, LinkedIn, Reddit, and analytics. Use when requesting integrations from Maks or Nick, or when building the autonomous publishing infrastructure.
    0 repo stars
  44. ▌
    Prompt Engineering For Production · nickgallick
    Production LLM integration — structured output via tool_use, system prompt hardening, temperature tuning, cost optimization, reliability patterns, output validation.
    0 repo stars
  45. ▌
    Content Differentiation Strategy · nickgallick
    Define the three-tier Bouts content moat and enforce the 80/20 rule that keeps content Bouts-native and impossible for competitors to replicate. Use when planning content calendars, briefing writers, or deciding what type of content to produce for any channel.
    0 repo stars
  46. ▌
    Content Performance Optimization · nickgallick
    Track every Bouts content piece, run monthly performance reviews, identify patterns, and systematically improve content mix based on what actually drives agent signups and enterprise inquiries. Use when conducting monthly content reviews, spotting high/low-performance patterns, or deciding where to shift content investment.
    0 repo stars
  47. ▌
    Advanced Animation And Interaction · nickgallick
    Framer Motion patterns, micro-interactions, scroll animations, layout transitions, React Native Reanimated, and animation performance rules.
    0 repo stars
  48. ▌
    Trust And Methodology Communication · nickgallick
    Making the Bouts scoring system legible to competitors — evidence vs inference labeling, provisional vs final copy, methodology disclosure, and dispute acknowledgment patterns that open the black box without overwhelming users.
    0 repo stars
  49. ▌
    Openclaw Changelog Intelligence · nickgallick
    Complete OpenClaw changelog analysis — version history, config keys by version, breaking changes, upgrade paths. The authoritative reference for version-safe config changes. Covers 2026.1.5 through 2026.3.14 (Unreleased).
    0 repo stars
  50. ▌
    Evidence Grounded Feedback Synthesis · nickgallick
    Convert raw judge outputs into premium, evidence-anchored user feedback — with suppression rules, fallback logic, contradiction handling, and zero generic filler.
    0 repo stars
  51. ▌
    Email Marketing For Digital Products · nickgallick
    Write and operate Agent Arena email systems including the full welcome sequence, streak reminders, re-engagement, weekly digest, and launch broadcasts with real Arena copy. Use when creating lifecycle email copy, launch emails, activation nudges, or retention messaging tied to challenge participation, rankings, and replays.
    0 repo stars
  52. ▌
    Influencer And Partnership Marketing · nickgallick
    Build Agent Arena influencer, creator, and partnership programs with specific target lists, outreach copy, and partnership tiers tied to AI builder ecosystems. Use when seeding Arena with creators, approaching ecosystem partners, or building launch distribution through trusted technical audiences instead of generic promotion.
    0 repo stars
  53. ▌
    Self Improving Feedback Instrumentation · nickgallick
    Track which feedback blocks users actually engage with — expand, copy, revisit, dwell on — and use that engagement signal to improve feedback structure over time without compromising user trust.
    0 repo stars
  54. ▌
    Longitudinal Competitor Coaching Surfaces · nickgallick
    Surface structured coaching insights across multiple bouts for the same competitor — repeated failures, recurring strengths, trendline improvement, and same-lane persistence — grounded in real data with suppression rules that prevent surfacing patterns too early.
    0 repo stars
  55. ▌
    Monorepo And Dx · nickgallick
    Monorepo structure, developer experience tooling, CI/CD pipeline, database workflow, and environment management for production Next.js + Supabase projects.
    0 repo stars
  56. ▌
    Threat Modeling · nickgallick bundle
    Adversarial security review — think like an attacker to find exploit chains that checklists miss.
    0 repo stars
  57. ▌
    Agentic Planning · nickgallick
    Structured planning methodology from SWE-agent and OpenHands — localize, understand, reproduce, plan, implement, verify, reflect. Applied to both code review and code generation.
    0 repo stars
  58. ▌
    Web Apis Browser · nickgallick
    Modern browser APIs for Arena — IntersectionObserver, Web Workers, Clipboard, Web Share, Performance APIs, Service Workers.
    0 repo stars
  59. ▌
    Youtube Research · nickgallick
    Pull full YouTube video transcripts and analyze them for research intelligence. Uses TranscriptAPI.com.
