somnio-software
- 24 skills
- 0 followers
- 6 hours ago last updated
- ▌ Soc2 Audit · somnio-software bundleExecute a comprehensive, framework-agnostic SOC 2 readiness audit of an entire repository or application. Detects project type and stack at runtime and adapts evidence gathering accordingly. Inspects the whole project for observable evidence of AICPA Trust Services Criteria controls (Common Criteria CC1-CC9 plus the optional Availability, Confidentiality, Processing Integrity, and Privacy categories), organized around eleven control families (A-K). For every control it records a Status (met / partial / gap / organizational) with concrete evidence and an ownership lane (platform-auditable / organizational / client-CUEC), scores readiness per control family, lists gaps mapped to criteria references, and produces a prioritized remediation plan with an overall readiness score /100 and a readiness band. Read-only and evidence-based: never invents controls; absent evidence is a Gap; secret values are always redacted. Use when the user asks for a SOC 2 audit, SOC 2 readiness assessment, Trust Services Criteria revie
- ▌ Dora Metrics · somnio-software bundleFetches the DORA metrics Deployment Frequency and Lead Time for Changes, per project and per repo, from GitHub (API, not local git). Use this skill whenever the user asks to run or update the DORA metrics, measure the deployment frequency or lead time of a project (e.g. "Example Project"), generate the biweekly metrics report, or asks how many deploys a project made or how long a change takes to reach production. Also trigger on phrases like: "run the DORA metrics", "metrics for Example Project", "deployment frequency for [project]", "lead time for [project]", "biweekly metrics report", "how many deploys did we do this sprint".
- ▌ Harness Audit · somnio-software bundleExecute a comprehensive, framework-agnostic AI Harness Audit. Scores how complete a project's AI coding harness is — CLAUDE.md, .claude/rules, settings.json permissions and hooks, commands/skills, custom agents, and the autotest-to-green-PR lifecycle — then returns a /100 score, a maturity band, and a prioritized action plan. Read-only: never modifies the audited repo. Use when the user asks to audit the AI harness, score their Claude setup, assess AI adoption maturity, or check how paved the quality path is. Triggers on: 'harness audit', 'ai harness', 'claude harness score', 'ai adoption audit', 'harness health'.
- ▌ Iso27001 Audit · somnio-software bundleExecute a comprehensive, framework-agnostic ISO/IEC 27001:2022 readiness audit of an entire repository or application. Detects the stack at runtime and adapts evidence gathering accordingly. Inspects the whole project for evidence of an Information Security Management System (ISMS clauses 4-10) and Annex A controls (93 controls across 4 themes), organized into 11 auditable control categories. Records a Status and Owner/lane for every control, scores readiness per category, lists gaps mapped to Annex A references, and produces a prioritized remediation plan, a Statement of Applicability starter, and an ISMS clause coverage check - with an overall readiness score /100 and a readiness band. Read-only and evidence-based: never invents controls; absent evidence is marked a Gap. Use when the user asks to run an ISO 27001 readiness audit, an ISMS audit, an Annex A gap analysis, or an ISO compliance audit. Triggers on: 'iso 27001 audit', 'iso27001 readiness', 'isms audit', 'annex a gap analysis', 'iso compliance audi
- ▌ Security Audit · somnio-software bundleExecute a comprehensive, framework-agnostic Security Audit. Detects project type at runtime and adapts security checks accordingly. Analyzes sensitive files, source code secrets, dependency vulnerabilities, and optionally uses Gemini AI for advanced analysis. Produces a severity-classified report. Use when the user asks to audit security, scan for vulnerabilities, check for secrets, or assess dependency risks. Triggers on: 'security audit', 'vulnerability scan', 'secret scan', 'dependency audit', 'security check', 'pentest', 'owasp'.
- ▌ Clockify Tracker · somnio-softwareManages Clockify time tracking via the official Clockify REST API (v1): list workspaces and projects, create time entries with correct UTC timestamps. Use when the user wants to log time, track hours, record work in Clockify, or mentions Clockify or time entries.
- ▌ Workflow Builder · somnio-software bundleThis skill should be used when the user asks to "create a workflow", "run a workflow", "design a task pipeline", "execute a workflow", "resume a workflow", or "plan a multi-step automation". Creates and executes custom, repeatable workflows with multiple steps that can each use different AI models and run in parallel waves. Triggers on: 'create workflow', 'run workflow', 'execute workflow', 'workflow plan', 'workflow run', 'resume workflow', 'multi-step workflow', 'task pipeline', 'automation'.
