nickgallick
- 731 skills
- 0 followers
- 2 weeks ago last updated
- ▌ SEO Content Engine · nickgallickTarget the four Bouts keyword clusters — benchmark searches, agent builder searches, enterprise searches, and long-tail data queries — with a proven SEO article formula that leads with the answer and anchors on Bouts-native data. Use when planning or writing blog content to compound organic search traffic over time.
- ▌ CSS Effects Library · nickgallickGlass morphism, gradients, shadows, blur, borders, cursor effects. Every effect with exact CSS/Tailwind. Use when specifying visual effects for any screen — glass cards, gradient borders, glow, vignettes, halftone patterns, shimmer loading. Copy-pasteable CSS for every effect.
- ▌ Sales Qualification · nickgallickScout research skill — Discovery Calls, Deal Qualification (MEDDPICC), and Sales Frameworks for evaluating sales-heavy products and supporting UberKiwi/OUTBOUND sales motion.
- ▌ Accessibility Review · nickgallickAccessibility (a11y) code review — WCAG AA violations, keyboard navigation, screen reader support, and React/Next.js-specific accessibility patterns.
- ▌ API Contract Testing · nickgallickTest Agent Arena API endpoints directly via Node.js fetch — not through the browser. Validates request/response contracts, auth gating, error shapes, and status codes for every route.
- ▌ Code Review Protocol · nickgallickForge's standard operating procedure for receiving and executing code reviews.
- ▌ Concurrency Patterns · nickgallickRace condition prevention, database concurrency, concurrent request handling, and real-time event ordering for Arena's high-concurrency architecture.
- ▌ Documentation Review · nickgallickWhat needs docs, what doesn't, documentation quality assessment, inline doc patterns, and ADR (Architecture Decision Record) format.
- ▌ Feature Flag Systems · nickgallickFeature flags — env var flags, database-backed runtime flags, percentage rollout, flag lifecycle, and cleanup discipline.
- ▌ Internationalization · nickgallicki18n for Next.js App Router — next-intl, message files, date/number formatting, RTL support, pluralization, SEO for multi-language.
- ▌ Mobile Security Expo · nickgallickSecurity review patterns for React Native and Expo mobile applications. Use when reviewing mobile app code, auditing Expo configuration, checking deep link handling, reviewing local storage usage, evaluating certificate pinning, or assessing mobile-specific attack surfaces. Covers CVE-2025-11953 (React Native CLI RCE), deep link hijacking, insecure local storage (AsyncStorage), missing certificate pinning, biometric bypass, binary reverse engineering exposure, Expo-specific security (EAS Build, OTA updates), and the unique threats mobile apps face that web apps don't.
- ▌ Owasp Stack Specific · nickgallickOWASP Top 10 mapped to our exact stack — Next.js + Supabase + TypeScript + Tailwind. Used during every code review to catch vulnerabilities specific to our architecture.
- ▌ Production Hardening · nickgallickProduction readiness patterns — observability, resilience, graceful degradation, deployment safety, and security headers for Next.js + Supabase + Vercel.
- ▌ Race Condition Async · nickgallickRace condition detection and exploitation patterns in Node.js, Next.js, and async JavaScript/TypeScript applications. Use when reviewing code with concurrent operations, database transactions without proper locking, payment/financial operations, resource allocation (coupons, slots, inventory), server actions that mutate state, real-time features, cache operations, and any code where timing between check and use matters (TOCTOU). Covers the Next.js batcher race condition (CVE-2025-32421 / Eclipse attack), async TOCTOU in server actions, double-spend in financial flows, optimistic concurrency without version checks, and Supabase transaction patterns.
- ▌ Systematic Debugging · nickgallickScientific debugging methodology — observe, hypothesize, isolate, fix, prevent. Stack-specific debugging patterns for Next.js, Supabase, and TypeScript.
- ▌ Tailwind CSS Mastery · nickgallickTailwind CSS architecture — how it works, responsive patterns, animation performance, dark mode, and anti-patterns to flag in review.
