{"_id":"@asaje/skills","_rev":"2-c529f2b0494ded73f61e300ad9b53524","name":"@asaje/skills","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@asaje/skills","version":"1.0.0","keywords":["ai","skills","agent","coding-agent","ai-agent","opencode","claude-code","cursor","codex","windsurf","copilot","prompt-engineering","developer-tools","swe","cursor-rules","claude-skills","agent-skills","best-practices","code-quality","security","octs"],"author":{"name":"OpenCTS"},"license":"MIT","_id":"@asaje/skills@1.0.0","maintainers":[{"name":"asaje379","email":"salemaffa@gmail.com"}],"homepage":"https://github.com/opencts/opencts-skills#readme","bugs":{"url":"https://github.com/opencts/opencts-skills/issues"},"bin":{"octs-skills":"bin/cli.js"},"dist":{"shasum":"189879b78016ee49799339e53fc15fbbd2dfe751","tarball":"https://registry.npmjs.org/@asaje/skills/-/skills-1.0.0.tgz","fileCount":35,"integrity":"sha512-btSRv3XpL9eHygJvBN4f9Mlh8IbiX8N0hLfWAQtPj9f4vADDICOwQ3pXbNzJ+HEZfYbRtLnLQY+f2f/WCPZl0A==","signatures":[{"sig":"MEUCIBUvor2XkKVDAapvhPBJiXs9P3yRtF9LhZX/CRuUacrwAiEA7Ty3QARhoYp+LqdqSmiC+H9VcuSZqVPnmP8LE9F4wLQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":458412},"type":"module","engines":{"node":">=18.0.0"},"gitHead":"07cf489eaacce3aa59480a72908f4837a4d7b826","scripts":{"test":"node --test lib/*.test.js"},"_npmUser":{"name":"asaje379","email":"salemaffa@gmail.com"},"repository":{"url":"git+https://github.com/opencts/opencts-skills.git","type":"git"},"_npmVersion":"11.16.0","description":"Production-grade AI coding agent skills library — 28 reusable, security-audited skills for OpenCode, Claude Code, Cursor, Codex CLI, Windsurf, and GitHub Copilot","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/skills_1.0.0_1785629276886_0.11716822022020534","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@asaje/skills","version":"1.0.1","description":"Production-grade AI coding agent skills library — 28 reusable, security-audited skills for OpenCode, Claude Code, Cursor, Codex CLI, Windsurf, and GitHub Copilot","keywords":["ai","skills","agent","coding-agent","ai-agent","opencode","claude-code","cursor","codex","windsurf","copilot","prompt-engineering","developer-tools","swe","cursor-rules","claude-skills","agent-skills","best-practices","code-quality","security","octs"],"license":"MIT","author":{"name":"OpenCTS"},"repository":{"type":"git","url":"git+https://github.com/asaje379/opencts-skills.git"},"bin":{"octs-skills":"bin/cli.js"},"engines":{"node":">=18.0.0"},"type":"module","scripts":{"test":"node --test lib/*.test.js"},"publishConfig":{"access":"public"},"gitHead":"542ec343755c64c5016b8a6efaea46d1e5ced364","_id":"@asaje/skills@1.0.1","bugs":{"url":"https://github.com/asaje379/opencts-skills/issues"},"homepage":"https://github.com/asaje379/opencts-skills#readme","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-SB1PHUgB+8f7e5UZrR0+wlYIxkhyMNcuc1n+yRHZpv0g0NrfgBMQhI9/2TxK7lVX8UyRVUx60iv9qzkwxe+xpA==","shasum":"413a79be624e70728364f4d1d14d4485ec245e7e","tarball":"https://registry.npmjs.org/@asaje/skills/-/skills-1.0.1.tgz","fileCount":35,"unpackedSize":458441,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDLCGBWOvi8pd9fXUHyxkArTI46XKfgo0Z/MwEiFRKF8AIgOmDaMK2k5Gfn9O/MwvujqVovVYjXy0QqRADECu5TRR0="}]},"_npmUser":{"name":"asaje379","email":"salemaffa@gmail.com"},"directories":{},"maintainers":[{"name":"asaje379","email":"salemaffa@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skills_1.0.1_1785630145312_0.625508090302616"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-02T00:07:56.762Z","modified":"2026-08-02T00:22:25.656Z","1.0.0":"2026-08-02T00:07:57.055Z","1.0.1":"2026-08-02T00:22:25.489Z"},"bugs":{"url":"https://github.com/asaje379/opencts-skills/issues"},"author":{"name":"OpenCTS"},"license":"MIT","homepage":"https://github.com/asaje379/opencts-skills#readme","keywords":["ai","skills","agent","coding-agent","ai-agent","opencode","claude-code","cursor","codex","windsurf","copilot","prompt-engineering","developer-tools","swe","cursor-rules","claude-skills","agent-skills","best-practices","code-quality","security","octs"],"repository":{"type":"git","url":"git+https://github.com/asaje379/opencts-skills.git"},"description":"Production-grade