    0 repo stars
  60. ▌
    Linkedin Launch · nickgallick bundle
    LinkedIn content strategy and launch playbook for founder personal brand and B2B product launches. Use when writing LinkedIn posts for Nick (Perlantir AI Studio founder), planning LinkedIn launch sequences, creating carousel content, or positioning Nick as an AI infrastructure leader to enterprise/B2B audiences. Covers post formats, hook engineering, algorithm optimization, content pillars, and profile optimization.
    0 repo stars
  61. ▌
    Design Ecosystem · nickgallick
    Complete map of every design component library, animation framework, and pattern available. Reference when selecting components, animations, or patterns for V0 prompts. Covers Magic UI (70 animated components), Shadcn UI (40+ core), 150+ community registries, Framer Motion patterns, and Apple HIG rules.
    0 repo stars
  62. ▌
    Image Generation · nickgallick bundle
    Generate high-quality images via Midjourney, DALL-E 3, Flux, and Ideogram through Apiframe API. Use when designs need hero images, card thumbnails, realistic photos, background textures, illustrations, user avatars, product mockups, or any visual asset that isn't a UI component or icon. Triggers on phrases like "generate an image", "need a hero image", "create a photo", "stock image", "illustration for", "background for", or when a V0 design has gray placeholder images that need replacing.
    0 repo stars
  63. ▌
    Shapeup Methodology · nickgallick
    Shape Up methodology adapted for agent-orchestrated development. Fixed time, variable scope. Ship fast.
    0 repo stars
  64. ▌
    Advanced Postgres · nickgallick
    Advanced PostgreSQL patterns for Supabase — CTEs, window functions, JSONB, FTS, EXPLAIN ANALYZE, index strategy, migration safety, partitioning, advisory locks.
    0 repo stars
  65. ▌
    Caching Deep Dive · nickgallick
    All caching layers in Next.js + Supabase — request memoization, data cache, route cache, router cache, invalidation strategies, stampede prevention.
    0 repo stars
  66. ▌
    Cost Optimization · nickgallick
    Building profitably — Vercel, Supabase, and Anthropic cost optimization, model tiering, cost tracking per feature, and budget alerting.
    0 repo stars
  67. ▌
    Ssrf Exploitation · nickgallick
    Server-Side Request Forgery (SSRF) detection, exploitation chains, and defense for Next.js, Vercel, and Node.js applications. Use when reviewing code that makes outbound HTTP requests, proxies user input, uses Next.js Image optimization, implements middleware with next(), uses Server Actions with redirects, fetches user-provided URLs, handles webhooks/OAuth callbacks, or generates previews. Covers CVE-2025-57822 (Next.js middleware SSRF), CVE-2026-3125 (OpenNextJS Cloudflare path normalization), Next.js Image component misconfiguration, Server Actions SSRF (Assetnote research), and full SSRF→cloud metadata→credential theft chains.
    0 repo stars
  68. ▌
    Test Data Seeding · nickgallick
    Seed Supabase with known test data before Arena E2E runs, then clean up after. Uses service key to bypass RLS. Idempotent — safe to re-run. Covers challenges, agents, and challenge_entries.
    0 repo stars
  69. ▌
    Launch Playbooks · nickgallick
    Step-by-step launch playbooks for different channels and product types.
    0 repo stars
  70. ▌
    SEO Fundamentals · nickgallick
    SEO fundamentals for every launch — technical SEO, on-page, meta tags, schema markup.
    0 repo stars
  71. ▌
    Weekly Data Pull · nickgallick
    Extract and structure the weekly Bouts platform data package into content-ready intelligence including challenge completion stats, model family scores, ELO movements, failure archetype trends, and highlights. Use every Monday to produce the raw material that drives all weekly content across every channel.
    0 repo stars
  72. ▌
    Developer Handoff · nickgallick
    How to hand off designs to Maks with exact specifications that leave zero ambiguity.
    0 repo stars
  73. ▌
    Handoff Checklist · nickgallick
    Structured handoff document template for delivering designs to Maks. Use after all screens are generated and approved. Produces ONE document per project that gives Maks everything he needs to build — no scattered specs, no guessing.
    0 repo stars
  74. ▌
    Deep Web Research · nickgallick
    Scout research skill — Deep Web Research
    0 repo stars
  75. ▌
    Nemoclaw Deep · nickgallick
    Deep NemoClaw analysis — NVIDIA's enterprise multi-tenant OpenClaw fork. Architecture, isolation model, sandbox policies, enterprise deployment patterns, and applicable patterns for Perlantir.
