yanacuti1121
- 1.8k skills
- 0 followers
- 2 repo stars
- 2 weeks ago last updated
- ▌ Web Performance · yanacuti1121Audit and optimize web performance — Core Web Vitals (LCP, INP, CLS), bundle splitting, lazy loading, image optimization, caching strategies, and resource hints. Use when asked to "improve performance", "fix LCP/CLS/INP", "optimize bundle", "reduce load time", "lazy load images", "add caching", or before marking any public-facing page as production-ready. Do NOT use for server-side database performance — this covers frontend and network-layer only.
- ▌ Worktree Safety · yanacuti1121Use when starting a new feature task, before making experimental changes, or when user says 'try this', 'experiment with', 'test out'. Ensures work happens on a branch, not directly on main.
- ▌ 666ghj Mirofish · yanacuti1121MiroFish — Swarm Intelligence Engine: upload seed data → simulate thousands of agents → predict future trajectories. GraphRAG + multi-agent simulation + interactive chat.
- ▌ Aesthetic Anchor · yanacuti1121Lock a specific visual aesthetic before building UI — choose one of 8 design anchors (Swiss, Industrial, Brutalist, Aurora Maximalism, Chaotic Maximalism, Retro-Futuristic, Organic, Lo-Fi) and apply its palette, typography, and texture tokens consistently throughout the build. Use when the user says "make it look like X", names a visual style, wants a specific aesthetic mood, or asks to avoid generic AI output. Do NOT use when the project already has an established design system — apply that system instead.
- ▌ AI Team Workflow · yanacuti1121Organize AI agents as a structured team — role assignment, proposal/vote/ review/ship cycle, cross-agent code review, consensus mechanisms, and escalation to human for deadlocks. Use when asked about "AI team", "agents working as a team", "multi-agent workflow", "agent roles", "agent review", "agents vote", "Hivemoot", "AI proposes and votes", "agent consensus", "agents reviewing each other's work", "define agent roles", "AI standup", or "autonomous team of agents". Do NOT use for: git-based task coordination — see git-native-agent-protocol. Do NOT use for: safety gates — see agent-safety-patterns.
- ▌ Bot From Scratch · yanacuti1121Use when building a chat-platform bot (Discord/Telegram/Slack/Twitter-style) from first principles — the event loop, command routing, and platform API integration, not an LLM agent framework. Triggers on: 'build a discord bot from scratch', 'implement a telegram bot event loop', 'webhook vs polling for a bot', 'command router for a chat bot', 'rate limiting a platform API bot'. Covers polling vs webhook architecture, command parsing/routing, and state management.
- ▌ Caching Patterns · yanacuti1121Design and implement caching — strategy selection (cache-aside, read-through, write-through, write-behind), cache invalidation, TTL tuning, Redis patterns, cache stampede prevention, and distributed cache consistency. Use when asked to "add caching", "Redis cache", "cache invalidation", "reduce database load", "cache-aside", "CDN caching", "stale-while-revalidate", "cache stampede", "cache warming", or "response is too slow and hits the DB every time". Do NOT use for: HTTP browser caching headers alone — use web-performance. Do NOT use for: feature flag caching — use feature-flags skill.
- ▌ Codebase Onboard · yanacuti1121Use when asked to understand, tour, or onboard to a codebase. Triggers on: 'onboard', 'explain codebase', 'walk me through the code', 'new to this project', 'codebase overview', 'how is this structured', 'give me a tour', 'tổng quan codebase', 'giải thích project', 'entry point', 'where to start reading'.
- ▌ Coding Standards · yanacuti1121Baseline cross-project coding conventions for naming, readability, immutability, and code-quality review. Use detailed frontend or backend skills for framework-specific patterns.
- ▌ Contract Testing · yanacuti1121Design and implement consumer-driven contract tests — Pact consumer interactions, provider verification, Pact Broker publishing, and CI/CD integration. Use when asked to "contract testing", "Pact", "consumer-driven contracts", "provider verification", "Pact Broker", "can I deploy", "breaking API changes", "how to test microservice boundaries without E2E tests", or "verify this API change won't break consumers". Do NOT use for: full E2E testing of a user journey — use e2e-testing skill. Do NOT use for: API schema validation alone — contracts go further by verifying consumer-specific interactions.
- ▌ Council Of Minds · yanacuti1121Convene 6 intellectual personas across multiple LLM providers for hard decisions. Each persona runs on a different provider for genuinely different reasoning — not costume changes on one model. Inspired by council-of-high-intelligence (CC0).
- ▌ Github Spec Kit · yanacuti1121Spec-Driven Development toolkit của GitHub — specs executable, không phải tài liệu. 5 core commands: constitution→specify→plan→tasks→implement. 30+ agent integrations.