AI coding agent skills library — 28 reusable, security-audited skills for OpenCode, Claude Code, Cursor, Codex CLI, Windsurf, and GitHub Copilot","maintainers":[{"name":"asaje379","email":"salemaffa@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\"https://img.shields.io/npm/v/@asaje/skills?color=blue\" alt=\"npm version\">\n  <img src=\"https://img.shields.io/github/license/asaje379/opencts-skills\" alt=\"license\">\n  <img src=\"https://img.shields.io/npm/dt/@asaje/skills\" alt=\"downloads\">\n  <img src=\"https://img.shields.io/badge/skills-28-blueviolet\" alt=\"28 skills\">\n</p>\n\n# @asaje/skills\n\nProduction-grade AI coding agent skills library — **28 reusable, security-audited skills** for OpenCode, Claude Code, Cursor, Codex CLI, Windsurf, and GitHub Copilot.\n\nTransform any AI coding agent into a disciplined, senior-level software engineer that understands your project, follows best practices, and never ships unchecked code.\n\n---\n\n## Why @asaje/skills?\n\nAI coding agents are powerful but undisciplined. They generate code without understanding your codebase, skip tests, ignore conventions, and declare work \"done\" without real verification.\n\n`@asaje/skills` fixes this. Every skill enforces two non-negotiable rules:\n\n1. **Project Context First** — Before generating code, analyze the existing architecture, conventions, components, and dependencies.\n2. **Verify Before Declaring Done** — Never say \"done\" without verifying compile/lint/tests/types/coherence.\n\nThe result: your AI agent behaves like a senior developer who has worked on the project for months.\n\n---\n\n## Quick Start\n\n### Zero-install (recommended)\n\n```bash\nnpx @asaje/skills init\n```\n\nThis auto-detects your AI coding agent, installs all 28 skills in the right directory, and sets up project memory.\n\n### Global install\n\n```bash\nnpm install -g @asaje/skills\nocts-skills init\n```\n\n### With options\n\n```bash\n# Target a specific agent\nnpx @asaje/skills init --agent claude-code\n\n# Install only specific categories\nnpx @asaje/skills init --categories frontend,backend,architecture\n\n# Install in a different directory\nnpx @asaje/skills init /path/to/project --agent cursor\n\n# Skip project memory\nnpx @asaje/skills init --no-memory\n\n# Only initialize project memory\nnpx @asaje/skills init --memory-only\n```\n\n---\n\n## Supported Agents\n\n| Agent | Skills Directory | CLI flag |\n|---|---|---|\n| OpenCode | `.opencode/skills/` | `--agent opencode` |\n| Claude Code | `.claude/skills/` | `--agent claude-code` |\n| Cursor | `.cursor/rules/` | `--agent cursor` |\n| Codex CLI | `.codex/skills/` | `--agent codex` |\n| Windsurf | `.windsurf/rules/` | `--agent windsurf` |\n| GitHub Copilot | `.github/copilot/skills/` | `--agent copilot` |\n\nAuto-detection works by checking for existing agent configuration directories. Falls back to OpenCode if none is detected.\n\n---\n\n## Skills Catalog\n\n### Skill Architecture\n\n```\n@octs/project-awareness        ← Root skill. All 27 others depend on it.\n    ├── @octs/isolated-test-environment\n    ├── @octs/frontend-verification       (11-phase quality gate)\n    ├── @octs/backend-verification        (10-phase quality gate)\n    ├── 5 frontend skills\n    ├── 5 backend skills\n    ├── 4 testing skills\n    ├── 5 architecture skills\n    └── 5 reasoning skills\n```\n\n### Infrastructure (2)\n\n| Skill | Purpose |\n|---|---|\n| `@octs/project-awareness` | Auto-detect stack, architecture, conventions, existing components. Generate and maintain project memory (`docs/` + `.project-ai/`). All other skills depend on this. |\n| `@octs/isolated-test-environment` | Create disposable, isolated test sandboxes with Docker. Lifecycle: create → init → seed → validate → collect → destroy. Ensures reproducibility. |\n\n### Verification Gates (2)\n\n| Skill | Purpose |\n|---|---|\n| `@octs/frontend-verification` | 11-phase frontend validation: code review, build/lint/tests, Playwright browser testing, visual/accessibility/responsive checks, state coverage, console