    0 repo stars
  76. ▌
    AI Judge Hardening · nickgallick
    AI judge security — prompt injection defense, structured output enforcement, multi-judge consensus, bias detection, and adversarial submission defense for LLM-as-a-Judge systems.
    0 repo stars
  77. ▌
    API Design Mastery · nickgallick
    API design patterns — RESTful conventions, Next.js Route Handlers, webhook security, rate limiting implementation, pagination, and error formats.
    0 repo stars
  78. ▌
    Data Visualization · nickgallick
    Recharts-based data visualization in Next.js/React — percentile bars, trend lines, comparative charts, responsive containers, and accessibility standards.
    0 repo stars
  79. ▌
    Developer Patterns · nickgallick
    Tracks patterns, blind spots, and habits of each developer agent. Calibrates reviews to catch their specific recurring mistakes faster.
    0 repo stars
  80. ▌
    Dns Deep Knowledge · nickgallick
    DNS mastery — record types, email deliverability (SPF/DKIM/DMARC), Vercel DNS, cold email domains, Cloudflare specifics.
    0 repo stars
  81. ▌
    Performance Review · nickgallick
    Performance anti-patterns in React/Next.js, Supabase queries, API design, and general algorithms. Catches code that works but will be painfully slow at scale.
    0 repo stars
  82. ▌
    Rls Bypass Testing · nickgallick
    Systematic testing and review of Supabase Row Level Security (RLS) policies for bypasses, misconfigurations, and logic errors. Use when reviewing database schemas, auditing RLS policies, checking table security before deploy, reviewing Supabase migrations, or investigating data exposure. Covers RLS disabled by default (170+ apps exposed via CVE-2025-48757), service_role key exposure, missing write policies (INSERT/UPDATE/DELETE), policy logic errors, performance issues with auth.uid() vs (select auth.uid()), storage bucket RLS, RPC function security, and the MCP prompt injection risk with service_role. The
    0 repo stars
  83. ▌
    Security Forensics · nickgallick
    Post-incident forensic analysis — determining what happened, when, what was accessed, and whether data was exfiltrated after a security incident. Use after activating the incident response playbook when the investigation phase requires detailed log analysis, timeline reconstruction, blast radius determination, and evidence-based answers to "what did they access?" Covers Supabase log analysis, Vercel deployment forensics, Git history forensics, database audit trail analysis, and network-level evidence collection for our Next.js + Supabase + Vercel stack.
    0 repo stars
  84. ▌
    Supply Chain Audit · nickgallick bundle
    Pre-install and post-install security audit for npm packages, GitHub repos, VS Code extensions, and OpenClaw skills. Detects postinstall script attacks, Remote Dynamic Dependencies (RDD), typosquatting, slopsquatting (LLM-suggested fake names), trojanized build scripts, stolen token propagation, and dependency confusion. Use when installing new npm packages, cloning repos, adding VS Code extensions, installing ClawHub skills, reviewing package.json changes in PRs, or auditing existing node_modules. Covers the PhantomRaven, CanisterWorm, GlassWorm, and malicious Next.js repo campaigns of 2025-2026.
    0 repo stars
  85. ▌
    Websocket Security · nickgallick
    Security review for WebSocket implementations — Supabase Realtime, OpenClaw gateway, Socket.IO, and custom WebSocket endpoints. Use when reviewing WebSocket connection handling, authentication on WS connections, origin validation, message validation, broadcast security, and any real-time communication feature. Covers Cross-Site WebSocket Hijacking (CSWSH), missing origin validation, authentication bypass on WS upgrade, message injection, DoS via message flooding, and the ClawJacked vulnerability (OpenClaw WebSocket hijack).
    0 repo stars
  86. ▌
    A16z Go To Market · nickgallick
    Apply a16z-style startup and marketplace metrics, ICP selection, pricing logic, and GTM decision frameworks to digital products. Use when defining startup dashboards, ideal customer profiles, marketplace health metrics, or scale-stage go-to-market decisions.
    0 repo stars
  87. ▌
    Arena Short Video · nickgallick bundle
    Short-form video strategy for Agent Arena battle content on TikTok, YouTube Shorts, and Instagram Reels. Use when turning live battle moments, challenge results, upset victories, or leaderboard drama into viral clips. Covers hook patterns, shot lists, editing structure, algorithm optimization, and posting schedules. Designed for Nick's existing TikTok presence (@golfscenarios 13K+, @ogfinancebro) crossover to AI builder audience.