- ▌ Weekly Security Scan · nickgallickProactive weekly security scan across all active Perlantir projects in ~/Projects/. Finds issues without waiting for a PR.
- ▌ Hackernews Strategy · nickgallickBuild consistent Hacker News front page presence for Bouts with content types that earn upvotes, title formulas, posting timing, and engagement rules. Use when submitting Bouts content to HN or writing technical posts designed to reach the HN front page.
- ▌ Messaging Framework · nickgallickPre-built Bouts pitch messages for every context — 10-second elevator, 60-second conference, 3-minute investor, AI lab sales, and developer onboarding. Use when writing quick pitches, preparing for outreach, creating launch copy, or drafting any communication where Bouts needs to be explained compellingly in a fixed time window.
- ▌ Product Hunt Launch · nickgallickExecute a Bouts Product Hunt launch for top 5 Product of the Day with pre-launch preparation, launch day coordination, comment strategy, and post-launch follow-up. Use when planning or running any Bouts Product Hunt campaign.
- ▌ Product Positioning · nickgallickBuild sharp product positioning for digital products using competitive alternatives, differentiated attributes, value mapping, audience-specific messaging, category design, and 2x2 competitive maps. Use when defining or refining positioning statements, market category, messaging angles, or competitor differentiation for a product launch or GTM plan.
- ▌ Layout Specification · nickgallickSpacing system, section structure pattern, grid patterns, z-index system, container widths. All exact Tailwind values. Use when defining page layout, section spacing, grid columns, z-layering, or responsive structure.
- ▌ Adversarial Pr Review · nickgallickAdversarial review methodology for code PRs — treats every PR as potentially malicious until proven clean. Use when reviewing any PR from external contributors, dependency updates, refactors of security-sensitive code, PRs claiming "no functional changes", or any code that handles authentication, authorization, secrets, or user data. Goes beyond bug-finding to detect intentional concealment, deceptive commit messages, scattered payloads, environment-gated backdoors, and social engineering in PR descriptions. Complements standard code review (which assumes good faith) with an attacker-mindset review (which assumes hostile intent).
- ▌ CI CD Pipeline Design · nickgallickGitHub Actions CI/CD for Next.js + Supabase + Vercel — lint, typecheck, test, build, deploy migrations, deploy Edge Functions, preview deployments, branch protection.
- ▌ Complex Form Patterns · nickgallickReact Hook Form + Zod patterns, multi-step forms, optimistic submission, file uploads in forms, and accessible form architecture.
- ▌ Edge Function Mastery · nickgallickSupabase Edge Function patterns — Deno runtime, cold start optimization, challenge orchestration, judge pipeline, ELO calculation, long-running operations.
- ▌ Error Handling Review · nickgallickError handling patterns and anti-patterns — catching silent failures, inconsistent error shapes, missing error boundaries, and logging hygiene.
- ▌ Framework Source Code · nickgallickIndex of cloned framework repos and how to use them for review validation.
- ▌ HTTP Smuggling Desync · nickgallickHTTP request smuggling, HTTP/2 desync attacks, and parser differential vulnerabilities. Use when reviewing reverse proxy configurations, load balancer setups, Next.js rewrite/redirect rules, middleware that manipulates headers, or any architecture where multiple HTTP processors handle the same request. Covers CL/TE and TE/CL desync, HTTP/2 downgrade attacks, H2C smuggling, response queue poisoning, CVE-2026-29057 (Next.js chunked request smuggling), and the general principle of parser differentials that apply beyond HTTP.
- ▌ Performance Profiling · nickgallickGo beyond "this looks slow" to "this IS slow and here's the proof." Frontend, database, and API profiling with measurement-first optimization.
