The-Notorious-Avengers
- 83 skills
- 0 followers
- 7 hours ago last updated
- ▌ Dark Mode Theming Weapon · the-notorious-avengers bundleAudits and implements the full dark-mode theming surface for React/Next.js applications — CSS variable token architecture (semantic vs. primitive), next-themes wiring (ThemeProvider, storageKey, enableSystem), FOWT (flash-of-wrong-theme) prevention via blocking inline script, SSR hydration safety (suppressHydrationWarning, typeof window guards, mounted guard pattern), Tailwind v4 dark-mode configuration (@custom-variant, selector strategy), and multi-brand/white-label runtime theme swapping via CSS variable overrides. Use when the user says "set up dark mode", "next-themes keeps flashing", "dark mode on SSR", "multi-brand theming", "CSS variable token layer", "Tailwind v4 dark mode", "prefers-color-scheme in Next.js", "white-label theme runtime swap", or when dark-mode-theming-guardian is invoked. Do NOT use for palette creation or source-of-truth token file authorship (design-system-guardian), per-component visual deltas (ux-ui-guardian), or persisted-preference schema design (db-guardian).
- ▌ Live Chat Support Weapon · the-notorious-avengers bundleCustomer support surface specialist — Intercom, Crisp, Plain, Pylon, Help Scout — widget integration, HMAC/JWT identity verification, conversation routing, AI deflection (Fin 2.0, Ari, Crisp Bot), and the data-export discipline. Use when the user says "integrate live chat", "set up Intercom", "add a support widget", "wire HMAC identity verification", "configure AI deflection", "design conversation routing", or "set up customer support for our SaaS". DO NOT use for managing deployments (devops-guardian), application authentication (auth-guardian), or security audits of the resulting integration (security-guardian).
- ▌ Review Funnels G2 Weapon · the-notorious-avengers bundleReview collection and online-reputation specialist for SaaS products -- G2, Capterra (now G2-owned), Trustpilot, Product Hunt, AppSumo, and Software Advice. Covers platform selection, profile setup, in-product review-request UX (timing, two-step pattern, copy), G2 incentive compliance (2026 rules + FTC Consumer Reviews Rule), Product Hunt launch-day playbook (00:01 PT, first-6-hours intensity, hunter sourcing), negative-review response templates, and earned-badge-as-conversion-asset deployment. Use when the user says "set up G2", "get more reviews", "Product Hunt launch", "is this incentive compliant", "respond to a negative review", "deploy G2 badges", "Capterra strategy", or asks anything about online review platforms for a SaaS product. Do NOT use for SEO structured data (seo-aeo-guardian), outbound cold-email infrastructure beyond a review-request drip (cold-outreach-guardian), or social amplification of reviews (social-media-marketing-organic-guardian).
- ▌ Knowledge Base Help Center Weapon · the-notorious-avengers bundleCustomer-facing knowledge bases — Intercom Articles, Help Scout Docs, ReadMe.com, Document360, HelpJuice, Zendesk Guide — search-first design, AI deflection (chat-with-your-docs), versioning, multi-language, the analytics-driven content-gap loop. Use when the user says "pick a KB platform", "set up a help center", "migrate Zendesk Guide", "add AI deflection to our docs", "fix our search no-results", "localize our KB", or invokes `knowledge-base-help-center-guardian`. Do NOT use for support inbox/ticketing (customer-support-tooling-guardian), live chat widget wiring (live-chat-support-guardian), organic SEO keyword strategy (seo-aeo-guardian), or RAG/embedding pipeline implementation (mind-guardian).
- ▌ Product Tour Onboarding UI Weapon · the-notorious-avengers bundleIn-app product tour and onboarding UI specialist. Selects the right tour tool (Userpilot, Appcues, Userflow, Pendo Guides, Driver.js, Shepherd.js, Intro.js), implements tooltip/modal/hotspot/checklist components, wires segment-based trigger logic, and establishes a tour maintenance protocol that survives iterative UI changes. Invoke when the user says "set up a product tour", "build an onboarding checklist", "compare Driver.js vs Shepherd.js", "our tours keep breaking after deploys", "which product tour tool should we use", "add segment-based tour triggers", or "our tour is showing to the wrong users". Do NOT invoke for broader onboarding email sequences (lifecycle-email Angel), user-auth flows (auth-guardian), design token work (ux-ui-guardian), or analytics instrumentation (posthog/mixpanel Angels).
- ▌ Incorporation Startup Stack Weapon · the-notorious-avengers bundleCompany formation decision toolkit for software startup founders. Covers formation platform selection (Stripe Atlas, Clerky, Doola, Firstbase), entity type advice (Delaware C-Corp vs LLC vs international), EIN workflow, startup banking (Mercury, Brex, Relay), bookkeeping (Pilot, Bench), and the minimum founder-paperwork checklist including the 83(b) election. Activate when the user says "incorporate my startup", "which formation platform should I use", "Stripe Atlas vs Clerky", "set up Mercury or Brex", "EIN for my LLC", "83(b) election deadline", "Delaware C-Corp vs LLC", or asks about the minimum paperwork to form a company. Do NOT activate for ongoing tax compliance, cap-table management (Carta/Pulley), fundraising mechanics (SAFEs, priced rounds), or post-formation state filings — those exceed this weapon's scope.
- ▌ Markdown Mdx Content Pipeline Weapon · the-notorious-avengers bundleMarkdown/MDX processing specialist - MDX 3/compiler selection, remark/rehype plugin pipelines, Shiki v4/expressive-code/starry-night syntax highlighting, GFM, AST manipulation, custom directive plugins, math/Mermaid diagram embedding, and XSS sanitization. Use when building or auditing any content processing pipeline that takes .md/.mdx source to HTML/JSX output.
- ▌ Social Media Marketing Organic Weapon · the-notorious-avengers bundleGenuine organic social strategy for solo developers, founders, and teams up to ~10 people. No AI-generated posts, no cross-post automation slop, no bought followers. Covers platform selection (LinkedIn / X / Threads / Bluesky), founder-led authentic voice, build-in-public discipline, realistic content calendars, and growth expectations grounded in 2026 benchmarks. Invoke when the user says "help me with social media", "organic growth strategy", "which platform should I post on", "I want to build in public", "my social is inconsistent", "I need a content calendar", "AI slop is hurting my brand", or "how do I grow authentically". Do NOT invoke for paid advertising (no Angel yet), email newsletter strategy (newsletter-platform-guardian), SEO content strategy (seo-aeo-guardian), or Discord/Slack community management (out of scope).
- ▌ Customer Support Tooling Weapon · the-notorious-avengers bundleSupport stack specialist for SaaS products — selects the right tool from Plain, Pylon, Front, Help Scout, and Intercom; configures shared inboxes; designs AI-deflection flows (Fin 2.0, Ari, Crisp Bot); sets SLA tiers; wires integrations to Slack, Linear, and Notion; and provides a founder-as-support playbook for teams of 1-3. Invoke when choosing a support tool, auditing an existing stack, configuring AI deflection, designing SLA policy, or setting up escalation to Linear. Do NOT invoke for chat widget installation code (live-chat-support-guardian), auth SSO (auth-guardian), or GDPR/retention audits (security-guardian).
