# Claude Code skills for testing, security and devops

Claude Code skills to generate tests, audit security, debug errors, automate CI/CD, manage git and review code across any tech stack.

These Claude Code skills cover everyday development and adapt to the language and framework of your project. On quality, [generate tests](https://skills.sgomez.dev/en/s/testing--test-gen.md) writes tests for your code, [review code](https://skills.sgomez.dev/en/s/code-quality--review.md) analyzes a change for problems, and [refactor code](https://skills.sgomez.dev/en/s/code-quality--refactor.md) simplifies it without changing its behavior.

On security, [audit a project's security](https://skills.sgomez.dev/en/s/security--security-audit.md) checks for common vulnerabilities and [scan for exposed secrets](https://skills.sgomez.dev/en/s/security--secrets-scan.md) finds keys and passwords in the repository. When something breaks, [decode a stack trace](https://skills.sgomez.dev/en/s/debugging--stack-trace.md) explains the error and [debug a production failure](https://skills.sgomez.dev/en/s/debugging--production-debug.md) guides the investigation from what you observe.

For the workflow, [write commit messages](https://skills.sgomez.dev/en/s/git--commit.md) summarizes your changes, [review a pull request](https://skills.sgomez.dev/en/s/git--pr-review.md) comments on it, and [create a GitHub Actions workflow](https://skills.sgomez.dev/en/s/devops--github-actions.md) automates tests and deploys. On infrastructure, [write a Dockerfile](https://skills.sgomez.dev/en/s/devops--dockerfile.md) packages the app and [audit cloud costs](https://skills.sgomez.dev/en/s/cloud--cloud-cost-audit.md) looks for where the spend goes. Each one starts from a plain-language request in Claude Code, so you describe the change or the problem and review the result, whatever your stack.

Web version: https://skills.sgomez.dev/en/code
Updated 29 Sept 2026

## Skills (190)

- [Browser automation with agent-browser (/agent-browser)](https://skills.sgomez.dev/en/s/agent-browser.md): Drives Chrome or Chromium through the agent-browser CLI to open pages, fill forms, click buttons, take screenshots and extract data.
- [Complete API endpoint (/api--endpoint)](https://skills.sgomez.dev/en/s/api--endpoint.md): Generates an API endpoint with validation, authentication, types and tests, following your project's framework and conventions.
- [GraphQL schema with resolvers (/api--graphql-schema)](https://skills.sgomez.dev/en/s/api--graphql-schema.md): Generates a GraphQL schema with types, queries, mutations, cursor pagination and resolvers for the domain you describe.
- [Messaging bot connected to Claude (/api--messaging-bridge)](https://skills.sgomez.dev/en/s/api--messaging-bridge.md): Builds a Node.js/TypeScript server linking Telegram, WhatsApp, Instagram and Messenger to the Claude API, with one session per user.
- [Mock API server (/api--mock-api)](https://skills.sgomez.dev/en/s/api--mock-api.md): Creates a mock API server with realistic data, error responses and latency, so you can build or test a frontend without the real backend.
- [Type-safe API client (/api--rest-client)](https://skills.sgomez.dev/en/s/api--rest-client.md): Generates a typed client SDK for your API from its OpenAPI spec or route files, with error handling, retries and timeouts.
- [Browser task automation (/automation--browser-automation)](https://skills.sgomez.dev/en/s/automation--browser-automation.md): Builds a Playwright script that logs in, fills forms or downloads files on sites you legitimately have access to.
- [Email automation (/automation--email-automation)](https://skills.sgomez.dev/en/s/automation--email-automation.md): Builds email automations: parse inbound mail, send templated messages and run sequences with unsubscribe handling and GDPR/CAN-SPAM safeguards.
- [PDF processing workflows (/automation--pdf-processing)](https://skills.sgomez.dev/en/s/automation--pdf-processing.md): Builds a workflow to extract text and tables from PDFs, fill forms, merge or split pages, and run OCR on scanned documents.