- ▌ React Flight Security · nickgallick bundleSecurity hardening for React Server Components (RSC), React Flight protocol, and Next.js App Router against CVE-2025-55182 (React2Shell) and related deserialization attacks. Use when building, reviewing, or auditing any application using React Server Components, Next.js App Router, server actions, or the Flight protocol. Covers version verification, patch validation, server component boundary security, serialization attack surfaces, and HTTP request smuggling (CVE-2026-29057). Essential for any Next.js 13+ / React 19 application.
- ▌ React Nextjs Security · nickgallickReact and Next.js specific security patterns, XSS prevention, server/client boundary safety, and auth flow best practices for our stack.
- ▌ Realtime Architecture · nickgallick bundleArchitecture patterns for Supabase Realtime in competitive/live applications. Covers channel design, broadcast vs postgres_changes, presence, scaling, anti-cheat delays, reconnection, cleanup, security (RLS on realtime, channel auth, anti-spoofing), performance (batching, throttling, filters). Includes decision framework for Realtime vs polling vs SSE.
- ▌ Search Implementation · nickgallickSearch implementation — Postgres FTS, fuzzy search with pg_trgm, vector search with pgvector, search UX patterns, and when to use external search.
- ▌ Typescript Strictness · nickgallickTypeScript type safety review — catching any, unsafe assertions, weak validation, and common TS mistakes in Next.js + Supabase applications.
- ▌ Ab Testing Framework · nickgallickSystematically test headlines, content formats, CTAs, channels, and posting timing for Bouts marketing with a one-variable-at-a-time discipline, minimum sample sizes, winner criteria, and immediate application of results. Use when running any Bouts content optimization test.
- ▌ Fundraising Literacy · nickgallickApply investor-grade thinking to Agent Arena by framing traction, TAM/SAM/SOM, stage readiness, and fundraising gaps even if the company is bootstrapped. Use when evaluating whether Arena looks venture-backable, preparing investor materials, or making strategic decisions with investor-quality metrics in mind.
- ▌ Search Ads Execution · nickgallickRun Google Search ads for Bouts targeting high-intent benchmark and AI agent evaluation searches with keyword strategy, ad copy formulas, and purpose-built landing pages for each keyword cluster. Use when capturing intent-driven traffic from builders and enterprises actively searching for AI agent evaluation solutions.
- ▌
- ▌ Outbound Intelligence · nickgallickScout research skill — Signal-Based Outbound & Lead Scoring for evaluating outbound SaaS ideas and designing cold outreach strategy for UberKiwi and OUTBOUND.
- ▌
- ▌ Clawhub Ecosystem · nickgallickComplete ClawHub skill ecosystem catalog — community skills, what we have, what we're missing, recommended installs. Use when researching available community skills, planning installs for any agent workspace, auditing coverage gaps, or managing the skill ecosystem across all 7 agents.
- ▌ Nemoclaw Patterns · nickgallickPatterns from NVIDIA NemoClaw — security, sandboxing, enterprise agent patterns.
- ▌ Openclaw Concepts · nickgallickExpert reference for all OpenClaw core concepts — agents, sessions, context, compaction, memory, multi-agent routing, model providers, failover, streaming, queues, pruning, system prompt, timezones, usage tracking, and features.
- ▌ Analytics Architecture · nickgallickProduct analytics — self-hosted privacy-friendly tracking, event architecture, funnel/cohort analysis, and key metrics per product.
- ▌ Application Blueprints · nickgallickComplete production starter architecture for Next.js + Supabase + Vercel. Given a product spec, produce the full file tree, schema, middleware, error handling, logging, auth pattern, and env template in one shot.
- ▌ Cicd Pipeline Security · nickgallickSecurity review and hardening for GitHub Actions CI/CD pipelines. Use when reviewing workflow files (.github/workflows/), auditing third-party actions, checking secret exposure in CI, reviewing deployment pipelines, or investigating CI/CD supply chain attacks. Covers the tj-actions/changed-files compromise (23K repos, March 2025), Trivy GitHub Actions compromise (March 2026), Clinejection (prompt injection → cache poisoning → npm publish, Feb 2026), Shai Hulud attacks, workflow injection via issue/PR titles, cache poisoning, secret exfiltration, and the full taxonomy of GitHub Actions attack vectors.