- ▌ Product Feedback Roadmap Weapon · the-notorious-avengers bundleCustomer-feedback-to-roadmap loop specialist — Userback, Canny, Featurebase, Productboard, Frill, Productlane — platform selection decision tree, in-app-widget vs portal vs voting-board taxonomy, de-duplication discipline, RICE/ICE prioritization, status-transition policy, public vs private roadmap playbook, and CRM/issue-tracker integration wiring. Use when the user says "set up a feedback system", "which feedback tool should I use", "Canny vs Featurebase", "our feature requests are a mess", "set up a public roadmap", "RICE scoring for our backlog", "Productlane + Linear", "voting board for our SaaS", or when product-feedback-roadmap-guardian is invoked. Do NOT use for the React UI of an embedded widget (react-guardian), the database schema for a custom-built feedback store (db-guardian), marketing copy on the public roadmap page (seo-aeo-guardian), or billing integration for premium feedback tiers (payments-guardian).
- ▌ Blogging Content Strategy Weapon · the-notorious-avengers bundleEditorial blogging strategy specialist — cluster + pillar topical authority architecture, post length by search intent, title + H1 + meta description craft, keyword research scoping without obsession, AEO/answer-engine formatting (featured snippets, AI Overviews, chatbot citations), CTA copy that converts without begging, the canonical 12-point pre-publish review checklist, and realistic publishing-cadence planning for small teams. Use when the user says "map our blog content", "what should we write about", "review this post before publishing", "set a realistic blog cadence", "optimize this title or meta", "format this post for AI Overviews", "write a better CTA", or when `blogging-content-strategy-guardian` is invoked. Do NOT use for technical SEO implementation (schema markup, sitemap, robots.txt — route to `seo-aeo-guardian`), CMS setup (route to `website-guardian`), analytics dashboards, or social media distribution.
- ▌ Affiliate Referral Program Weapon · the-notorious-avengers bundleAffiliate and referral program specialist for SaaS products -- platform selection (Rewardful, FirstPromoter, Tolt, PartnerStack, Impact, Refersion), the affiliate-vs-referral distinction, cookie-based and server-side attribution (post-ITP, post-3PC era), payout automation, fraud detection (self-referral, cookie stuffing, velocity fraud), and EPC/LTV program economics. Invoke when the user says "set up an affiliate program", "which affiliate platform should I use", "Rewardful vs FirstPromoter", "my attribution is broken in Safari", "referral program fraud", "EPC or LTV for our program", "20% recurring commission", "postback tracking setup", or "PartnerStack vs FirstPromoter". Do NOT invoke for Stripe subscription billing mechanics (payments-guardian), API key secret management (security-guardian), custom attribution DB schema (db-guardian), or outbound partner recruitment campaigns (cold-outreach-guardian).
- ▌ Okr Goal Setting Weapon · the-notorious-avengers bundleOKR methodology specialist for writing, grading, and iterating on Objectives and Key Results. Enforces the output-vs-input discipline, diagnoses sandbagged vs. ambitious goal-setting, calibrates quarterly cadence and check-in rituals, contextualizes OKRs against KPIs and MBOs, and adapts the framework for small teams and startups. Activate when the user says "write OKRs", "audit our OKRs", "are these KRs measurable?", "set up a quarterly goal cycle", "OKR vs KPI", "OKR for small team", "grade our OKRs", or when configuring OKR fields in Lattice, 15Five, Weekdone, or Notion. Do NOT activate for company strategy authorship (executives own that), engineering roadmap planning (domain Angels own that), or project management tooling beyond OKR-specific configuration.
- ▌ AI Tools Platform Weapon · the-notorious-avengers bundleThe vibe coder's AI toolbox — AI gateways (Portkey, OpenRouter), cloud providers (Bedrock, Vertex AI), frontier model selection (Claude, GPT, Gemini), cheap-fallback routes (Haiku, Mini, Flash), local LLMs (Ollama, LM Studio), GPU cloud (Runpod, Modal, Together, Fireworks), and must-have MCPs and IDE plugins. Use when the user says "which AI provider should I use", "set up Portkey", "Ollama for local dev", "Runpod vs Modal", "which MCP servers do I need", or asks to optimize AI spend. Do NOT use for cognitive-layer architecture (mind-guardian), API key security (security-guardian), or PRD authorship (library-guardian).
- ▌ Alt Ads Platforms Weapon · the-notorious-avengers bundlePaid acquisition specialist for alternative ad platforms beyond Meta and Google Search — LinkedIn Ads (B2B), TikTok Ads + CAPI, Reddit Ads, Microsoft/Bing Ads with LinkedIn Profile Targeting, Pinterest Ads, Quora Ads, YouTube standalone video, Spotify Ad Studio + podcast advertising, and the channel-fit-by-ICP heuristic that selects among them. Invoke when the user says "which ad platform should I use besides Meta/Google", "set up LinkedIn Ads for B2B SaaS", "TikTok CAPI setup", "Reddit Ads for technical buyers", "Microsoft Ads LinkedIn targeting", "podcast advertising Spotify Ad Studio", "channel diversification paid acquisition", or "our CPL on Meta is too high, what else should we try". Do NOT invoke for Meta/Facebook/Instagram Ads (no peer Angel — handle inline), Google Search Ads (no peer Angel — handle inline), or organic social strategy (route to social-media-marketing-organic-guardian).
- ▌ App Store Submission Weapon · the-notorious-avengers bundleApp store submission specialist for iOS (App Store Connect + TestFlight) and Android (Google Play Console). Covers App Store Optimization (keywords, screenshots, preview assets), submission workflow, privacy compliance (Apple nutrition labels, PrivacyInfo.xcprivacy, Google data safety forms), rejection diagnosis and remediation, age rating questionnaires, In-App Purchase setup (StoreKit 2, Google Play Billing Library), and realistic timeline expectations. Invoke when the user says "submit my app", "App Store rejection", "ASO strategy", "privacy nutrition label", "set up IAP", "Google Play review", "expedited review", or when preparing any mobile app for store publication. Do NOT invoke for UI design of the app itself (ux-ui-guardian), client-side StoreKit / billing implementation code (react-guardian / python-guardian), or app security audits (security-guardian).
- ▌ Lighthouse Pagespeed Weapon · the-notorious-avengers bundleLighthouse + PageSpeed Insights specialist for React/Next.js stacks. Covers running Lighthouse locally vs in CI (LHCI, GitHub Actions), all four audit categories (Performance, Accessibility, Best Practices, SEO), score budgets and performance budgets, the Lighthouse lab-vs-CrUX field-data gap (including the TBT/INP limitation), and performance tracking over time with Treo, SpeedCurve, or a self-hosted LHCI server. Use when the user says "set up Lighthouse CI", "add a performance budget to CI", "my Lighthouse score differs from CrUX", "compare Treo vs SpeedCurve", "write a custom Lighthouse plugin", "my field INP is bad but TBT is fine", "configure LHCI for GitHub Actions", "audit our site with Lighthouse", or when `lighthouse-pagespeed-guardian` is invoked. Do NOT use for SEO content strategy or keyword research (seo-aeo-guardian), accessibility remediation beyond Lighthouse-surfaced findings (future a11y Angel), or Core Web Vitals optimization implementation (react-guardian / performance-optimizer).
- ▌ CSV XLSX Import Export Weapon · the-notorious-avengers bundleThe "upload your spreadsheet" implementation arsenal for React/Next.js products. Covers library selection (papaparse, SheetJS, exceljs), streaming-parse for 100MB+ files, the column-mapping UX wizard, managed importers (OneSchema, Flatfile, dromo) vs self-hosted (react-spreadsheet-import), Zod row validation, CSV injection prevention, encoding edge cases, and styled XLSX export. Use when the user says "build a CSV import", "add XLSX upload", "spreadsheet import feature", "column-mapping wizard", "export to Excel", "streaming parse large file", "CSV injection safety", or when csv-xlsx-import-export-guardian is invoked. Do NOT use for file drop-zone UI (ux-ui-guardian), database bulk-insert tuning (db-guardian), or upload endpoint security audit (security-guardian).