- ▌ GRAPHQL Patterns · yanacuti1121Design and optimize GraphQL APIs — schema design, N+1 elimination with DataLoader, pagination (cursor/connection spec), authorization in resolvers, subscriptions, and error handling. Use when asked about "GraphQL schema", "resolver N+1", "DataLoader", "GraphQL pagination", "GraphQL subscriptions", "GraphQL authorization", or "how to structure a GraphQL API". Do NOT use for: REST API design — use `api-design`. General query optimization on the database layer — use `database-patterns`.
- ▌ Modal Serverless · yanacuti1121Deploy AI workloads to serverless GPU/CPU with Modal — define @app.function with GPU/memory specs, build custom container images, run batch jobs and web endpoints, schedule cron tasks, and use distributed volumes for model caching.
- ▌ Plan Orchestrate · yanacuti1121Read a plan document, decompose it into steps, design a per-step agent chain from the ECC catalogue, and emit ready-to-paste /orchestrate custom prompts. Generative only — never invokes /orchestrate itself. Use when the user has a multi-step plan and wants to drive it through orchestrate without composing chains by hand.
- ▌ Remove Dead Code · yanacuti1121Safely identifies and removes dead code in TypeScript/JavaScript projects using multi-agent analysis with automatic backup branches. Use when cleaning up unused exports, orphaned files, dead imports, unreachable functions, or unused dependencies.
- ▌ Semantic Scholar · yanacuti1121Use when asked about citation counts, paper impact, who cited a paper, research influence, finding references of a paper, author h-index, or publication metrics. Triggers on: 'citation count', 'who cited', 'how many citations', 'paper impact', 'semantic scholar', 'research influence', 'find references', 'author publications', 'h-index', 'số lần trích dẫn', 'tìm tài liệu tham khảo', 'bài báo có ảnh hưởng'.
- ▌ Session To Skill · yanacuti1121Auto-extract a reusable skill from the current session conversation. Use when the user says "save this as a skill", "turn this into a skill", "I want to reuse this workflow", "make this repeatable", "skillify this", "we just did something I want to automate", or after completing a useful multi-step task that could be repeated. Do NOT use for one-off fixes or tasks with no repeatable value.
- ▌ Setup Agent Tail · yanacuti1121Configure agent-tail log aggregation for the current project. Auto-detects framework (Vite, Next.js, plain Node, monorepo) and sets up CLI runner, browser log plugins, and output destinations. Use when setting up agent-tail, configuring dev server logging, or piping logs for AI agent consumption.
- ▌ Social Publisher · yanacuti1121Agent-driven social media scheduling and publishing via SocialClaw across 13 platforms — X, LinkedIn, Instagram, TikTok, Discord, Telegram, YouTube, Reddit, WordPress, Pinterest, Facebook, Threads, Bluesky.
- ▌ Testing Strategy · yanacuti1121Testing strategy — unit/integration/e2e pyramid, TDD workflow, mocking best practices, test isolation, coverage targets
- ▌ Tree Of Thoughts · yanacuti1121Multi-path reasoning before acting. Agent generates 3 candidate solutions, self-scores each on correctness/token-cost/safety, selects the best branch, and backtracks if it hits a dead end. Use before /deep-heal or any complex fix. Inspired by kyegomez/TreeofThoughts (ToT) — DFS/BFS over solution space.
- ▌ Agentskills Spec · yanacuti1121Specification và docs cho Agent Skills format — chuẩn open format để extend AI agent capabilities. Dùng khi viết SKILL.md mới hoặc cần hiểu spec.
- ▌ API Rate Limiting · yanacuti1121Design and implement API rate limiting — algorithm selection (token bucket, sliding window, fixed window), Redis-based distributed limiting, per-user and per-IP limits, rate limit headers, retry-after, and burst handling. Use when asked to "add rate limiting", "throttle requests", "too many requests", "429", "token bucket", "sliding window counter", "per-user quota", "API abuse", "burst traffic", or "rate limit this endpoint". Do NOT use for: load shedding at the infrastructure layer — that belongs in a load balancer or API gateway config, not application code.
- ▌ Can1357 Oh My Pi · yanacuti1121omp — AI coding agent viết bằng Rust (27K lines), hash-anchored edits (-61% output tokens), LSP+debugger tích hợp, 32 tools, 40+ LLM providers. Fork của Pi platform.
- ▌ Chaos Engineering · yanacuti1121Use when planning, running, or learning from chaos engineering experiments. Triggers on "chaos experiment", "fault injection", "gameday", "resilience test", "blast radius", "steady state", "abort criteria", "Chaos Toolkit", "Chaos Mesh", "Litmus", "Gremlin", "AWS FIS", or any deliberate failure-injection question. Ships experiment designer, blast-radius calculator, and postmortem generator (all stdlib Python), 4 references on chaos principles + experiment design + attack taxonomy + tooling landscape, and a /chaos-experiment slash command. Composes with feature-flags-architect (kill switches as abort triggers) and kubernetes-operator (common chaos targets).