- ▌ Git Branch Format · somnio-softwareGenerates properly formatted Git branch names following project conventions. Use this skill whenever the user wants to name a branch, create a branch, or asks things like "what should I call this branch?", "what branch name should I use?", "help me with the branch name", or describes a feature/fix and needs a branch name. Always use this skill when the user needs a git branch name, even if they don't explicitly say "branch".
- ▌ Git Commit Format · somnio-softwareGenerates properly formatted Git commit messages (title + description) following Conventional Commits. Use this skill whenever the user wants to write a commit message, document code changes in git format, or asks things like "how should I commit this?", "write a commit for these changes", "help me with my commit message", or describes what they changed and needs a git-ready output. Always use this skill when the user describes code changes and needs a commit, even if they don't explicitly say "commit".
- ▌ React Health Audit · somnio-software bundleExecute a comprehensive React Project Health Audit. Analyzes tech stack, architecture, state management, testing, code quality, performance, CI/CD, and documentation. Produces a Google Docs-ready report with section scores and weighted overall score. Use when the user asks to audit a React project, run a health check, evaluate frontend quality, or assess technical debt. Triggers on: 'react audit', 'health audit', 'react health', 'frontend audit', 'next.js audit', 'vite audit', 'project quality check'.
- ▌ Nestjs Health Audit · somnio-software bundleExecute a comprehensive NestJS Project Health Audit. Analyzes tech stack, architecture, API design, data layer, testing, code quality, CI/CD, and documentation. Produces a Google Docs-ready report with section scores and weighted overall score. Use when the user asks to audit a NestJS project, run a health check, evaluate backend quality, or assess technical debt. Triggers on: 'nestjs audit', 'health audit', 'backend audit', 'nestjs health', 'node audit', 'api audit', 'project quality check'.
- ▌ Python Health Audit · somnio-software bundleExecute a comprehensive Python Project Health Audit. Analyzes tech stack, architecture, API/interface design, data layer, testing, code quality, CI/CD, and documentation. Produces a Google Docs-ready report with section scores and weighted overall score. Use when the user asks to audit a Python project, run a health check, evaluate backend quality, or assess technical debt. Triggers on: 'python audit', 'python health audit', 'fastapi audit', 'django audit', 'flask audit', 'tech debt assessment', 'python health', 'python project quality', 'python quality check', 'python code review'.
- ▌ Angular Health Audit · somnio-software bundleExecute a comprehensive modern Angular (2+/Angular CLI, TypeScript) frontend Project Health Audit. Analyzes tech stack & runtime, module/component architecture, state & data flow (services/RxJS/signals), templating & change detection, build & bundle pipeline (Angular CLI), testing (Karma/Jasmine or Jest), code quality & tooling (TS strictness, Angular ESLint), dependency hygiene, and documentation. NOT for AngularJS 1.x (use angularjs-health-audit for that). Produces a Markdown report with per-section scores and a weighted overall score. Use when the user asks to audit an Angular project, run a health check, evaluate frontend quality, or assess technical debt. Triggers on: 'angular audit', 'angular health', 'angular cli audit', 'typescript frontend audit', 'ngx audit', 'project quality check'.
- ▌ Dart Model From JSON · somnio-softwareGenerates Dart models from a JSON structure using json_annotation and equatable. Use this skill when the user provides a JSON object and wants the corresponding Dart model classes generated, or asks things like "generate a Dart model for this JSON", "create a model from this response", "dart model from json". Always use this skill when the user provides JSON and needs Dart model output.
- ▌ Flutter Health Audit · somnio-software bundleExecute a comprehensive Flutter Project Health Audit. Analyzes tech stack, architecture, state management, testing, code quality, CI/CD, and documentation. Produces a Google Docs-ready report with section scores and weighted overall score. Use when the user asks to audit a Flutter project, run a health check, evaluate project quality, or assess technical debt. Triggers on: 'flutter audit', 'health audit', 'project audit', 'flutter health', 'tech debt assessment', 'project quality check'.
- ▌ React Best Practices · somnio-software bundleExecute a micro-level React code quality audit. Validates code against live GitHub standards for testing, component architecture, hooks patterns, state management, performance, and TypeScript. Produces a detailed violations report with prioritized action plan. Use when the user asks to check React code quality, validate best practices, or review frontend code standards. Triggers on: 'react best practices', 'react code quality', 'component review', 'hooks review', 'react standards', 'frontend code quality'.