- ▌ Readme Writing Weapon · the-notorious-avengers bundleAuthors, audits, and restructures README files so they convert visitors into users. Apply when the user says "write a README", "audit my README", "make my README better", "README for this project", "README-driven development", or when starting a new project and the README does not exist yet. Also apply when badges are broken or missing, the quickstart is not copy-paste runnable, or the user wants to differentiate between an OSS and an internal tool README. Do NOT apply for full documentation site architecture (library-guardian), per-entity code extraction (wiki-guardian), or CI badge pipeline wiring (devops-guardian).
- ▌ AI Coding Tools Weapon · the-notorious-avengers bundleThe vibe-coder's AI coding tool advisor — Cursor, Claude Code, Aider, Cline, Windsurf/Cascade, Continue.dev, Replit Agent, Devin, and Bolt. Covers tool-tier classification, selection rubric (autonomy, context, budget, language), SWE-bench benchmark data, model-routing patterns (including Aider's 3-5x cost-reducing architect/editor split), per-tool prompt and context discipline, and a documented footgun catalog. Use when the user says "which AI coding tool should I use", "Cursor vs Claude Code vs Aider", "set up Aider", "Cline keeps breaking", "is Devin worth it", "which tool for autonomous tasks", "how do I reduce AI coding costs", "prompt discipline for Aider/Claude Code/Cline", or any question comparing or configuring AI-assisted development tools. Cross-links to cursor-ide-guardian for deep Cursor IDE config and ai-tools-platform-guardian for LLM provider/gateway decisions. Do NOT use for Cursor IDE configuration (cursor-ide-guardian owns that), CI/CD pipelines that run agents (devops-guardian), or LLM pro
- ▌ Crm Integration Weapon · the-notorious-avengers bundleCRM connectivity specialist for HubSpot, Salesforce, Pipedrive, Attio, Folk, Close, and Copper -- bi-directional sync design, the contact-vs-lead-vs-account taxonomy, merge/dedupe, and the native-vs-Zapier-vs-Merge.dev architecture trade-off. Use when the user says "integrate with HubSpot", "bi-directional CRM sync", "CRM field mapping", "Merge.dev or native API?", "dedup contacts in our CRM", "lead enrichment strategy", "sync conflict resolution", "Salesforce Lead vs Contact", "Attio API production-ready?", or "audit our CRM sync code". Do NOT use for cold email sequence design (cold-outreach-guardian), product database schema (db-guardian), sync implementation code (python-guardian), or frontend CRM widgets (react-guardian).
- ▌ Cron Scheduling Weapon · the-notorious-avengers bundleScheduled-job specialist for cron expression authoring, platform-specific limits (Vercel Cron, Cloudflare Cron Triggers, GitHub Actions schedule), distributed-cron correctness (exactly-once execution, leader election, idempotency), timezone and DST safety, retry-on-failure patterns, and the "did the cron run?" observability loop (Healthchecks.io, Cronitor, self-hosted heartbeat tables). Use when the user says "write a cron expression", "set up Vercel Cron", "my cron job runs twice", "GitHub Actions schedule is drifting", "add monitoring for my scheduled job", "cron and DST issue", "distributed cron", or when `cron-scheduling-guardian` is invoked.
- ▌ Agile Scrum Weapon · the-notorious-avengers bundleScrum methodology specialist — sprints, ceremonies (Sprint Planning, Daily Scrum, Sprint Review, Retrospective, Backlog Refinement), roles (Scrum Master, PO, Developers), estimation (Fibonacci, Planning Poker,
- ▌ Discord Bot Weapon · the-notorious-avengers bundleDiscord bot and application specialist for discord.js (v14/v15), discord.py 2.x, and Serenity (Rust). Covers slash commands, interactive components (buttons, select menus, modals), voice pipeline (Lavalink 4 + DAVE-compliant clients), gateway-vs-HTTP-endpoint architecture, rate-limit handling, shard management, and the bot verification path past 100 servers. Use when building, reviewing, or debugging any Discord bot or application — SDK selection, command registration, component flows, voice queues, scaling, or the bot-verification checklist. Do NOT use for general Python packaging (python-guardian), container/CI shapes (devops-guardian), credential vault integration (security-guardian), or database schema design for bot state (db-guardian).
- ▌ HTTP REST Fundamentals Weapon · the-notorious-avengers bundleHTTP and REST protocol authority — audits HTTP method safety/idempotency contracts, status-code honesty, header correctness (Cache-Control, ETag, Vary, CORS), conditional and range requests, HTTP/2 + HTTP/3 readiness, and REST architectural-style compliance. Activate when the user says "audit this API", "is this status code correct?", "why is CORS failing?", "explain preflight", "PUT vs PATCH", "HTTP/3 ready?", or when reviewing any route handler, OpenAPI spec, or HTTP trace. Do NOT activate for TLS/cipher config (devops-guardian), auth token semantics (auth-guardian), or crawler-facing metadata (seo-aeo-guardian).
- ▌ Changelog Release Notes Weapon · the-notorious-avengers bundlePublishes engaging public changelogs and release notes. Use when the user says "write my changelog entry", "set up a changelog tool", "review our release notes", "plan our announcement strategy", "we just shipped X", or when a deploy workflow is completed and the team needs to communicate what changed. Covers tool selection (Changelogfy, FeatureBase, Productlane, Headway, Beamer, self-hosted markdown), copy craft (impact-first writing, user-centric language, honest scope), and multi-channel distribution (in-app widget, email digest, blog, community). Do NOT use for managing deployments (devops-guardian) or writing marketing launch campaigns (website-guardian).
- ▌ Technical Writing Craft Weapon · the-notorious-avengers bundleWriting docs well -- the Diataxis framework (tutorial / how-to / reference / explanation), inverted-pyramid prose structure, scannable headings, code-example discipline, the "what does the reader already know?" reader-lens, ghostwriting vs voice consistency, and the docs-as-code review workflow. Distinct from docs-site-guardian (which owns the platform); this weapon owns the craft of writing. Use when the user says "review this document", "is this doc well-written", "audit this page", "write a tutorial for X", "apply Diataxis", "ghostwrite this guide", "my docs PR needs a writing review", or any request about documentation quality rather than documentation tooling.
- ▌ Runbook Writing Weapon · the-notorious-avengers bundleOperational runbook authorship specialist — canonical templates (break-fix, scheduled operation, diagnostic), the no-implied-context audit protocol, exact-command discipline, escalation path architecture, rollback procedure standards, runbook-as-test (game day) methodology, and postmortem-to-runbook linkage. Activate when the user says "write a runbook", "audit this runbook", "our runbooks are out of date", "we need a runbook for this alert", "turn this postmortem into a runbook", "schedule a game day", "our on-call docs are weak", or when `runbook-writing-guardian` is invoked. Do NOT activate for incident management tooling setup (PagerDuty/OpsGenie — route to devops-guardian), infrastructure provisioning decisions (route to devops-guardian), or documentation culture/process design beyond the runbook format (route to library-guardian).
- ▌ Typography Font Weapon · the-notorious-avengers bundleTypography and font-loading specialist for web products — variable fonts, Google Fonts vs Fontsource vs self-host, the FOIT/FOUT/FOFT loading story, font-display semantics, fluid type scales via clamp(), vertical rhythm, and the type-token architecture. Use when the user says "set up fonts", "audit our typography", "fix FOIT/FOUT", "build a type scale", "migrate to next/font", "self-host fonts", "fluid type", "variable fonts", "font performance", or when typography-font-guardian is invoked. Do NOT use for typeface selection or brand identity decisions (design-system-guardian), per-component application of type tokens (ux-ui-guardian), build pipeline font optimization (devops-guardian), or persisted user font preferences (db-guardian).