- ▌ Database Patterns · yanacuti1121Design and optimize relational database schemas — normalization, indexing strategy, query optimization, N+1 elimination, pagination patterns, and migration safety. Use when asked to "design a schema", "fix slow queries", "add an index", "N+1 problem", "paginate results", "write a migration", or "database is slow". Covers PostgreSQL/MySQL patterns. Do NOT use for: NoSQL document design — that requires a separate approach. Do NOT use for: frontend performance.
- ▌ Design System Gen · yanacuti1121Generate a complete design token system for a new project — color palette, typography scale, spacing, shadows, and border radius — tailored to the product type (SaaS, e-commerce, healthcare, fintech, creative, etc.). Use when starting a new project with no design system, when the user asks to "set up design tokens", "create a design system", or "what colors/fonts should I use for a [product type]". Do NOT use when the project already has tokens — use ui-redesign instead.
- ▌ Flox Environments · yanacuti1121Create reproducible, cross-platform development environments with Flox — a declarative environment manager built on Nix. ALWAYS use this skill when the user needs to: set up a project with system-level dependencies (compilers, databases, native libraries like openssl, libvips, BLAS, LAPACK); configure reproducible toolchains for Python, Node.js, Rust, Go, C/C++, Java, Ruby, Elixir, PHP, or any language; manage environments that must work identically across macOS and Linux; pin exact package versions for a team; run local services (PostgreSQL, Redis, Kafka) alongside development tools; onboard new developers with a single command; or solve 'works on my machine' problems. Especially valuable for AI-assisted and vibe coding — Flox lets agents install tools into a project-scoped environment without sudo, system pollution, or sandbox restrictions, and the resulting environment is committed to the repo so anyone can reproduce it instantly. Use this skill even if the user doesn't mention Flox — if they describe need
- ▌ Frontend Patterns · yanacuti1121Frontend development patterns for React, Next.js, state management, performance optimization, and UI best practices.
- ▌
- ▌ Microsoft Bitnet · yanacuti1121BitNet.cpp — official inference framework cho 1-bit LLMs: 1.37x-6.17x speedup, -55-82% energy. Chạy 100B model trên single CPU 5-7 tok/s. ARM + x86.
- ▌ Monorepo Patterns · yanacuti1121Structure and operate a monorepo — Turborepo or Nx workspace setup, shared packages, task pipeline caching, change detection, publishable vs internal packages, versioning strategy, and CI optimization. Use when asked about "monorepo", "Turborepo", "Nx", "workspace", "shared packages", "internal packages", "turbo.json", "task pipeline", "remote cache", "affected packages", "package dependency graph", "pnpm workspaces", "yarn workspaces", or "how to share code between apps". Do NOT use for: CI/CD pipeline wiring — see cicd-patterns. Do NOT use for: npm package publishing — see api-design for versioning principles.
- ▌ Option Tournament · yanacuti1121Generate many candidate options across different styles (concise, simple, creative, professional), then run pairwise elimination rounds to select the top 3 with reasons. Use when asked for 'phương án', 'cho mấy phương án', 'generate options and pick best', 'so sánh phương án', 'naming candidates', 'top 3 approaches', 'loại dần phương án yếu', or 'which wording is best'. Do NOT use for: prioritizing a task list — see pairwise-prioritization. Do NOT use for: exploring solution trees in reasoning — see tree-of-thoughts.
- ▌ React Performance · yanacuti1121React and Next.js performance optimization — eliminate waterfalls, reduce bundle size, optimize renders, server-side patterns. 70+ rules by impact priority. Profile first, optimize second.
- ▌ Refactor Patterns · yanacuti1121Apply systematic refactoring patterns — strangler fig for legacy migration, seam detection, extract method/class, introduce parameter object, replace conditional with polymorphism, and safe refactoring sequencing. Use when asked to "refactor this", "clean up legacy code", "this is unmaintainable", "too many if statements", "extract this logic", or "how do I migrate without breaking everything". Do NOT use for: full rewrites — that is an architecture decision, not a refactoring task.
- ▌ Secret Management · yanacuti1121Store, access, rotate, and audit secrets safely — provider selection (Vault, AWS Secrets Manager, GCP Secret Manager), runtime injection, rotation policy, least-privilege IAM, CI/CD secret handling, and secret scanning in pipelines. Use when asked to "store API keys", "rotate secrets", "Vault", "AWS Secrets Manager", "secret rotation", "least privilege", "secrets in CI", "secret scanning", "gitleaks", "trufflehog", "don't hardcode credentials", or "how to manage secrets in production". Do NOT use for: general auth token lifecycle — see auth-patterns. Do NOT use for: environment variable naming conventions alone — this covers secret storage architecture.