- ▌ Cors And Csp Hardening · nickgallickCORS (Cross-Origin Resource Sharing) and CSP (Content Security Policy) configuration review and hardening for Next.js applications. Use when reviewing security headers, API route CORS configuration, middleware header injection, next.config.js headers, or any frontend security policy. Covers CORS misconfigurations that enable cross-origin data theft, CSP bypasses that enable XSS, header injection, clickjacking prevention, and the complete security headers checklist for production Next.js + Vercel deployments.
- ▌ Database Schema Design · nickgallickSchema design from product specs — entity extraction, normalization, naming conventions, index strategy, RLS patterns, migration generation, and seed data.
- ▌ Multi Tenant Isolation · nickgallickSecurity patterns for multi-tenant SaaS applications built on Supabase + Next.js. Use when reviewing applications where multiple organizations/teams share the same database, reviewing RLS policies with org/team scoping, checking for cross-tenant data leakage, auditing shared resource isolation, or building any B2B SaaS product (UberKiwi, white-label platforms). Covers tenant isolation via RLS, tenant context propagation, cross-tenant IDOR, shared resource abuse, tenant-scoped API keys, data export isolation, and the specific patterns where Supabase's architecture creates multi-tenant risks.
- ▌ Redos And Dos Patterns · nickgallickDetection and prevention of Denial of Service vulnerabilities in Node.js applications — ReDoS (Regular Expression Denial of Service), event loop blocking, resource exhaustion, algorithmic complexity attacks, and application-layer DoS patterns. Use when reviewing code containing regular expressions, input parsing, file processing, database queries without limits, recursive operations, or any code that processes user-controlled input where processing time is proportional to input complexity. Covers CVE-2026-30925 (Parse Server ReDoS — CRITICAL), catastrophic backtracking, polynomial/exponential regex patterns, and Node.js-specific event loop starvation.
- ▌ State Machine Patterns · nickgallickState machines for Arena challenges, OUTBOUND leads, and payment flows — TypeScript discriminated unions, transition validation, XState for complex flows.
- ▌ System Design Patterns · nickgallickDistributed system patterns applied to Next.js + Supabase + Vercel — idempotency, circuit breakers, caching, event-driven architecture, sagas, and rate limiting.
- ▌ Webhook Infrastructure · nickgallickWebhook patterns at scale — inbound handling (Stripe, Supabase), outbound sending with retry, monitoring, and dead letter queues.
- ▌ 90 Day Operating Plan · nickgallickThe Bouts first 90-day marketing operating plan with week-by-week content, distribution, enterprise outreach, and growth targets from 0 to 500 agents enrolled and first data licensing revenue. Use when planning or executing the Bouts launch phase marketing operation.
- ▌ Bouts Product Mastery · nickgallickDeep product knowledge of Bouts — what it is, how the 5-judge scoring works, the 6 challenge families, 4 formats, weight classes, revenue model, and the core thesis. Use when writing any Bouts content, copy, or positioning to ensure every output is specific, accurate, and impossible for a generic agent to replicate.
- ▌ Brand Voice For Bouts · nickgallickThe specific voice, tone, writing rules, approved vocabulary, and forbidden phrases for all Bouts content. Use when writing or reviewing any Bouts copy — landing pages, social posts, emails, reports, DMs, press pitches — to ensure the brand sounds authoritative, data-driven, and impossible to confuse with generic AI marketing.
- ▌ Competitor Monitoring · nickgallickMonitor AI benchmark competitors weekly including SWE-bench, HumanEval, LiveCodeBench, Aider, CodeClash, and new entrants — tracking methodology changes, adoption, community growth, and market signals that should feed into Bouts content, positioning, or feature decisions.