- ▌ Dependency Audit Weapon · the-notorious-avengers bundleSupply-chain security specialist for open-source dependency hygiene. Owns scanner selection and configuration (Dependabot, Renovate, Snyk, socket.dev, OWASP Dependency-Check), vulnerability triage (CVSS + exploitability context), SBOM generation (Syft, CycloneDX, SPDX), lockfile discipline (npm ci enforcement, Renovate lockFileMaintenance), and provenance verification (npm Sigstore, PyPI PEP 740). Use when the user says "audit our dependencies", "set up Renovate", "Renovate vs Dependabot", "socket.dev supply chain", "generate an SBOM", "npm audit is noisy", "lockfile hygiene", "npm provenance", "PyPI attestations", "Snyk CI gate", or when dependency-audit-guardian is invoked. Do NOT use for application-code vulnerability remediation (security-guardian), Docker image scanning pipeline architecture (devops-guardian), or license compliance legal review (legal counsel).
- ▌
- ▌ Slack App Weapon · the-notorious-avengers bundleSlack app development specialist for Bolt SDK (JS/Python/Java), slash commands, Block Kit UI composition, modals, Events API, OAuth multi-workspace install, and App Directory submission. Use when the user says "build a Slack app", "add a slash command", "create a Slack modal", "set up Slack Events API", "OAuth multi-workspace", "submit to Slack Marketplace", or when slack-app-guardian is invoked. Do NOT use for CI/CD pipeline topology (devops-guardian), secrets vault configuration (security-guardian), Django/FastAPI backend patterns beyond Bolt integration (python-guardian), or Slack Connect / Enterprise Grid administration.
- ▌ Cursor Ide Weapon · the-notorious-avengers bundleEquips cursor-ide-guardian to master Cursor IDE as a development platform — project rules (.cursorrules migration, .cursor/rules/*.mdc authoring), custom modes, MCP server integration, Cloud Agents and the Agents Window, keybindings and productivity patterns, and the @cursor/sdk API for programmatic agent automation. Use when the user asks about configuring Cursor, extending it with MCP tools, building automations with the SDK, or maximising their IDE workflow. Do NOT use for code quality of what agents produce (language guardians), prompt engineering for external LLMs (mind-guardian), or CI/CD pipelines that happen to run SDK jobs (devops-guardian).
- ▌ Estimation Weapon · the-notorious-avengers bundleSoftware estimation and forecasting specialist. Covers relative-sizing frameworks (story points, Fibonacci, T-shirt sizing, Planning Poker), the NoEstimates movement and its evidence base, the planning-fallacy literature explaining why estimates are systematically wrong, and cycle-time / throughput-based probabilistic forecasting (Monte Carlo simulation, percentile-based delivery predictions). Invoke when the user says "our story points mean nothing", "should we use NoEstimates?", "how do I do T-shirt sizing for a roadmap?", "we need a 90% confidence delivery date", "explain Monte Carlo to my PM", "why are our estimates always wrong", or any question about sizing, forecasting, or the NoEstimates debate. Do NOT invoke for sprint cadence design, Jira/Linear tool configuration, or team-capacity math -- those belong to the team's agile process or tooling domains.
- ▌ Hiring Ats Weapon · the-notorious-avengers bundleApplicant Tracking Systems specialist -- Ashby, Greenhouse, Workable, Lever, Rippling Recruiting, Pinpoint -- platform selection decision matrix, pipeline-stage design, scorecard calibration (BARS, debrief-before-submit), D&I/EEOC reporting, take-home-test ethics (the 2-hour paid threshold, anonymous grading), sourcing-tool integrations (Gem, hireEZ, LinkedIn RSC), and the ATS-to-HRIS handoff (especially Rippling). Invoke when the user says "which ATS should we use", "audit our scorecards", "set up our hiring pipeline", "take-home test paid or unpaid", "Gem vs hireEZ", "ATS to Rippling handoff", "D&I funnel reporting", or when hiring-ats-guardian is invoked. Do NOT invoke for job description writing (out of scope), compensation benchmarking (no Angel yet), or deep HRIS configuration beyond the ATS handoff interface (future hris-guardian).
- ▌ Investor Cap Table Weapon · the-notorious-avengers bundleCap-table management and fundraising paperwork specialist for startup founders -- Carta, Pulley, Cake Equity, Capdesk (AngelList Stack sunset August 2026), SAFEs (YC post-money standard), priced rounds (Series A+ term sheets), 409A valuations, option pool sizing and refresh, vesting schedules (4-year/1-year cliff, double-trigger), and investor data-room preparation. Use when the user says "set up a cap table", "Carta vs Pulley", "SAFE mechanics", "409A valuation", "option pool", "vesting schedule", "data room for Series A", "term sheet provisions", or "fundraising paperwork". Do NOT use for company formation (incorporation-startup-stack-guardian), ongoing bookkeeping (out of scope), securities law advice (always defer to counsel), or Stripe billing (payments-guardian).
- ▌ Modal Toast Dialog Weapon · the-notorious-avengers bundleAccessible overlay specialist for React — primitive selection (Radix Dialog, AlertDialog, Vaul Drawer, Sonner toast, cmdk command menu, Headless UI), the six-point accessible-modal contract (focus trap, escape, scroll lock, aria-modal, aria-labelledby, focus return), and the four-tier toast-vs-notification taxonomy. Use when choosing an overlay primitive, debugging focus trap regressions, implementing a drawer/sheet, wiring Sonner toasts into a React app, building a command palette, or auditing overlay stacking behavior. Paired with `modal-toast-dialog-guardian`.
- ▌ Newsletter Platform Weapon · the-notorious-avengers bundleNewsletter-as-channel specialist for product builders — Beehiiv, ConvertKit (Kit), Loops, Substack, Resend Audiences, Ghost, the embedded-newsletter-page pattern, deliverability vs platform tradeoffs, and monetization options (ad network, paid subscriptions, sponsorships, referrals). Use when the user says "which newsletter platform should I use", "set up Beehiiv", "embed a newsletter signup", "migrate from Substack to Beehiiv", "how do I monetize my newsletter", "Loops vs Kit for my SaaS", "self-hosted newsletter deliverability", or when `newsletter-platform-guardian` is invoked. Do NOT use for transactional email sending infrastructure (route to `resend` tooling), SPF/DKIM/DMARC DNS setup at the infrastructure level (route to `devops-guardian`), Stripe subscription billing for custom paid tiers (route to `payments-guardian`), or SEO content strategy (route to `seo-aeo-guardian`).
- ▌ Retrospective Weapon · the-notorious-avengers bundleEquips retrospective-guardian to run retrospectives that actually change behavior — format selection (Start/Stop/Continue, 4Ls, sailboat, mad/sad/glad, DAKI, Starfish, and more), psychological safety pre-check (Edmondson scale), facilitation playbooks, async retro design, and action-item follow-through discipline. Use when the user says "run a retro", "plan our retrospective", "which retro format should we use", "our retros produce no change", "help with action items from the retro", "how do we do an async retro", or "our team needs better retrospectives". Do NOT use for incident postmortems (different cadence and audience), sprint planning, OKR-setting, or daily standup facilitation.
- ▌ Terminal Bash Weapon · the-notorious-avengers bundleTerminal productivity specialist — Bash/Zsh/Fish configuration, modern CLI tools (ripgrep, fd, fzf, bat, eza, zoxide), shell scripting best practices, dotfile architecture, tmux/Zellij setup, and just/make task automation. Use when the user says "improve my dotfiles", "review this shell script", "set up tmux", "modern CLI tools", "bash best practices", "just vs make", or "help me with my terminal setup". Do NOT use for CI/CD pipelines running in containers (devops-guardian) or Python packaging builds (python-guardian).