- ▌ Nestjs Best Practices · somnio-software bundleExecute a micro-level NestJS code quality audit. Validates code against live GitHub standards for testing, architecture, DTO validation, error handling, and code implementation. Produces a detailed violations report with prioritized action plan. Use when the user asks to check NestJS code quality, validate best practices, or review backend code standards. Triggers on: 'nestjs best practices', 'backend code quality', 'code review', 'nestjs standards', 'dto validation', 'error handling review'.
- ▌ Python Best Practices · somnio-software bundleExecute a micro-level Python code quality audit. Validates code against live GitHub standards for typing, code style, function design, data validation, error handling, module structure, and testing. Produces a detailed violations report with prioritized action plan. Use when the user asks to check Python code quality, validate best practices, or review Python code standards. Triggers on: 'python best practices', 'python code quality', 'code review', 'python standards', 'type hints review', 'pytest review', 'pydantic validation'.
- ▌ Angular Best Practices · somnio-software bundleExecute a micro-level modern Angular (2+/Angular CLI, TypeScript) code quality audit. Validates code against live GitHub standards for testing, component & module architecture, lifecycle & dependency-injection patterns, services & RxJS/signals state, change detection & performance, and TypeScript strictness. Produces a detailed violations report with prioritized action plan. This is modern Angular 2+ (components, NgModules/standalone, DI, RxJS, Angular CLI) — NOT AngularJS 1.x. Use when the user asks to check Angular code quality, validate best practices, or review frontend code standards. Triggers on: 'angular best practices', 'angular code quality', 'angular standards', 'rxjs review', 'ngx best practices'.
- ▌ Angularjs Health Audit · somnio-software bundleExecute a comprehensive AngularJS (Angular 1.x) Project Health Audit. Analyzes tech stack, module/component architecture, services & data flow, templating & digest hygiene, testing, code quality, build & asset pipeline, and documentation. Produces a Google Docs-ready report with section scores and weighted overall score. Use when the user asks to audit an AngularJS / Angular 1 project, run a legacy frontend health check, evaluate a Bower/Grunt codebase, or assess technical debt. Triggers on: 'angularjs audit', 'angular 1 audit', 'angularjs health', 'legacy frontend audit', 'bower audit', 'project quality check'.
- ▌ Flutter Best Practices · somnio-software bundleExecute a micro-level Flutter code quality audit. Validates code against live GitHub standards for testing, architecture, and code implementation. Produces a detailed violations report with prioritized action plan. Use when the user asks to check Flutter code quality, validate best practices, or review code standards compliance. Triggers on: 'flutter best practices', 'code quality', 'code review', 'flutter standards', 'architecture compliance', 'testing quality'.
- ▌ Optimize Claude Config · somnio-softwareAudits and optimizes a repository's Claude Code configuration so path-scoped rules load lazily and CLAUDE.md stays a lightweight always-loaded index. First maps the real project tree (domains, monorepo package roots, extensions, generated/frozen areas) so every path glob is derived from and validated against actual files — stale globs that match zero files and over-broad ones are caught. Three areas: (1) migrate .claude/rules/**/*.md frontmatter to the native lazy-load `paths:` YAML-array form (away from eager `globs:` or red-flagged CSV `paths:`) with accurate, tree-validated patterns; (2) slim CLAUDE.md files to an index + rule map and delete redundant @import-only shells; (3) audit/install the PreToolUse(Write) hook that works around the read-not-create caveat. Audits first, shows a report, asks for confirmation, then applies. Pass --audit-only to skip applying.
- ▌ Angularjs Best Practices · somnio-software bundleExecute a micro-level AngularJS (Angular 1.x) code quality audit. Validates code against live GitHub standards for testing, module/component architecture, scope & binding patterns, services & data flow, digest performance, and minification-safe JavaScript standards. Produces a detailed violations report with prioritized action plan. Use when the user asks to check AngularJS 1.x code quality, validate best practices, or review legacy frontend code standards. Triggers on: 'angularjs best practices', 'angular 1 code quality', 'angularjs standards', 'minification-safe DI review'.
- ▌ Slack Release Announcement · somnio-softwareUse when the user asks for a Slack message, announcement, or "mensaje de update" about one or more released CLI versions (e.g. "mensaje para slack de la 2.10.0", "anuncia el release", "post de la nueva version").