audit, performance, SEO, backoffice. Mandatory report before declaring done. |\n| `@octs/backend-verification` | 10-phase backend validation: architecture review, API contract check, OWASP security audit, database analysis, resilience patterns, tests, observability, performance, documentation. Mandatory report. |\n\n### Frontend (5)\n\n| Skill | Purpose |\n|---|---|\n| `@octs/landing-page` | Premium landing pages: Hero, Features, CTA, Pricing, FAQ, Testimonials, Bento Grid, animations, SEO, Core Web Vitals. |\n| `@octs/admin-dashboard` | Admin interfaces: TanStack Table, filters, pagination, exports (CSV/Excel/PDF), KPI dashboards, Command Palette, keyboard shortcuts. |\n| `@octs/react-best-practices` | React quality: composition over inheritance, proper hook usage, performance (memo/lazy/Suspense), feature-based architecture, TypeScript patterns. |\n| `@octs/tailwind-design-system` | Design systems: design tokens, CVA variants, dark mode, responsive breakpoints, accessibility, class ordering conventions. |\n| `@octs/async-state` | TanStack Query: useQuery/useMutation, cache strategy, optimistic updates, infinite queries, prefetching, server vs client state separation. |\n\n### Backend (5)\n\n| Skill | Purpose |\n|---|---|\n| `@octs/rest-api` | REST APIs: resource-oriented design, correct HTTP methods/status codes, OpenAPI 3.x, DTOs, validation, pagination (cursor/offset), Problem Details RFC 9457, idempotence. |\n| `@octs/graphql` | GraphQL: schema-first design, Apollo/Yoga, DataLoader for N+1, persisted queries, complexity/depth limits, subscriptions, Relay pagination. |\n| `@octs/backend-security` | Security: OWASP Top 10, JWT/OAuth2/OIDC, RBAC/ABAC, Helmet/CSP/CORS, rate limiting, CSRF/XSS/injection prevention, secrets management. |\n| `@octs/observability` | Observability: structured JSON logging, OpenTelemetry tracing, RED/USE metrics, correlation IDs, health/readiness/liveness checks. |\n| `@octs/caching` | Caching: Redis patterns (Cache Aside, Read/Write-Through), HTTP caching (ETag, Cache-Control), invalidation strategies, cache warming, stampede/avalanche prevention. |\n\n### Tests (4)\n\n| Skill | Purpose |\n|---|---|\n| `@octs/unit-testing` | Unit tests: AAA pattern, Vitest/Jest, mocking strategy, edge cases, property-based testing with fast-check, snapshot discipline, coverage targets. |\n| `@octs/integration-testing` | Integration: Supertest, Testcontainers, Docker, factories/fixtures, API + database + cache testing, transaction-based isolation. |\n| `@octs/e2e` | End-to-end: Playwright (Chromium/Firefox/WebKit), mobile emulation, visual regression, offline/upload scenarios, CI artifacts (screenshot/video/trace). |\n| `@octs/coverage` | Coverage: targets (branches ≥80%, functions ≥90%, lines ≥85%), 100% on auth/security/business-logic/payments, mutation testing, CI thresholds. |\n\n### Architecture (5)\n\n| Skill | Purpose |\n|---|---|\n| `@octs/clean-architecture` | SOLID principles, Clean Architecture layers (Entities/UseCases/Adapters/Frameworks), Hexagonal (Ports & Adapters), dependency injection. |\n| `@octs/ddd` | Domain-Driven Design: bounded contexts, entities/value objects/aggregates, repositories, domain services/events, ubiquitous language, strategic design. |\n| `@octs/event-driven` | Event-driven: RabbitMQ/Kafka, Outbox pattern, Saga (orchestration/choreography), Event Sourcing, CQRS, DLQ, schema evolution with Avro. |\n| `@octs/resilience` | Resilience: retry with exponential backoff + jitter, circuit breaker (Closed/Open/Half-Open), graceful shutdown, idempotence, bulkhead, fallbacks. |\n| `@octs/database` | Databases: migrations, indexes (B-tree/GiST/GIN/composite/partial), audit trail, soft delete, multi-tenancy, SQL optimization, transactions, optimistic/pessimistic locking. |\n\n### Reasoning (5)\n\n| Skill | Purpose |\n|---|---|\n| `@octs/feature-planner` | Plan before coding: analyze need, identify constraints, propose multiple approaches, compare tradeoffs, decompose into atomic tasks. **Never start coding without a validated plan.