- [Automated recurring reports (/automation--report-automation)](https://skills.sgomez.dev/en/s/automation--report-automation.md): Turns a hand-made report into a scheduled pipeline that pulls the data, fills a template and delivers it by email or Slack.
- [Reliable scheduled tasks (/automation--scheduled-tasks)](https://skills.sgomez.dev/en/s/automation--scheduled-tasks.md): Designs scheduled jobs that run on time: picks cron or a queue, and adds retries, locking, monitoring and timezone handling.
- [Site crawl with scrape-it-now (/automation--scrape-it-now)](https://skills.sgomez.dev/en/s/automation--scrape-it-now.md): Sets up and runs a site-wide crawl with scrape-it-now to get clean markdown, locally or on Azure, with optional indexing.
- [LLM-powered scraper (scrapegraph-ai) (/automation--scrapegraph-scraper)](https://skills.sgomez.dev/en/s/automation--scrapegraph-scraper.md): Builds a scraper on scrapegraph-ai where an LLM extracts data into Pydantic schemas, after checking whether the token cost is worth it.
- [Spreadsheet automation (/automation--spreadsheet-automation)](https://skills.sgomez.dev/en/s/automation--spreadsheet-automation.md): Automates a spreadsheet with formulas, Google Apps Script or Python (openpyxl/pandas) for reliable imports, validation and calculations.
- [Polite web scraper (/automation--web-scraper)](https://skills.sgomez.dev/en/s/automation--web-scraper.md): Builds a scraper that checks robots.txt and terms of service, throttles requests, handles pagination and saves results so runs can resume.
- [n8n, Zapier and Make workflows (/automation--workflow-automation)](https://skills.sgomez.dev/en/s/automation--workflow-automation.md): Designs an n8n, Zapier or Make workflow with trigger, steps and error handling, delivered as an n8n JSON export or a build sheet.
- [Automate your Chrome by screenshots (/chrome-bridge-automation)](https://skills.sgomez.dev/en/s/chrome-bridge-automation.md): Controls your own Chrome, with its logins and cookies, through Midscene Bridge, acting from screenshots rather than the DOM.
- [Autoscaling strategy (/cloud--autoscaling-strategy)](https://skills.sgomez.dev/en/s/cloud--autoscaling-strategy.md): Designs a service's autoscaling: scaling metric, bounds, cooldowns and cold-start handling, validated with a load test.
- [AWS architecture design (/cloud--aws-architect)](https://skills.sgomez.dev/en/s/cloud--aws-architect.md): Designs an AWS architecture for your app with a minimal set of services, a Mermaid diagram and a Terraform starter.
- [Azure architecture design (/cloud--azure-architect)](https://skills.sgomez.dev/en/s/cloud--azure-architect.md): Designs an Azure architecture for your app with a minimal set of services, a Mermaid diagram and a Terraform or Bicep starter.
- [Cloud cost audit (/cloud--cloud-cost-audit)](https://skills.sgomez.dev/en/s/cloud--cloud-cost-audit.md): Analyses billing exports and infrastructure code to find wasted spend and returns a prioritised savings plan with estimated monthly savings.
- [Cloud migration plan (/cloud--cloud-migration)](https://skills.sgomez.dev/en/s/cloud--cloud-migration.md): Creates a phased migration plan with an inventory, a 6 Rs strategy per component, cutover and rollback steps, and estimated costs.
- [Disaster recovery plan (/cloud--disaster-recovery)](https://skills.sgomez.dev/en/s/cloud--disaster-recovery.md): Builds a disaster recovery plan: RTO and RPO targets, backup strategy, a failover runbook and a schedule for testing it.
- [Google Cloud architecture design (/cloud--gcp-architect)](https://skills.sgomez.dev/en/s/cloud--gcp-architect.md): Designs a Google Cloud architecture for your app with a minimal set of services, a Mermaid diagram and a Terraform starter.