- ▌ Typography System · yanacuti1121Design a complete typography system — font pairing, type hierarchy, micro-typography (line-height, letter-spacing, measure), web font performance (font-display, preload, system stacks), and Vietnamese diacritic considerations. Use when the user asks to "choose fonts", "set up typography", "fix text spacing", "font pairing", "type scale", or "web font loading". Do NOT use when a design token system already exists — extend it instead. Works standalone or as a layer on top of design-system-gen output.
- ▌ Auto Feedback Loop · yanacuti1121Implement self-correcting agent loops — run tests, capture failures, feed error context back to the writing agent, and repeat until pass or max-attempts reached. Inspired by Microsoft AutoGen's multi-agent reflection pattern. Use when asked about "auto-feedback loop", "self-correcting agent", "AutoGen reflection", "agent retry on failure", "tdd feedback loop", "automatic fix loop", "agent keeps fixing until tests pass", "feedback-loop script", "run-until-green", or "agent self-correction". Do NOT use for: one-shot test runs — see tdd-workflow. Do NOT use for: multi-agent task assignment — see ai-team-workflow.
- ▌ Cloudflare Vinext · yanacuti1121Vinext — Next.js API trên Vite, deploy tới Cloudflare Workers. 94% Next.js 16 API coverage, App Router + RSC, Cloudflare Bindings (D1/R2/KV/AI). Builds nhanh hơn.
- ▌ D4vinci Scrapling · yanacuti1121Adaptive web scraping framework — handles everything từ single request đến full-scale crawl, tự động thích nghi khi site thay đổi. 59K stars.
- ▌ Design Engineering · yanacuti1121Practice the design-engineering discipline — bridging design intent and implementation, working directly in code, component exploration workflow, design tool to code handoff, and building UI systems that stay true to their design spec. Use when asked about "design engineering", "design engineer", "design in code", "design-to-dev handoff", "bridge design and development", "design system in code", "component playground", "Storybook for design", "Figma to code", "interactive prototyping in code", or "when to use design tools vs code". Do NOT use for: building an actual design system token spec — see design-system-gen. Do NOT use for: specific animation implementation — see motion-design.
- ▌ Gitnexus Pr Review · yanacuti1121Use when the user wants to review a pull request, understand what a PR changes, assess risk of merging, or check for missing test coverage. Examples: "Review this PR", "What does PR #42 change?", "Is this PR safe to merge?"
- ▌ Marketing Campaign · yanacuti1121End-to-end marketing campaign — audience research, positioning, landing page copy, email sequences, social posts, ad copy, video scripts, content calendars. Use with marketing-agent.
- ▌ Triage · yanacuti1121 bundleMove issues and external PRs through a state machine of triage roles — categorise, verify, grill if needed, and write agent-ready briefs.
- ▌ Openclaw Openclaw · yanacuti1121Personal AI assistant chạy trên mọi OS/platform — 20+ channels (WhatsApp, Telegram, Zalo, WeChat, Discord, Slack...), Skills system, voice, Canvas. Dùng khi build hoặc setup personal AI assistant đa kênh.
- ▌ Output Enforcement · yanacuti1121Run a final quality gate on UI output before delivering it to the user. Checks code quality, visual correctness, accessibility baseline, and that no placeholder content remains. Use when about to deliver any frontend implementation — before saying "done", "here is the component", or marking a UI task complete. Do NOT use as a standalone task — this is a pre-delivery gate, not a redesign skill.
- ▌ Pre Compact Backup · yanacuti1121Back up conversation transcript before context compaction. Use when: PreCompact hook fires, user asks to save session state, or before long tasks where context loss would be costly. Creates timestamped backup in logs/transcript_backups/. Inspired by: disler/claude-code-hooks-mastery pre_compact pattern.
- ▌ Prompt Engineering · yanacuti1121Design, version, and optimize LLM prompts — few-shot examples, chain-of-thought, role framing, constraint injection, A/B testing, and prompt version management. Use when asked to "write a system prompt", "improve this prompt", "prompt isn't working", "add few-shot examples", "prompt A/B test", or "how do I get better outputs from the model". Do NOT use for: RAG retrieval design — use `rag-architect`. UI for streaming responses — use `llm-ui-patterns`.
- ▌ Purple Team Report · yanacuti1121Synthesize red team findings and blue team fixes into a structured security report. Use when the user wants a consolidated security report after red-team-check and blue-team-fix have been run, or when presenting security findings to stakeholders. Produces: executive summary, finding table with evidence, fix status, and open items.