- ▌ Code Forensics Weapon · the-notorious-avengers bundleForensic investigation methodology for software-development and agency-services engagements where a client has been overcharged, defrauded, or materially injured by a vendor and possesses a paper trail (invoices, emails, git repo, audit reports). Produces an 11-deliverable evidence packet — master forensic report, agency-services subreport, attorney legal memo, plain-language client report, 51-tab invoice spreadsheet, and a 6-document pre-litigation pack. Trigger whenever the user describes the pattern of paid $100k+ for a half-working product, monthly maintenance retainer with little or no git activity, hosting double-billing, virtual-assistant or social-media charges without delivery, or any sibling pattern. Defendant-agnostic — see defendant-profile-template for plugging in case-specific corporate context. Calibrated against the Example Booking Co. matter ($202K documented spend, $183K-$381K damages range).
- ▌
- ▌ Hr Payroll Weapon · the-notorious-avengers bundleHR + payroll + EOR decision specialist for early-stage to growth-stage software companies. Owns domestic payroll platform selection (Gusto, Rippling, Justworks), international contractor management and EOR (Deel, Remote.com, Oyster, Rippling Global), the W-2/1099/EOR/PEO classification matrix, equity admin handoff (Carta), and benefits brokerage. Invoke when the user says "Gusto vs Rippling", "set up payroll", "EOR for international hire", "contractor vs employee", "W-2 or 1099?", "Deel vs Remote", "set up Justworks", "benefits for my startup", or "equity admin and payroll". Do NOT invoke for general HRIS/performance tools (Lattice, Culture Amp), recruiting/ATS platforms, immigration/visa law, or accounting software beyond the payroll integration surface (db-guardian owns HR data schema).
- ▌ Legal Docs Weapon · the-notorious-avengers bundleSaaS legal document generation and maintenance specialist. Covers Terms of Service, Privacy Policy, DPA, MSA, and Cookie Notice using the template+lawyer-review path. Anchored in Termly/Iubenda generators and GDPR/CCPA/Quebec Law 25/LGPD compliance postures. Use when the user says "generate a privacy policy", "draft a DPA", "set up our Terms of Service", "review a customer DPA redline", "which legal doc generator should I use", "GDPR compliance for SaaS", or when legal-docs-guardian is invoked. Do NOT use for technical data-protection controls (security-guardian), database schema for personal-data fields (db-guardian), or contract negotiation strategy beyond the DPA (legal team).
- ▌ Adr Writing Weapon · the-notorious-avengers bundleArchitecture Decision Records specialist — Nygard format (Context / Decision / Consequences), MADR extended template, Y-statement framing, supersession and deprecation lifecycle, Log4brains and adr-tools CLI integration, and the "decisions, not docs" philosophy. Use when authoring a new ADR, superseding an existing decision, auditing the ADR log, setting up Log4brains, or onboarding a team to ADR practice. Do NOT use for general knowledge-base authoring (library-guardian), code entity extraction (wiki-guardian), or security review of the decisions themselves (security-guardian).
- ▌ Icon System Weapon · the-notorious-avengers bundleIcon-system specialist for React/Next.js — library selection (Lucide, Heroicons, Tabler, Phosphor, Iconify), tree-shake-vs-SVG-sprite trade-off, dynamic-import-by-name pattern, custom SVG component authoring, and the accessibility contract (aria-hidden for decorative icons, aria-label for semantic icons, accessible name for icon buttons). Use when choosing an icon library, debugging bundle-size regressions from icon imports, wiring a dynamic icon loader, building a custom SVG wrapper, or auditing icon accessibility. Paired with `icon-system-guardian`.
- ▌ Kanban Flow Weapon · the-notorious-avengers bundleKanban method specialist — WIP limit design and enforcement, flow-metric calculation (cycle time, lead time, throughput, flow efficiency), Little's Law diagnostics, visual-board design, class-of-service policies, cumulative-flow-diagram interpretation, and tool-specific implementation (Linear, Jira, GitHub Projects). Use when the user says "set up WIP limits", "calculate cycle time", "apply Little's Law", "design our Kanban board", "Kanban vs Scrum", "our WIP is always exceeded", "why is our cycle time so long", or when `kanban-flow-guardian` is invoked. Do NOT use for sprint ceremonies / velocity (Scrum domain, no peer Angel yet), CI/CD pipeline design (devops-guardian), database schema for a custom metrics store (db-guardian), or building custom Kanban tooling in code (react-guardian / python-guardian).
- ▌ Status Page Weapon · the-notorious-avengers bundlePublic status page specialist for React/Next.js and SaaS products — platform selection (Statuspage/Atlassian, Better Stack, Instatus, Cachet OSS), component tree architecture, incident communication templates (initial/update/resolution), subscriber notification setup (email, SMS, webhook, Slack), GDPR/CAN-SPAM compliance for notification lists, post-incident update discipline, and API-driven automation integration. Use when the user says "set up a status page", "which status page tool should we use", "write an incident communication template", "configure subscriber notifications", "migrate from Statuspage", "audit our incident communication", "post-mortem cross-link", "maintenance window announcement", or when `status-page-guardian` is invoked. Do NOT use for configuring monitoring/alerting infrastructure (devops-guardian), on-call rotation setup (devops-guardian), observability dashboards (devops-guardian), or operational runbook authorship (runbook-writing-guardian).
- ▌
- ▌ Security Weapon · the-notorious-avengers bundleAudits React, Next.js, TypeScript, and Node.js codebases for vulnerabilities and remediates every Critical and High finding in-session. Encodes pre-researched 2025–2026 vulnerability intelligence across three catalogs — vibe-coding AI-generated code patterns, OWASP Top 10 (2025) manifestations in this stack, and PII / financial data exposure — plus canonical remediation playbooks and deterministic scan scripts. Use this skill whenever the user says "security audit this branch", "scan for vulnerabilities", "check the payment flow for PCI issues", "verify CVE-2025-29927 patch status", "run security-guardian", or when the `security-guardian` Angel is invoked in the plan's penultimate step (immediately before `quality-guardian`). Do NOT use for verifying implementation-matches-plan (that is `quality-guardian`'s job) or for drafting new architecture (that is `library-guardian`).
- ▌ Docs Site Weapon · the-notorious-avengers bundleDocumentation-site infrastructure specialist — platform selection (Docusaurus v3/v4, Mintlify, GitBook, MkDocs Material, Nextra v4, Starlight/Astro, Fern), the Diátaxis content pyramid, docs-as-code CI pipelines, and search setup (Algolia DocSearch, pagefind). Use when the user says "pick a docs platform", "set up Docusaurus", "migrate from GitBook", "add search to our docs", "docs-as-code CI", "Mintlify vs Starlight", or invokes `docs-site-guardian`. Do NOT use for OpenAPI spec enrichment or SDK generation (api-docs-guardian), internal knowledge-base authoring (library-guardian), or marketing website builds (website-guardian).