- [Least-privilege IAM review (/cloud--iam-least-privilege)](https://skills.sgomez.dev/en/s/cloud--iam-least-privilege.md): Audits IAM policies and writes least-privilege replacements as reviewable code changes, without applying anything itself.
- [Infrastructure diagram (/cloud--infra-diagram)](https://skills.sgomez.dev/en/s/cloud--infra-diagram.md): Generates a Mermaid diagram of your infrastructure from Terraform, Kubernetes, docker-compose and other config files.
- [Serverless API (/cloud--serverless-api)](https://skills.sgomez.dev/en/s/cloud--serverless-api.md): Builds or converts an app into a serverless HTTP API, with functions, routing, infrastructure code and a local dev loop, without deploying it.
- [Code smell detection (/code-quality--code-smells)](https://skills.sgomez.dev/en/s/code-quality--code-smells.md): Scans code for smells and anti-patterns, reporting each one's location, severity and a concrete refactoring suggestion.
- [Code complexity analysis (/code-quality--complexity)](https://skills.sgomez.dev/en/s/code-quality--complexity.md): Measures cyclomatic and cognitive complexity per function, flags those over the thresholds and suggests how to simplify them.
- [Dead code cleanup (/code-quality--dead-code)](https://skills.sgomez.dev/en/s/code-quality--dead-code.md): Finds unused imports, variables, functions, files and dependencies, verifies each finding and only removes code after you confirm.
- [Dependency audit (/code-quality--dependency-audit)](https://skills.sgomez.dev/en/s/code-quality--dependency-audit.md): Audits your project's dependencies (npm, pip, Go, Cargo) for known vulnerabilities, unmaintained packages and lighter alternatives, then ranks the actions.
- [Duplicate code finder (/code-quality--dry)](https://skills.sgomez.dev/en/s/code-quality--dry.md): Scans your codebase for duplicated code, shows every location, and suggests a shared abstraction with refactored code, ranked by occurrences and risk.
- [Error handling review (/code-quality--error-handling)](https://skills.sgomez.dev/en/s/code-quality--error-handling.md): Audits how your code handles errors, finding swallowed errors, generic catches and poor messages, and suggests concrete improvements.
- [Code naming review (/code-quality--naming)](https://skills.sgomez.dev/en/s/code-quality--naming.md): Reviews variable, function and class names in your code and returns a table of current name, suggested name and the reason for each change.
- [Safe code refactoring (/code-quality--refactor)](https://skills.sgomez.dev/en/s/code-quality--refactor.md): Refactors the code you point to for quality without changing its behavior, explaining each change with a before and after.
- [Full code review (/code-quality--review)](https://skills.sgomez.dev/en/s/code-quality--review.md): Reviews your changed files or the ones you name, rating issues in correctness, security, performance and maintainability by severity with fix suggestions.
- [TypeScript and Python type hints (/code-quality--type-check)](https://skills.sgomez.dev/en/s/code-quality--type-check.md): Adds or fixes type annotations in TypeScript/JavaScript and Python code without changing how it behaves at runtime.
- [Async bug debugging (/debugging--async-debug)](https://skills.sgomez.dev/en/s/debugging--async-debug.md): Analyzes async/await, promise and concurrency code to find swallowed errors, ordering issues and deadlocks, and proposes the fix.
- [Breakpoint plan (/debugging--breakpoint-guide)](https://skills.sgomez.dev/en/s/debugging--breakpoint-guide.md): Builds a three-tier breakpoint plan with file, line, condition and what to check, so you can locate a specific bug quickly.
- [Chaos testing for your code (/debugging--chaos-debug)](https://skills.sgomez.dev/en/s/debugging--chaos-debug.md): Stress-tests code with extreme inputs and simulated failures, writes tests per scenario, and rates the bugs it finds by severity.
- [Strategic debug logging (/debugging--console-debug)](https://skills.sgomez.dev/en/s/debugging--console-debug.md): Adds debug logs at key points of your code to trace a bug, each tagged so it can be removed in one pass once the bug is found.