- ▌ Data Room · yanacuti1121When the user wants to prepare a due diligence data room for fundraising, or when an investor has requested additional materials after a pitch. Also activates for "data room", "due diligence", "DD checklist", or "what documents do investors need?".
- ▌ Soc2 Prep · yanacuti1121When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".
- ▌ Telemetry Analysis · yanacuti1121Use when asked to analyze hook activity, token usage, audit logs, or agent behavior patterns. Triggers on: 'xem log', 'hook nào fire nhiều', 'token usage', 'audit trail', 'what hooks fired', 'session summary', 'telemetry report', 'hook health', 'agent activity'.
- ▌ Terraform Patterns · yanacuti1121Write production-grade Terraform — module structure, remote state, workspace strategy, variable validation, lifecycle rules, data sources, provider version pinning, and safe plan/apply workflow. Use when asked about "Terraform", "IaC", "infrastructure as code", "Terraform module", "remote state", "terraform plan", "terraform apply", "state locking", "Terraform workspace", "provider version", "terraform import", "destroy protection", "variable validation", or "Terraform best practices". Do NOT use for: Kubernetes resource manifests — see kubernetes-patterns. Do NOT use for: Pulumi or CDK — patterns differ significantly.
- ▌ Verify Before Done · yanacuti1121Use before claiming any task is complete, fixed, passing, or ready. Triggers on: 'done', 'fixed', 'tests pass', 'should work now', 'looks good', 'complete', 'finished', 'ready to merge', or any expression of satisfaction before showing evidence.
- ▌ Websocket Patterns · yanacuti1121Design and implement WebSocket connections — connection lifecycle, message protocol, authentication, reconnection strategy, backpressure, and horizontal scaling with a pub/sub broker. Use when asked to "add WebSocket", "real-time updates", "live feed", "Socket.IO", "ws library", "reconnect logic", "backpressure", "scale WebSocket", or "pub/sub over WebSocket". Do NOT use for: one-way server push with no client messages — use SSE instead. Do NOT use for: request/response APIs where HTTP polling is acceptable.
- ▌ 0x4m4 Hexstrike AI · yanacuti1121HexStrike AI — MCP server cho 150+ cybersecurity tools: Nmap, SQLMap, Nuclei, Ghidra, Prowler... AI agent tự chọn tool, chạy pentest, bug bounty automation. Cần authorization.
- ▌ Accessibility Audit · yanacuti1121Audit UI code for WCAG 2.1 AA compliance — color contrast, keyboard navigation, ARIA roles, focus management, and screen reader compatibility. Use when the user asks to "check accessibility", "make this accessible", "WCAG audit", "a11y review", or before marking any public-facing UI as done. Do NOT use for quick pre-delivery checks — use output-enforcement for that. This skill goes deeper: it covers ARIA semantics, focus order, and live regions.
- ▌ API Design Patterns · yanacuti1121REST API design — versioning, pagination, error responses, idempotency, rate limiting, OpenAPI spec
- ▌ App Store Preflight · yanacuti1121Use when asked to check an iOS/macOS app before App Store submission, scan for App Store rejection patterns, validate app metadata/privacy manifest/subscription compliance, or run pre-submission Apple Review guidelines checks. Triggers on: 'app store preflight', 'app store rejection check', 'ios submission check', 'apple review guidelines scan', 'preflight ios', 'kiểm tra trước khi nộp app store', 'scan lỗi app store', 'app store compliance', 'privacy manifest check', 'xcode preflight', 'truongduy2611 preflight'.
- ▌ Audit Env Variables · yanacuti1121Analyze environment variables in JavaScript/TypeScript projects. Identifies unused variables, infers permission scopes, detects specific services (Stripe, AWS, Supabase), and documents code paths. Includes optional cleanup of unused variables with regression detection. Use when auditing .env files, reviewing security, or documenting project configuration.
- ▌ Claude Code Harness · yanacuti1121Use when setting up a structured Plan→Work→Review→Release cycle for autonomous agents, integrating Claude Code with Codex/Cursor/OpenCode, enforcing spec-first development gates, or protecting against agent self-modification. Triggers on: 'claude-code-harness', 'harness cycle', 'agent release cycle', 'spec gate', 'plan work review release', 'harness-plan', 'harness-work', 'harness-review', 'harness-release', 'codex integration', 'cursor integration', 'opencode integration', 'multi-tool agent workflow', 'autonomous agent cycle', 'agent tự động release'.
- ▌ Continuous Learning · yanacuti1121Learning system v1 — học từ session patterns, tạo reusable skills/commands từ repeated workflows. Phiên bản cũ hơn continuous-learning-v2.