** |\n| `@octs/bug-investigator` | Scientific debugging: reproduce → collect logs → propose hypotheses → eliminate → identify root cause → fix → add regression test → verify. |\n| `@octs/architecture-review` | Architecture audit: coherence, technical debt, duplication, performance, security, scalability, maintainability. Structured report with severity-ranked findings. |\n| `@octs/code-review` | Code review: readability, architecture, SOLID, security, performance, duplication, naming, complexity. Constructive, never personal. Blocking vs suggestion classification. |\n| `@octs/refactoring` | Safe refactoring: SOLID/DRY/KISS/YAGNI/AHA principles, incremental steps with test verification at each step. **Never change external behavior during refactoring.** |\n\n---\n\n## Project Memory\n\n`octs-skills init` automatically creates a project memory structure that agents use to understand your project:\n\n```\ndocs/\n├── index.md          ← Project at a glance (stack, architecture, key rules, <300 lines)\n├── conventions.md    ← Coding standards (TypeScript, React, API, Git, naming, tests)\n├── architecture.md   ← Module responsibilities, dependencies, data flows, diagrams\n├── decisions.md      ← Architecture Decision Records (date, context, options, rationale)\n└── glossary.md       ← Domain-specific terminology (ubiquitous language)\n\n.project-ai/\n├── project.json      ← Machine-readable manifest (frameworks, versions, tools, CI/CD)\n├── inventory.json    ← Auto-inventory (components, hooks, services, routes, schemas)\n└── skills.lock.json  ← Installed skills registry (name, version, hash, validated)\n```\n\n---\n\n## CLI Reference\n\n```\nocts-skills <command> [options]\n\nCommands:\n  init [dir]       Initialize skills in a project directory (default: cwd)\n  list             List all available skills by category\n  info             Show library information and version\n\nOptions for init:\n  --agent, -a      Target agent (opencode, claude-code, cursor, codex, windsurf, copilot)\n  --categories, -c Comma-separated categories to install\n  --no-memory      Skip project memory initialization\n  --memory-only    Only initialize project memory, skip skills\n  --help, -h       Show help\n```\n\n### Examples\n\n```bash\n# Full setup for OpenCode\nocts-skills init\n\n# Claude Code with only backend + security skills\nocts-skills init --agent claude-code --categories backend,tests\n\n# Cursor project, only project memory (no skills)\nocts-skills init /path/to/project --agent cursor --memory-only\n```\n\n---\n\n## Security\n\nEvery skill in this library has been audited using the research pipeline in `prompts/master-prompt.md`:\n\n1. **Research** public skills (official sources prioritized)\n2. **Download** and analyze structure\n3. **Audit** for: prompt injection, hidden instructions, jailbreak attempts, data exfiltration, suspicious external references, system prompt overrides\n4. **Remove** any dangerous content\n5. **Merge** with OpenCTS requirements and guardrails\n6. **Generate** finalized, secured skill\n\nOnly legitimate technical instructions are retained. No skill attempts to override system prompts, exfiltrate data, or redirect agent behavior.\n\n---\n\n## Contributing\n\nSkills are generated following the pipeline in `prompts/master-prompt.md`. To contribute a new skill:\n\n1. Follow the 6-step research pipeline (official sources → audit → merge → generate)\n2. Place the skill in the appropriate `skills/<category>/` directory\n3. Use the `@octs/` name prefix\n4. Include YAML frontmatter with `name`, `description`, `depends_on`, and `tools`\n5. All skills must depend on `@octs/project-awareness` (except `project-awareness` itself)\n6. Include both universal guardrails in every skill\n7. Run `octs-skills list` to verify the skill is discoverable\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) for the full authoring guide.\n\n---\n\n## Publishing to npm\n\n```bash\n# Manual publish\nnpm publish\n\n# Automated: push a version tag\ngit tag v1.0.0\ngit push origin v1.0.0\n# GitHub Actions publishes to npm automatically\n```\n\nRequires `NPM_TOKEN` secret set in GitHub repository settings.\n\n---\n\n## License\n\nMIT © OpenCTS — See [LICENSE](LICENSE) for details.\n","readmeFilename":"README.md"}