- [Crash dump analysis (/debugging--core-dump)](https://skills.sgomez.dev/en/s/debugging--core-dump.md): Analyzes core dumps, segfaults and panics (Go, Rust, JVM, Python) to identify the root cause of a fatal process crash.
- [Microservice failure tracing (/debugging--distributed-trace)](https://skills.sgomez.dev/en/s/debugging--distributed-trace.md): Traces a failing request across microservices using correlation IDs to find the service, timeout or retry behind the failure.
- [Error code explainer (/debugging--error-decode)](https://skills.sgomez.dev/en/s/debugging--error-decode.md): Turns a cryptic error code or message into plain English with likely causes, checks to run, fix steps and how to prevent it.
- [Memory leak hunting (/debugging--memory-leak)](https://skills.sgomez.dev/en/s/debugging--memory-leak.md): Analyzes your code for memory leak patterns by language (JavaScript, Python, Go and more) and suggests how to fix them.
- [Network issue debugging (/debugging--network-debug)](https://skills.sgomez.dev/en/s/debugging--network-debug.md): Diagnoses connection, TLS, HTTP, WebSocket and gRPC failures by reading your network code and explaining the likely cause and fix.
- [Flamegraph profiling (/debugging--perf-flamegraph)](https://skills.sgomez.dev/en/s/debugging--perf-flamegraph.md): Characterizes a performance bottleneck, inspects the code and generates the profiling commands for your language to build and read flamegraphs.
- [Production-only bug debugging (/debugging--production-debug)](https://skills.sgomez.dev/en/s/debugging--production-debug.md): Investigates bugs that only appear in production using logs, metrics and environment differences, without touching the live system.
- [Race condition fixing (/debugging--race-condition)](https://skills.sgomez.dev/en/s/debugging--race-condition.md): Detects race conditions, data races and TOCTOU bugs in your concurrent code and proposes how to fix them.
- [Stack trace analysis (/debugging--stack-trace)](https://skills.sgomez.dev/en/s/debugging--stack-trace.md): Analyzes a stack trace or error message, pinpoints the root cause, and explains what happened, why and how to fix it with a code snippet.
- [Application state debugging (/debugging--state-debug)](https://skills.sgomez.dev/en/s/debugging--state-debug.md): Debugs state bugs from UI state (React, Vue, Redux) to caches, sessions and databases, and proposes the fix.
- [Variable lifecycle tracing (/debugging--variable-inspect)](https://skills.sgomez.dev/en/s/debugging--variable-inspect.md): Follows a variable through your codebase from declaration to every read and write to find where its value goes wrong.
- [Ansible playbooks (/devops--ansible)](https://skills.sgomez.dev/en/s/devops--ansible.md): Creates or refactors Ansible automation with roles, per-environment inventories, idempotent tasks and secrets encrypted with Ansible Vault.
- [CI/CD pipeline setup (/devops--ci)](https://skills.sgomez.dev/en/s/devops--ci.md): Generates the continuous integration and deployment config for your project on GitHub Actions, GitLab CI, CircleCI or Jenkins.
- [Pre-deployment checklist (/devops--deploy-check)](https://skills.sgomez.dev/en/s/devops--deploy-check.md): Runs a checklist before you ship, covering code quality, security, database and configuration, to catch problems before release.
- [docker-compose file (/devops--docker-compose)](https://skills.sgomez.dev/en/s/devops--docker-compose.md): Generates a docker-compose.yml for local development or production with the services your project needs, health checks and volumes.
- [Production-ready Dockerfile (/devops--dockerfile)](https://skills.sgomez.dev/en/s/devops--dockerfile.md): Generates or optimizes a multi-stage Dockerfile for your project, with a minimal image, layer caching and a non-root user.
- [GitHub Actions workflows (/devops--github-actions)](https://skills.sgomez.dev/en/s/devops--github-actions.md): Generates GitHub Actions workflows for CI, CD, auto-labeling and other automation in your repository.