- ▌ Crisis Communications · nickgallickRespond to Bouts crises including methodology criticism, challenge exploits, AI lab complaints, downtime, and negative press with specific response templates, escalation rules, and the principle of always responding with data and transparency instead of defensiveness.
- ▌ Go To Market Strategy · nickgallickDesign full go-to-market strategies for digital product launches across pre-launch, launch, post-launch growth, and scale phases. Use when creating 30/60/90-day GTM plans, launch timelines, channel priorities, budgets, KPI targets, content calendars, risk mitigation plans, or cross-team launch execution documents.
- ▌ Paid Social Execution · nickgallickRun paid campaigns on X/Twitter and LinkedIn for Bouts including campaign types, targeting, ad formats, budget allocation, and kill/scale rules for developer and enterprise audiences. Use when planning or executing Bouts paid social campaigns to drive awareness, signups, and enterprise lead generation.
- ▌ Partnership Execution · nickgallickBuild and execute Bouts partnerships across four tiers — AI tooling companies, model providers, developer platforms, and media/content partners — with specific targets, partnership models, and outreach templates for each tier. Use when prospecting partners, writing outreach, or structuring partnership deals that drive agent enrollment and data licensing revenue.
- ▌ Sponsored Track Sales · nickgallickSell Bouts sponsored challenge tracks to AI companies and developer platforms with pricing, value propositions, examples, and sales copy for each track type. Use when creating pitch materials, writing outreach to potential track sponsors, or structuring co-branded challenge proposals.
- ▌ Animation Choreography · nickgallickScroll-triggered entrances, stagger patterns, choreography rules, timing/easing, page transitions, parallax. Exact Framer Motion props for every animation. Use when specifying motion for any screen — entrances, exits, hover, scroll, live data updates, celebrations.
- ▌ Typography Engineering · nickgallick10+ premium font pairings, type scale system, responsive typography, advanced CSS. Every pairing with Google Fonts URL + Tailwind config. Use when choosing fonts, building type scales, or specifying typography for any project.
- ▌
- ▌ Openclaw Ecosystem · nickgallickCommunity, marketplace, security landscape, and external knowledge about OpenClaw. Updated from live research.
- ▌ Openclaw Providers · nickgallickExpert reference for all OpenClaw model providers — Anthropic, OpenAI, Google, Ollama, OpenRouter, GitHub Copilot, and more. Covers model string format (provider/model-id), auth modes (API key / token / OAuth / setup-token), model aliases, prompt caching, cost tracking, and fast mode. Includes our live setup (Anthropic token mode, sonnet-4-6 / opus-4-6 / haiku-4-5).
- ▌ Advanced React Patterns · nickgallickAdvanced React composition patterns, hooks architecture, Server Component patterns, and Next.js App Router patterns for building elegant, maintainable UIs.
- ▌ API Rate Limiting Abuse · nickgallickRate limiting design, implementation review, and bypass detection for Next.js API routes and Supabase Edge Functions. Use when reviewing API endpoints for abuse resistance, checking authentication endpoints for brute force protection, reviewing data endpoints for scraping prevention, or auditing public endpoints for DoS resistance. Covers per-user, per-IP, per-endpoint strategies, sliding window vs fixed window vs token bucket algorithms, common bypass techniques (header spoofing, distributed attacks, account rotation), Vercel-specific rate limiting, and Supabase's built-in limits.
- ▌ Blockchain Fundamentals · nickgallickHow blockchain actually works — consensus, EVM, gas, transactions, smart contracts, token standards, L1 vs L2. The engineering, not the hype.
- ▌ Confidence Layer Design · nickgallickExpose when a judgment is high-confidence vs thin-evidence without undermining the platform's authority — covering the confidence trilemma, per-tier UI patterns, data model, copy patterns, and hard rules on when NOT to show confidence indicators.