- ▌ Database Migrations · yanacuti1121Manage database schema migrations safely — Prisma Migrate, Flyway, zero-downtime migration strategies, expand-contract pattern, rollback procedures, migration testing, and production deploy sequence. Use when asked about "database migration", "Prisma migrate", "Flyway", "schema change", "add column", "rename column", "backfill data", "zero-downtime migration", "expand-contract", "migration rollback", "migrate in production", "NOT NULL column", "dropping a column safely", or "migration testing". Do NOT use for: query optimization — see database-patterns. Do NOT use for: seed data for dev — separate from migration concern.
- ▌ Distributed Tracing · yanacuti1121Instrument and debug distributed systems with tracing — OpenTelemetry setup, span creation, context propagation (W3C traceparent), sampling strategy, exporter configuration (Jaeger/Tempo/Honeycomb/Datadog), and correlating traces with logs. Use when asked to "add tracing", "OpenTelemetry", "OTel", "distributed trace", "trace propagation", "traceparent header", "find slow span", "Jaeger", "Tempo", "Honeycomb", "why is this request slow across services", or "trace ID in logs". Do NOT use for: metrics collection alone — see observability-instrumentation. Do NOT use for: single-service profiling — tracing spans cross-service boundaries.
- ▌ Github Copilot Sdk · yanacuti1121GitHub Copilot SDK — embed Copilot agent runtime vào app: Node/Python/Go/.NET/Java/Rust. JSON-RPC tới Copilot CLI. Custom agents + tools + model selection. MIT.
- ▌ API Security · yanacuti1121Apply the OWASP API Security Top 10 to REST and GraphQL endpoints. Covers broken object-level authorization (BOLA), mass assignment, excessive data exposure, unrestricted resource consumption, SSRF, broken function-level authorization, and GraphQL depth and complexity limits. Invoke when designing a new API, reviewing one before scaling, or after API abuse (scraping, account takeover).
- ▌ IOS Security · yanacuti1121Harden iOS and macOS apps against the platform-specific failure modes. Covers Keychain accessibility tiers, App Transport Security, certificate pinning tradeoffs, file protection classes, biometric authentication, jailbreak detection as a signal rather than a defense, and third-party SDK review. Invoke when shipping a native app that holds credentials, before App Store submission, or after a mobile security advisory.
- ▌ Log Strategy · yanacuti1121Design logging that supports investigations without becoming a privacy liability. Covers what to log and what never to log (PII, secrets), structured logging, retention tiers, centralization choices, alert routing, and the operational-versus-access-versus-audit log split. Invoke when starting a new service, when investigation revealed missing log fields, or when log volume is becoming expensive.
- ▌ MCP Security · yanacuti1121Audit Model Context Protocol server configurations and apply least-privilege scoping. Covers MCP inventory, capability risk-tiering, secret detection in configuration, malicious or compromised package indicators, and the lifecycle from install through rotation to revocation. Invoke before granting an MCP write access to production, after an MCP security advisory, or as periodic audit.
- ▌ Hook Block Commands · yanacuti1121Pattern guide for writing PreToolUse hooks that block dangerous shell commands. Use when: building or auditing a guard-destructive hook, adding new blocked patterns, reviewing what the current hook covers. Covers 3 safety levels (critical/high/strict) and 58+ regex patterns. Inspired by: karanb192/claude-code-hooks block-dangerous-commands pattern (MIT).
- ▌ Karpathy Guidelines · yanacuti1121Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.
- ▌ Kubernetes Patterns · yanacuti1121Design and debug Kubernetes workloads — Deployment/StatefulSet patterns, resource requests/limits, liveness/readiness/startup probes, HPA/KEDA autoscaling, ConfigMap/Secret injection, PodDisruptionBudget, rolling update strategy, and debugging CrashLoopBackOff. Use when asked about "Kubernetes deployment", "k8s", "pod crashing", "CrashLoopBackOff", "OOMKilled", "resource limits", "liveness probe", "readiness probe", "HPA", "horizontal pod autoscaler", "rolling update", "kubectl debug", "pod not starting", "namespace isolation", or "Kubernetes health check". Do NOT use for: Helm chart authoring — that's a separate concern. Do NOT use for: cluster provisioning — see terraform-patterns.
- ▌ To Spec · yanacuti1121Turn the current conversation into a spec and publish it to the project issue tracker — no interview, just synthesis of what you've already discussed.
- ▌ Multi Agent Handoff · yanacuti1121Safe context passing at the boundary between agents in a multi-agent pipeline — compress outgoing context, validate freshness of incoming context, detect bad-handoff signals (context bleed, hallucinated consensus, Agent Tennis). Use when an agent is about to pass work to another agent, receive results from a sub-agent, or when a multi-agent flow starts showing loop or drift symptoms. Do NOT use for session-level human handoffs — use the `handoff` skill for that. Do NOT use for dispatch planning — use `subagent-dependency` for DAG orchestration.