- [GitOps with ArgoCD or Flux (/devops--gitops)](https://skills.sgomez.dev/en/s/devops--gitops.md): Sets up GitOps for Kubernetes: picks between ArgoCD and Flux, lays out the config repo and defines sync policies and git revert rollbacks.
- [Helm chart for Kubernetes (/devops--helm-chart)](https://skills.sgomez.dev/en/s/devops--helm-chart.md): Creates or improves a Helm chart with clean templates, a values contract, dependencies and a versioning strategy, checked with helm lint.
- [Kubernetes manifests for your app (/devops--k8s)](https://skills.sgomez.dev/en/s/devops--k8s.md): Generates Kubernetes manifests for your app: Deployment, Service, Ingress, autoscaling and config, as separate YAML files or a Kustomize layout.
- [Nginx configuration (/devops--nginx)](https://skills.sgomez.dev/en/s/devops--nginx.md): Builds an optimized nginx.conf for your project as reverse proxy, SPA host, load balancer or API gateway, with HTTPS, security headers and dev and prod configs.
- [Secrets management (/devops--secrets-management)](https://skills.sgomez.dev/en/s/devops--secrets-management.md): Finds hardcoded secrets in code and git history, migrates them to a secret manager and sets up a rotation and access plan.
- [Infrastructure with Terraform (/devops--terraform)](https://skills.sgomez.dev/en/s/devops--terraform.md): Generates Terraform configurations for AWS, GCP or Azure: resources, variables, outputs, remote state backend and an example tfvars file.
- [Architecture decision record (/docs--adr)](https://skills.sgomez.dev/en/s/docs--adr.md): Writes an Architecture Decision Record with context, decision, consequences and alternatives, and saves it under docs/adr.
- [API changelog (/docs--api-changelog)](https://skills.sgomez.dev/en/s/docs--api-changelog.md): Compares two versions of your API, classifies changes as breaking, non-breaking or deprecations, and writes migration notes.
- [API documentation (/docs--api-doc)](https://skills.sgomez.dev/en/s/docs--api-doc.md): Scans your routes and controllers and documents each endpoint with parameters, responses and examples, as Markdown or OpenAPI.
- [CONTRIBUTING.md guide (/docs--contributing)](https://skills.sgomez.dev/en/s/docs--contributing.md): Generates a CONTRIBUTING.md tailored to your project: dev setup, code standards detected from your tooling, and the pull request process.
- [Architecture diagrams (/docs--diagram)](https://skills.sgomez.dev/en/s/docs--diagram.md): Reads your code and draws Mermaid diagrams (flowchart, sequence, class, ER, state or C4) with a plain-text explanation.
- [Code documentation (/docs--doc-gen)](https://skills.sgomez.dev/en/s/docs--doc-gen.md): Documents a file, module or API with overview, usage examples, function reference and configuration, in your project doc format.
- [Developer onboarding guide (/docs--onboarding-guide)](https://skills.sgomez.dev/en/s/docs--onboarding-guide.md): Builds an onboarding guide from your actual repo: prerequisites, environment variables, commands and how to get to a first pull request.
- [OpenAPI specification (/docs--openapi-gen)](https://skills.sgomez.dev/en/s/docs--openapi-gen.md): Scans your code endpoints and generates or updates an OpenAPI 3.0 YAML spec with schemas, security schemes and examples.
- [Professional README (/docs--readme-gen)](https://skills.sgomez.dev/en/s/docs--readme-gen.md): Analyzes your project and writes a complete README.md: description, quick start, installation, usage, configuration and development.
- [Admin panel (/fullstack--admin-panel)](https://skills.sgomez.dev/en/s/fullstack--admin-panel.md): Builds an internal admin panel with CRUD for your models, user impersonation for support, an audit log and server-side role gates.
- [Full authentication flow (/fullstack--auth-flow)](https://skills.sgomez.dev/en/s/fullstack--auth-flow.md): Implements email and OAuth login, sessions or JWT, role-based access and password reset, extending any auth your app already has.