- ▌ Deserialization Attacks · nickgallickDetection and defense against unsafe deserialization vulnerabilities across all boundaries where data becomes code. Use when reviewing code that deserializes user input, parses structured data formats (JSON, YAML, XML, MessagePack, Protocol Buffers), uses React Flight/RSC protocol, handles webhooks, processes file uploads, reads cached data, or uses any library that reconstructs objects from wire format. Covers React Flight (CVE-2025-55182), Svelte devalue (CVE-2026-30226), flatted (CVE-2026-33228), Python pickle, YAML load, Node.js node-serialize, and every deserialization boundary in our Next.js + Supabase stack.
- ▌ Docker Containerization · nickgallickDocker best practices — multi-stage builds, security, Docker Compose for dev, and OpenClaw container specifics.
- ▌ Failure Mode Classifier · nickgallickPurpose-built LLM classifier design for failure mode taxonomy — 15-code classification with confidence scoring, anti-convergence patterns, evidence anchoring, and anti-generic prompt enforcement.
- ▌ File Upload And Storage · nickgallickFile upload security, Supabase Storage patterns, presigned URLs, file validation, CDN caching, and storage architecture for Arena/MathMind/OUTBOUND.
- ▌ Malicious Code Patterns · nickgallick bundleSystematic detection of obfuscated code execution, hidden backdoors, and malicious patterns in Python and JavaScript/TypeScript. Use when reviewing code for backdoors, auditing new dependencies, scanning PRs for obfuscated exec/eval/compile patterns, detecting dynamic code generation disguises (builtins aliasing, importlib abuse, getattr chains, compile+FunctionType, base64+eval), homoglyph identifiers, environment-gated payloads, dead-code-that-isn't-dead, and intentional syntax errors used as evasion. Covers all known exec/eval obfuscation families and their detection methods including AST-level analysis.
- ▌ Playwright OAUTH Github · nickgallickHandle GitHub OAuth flows in Playwright for Agent Arena. Correct technique using page.goto() for the auth initiation URL — not button clicks or fetch interception. Handles login, authorization grant, callback, and session verification.
- ▌ Secure Coding Standards · nickgallickThe definitive secure coding reference for our Next.js + Supabase + TypeScript stack — the ONE document that, if followed, produces secure code on first write. Use when Maks needs a reference for how to write secure code, when onboarding new developers, when creating coding guidelines, or when establishing the "one right way" for common security-sensitive patterns. Not "here's what's wrong" but "here's exactly how to write it correctly." Every pattern is copy-pasteable and production-ready.
- ▌ Shell Scripting And CLI · nickgallickBash scripting best practices, Node.js CLI tools, and shell script review checklist for OpenClaw deployment, Arena installer, and migration scripts.
- ▌ Stripe Payment Patterns · nickgallickStripe Checkout, subscriptions, webhook handling, one-time payments, and Supabase integration patterns. Covers the complete payment lifecycle for Arena and OUTBOUND.
- ▌ Supabase Attack Vectors · nickgallickSupabase-specific security vulnerabilities, RLS bypass techniques, auth pitfalls, and attack vectors that are unique to the Supabase + Next.js stack.
- ▌ AI Lab Outreach System · nickgallickSystematic 4-week outreach system for AI labs (Anthropic, OpenAI, Google, Meta, Cognition, Cursor, and 13 others) to sell Bouts data licensing and private benchmarks — from warm-up through commercial conversation. Use when prospecting AI labs, writing outreach copy, or building the pipeline for data licensing revenue.
- ▌ Autonomous Weekly Loop · nickgallickThe self-executing weekly Bouts marketing operation that runs Monday through Friday without manual triggers — data pull, content production, publishing, distribution, community engagement, and analytics review. Use as the master operational guide for running the Bouts content machine autonomously each week.
- ▌ Copywriting Frameworks · nickgallickProven copywriting frameworks for headlines, CTAs, landing pages, emails, and social posts.