- ▌ Reconurge Flowsint · yanacuti1121OSINT graph investigation platform — visual, flexible, extensible. Dùng khi cần map relationships, investigate entities, trace connections giữa người/tổ chức/domains.
- ▌ Resilience Patterns · yanacuti1121Design resilient distributed services — circuit breaker, retry with backoff, timeout, bulkhead isolation, rate limiting, and fallback strategies. Use when asked about "circuit breaker", "retry logic", "timeouts", "cascading failures", "service keeps going down", "bulkhead", "rate limit", or "what happens when a dependency is slow/down". Do NOT use for: SLO target design — use `slo-design`.
- ▌ Revfactory Harness · yanacuti1121Claude Code plugin tự động thiết kế agent team + sinh skill từ domain description — 6 architecture patterns, tạo .claude/agents/ + .claude/skills/ tự động. +2098⭐/week.
- ▌ Serverless Patterns · yanacuti1121Build and optimize serverless functions — AWS Lambda cold starts, Cloudflare Workers edge patterns, function composition, idempotency, dead-letter queues, concurrency limits, observability, and IaC deployment with SAM/SST. Use when asked about "Lambda", "serverless function", "cold start", "Cloudflare Workers", "edge function", "AWS SAM", "SST framework", "function timeout", "Lambda concurrency", "DLQ", "dead-letter queue", "idempotent Lambda", "serverless observability", or "deploy serverless". Do NOT use for: long-running container workloads — see kubernetes-patterns or docker-patterns.
- ▌ Cicd Setup · yanacuti1121When the user needs to set up or improve CI/CD pipelines — GitHub Actions, GitLab CI, deployment automation, or says "set up CI", "automate deployment", "add tests to pipeline", "fix my build".
- ▌ Pitch Deck · yanacuti1121When the user wants to create, review, or restructure a fundraising pitch deck for seed or Series A. Also activates when the user mentions "deck", "pitch", "investor presentation", or "slide structure".
- ▌ Subagent Dependency · yanacuti1121Use when orchestrating multiple subagents with dependencies between them, running agents in parallel, or managing complex multi-agent workflows. Triggers on: 'orchestrate agents', 'chạy song song', 'parallel agents', 'agent dependency', 'subagent graph', 'multi-agent flow', 'agent pipeline', 'which agents can run in parallel', 'agent coordination'.
- ▌ Setup Ralph · yanacuti1121Set up and configure Geoffrey Huntley's original Ralph Wiggum autonomous coding loop in any directory with proper structure, prompts, and backpressure.
- ▌ Tinystruct Patterns · yanacuti1121Expert guidance for developing with the tinystruct Java framework. Use when working on the tinystruct codebase or any project built on tinystruct — including creating Application classes, @Action-mapped routes, unit tests, ActionRegistry, HTTP/CLI dual-mode handling, the built-in HTTP server, the event system, JSON with Builder/Builders, database persistence with AbstractData, POJO generation, Server-Sent Events (SSE), file uploads, and outbound HTTP networking.
- ▌ Typescript Patterns · yanacuti1121Write precise TypeScript — generic constraints, conditional types, mapped types, template literal types, branded/nominal types, type narrowing, satisfies operator, and utility type composition. Use when asked about "TypeScript generics", "conditional type", "mapped type", "infer keyword", "branded type", "nominal typing", "template literal type", "satisfies", "utility types", "type narrowing", "discriminated union", "type predicate", "TypeScript strict mode", "keyof typeof", or "TypeScript advanced patterns". Do NOT use for: React-specific TypeScript — see frontend-patterns. Do NOT use for: API type generation — see api-design.
- ▌ Venice Venice Auth · yanacuti1121Authenticate to the Venice API with a Bearer API key or with an x402 / SIWE wallet. Covers header formats, the SIWE message fields, TTL and nonce rules, the venice-x402-client SDK, and how to choose between the two modes.