- [Background jobs (/fullstack--background-jobs)](https://skills.sgomez.dev/en/s/fullstack--background-jobs.md): Sets up a job queue suited to your stack: workers, retries, scheduled jobs and a way to monitor failures.
- [Feature flags setup (/fullstack--feature-flags)](https://skills.sgomez.dev/en/s/fullstack--feature-flags.md): Adds feature flags to your app: hosted provider or homegrown choice, targeting, kill switches and a cleanup process for old flags.
- [File uploads (/fullstack--file-upload)](https://skills.sgomez.dev/en/s/fullstack--file-upload.md): Implements direct uploads to S3 or R2 with presigned URLs, server-side validation, progress tracking and thumbnails.
- [SaaS multi-tenancy setup (/fullstack--multi-tenancy)](https://skills.sgomez.dev/en/s/fullstack--multi-tenancy.md): Converts your app to multi-tenant: picks the isolation model, enforces tenant scoping and produces migrations and a backfill plan.
- [Notification system (/fullstack--notification-system)](https://skills.sgomez.dev/en/s/fullstack--notification-system.md): Builds in-app, email and optional push notifications filtered by user preferences, with digests to avoid flooding people.
- [User onboarding flow (/fullstack--onboarding-flow)](https://skills.sgomez.dev/en/s/fullstack--onboarding-flow.md): Builds the path from signup to activation: a first-run wizard, checklist, empty states and metrics to see where users drop off.
- [Payments integration (/fullstack--payments-integration)](https://skills.sgomez.dev/en/s/fullstack--payments-integration.md): Integrates payments with Stripe or your existing provider: checkout, subscriptions, signed webhooks and a customer billing portal.
- [Realtime features (/fullstack--realtime-feature)](https://skills.sgomez.dev/en/s/fullstack--realtime-feature.md): Adds realtime to your app: picks WebSocket, SSE or a managed provider, with presence, optimistic UI and reconnection handling.
- [SaaS starter (/fullstack--saas-starter)](https://skills.sgomez.dev/en/s/fullstack--saas-starter.md): Scaffolds a SaaS foundation in your stack: authentication, organizations with invites, billing stubs, settings and transactional email.
- [Search feature (/fullstack--search-feature)](https://skills.sgomez.dev/en/s/fullstack--search-feature.md): Adds search to your app: picks an engine (Postgres, Meilisearch or Elastic), sets up indexing and ranking, and builds a search-as-you-type UI.
- [Code change history (/git--blame-detective)](https://skills.sgomez.dev/en/s/git--blame-detective.md): Investigates with git blame and log who changed a file or section and why, and presents a timeline of the significant changes.
- [Create a git branch (/git--branch)](https://skills.sgomez.dev/en/s/git--branch.md): Creates a well-named branch that follows your team conventions, like type/description or type/TICKET-description.
- [Changelog from git (/git--changelog)](https://skills.sgomez.dev/en/s/git--changelog.md): Generates a CHANGELOG.md from your git history using conventional commits, grouped by version and type of change.
- [Cherry-pick from a PR (/git--cherry-pick-pr)](https://skills.sgomez.dev/en/s/git--cherry-pick-pr.md): Brings selected commits from a pull request or another branch into your current branch, and helps resolve any conflicts.
- [Smart commit message (/git--commit)](https://skills.sgomez.dev/en/s/git--commit.md): Analyzes your staged changes and writes a Conventional Commits message, then creates the commit once you approve it.
- [Git hooks for your repo (/git--git-hooks)](https://skills.sgomez.dev/en/s/git--git-hooks.md): Sets up git hooks that lint staged files, validate commit messages and can run fast tests before push, using the hook manager that fits your stack.
- [Git workflows for monorepos (/git--monorepo-git)](https://skills.sgomez.dev/en/s/git--monorepo-git.md): Tunes git for a monorepo with sparse checkout, per-package CODEOWNERS and path-filtered CI so changes only build and test what they touch.
- [Complete pull request (/git--pr-create)](https://skills.sgomez.dev/en/s/git--pr-create.md): Builds a pull request from your commits and diff, with a title, summary, test plan and labels, pushes the branch and returns the PR URL.