    0 repo stars
  88. ▌
    Bouts Data Assets · nickgallick
    Map what data Bouts produces per challenge run, per week, and per month and how each data point becomes content for builders, AI labs, and the community. Use when planning content calendars, writing reports, or turning platform performance data into specific posts, articles, or outreach materials.
    0 repo stars
  89. ▌
    Category Creation · nickgallick
    Define and evangelize the Agent Arena category “AI Agent Competition” with a clear POV, education-first content plan, category-definition statement, competitor responses, and search/social ownership plan. Use when creating category strategy, thought leadership, founder narrative, or content that teaches the market why this category should exist now.
    0 repo stars
  90. ▌
    Nextjs SEO Launch · nickgallick bundle
    Technical SEO launch checklist and ongoing strategy for Next.js + Vercel apps. Use when preparing a Next.js app for launch (meta tags, OG images, structured data, sitemap, robots.txt), optimizing for Core Web Vitals, setting up topic cluster SEO strategy, or auditing SEO for a deployed Next.js site. Covers SSR/ISR indexing patterns, dynamic meta tags, canonical URLs, and Next.js-specific SEO gotchas.
    0 repo stars
  91. ▌
    Dark Theme Mastery · nickgallick
    7-level dark color hierarchy, text on dark, light accents, glass on dark, elevation without shadows. Use when designing any dark-themed UI — backgrounds, text contrast, surface hierarchy, accent usage, glass effects on dark, and dark mode accessibility.
    0 repo stars
  92. ▌
    Founder Market Fit · nickgallick
    Scout research skill — Founder Market Fit
    0 repo stars
  93. ▌
    Revenue Validation · nickgallick
    Scout research skill — Revenue Validation
    0 repo stars
  94. ▌
    Openclaw Tools · nickgallick
    Expert reference for all OpenClaw agent tools — exec, web, subagents, skills, llm-task, browser, thinking, elevated, ACP agents, agent-send, diffs, reactions, slash-commands, lobster, loop-detection, btw, exec-approvals, capability-cookbook, pdf, skills-config.
    0 repo stars
  95. ▌
    AI Product Security · nickgallick
    Security patterns specific to AI-powered products — competition platforms (Agent Arena), AI coding assistants, LLM-based features, and any application that exposes AI capabilities to users. Use when reviewing AI agent evaluation systems, LLM API integrations, prompt/response handling, model output rendering, API key management for AI services, cost controls for inference endpoints, competition integrity, and AI-specific abuse patterns. Covers prompt leaking between contestants, model extraction via API, cost attacks on inference, output injection (AI-generated XSS), competition manipulation, and embedding/similarity abuse.
    0 repo stars
  96. ▌
    Architecture Review · nickgallick
    Architecture patterns and anti-patterns for Next.js App Router + Supabase applications. Catches code that works today but creates nightmares tomorrow.
    0 repo stars
  97. ▌
    Dependency Security · nickgallick
    Supply chain security — npm audit, dependency hygiene, typosquatting, transitive risks, and Vercel/Supabase-specific dependency concerns.
    0 repo stars
  98. ▌
    JWT Session Attacks · nickgallick
    JWT, OAuth 2.0, and session security attacks and defenses for Supabase Auth + Next.js applications. Use when reviewing authentication flows, JWT verification code, OAuth/OIDC implementations, session management, token storage, Supabase Auth usage (getSession vs getUser vs getClaims), middleware auth patterns, API route protection, or any code that validates identity tokens. Covers algorithm confusion (alg:none, RS256→HS256), JWKS confusion, claim injection/tampering, token replay, timing attacks on auth, CVE-2026-29000 (pac4j-jwt bypass), and Supabase-specific auth pitfalls.
    0 repo stars
  99. ▌
    Refactoring Mastery · nickgallick
    When and how to refactor — the refactoring catalog adapted for React/Next.js/TypeScript, safe refactoring process, and when NOT to refactor.
    0 repo stars
  100. ▌
    Community Building · nickgallick
    Build and operate the Agent Arena community with a full Discord structure, onboarding flow, recurring rituals, moderator playbook, member journey stages, and health metrics. Use when creating, growing, or managing Arena’s community layer so it becomes a moat instead of a dead announcement server.
    0 repo stars