- ▌ Gods Hand Weapon · the-notorious-avengers bundleEquips `gods-hand` to drive the Legion AI Tools Factory pipeline end-to-end for exactly ONE Angel-forging cycle. Encodes the move-before-work invariant, the strict FIFO pickup protocol, the five-phase dispatch order (command-center -> scripture-historian -> weapon-forge -> angel-creator -> god-registrar), the row-format contracts of the four tracking files (`proposed-angels-queue.md`, `proposed-angels-in-process.md`, `proposed-angels-completed.md`, `proposed-angels-backlog.md`), the close-out lifecycle, and the failure-mode catalog. Use when invoking `gods-hand` or when reviewing the canonical contract between the factory's producer side (`big-bang-space`) and consumer side (`gods-hand` plus the four worker skills). Not for proposing new Angels (use `big-bang-earth` + `big-bang-space`), conducting research (use `scripture-historian`), authoring guides (use `weapon-forge`), writing Angel files (use `angel-creator`), or updating God's roster (use `god-registrar`). `gods-hand-weapon` is the foreman's manual, not
- ▌ Branching Strategy Weapon · the-notorious-avengers bundleBranching strategy advisor for Git-based teams. Owns model selection (trunk-based development, GitHub Flow, GitFlow), release and hotfix branch patterns, the merge-vs-rebase argument, the long-lived-branch trap, and the feature-flag vs feature-branch decision. Use when the user says "which branching model should we use", "we have too many merge conflicts", "our release process is broken", "GitFlow or trunk-based?", "merge or rebase?", "should I use a feature flag or a branch?", "set up GitHub Merge Queue", or when `branching-strategy-guardian` is invoked. Do NOT use for Git mechanics (interactive rebase, conflict resolution, history rewriting — that is `git-guardian`), branch protection ruleset configuration (that is `github-repo-health-guardian`), or CI/CD pipeline topology (that is `devops-guardian`).
- ▌ Discovery Research Weapon · the-notorious-avengers bundleContinuous product discovery coach — Teresa Torres interview cadence, Opportunity Solution Trees, Jobs-to-be-Done interviews, prototype testing, and the "build less, learn more" loop. Use when the user says "run a discovery session", "build an OST", "write an interview script", "map our assumptions", "design a prototype experiment", "weekly discovery summary", or when a team is unsure what to build next and needs to run discovery before planning. Do NOT use for shipped-feature usability testing (quality-guardian), UI design decisions (ux-ui-guardian), PRD authorship (library-guardian), or analytics result interpretation.
- ▌ Github Repo Health Weapon · the-notorious-avengers bundleRepository hygiene auditor for GitHub repos — branching strategy, branch protection rulesets, PR culture, commit history (Conventional Commits), CI workflow density, README/docs presence, .gitignore coverage, CODEOWNERS, issue/PR templates, and repo settings (merge strategy, secret scanning, auto-delete). Use when the user says "audit this repo", "repo health check", "review our branching strategy", "check branch protection", "CODEOWNERS audit", "are our CI checks configured correctly", "check PR templates", or "GitHub repo settings review". Do NOT use for deep CI/CD architecture (devops-guardian), code correctness (security-guardian, react-guardian), or database schema (db-guardian).
- ▌ Image Optimization Weapon · the-notorious-avengers bundleImage optimization specialist for React/Next.js and HTML contexts — AVIF/WebP format selection (AVIF is the 2026 production default), responsive srcset/sizes calculus, blur placeholders (LQIP via Sharp, BlurHash-as-CSS-gradient, ThumbHash), next/image remote patterns and the Next.js 16 priority→preload shift, and CLI tooling (Sharp Node API, Squoosh CLI for one-offs). Use when the user says "optimize my images", "convert to AVIF", "set up srcset", "add blur placeholders", "next/image remote patterns", "LCP image is slow", "fix layout shift from images", "AVIF vs WebP", or when auditing a codebase for unoptimized image delivery. Do NOT use for SVG icon systems (icon-system-guardian), general Lighthouse audits beyond image-specific findings (lighthouse-pagespeed-guardian), CDN/caching architecture beyond image Cache-Control (devops-guardian), or CSS animation performance (ux-ui-guardian).
- ▌ Telegram Bot Weapon · the-notorious-avengers bundleTelegram Bot specialist — Bot API (up to 10.0 / May 2026 including guest mode and managed bots), grammY v1.x (TypeScript, recommended) and aiogram 3.x (Python), webhook vs long-polling decision with quantitative thresholds, Telegram Mini Apps initData validation (HMAC-SHA256 + Ed25519), Telegram Stars payments (mandatory for digital goods in 2026), inline mode, and MTProto escalation via Telethon/TDLib. Invoke when building a new bot, debugging webhook delivery, wiring Mini Apps, implementing payments, or deciding between frameworks. Do NOT invoke for the Mini App frontend UI (react-guardian), hosting/CI beyond bot-specific concerns (devops-guardian), or external payment processor integrations beyond Telegram Payments (payments-guardian).
- ▌ Cold Outreach Weapon · the-notorious-avengers bundleOutbound sales specialist for founders running cold email. Covers Apollo / Clay / Smartlead / Instantly / Lemlist tool selection, email deliverability and domain warmup, multi-touch sequence design (3-5 steps), AI personalization without slop (Clay Claygent SKIP rule), reply classification and disqualification, and list hygiene. Use when the user says "set up cold outreach", "my cold email is landing in spam", "write a cold email sequence", "set up Clay personalization", "Apollo vs Instantly", "my reply rate is below 2%", "cold email warmup", "build a list in Apollo", or when cold-outreach-guardian is invoked. Do NOT use for inbound SDR workflows, CRM architecture (db-guardian), AE discovery call scripts, paid acquisition, or LinkedIn content strategy.
- ▌ Design System Weapon · the-notorious-avengers bundleBootstraps a complete design system from scratch for a product. Produces the seven-artifact folder — master design brief, master tokens CSS, utility layer CSS, per-component specs, per-screen specs, static HTML examples, and a README. Use when the user says "set up a design system", "bootstrap ux-ui", "scaffold the design language", "I need a design brief + tokens for <product>", "create the source-of-truth for our UI", or when `design-system-guardian` is invoked. Do NOT use for maintenance, PR review, or incremental token changes — that is `ux-ui-guardian`'s job.
- ▌ React Weapon · the-notorious-avengers bundleReviews, refactors, and authors React 18/19 codebases using the bulletproof-react architectural pillars and the curated 2025-2026 React ecosystem. Use when the user says "review this React code", "react architecture review", "audit our React app", "state management decision", "what's the bleeding-edge React pattern for X", "propose a React refactor", "is this React anti-pattern", or when `react-guardian` is invoked. Do NOT use for visual design (ux-ui-guardian), SEO/Next.js metadata strategy (seo-aeo-guardian), security audits (security-guardian), or PRD authoring (library-guardian).
- ▌ UX UI Weapon · the-notorious-avengers bundleEnforces a product's design system end-to-end — opens the source-of-truth folder first, cites governing sections, specifies pixel-perfect deltas in token-named terms, and applies per-library integration rules for shadcn/ui, Mantine, Lucide-react, and Framer Motion. Use when reviewing UI pull requests, authoring component or screen specs, wrapping an external component library, auditing a screen for token/utility/motion violations, or when the user says "is this on-brief?", "review this screen", "should we use shadcn for this?", "wrap this Mantine component", or "the brief doesn't cover this — extend it." Do NOT use for system-wide aesthetic overhauls (route to `design-system-guardian`) or for asset registration (route to `asset-guardian`).
- ▌ Library Weapon · the-notorious-avengers bundleEquips library-guardian with the documentation lifecycle — knowledge-base authoring (public vs private audience split), feature PRD authoring (prd-<###>-<slug>/ with index + sub-PRDs + qa/), issue IRD authoring (ird-<###>-<slug>/ with index + qa/), backwards-PRD generation, sync audits / drift detection, lifecycle moves (backlog/in-work/completed), and the standardize-library script for scaffolding any repo to schema v2. Use when initializing a library/, ingesting issues, planning features, writing knowledge docs, running drift audits, or moving a completed PRD/IRD to its completed/ tier. Not for QA report authorship (use quality-weapon) or asset-registry work (use asset-weapon).