- [Pull request code review (/git--pr-review)](https://skills.sgomez.dev/en/s/git--pr-review.md): Reviews a pull request by number and returns issues with file, line, severity and a suggested fix, ending with approve, request changes or comment.
- [Semantic version release (/git--release)](https://skills.sgomez.dev/en/s/git--release.md): Works out the next semantic version from your commits, updates CHANGELOG.md, creates the git tag and, if asked, a GitHub release.
- [Git stash manager (/git--stash-manager)](https://skills.sgomez.dev/en/s/git--stash-manager.md): Lists your git stashes, previews what each holds and helps you apply, drop, save a new one or branch from a stash, warning about likely conflicts.
- [Safe git undo (/git--undo)](https://skills.sgomez.dev/en/s/git--undo.md): Checks your recent history and proposes the safest way to undo the last commit, merge, rebase or change, explaining it before running anything.
- [Store listing for mobile apps (/mobile--app-store-listing)](https://skills.sgomez.dev/en/s/mobile--app-store-listing.md): Produces a store listing for your app on both stores: keyword research, title and subtitle, descriptions, a screenshot plan and compliance metadata.
- [Biometric login for mobile apps (/mobile--biometric-auth)](https://skills.sgomez.dev/en/s/mobile--biometric-auth.md): Adds Face ID, Touch ID or Android biometrics to your app, with the token held in the platform keystore and a real non-biometric fallback.
- [Deep links for mobile apps (/mobile--deep-linking)](https://skills.sgomez.dev/en/s/mobile--deep-linking.md): Sets up universal links and app links, in-app routing and the server files your web team must host, plus a QA matrix to test every link.
- [Production-ready Flutter app (/mobile--flutter-scaffold)](https://skills.sgomez.dev/en/s/mobile--flutter-scaffold.md): Scaffolds a Flutter app with routing, a confirmed state-management choice, a theme with dark mode and dev, staging and prod flavors.
- [Mobile app navigation design (/mobile--mobile-navigation)](https://skills.sgomez.dev/en/s/mobile--mobile-navigation.md): Designs your app's navigation: stacks, tabs and modals, login-based gating, correct back behaviour and state restoration after the OS kills the app.
- [Mobile app performance audit (/mobile--mobile-performance)](https://skills.sgomez.dev/en/s/mobile--mobile-performance.md): Audits app startup, jank, download size, memory and images, measuring before and after and returning a prioritised list of fixes.
- [Mobile app release pipeline (/mobile--mobile-release)](https://skills.sgomez.dev/en/s/mobile--mobile-release.md): Sets up your app's release pipeline: versioning, signing, TestFlight and Play beta tracks, staged rollout and a store-submission checklist.
- [Offline-first mobile app (/mobile--offline-sync)](https://skills.sgomez.dev/en/s/mobile--offline-sync.md): Makes your app offline-first: picks the local store, defines the sync strategy, resolves conflicts and queues writes so nothing is lost offline.
- [Push notifications for your app (/mobile--push-notifications)](https://skills.sgomez.dev/en/s/mobile--push-notifications.md): Implements push notifications with FCM and APNs: platform setup, device token lifecycle, payloads that open the right screen and a better permission prompt.
- [React Native Expo starter (/mobile--react-native-scaffold)](https://skills.sgomez.dev/en/s/mobile--react-native-scaffold.md): Scaffolds a production-grade React Native app with Expo: navigation, state, dark-mode theming, environment config, linting and CI.
- [API gateway configuration (/networking--api-gateway)](https://skills.sgomez.dev/en/s/networking--api-gateway.md): Designs an API gateway configuration for your API: routing, authentication, rate limits, request validation and observability, plus a matching OpenAPI spec.
- [CDN caching strategy (/networking--cdn-strategy)](https://skills.sgomez.dev/en/s/networking--cdn-strategy.md): Designs CDN cache rules for your web app across static assets, HTML and API responses, including cache keys, purging and ready-to-use headers.