- ▌ Data Licensing Content · nickgallickWrite and distribute content that sells Bouts data licensing tiers (Index Access at $2K/mo, Benchmark API at $5K/mo, Private Lane at $10K/mo, Enterprise custom) to AI labs and enterprises through specific pitch copy and value propositions per tier. Use when writing sales one-pagers, landing page copy, or outreach materials for the data licensing business.
- ▌ Launch Self Assessment · nickgallickProduce the monthly Bouts CMO report covering growth, content performance, channel effectiveness, budget ROI, what worked, what failed, and next month's priorities. Use to evaluate marketing performance, identify systemic issues, and produce the monthly report for Nick.
- ▌ Pr And Media Relations · nickgallickRun Agent Arena PR and media outreach with a concrete media list, pitch angles, actual pitch copy, and press kit requirements. Use when Arena needs launch coverage, creator/media briefings, data-story outreach, newsletter inclusion, or category-defining press narratives around AI Agent Competition.
- ▌ Component Specification · nickgallickComponent spec template with structure, states, responsive, animation, accessibility. Use when specifying any UI component — buttons, cards, badges, tables, forms, modals — to ensure every state and variant is covered.
- ▌ Feedback Prioritization · nickgallickScout research skill — Feature Prioritization & Feedback Analysis using RICE, Kano, and structured synthesis. Use when evaluating which features to build, analyzing user feedback, or prioritizing product backlogs for Agent Arena, OUTBOUND, or any Perlantir product.
- ▌ Openclaw Schema Map · nickgallickComplete map of the OpenClaw config schema from source code. THE single source of truth for valid config keys.
- ▌ Admin Evaluation Tooling · nickgallickInternal admin tools for inspecting, monitoring, and improving judge outputs — including raw output inspection, calibration drift detection, missing evidence detection, low-signal output flagging, and a feedback quality dashboard.
- ▌ Authentication Deep Dive · nickgallickAuth security deep dive — OAuth PKCE, Supabase Auth internals (getSession vs getUser vs getClaims), social login edge cases, session management, MFA.
- ▌ Evaluation Rubric Design · nickgallickDesign lane structure, scoring dimensions, weighting logic, calibration rules, and anchor-based criteria so Bouts produces defensible, consistent AI judgments instead of vibes.
- ▌ Fraud Detection Patterns · nickgallickFraud detection for Arena anti-cheat and OUTBOUND abuse prevention — behavioral analytics, statistical anomaly detection, velocity checks, fingerprinting, abuse pattern catalog.
- ▌ Multi Stage LLM Pipeline · nickgallickMulti-stage async LLM pipeline design — stage isolation, structured handoffs, idempotency, concurrency-safe profile updates, and failure handling across chained LLM calls.
- ▌ Payment Webhook Security · nickgallickSecurity patterns for Stripe payment integration, webhook verification, and financial transaction safety in Next.js + Supabase applications. Use when reviewing Stripe checkout flows, webhook handlers, subscription management, payment intent processing, refund logic, pricing endpoints, or any code that handles money. Covers CVE-2026-21894 (n8n missing Stripe-Signature verification — forged webhooks), CVE-2026-2890 (payment reuse for higher-cost items), legacy Stripe API skimming, webhook replay attacks, price manipulation, subscription state bypasses, and idempotency requirements.
- ▌ Self Correction Patterns · nickgallickSelf-review, confidence rating, red team/blue team thinking, and learning from mistakes. Applied to all Forge output before submission.
- ▌ Benchmark API Marketing · nickgallickMarket the Bouts Benchmark API to AI labs with the right value proposition, API documentation strategy, landing page copy structure, and quick-start framing. Use when writing API documentation, the /benchmark landing page, or any outreach targeted at AI labs that need programmatic access to contamination-resistant evaluation.
- ▌ Certification Marketing · nickgallickMarket Bouts agent certification tracks to enterprises and individual builders as independent proof of capability, with landing page copy, badge system, API verification, and the enterprise procurement angle. Use when creating certification marketing materials, writing the /certification landing page, or building the enterprise sales motion around verified agent capability.