- ▌ Quality Weapon · the-notorious-avengers bundleAudits a completed implementation against its source plan document and produces a structured findings report. The report goes in the source plan's `reports/` subfolder (e.g., `library/requirements/features/feature-<###>-<title>/reports/<date>-qa-report.md` or `library/requirements/issues/issue-<###>-<title>/reports/<date>-qa-report.md`); standalone audits go to `library/qa/<domain>/<date>-qa-report.md`. Use when the user says "QA this", "audit the implementation", "check the plan against the code", "run quality-guardian", "verify the PRD was built", or when `security-guardian` has just finished and the loop ends with a QA pass before merge. Produces a markdown findings report with scorecard, severity-tagged findings, and a plan-item traceability table. Does not write code, fix issues, or author plans.
- ▌ SEO Aeo Weapon · the-notorious-avengers bundleOptimizes Next.js 14+ App Router applications for the three parallel discovery systems — traditional search (Google, Bing), AI Overviews / Featured Snippets, and AI assistants (ChatGPT, Perplexity, Claude). Use when the user says "audit SEO", "optimize for AI Overviews", "review schema markup", "improve Core Web Vitals", "check metadata", "validate structured data", "fix LCP / INP / CLS", "implement the SEO/AEO playbook", or invokes `seo-aeo-guardian`. Covers technical foundation, on-page metadata, schema, E-E-A-T, AEO, Core Web Vitals, mobile, local SEO, and analytics. Does NOT write marketing copy, pick keywords, or audit non-Next.js stacks with full fidelity.
- ▌ Weapon Forge · the-notorious-avengers bundlePhase 2 of the Legion AI Tools Factory pipeline. Takes a completed Command Brief AND a pre-populated `research/` folder authored by `scripture-historian`, names the Weapon (Cursor skill), scaffolds the rest of the skill folder structure under `ai-tools/skills/`, and forges the Cursor-compatible SKILL.md plus its supporting guides, examples, templates, and reports. This skill no longer conducts its own research -- that is `scripture-historian`'s job, and weapon-forge refuses to run until that folder is populated. Use whenever the user says "forge the weapon", "build the skill", "scaffold the weapon folder", "build guides from the research", "the research is in, build the skill", or signals that scripture-historian has just announced its handoff. Also trigger when the user hands you a path to a filled-in `{angel-name}-command-brief.md` plus a non-empty `ai-tools/skills/<weapon-name>/research/` folder and says to proceed.
- ▌ Angel Creator · the-notorious-avengers bundlePhase 3 of the Legion AI Tools Factory pipeline. Authors the Cursor IDE subagent (Angel) file from a completed Command Brief and forged Weapon. Writes the YAML frontmatter, composes the body with proper Read-references to every file in the paired Weapon folder, wires the Angel to its guardrails and escalation paths, and declares a proactive/on-demand trigger policy. Use this skill whenever the user asks to "create the Angel", "author the subagent", "build the subagent file", "wire up the Angel", "finish the Angel", or signals that the Weapon is forged and it is time to assemble the subagent. Also trigger when weapon-forge has just announced its handoff or when the user points to a ready-to-use weapon folder and asks for its Angel.
- ▌ Devops Weapon · the-notorious-avengers bundleDesigns, audits, and authors Docker / Docker Compose / GitHub Actions / Depot pipelines for Node / Next.js / TypeScript stacks. Use when the user says "review my Dockerfile", "design our CI pipeline", "audit our workflow security", "migrate to Depot", "add a healthcheck to compose", "this build is slow", "we leaked a secret in CI", or when `devops-guardian` is invoked. Do NOT use for cloud provisioning (cloud-platform Angels), DB schema or migrations (db-guardian — devops-weapon wires the migration step but does not author it), security CVE deep audits (security-guardian — devops-weapon surfaces concerns and hands off), or PRD authoring (library-guardian).
- ▌ God Registrar · the-notorious-avengers bundlePhase 4 of the Legion AI Tools Factory pipeline. Registers a newly forged Angel with the God routing skill — adds a row to God's roster table in ai-tools/skills/god/SKILL.md and authors the Angel's guide file at ai-tools/skills/god/guides/. Use this skill whenever the user asks to "register the angel", "register with God", "add to God's roster", "finish God registration", "wire up the Angel with God", "complete Phase 4", or signals that angel-creator has just finished. Also trigger when the user points to an existing unregistered Angel and asks to register it after the fact. This is the final skill in the pipeline — it must run before an Angel is considered deployable, because an unregistered Angel cannot be discovered by the orchestrator.
- ▌ Website Weapon · the-notorious-avengers bundleBuilds production-grade SvelteKit (Svelte 5) + Payload CMS + Supabase websites end-to-end from a brief, applying a 12-phase playbook. Default CMS mode is Payload 3.x (self-hosted Next.js on Vercel, consumed via REST from SvelteKit). Fallback CMS mode is TypeScript-as-CMS for one-page lead-gen sites that skip Payload. Trigger on phrases like "build a website", "scaffold a SvelteKit site", "spin up a marketing site", "build me a lead-gen site", "ship a website from scratch", "create a SvelteKit + Supabase site", or whenever the paired `website-guardian` Angel is invoked. Do not trigger for one-off page tweaks, copy edits, or deploy-only tasks.
- ▌ API Docs Weapon · the-notorious-avengers bundleAPI documentation authority — Swagger UI / Redoc / Scalar / Mintlify / Stoplight / Bump.sh tool selection, OpenAPI spec enrichment with JSON examples, self-hosted and managed hosting, SDK generation (TypeScript / Python / Go via openapi-generator-cli and Fern/Speakeasy), and changelog discipline. Invoke when the user says "set up API docs", "which docs renderer should I use", "generate an SDK from my spec", "deploy my OpenAPI docs", "write an API changelog", "compare Redoc vs Scalar", or "publish API reference to GitHub Pages". Do NOT invoke for general documentation sites (library-guardian), API security scheme audits (security-guardian), or backend route design (python-guardian / react-guardian).
- ▌ Payments Weapon · the-notorious-avengers bundleImplements, audits, and debugs Stripe (non-Connect) integrations — Checkout, Payment Intents, Subscriptions, Customer Portal, Invoicing, Payment Links, and webhook processing. Use when the user says "integrate Stripe", "audit our payments", "webhook isn't firing", "subscription stuck in incomplete", "migrate to flexible billing mode", "set up Customer Portal", "compare Checkout vs Payment Intents", or when `payments-guardian` is invoked. Do NOT use for Stripe Connect / marketplace flows (out of scope), database schema (db-guardian), secret/PII audits (security-guardian), client-side Stripe.js components (react-guardian), or PRD authoring (library-guardian).
- ▌ Tawk To API · the-notorious-avengers bundleReference for the tawk.to REST API v1.1.0 (https://api.tawk.to/v1). Covers authentication (API key Basic Auth + OAuth2), every endpoint group (Property, Widgets, Members, Chats, Tickets, Tabs, Knowledge-Base, Webhook, Metrics, Contacts), scopes, error shapes, and pagination. Has deep coverage of the Knowledge-Base content-block model and a workflow for turning markdown files plus image links into KB articles (host images on Cloudflare R2 or DigitalOcean Spaces, then reference by URL). Use when integrating tawk.to, calling its API, programmatically creating or syncing knowledge base articles, categories, or sites, or converting markdown content into tawk articles.
- ▌ Wiki Weapon · the-notorious-avengers bundleEquips wiki-guardian with the 13-type code entity catalog, ts-morph AST extraction patterns, ADR detection from commit messages, the active four-artifact contradiction protocol, and canonical wiki page templates with code-aware frontmatter. Use when wiki-guardian is invoked to extract entities and concepts from code chunks plus git context into library/knowledge-base/wiki/, or to lint the existing wiki for orphans, dead links, and stale claims. Not for module narrative authorship (use library-weapon) or QA report authorship (use quality-weapon).