- ▌ Venice Venice Chat · yanacuti1121Call POST /chat/completions on Venice. Covers the OpenAI-compatible request shape, Venice-only venice_parameters (web search, E2EE, characters, thinking control, X search), multimodal inputs (images/audio/video), tool calls, reasoning controls, streaming, prompt caching, structured output, and model
- ▌ Venice Venice X402 · yanacuti1121Manage Venice x402 wallet credits. Covers POST /x402/top-up (payment discovery + signed USDC settlement), GET /x402/balance/{walletAddress}, GET /x402/transactions/{walletAddress}, USDC on Base (chain 8453), minimum $5 top-up, transaction types TOP_UP/CHARGE/REFUND, and the x402 v2 PAYMENT-REQUIRED
- ▌ Zero Trust Patterns · yanacuti1121Apply zero-trust architecture to services — mTLS with SPIFFE/SPIRE, per-request authentication, short-lived credentials, least-privilege service accounts, network policy enforcement, and audit logging every access decision. Use when asked about "zero trust", "ZTA", "never trust always verify", "mTLS", "SPIFFE", "SPIRE", "service identity", "network policy", "per-request auth", "service mesh security", "lateral movement prevention", "east-west traffic", or "microservice auth". Do NOT use for: user-facing authentication — see auth-patterns. Do NOT use for: secret storage — see secret-management.
- ▌ AI First Engineering · yanacuti1121Engineering practices for teams where AI generates most code. Use when planning architecture for AI-assisted projects, defining code review standards for AI-generated code, structuring requirements for agent handoff, or asking "how do we work with AI at scale?", "our AI code keeps breaking", "agents keep misunderstanding requirements", "how to review AI output". Do NOT use for one-off AI prompting or pure manual codebases.
- ▌ Animation Principles · yanacuti1121Apply Disney's 12 animation principles to web and app interfaces — squash-and-stretch, anticipation, staging, follow-through, slow-in/slow-out, arcs, secondary action, timing, exaggeration, solid form, straight-ahead vs pose-to-pose, and appeal. Use when asked about "animation principles", "12 principles of animation", "Disney animation", "squash and stretch", "anticipation in UI", "follow through animation", "animation feels lifeless", "make animation feel natural", "physics-based animation", or "why does my animation feel robotic". Do NOT use for: animation performance fixes — see fixing-motion-performance. Do NOT use for: easing curves and duration — see motion-design.
- ▌ Design Tokens System · yanacuti1121Enterprise design token architecture. Defines spacing, scaling, elevation, and grid systems following Adobe Spectrum, Salesforce Lightning, Amazon Style Dictionary, and 6 other production token systems. Use when building or auditing a token layer for any UI project.
- ▌ Ecc Tools Cost Audit · yanacuti1121Audit cost overrun cho ECC Tools GitHub App — investigate runaway PR creation, quota bypass, premium-model leakage, duplicate jobs, billing spikes.
- ▌ Fixing Accessibility · yanacuti1121Fix accessibility issues hands-on — focus management, keyboard traps, missing ARIA labels, skip links, color contrast failures, interactive element sizing, and screen reader announcements. Use when asked to "fix accessibility issues", "keyboard navigation broken", "focus trap", "ARIA label missing", "screen reader not announcing", "skip to content", "tab order wrong", "focus ring missing", "color contrast fails", or "make this accessible". Do NOT use for: full WCAG audit from scratch — see accessibility-audit. Do NOT use for: motion/animation accessibility — see fixing-motion-performance.
- ▌ Formatjs React Intl · yanacuti1121i18n cho React apps — react-intl, FormatJS. Dùng khi implement đa ngôn ngữ, format số/ngày/tiền tệ chuẩn theo locale.
- ▌ Vps Hardening · yanacuti1121Baseline-harden a Debian or Ubuntu VPS in roughly thirty minutes. Covers SSH key-only authentication, UFW firewall, fail2ban with web-app jails, unattended security upgrades, kernel sysctls, journalctl retention, and sudo policy. Invoke when provisioning a new VPS, inheriting one without documented hardening, or before exposing a service to the public internet.
- ▌ Hook Protect Secrets · yanacuti1121Pattern guide for writing PreToolUse hooks that block secret file access, credential exfiltration, and environment variable dumps. Use when: auditing token-scope-guard.sh, adding new sensitive file patterns, reviewing what secret paths are protected. Covers 33 file patterns + 24 bash patterns + 15 exfiltration patterns. Inspired by: karanb192/claude-code-hooks protect-secrets pattern (MIT).
- ▌ Mempalace Mempalace · yanacuti1121Local-first AI memory system — 96.6% R@5 trên LongMemEval, verbatim storage (không lossy summary), MCP server 29 tools, ChromaDB/Qdrant/pgvector backends. Zero API calls.
- ▌ Microsoft Vibevoice · yanacuti1121Microsoft VibeVoice — open-source Voice AI: ASR 7B (60-min audio 1 pass, 50+ ngôn ngữ), TTS 1.5B (90-min, 4 speakers), Realtime 0.5B (300ms latency). HuggingFace.
- ▌ Microsoft Webwright · yanacuti1121Browser agent mã nguồn mở của Microsoft Research — agent viết Python/Playwright script thay vì click từng bước, script có thể reuse. SOTA 86.7% trên Online-Mind2Web.