- ▌ Asset Weapon · the-notorious-avengers bundleEquips asset-guardian with the Universal Asset Registry — the 19-asset taxonomy (Features, Pages, Routes, Surfaces, Controls, Displays, Layouts, NavEntries, DesignTokens, Icons, MediaAssets, Fonts, Motion, Breakpoints, ContentEntries, Translations, FeatureFlagBindings, MeterBindings, Entitlements), the registration workflow, the code-vs-DB drift audit, the sync-generator contract, the deprecation/sunset rules, and the canonical Prisma + SQL schema. Use when registering, auditing, deprecating, or generating sync code for any of the 19 asset types, when checking for drift between code and the registry, or when standing up the registry in a new repo. Not for QA report authorship (use quality-weapon), PRD numbering (use library-weapon), UX design decisions (use ux-ui-weapon), or security audits of the registry tables (use security-weapon).
- ▌ Preact Weapon · the-notorious-avengers bundlePreact 11 specialist skill — signals-based reactivity (v2 API with createModel/useModel), preact/compat migration from React, third-party embed widgets (shadow DOM isolation, IIFE bundles), Astro island integration (client:* directives, >= 5.0.1 useId fix), and Fresh 2.x framework (Deno-native, islands + serializable props). Use when building Preact components, evaluating Preact vs React, migrating from React to Preact, embedding a widget on third-party pages, or working with Astro or Fresh projects. Do NOT use for React architecture in general (react-guardian), Next.js App Router configuration (react-guardian), or Deno infrastructure beyond Fresh (devops-guardian).
- ▌ Python Weapon · the-notorious-avengers bundleReviews, refactors, and authors modern Python codebases (Django, FastAPI, Celery, Channels, scripting, packaging, data) using a canonical opinionated stack — Django Ninja over DRF, Celery + Redis for jobs, Channels for realtime, pytest + factory_boy for tests, uv for packaging, Pydantic v2 at boundaries, Ruff and pyright for quality. Use when the user says "review this Python code", "Django app review", "audit this Django app", "ORM audit", "fix N+1", "DRF to Ninja migration", "Celery refactor", "Channels enablement", "pytest setup", "type-adoption plan", "Ruff config", "uv migration", "settings split", "async refactor", "Django + React audit", "Python scripting / packaging help", or when `python-guardian` is invoked. Do NOT use for React component shape (react-guardian), DB schema design / indexing / partitioning (db-guardian), security audit (security-guardian), auth provider choice / OAuth flow (auth-guardian), Stripe SDK design (payments-guardian), AI cognitive infra / RAG / coaches / evals (mind-guardian
- ▌ Big Bang Earth · the-notorious-avengersEquips the big-bang-space subagent with the canonical rubric, format, and routing logic for proposing brand new Angels (Cursor IDE subagents) into the Legion AI Tools Factory. Use whenever a new guardian needs to be added to `ai-tools/proposed-angels-backlog.md` plus `ai-tools/proposed-angels-queue.md`. Encodes the four-tier research depth rubric, the three-role model routing (Research / Analyst / Builder), the category overrides (math_science, cli_devops, self_hosted_open), the exact backlog entry shape, the exact queue row shape, the search-query authoring discipline, and the position-numbering invariants. Not for editing existing entries, claiming queue rows, or running downstream pipeline steps (command-brief, weapon-forge, create-angel, god-register); those are owned by other skills and agents.
- ▌ Command Center · the-notorious-avengers bundlePhase 1 of the Legion AI Tools Factory pipeline. Names a new Cursor IDE Angel (subagent) and its Weapon (skill) from the user's requested topic, copies the Command Brief template into the ai-tools command-briefs folder, populates the brief's YAML frontmatter (research_depth and model triplet, sourced from the backlog entry when one exists), and conversationally interviews the user to fill in every section. Use this skill whenever the user asks to "create a new Angel", "create a new subagent", "start a new Angel", "begin an Angel", "forge an Angel", "add a guardian", "start a Command Brief", "brief a new agent", "I want a subagent that does X", or any request that kicks off a fresh Angel/Weapon pair. Also trigger when the user names a topic area (security, UX, SEO, observability, etc.) and wants a dedicated agent for it. This is the first skill in the pipeline -- it MUST run before scripture-historian, weapon-forge, or angel-creator.
- ▌ Git Weapon · the-notorious-avengers bundleGit mastery specialist — interactive rebase (squash, fixup, reword, drop), conflict resolution, history rewriting (git filter-repo, BFG), reset/reflog recovery, worktrees for parallel branches, hooks (Husky, lefthook), submodules vs subtrees, Git LFS, partial clone, and sparse checkout. Use when the user says "squash my commits", "I pushed a secret", "my repo is huge", "undo that rebase", "work on two branches at once", "set up Git hooks", "submodules vs subtrees", or needs any Git recovery operation. Do NOT use for CI/CD pipeline configuration (devops-guardian) or credential rotation after a secrets incident (security-guardian).
- ▌ Auth Weapon · the-notorious-avengers bundleImplements end-to-end authentication — provider selection (Clerk / Better Auth / Auth.js / Supabase Auth / WorkOS / Stack Auth / Kinde / Stytch), Google OAuth flows including the October 2025 unused-client-deletion policy and GIS migration, MFA / passkeys, RBAC, session storage, and B2B SSO. Use when the user says "set up auth", "pick an auth provider", "wire up Google sign-in", "Google OAuth verification", "set up MFA / passkeys", "RBAC for multi-tenant", "migrate from NextAuth to Better Auth / Clerk", or when `auth-guardian` is invoked. Do NOT use for security audits of the resulting implementation (security-guardian), the React `<SignIn />` UI (react-guardian), the user / session schema (db-guardian), or the auth PRD (library-guardian).
- ▌ Mind Weapon · the-notorious-avengers bundleReviews, refactors, audits, and extends the cognitive layer of the deploying product — coach/agent routing, prompt cascade, RAG / GraphRAG, three-tier memory, observability, evaluation, multimodal pipeline, agent orchestration, matching, and onboarding. Encodes the recommended canonical stack (Qdrant + Cohere rerank-v3.5 + Valkey + OpenRouter + Llama 3.3 70B / 3.1 8B / 3.2 11B vision + Deepgram) as the default. The host product can override via `library/knowledge-base/ai/`. Use when the user says "review this AI code", "audit RAG", "investigate AiTrace", "add a coach", "change the prompt cascade", "tune retrieval", "trace a sycophancy spike", "enable GraphRAG", or when `mind-guardian` is invoked. Do NOT use for chat UI components (react-guardian), AI table indexing/partitioning (db-guardian), prompt-injection / provider-key / PII audits (security-guardian), AI PRD authoring (library-guardian).
- ▌
- ▌ DB Weapon · the-notorious-avengers bundleDesigns, reviews, and migrates PostgreSQL data layers — schema, indexing, zero-downtime migrations, performance, ORM choice, and serverless DB platform selection. Use when the user says "design this schema", "review this migration", "is this index right?", "should this be jsonb or columns?", "we need a NOT NULL on a 100M-row table", "Drizzle or Prisma?", "Supabase or Neon?", "production query is slow", or when `db-guardian` is invoked. Do NOT use for PRD authoring (library-guardian), data-layer consumption in components (react-guardian), security audits of RLS / PII / encryption-at-rest (security-guardian), or RAG / embedding retrieval pipelines (ai-platform-guardian).