- [Cloudflare D1 database setup (/networking--cloudflare-d1)](https://skills.sgomez.dev/en/s/networking--cloudflare-d1.md): Sets up a Cloudflare D1 (serverless SQLite) database with migrations, wrangler bindings, a typed data access layer and a development seed script.
- [Cloudflare DNS records (/networking--cloudflare-dns)](https://skills.sgomez.dev/en/s/networking--cloudflare-dns.md): Configures or audits DNS records for a Cloudflare domain, including A, CNAME, MX, SPF, DKIM and DMARC, proxy settings and verification.
- [Cloudflare KV storage (/networking--cloudflare-kv)](https://skills.sgomez.dev/en/s/networking--cloudflare-kv.md): Implements Cloudflare Workers KV for edge key-value storage, with bindings, key design, TTLs and typed helpers, noting KV is eventually consistent.
- [Cloudflare Pages deployment (/networking--cloudflare-pages)](https://skills.sgomez.dev/en/s/networking--cloudflare-pages.md): Configures Cloudflare Pages for your static or JAMstack site: build settings, redirects, headers, optional functions and branch preview deployments.
- [Cloudflare R2 object storage (/networking--cloudflare-r2)](https://skills.sgomez.dev/en/s/networking--cloudflare-r2.md): Sets up Cloudflare R2 storage with upload and download code, S3-compatible access, presigned URLs, CORS and security guidance.
- [Local services via Tunnel (/networking--cloudflare-tunnel)](https://skills.sgomez.dev/en/s/networking--cloudflare-tunnel.md): Configures a Cloudflare Tunnel to expose local services without a public IP, with ingress rules, DNS, access policies and deployment options.
- [Cloudflare WAF rules (/networking--cloudflare-waf)](https://skills.sgomez.dev/en/s/networking--cloudflare-waf.md): Designs Cloudflare WAF and rate-limiting rules based on your app's threat surface, plus a plan to test them without blocking legitimate traffic.
- [Cloudflare Workers project (/networking--cloudflare-workers)](https://skills.sgomez.dev/en/s/networking--cloudflare-workers.md): Scaffolds a Cloudflare Worker for your use case, with wrangler.toml, a TypeScript entry point, bindings and staging and production environments.
- [DNS troubleshooting (/networking--dns-debug)](https://skills.sgomez.dev/en/s/networking--dns-debug.md): Diagnoses why a domain fails to resolve or propagate by comparing resolvers and delegation, then proposes specific record changes to fix it.
- [Cloudflare Durable Objects (/networking--durable-objects)](https://skills.sgomez.dev/en/s/networking--durable-objects.md): Implements Cloudflare Durable Objects for stateful use cases such as WebSocket chat rooms, precise counters or locks, with bindings and migrations.
- [Edge functions for requests (/networking--edge-functions)](https://skills.sgomez.dev/en/s/networking--edge-functions.md): Builds edge functions that rewrite URLs, change headers or validate tokens, on Cloudflare Workers, Vercel Edge Functions or Deno Deploy.
- [Load balancing with failover (/networking--load-balancer)](https://skills.sgomez.dev/en/s/networking--load-balancer.md): Designs your app's load balancing setup, with origin pools, health checks and failover, as Cloudflare, Nginx or Kubernetes configuration.
- [Network problem diagnosis (/networking--network-debug)](https://skills.sgomez.dev/en/s/networking--network-debug.md): Diagnoses timeouts, high latency, refused connections or TLS failures with layered tests, then suggests remediation steps and monitoring.
- [Reverse proxy setup (/networking--reverse-proxy)](https://skills.sgomez.dev/en/s/networking--reverse-proxy.md): Generates a reverse proxy configuration for your app on a Cloudflare Worker, Nginx or Caddy, with routing, WebSocket support and security settings.
- [SSL/TLS audit and setup (/networking--ssl-tls)](https://skills.sgomez.dev/en/s/networking--ssl-tls.md): Audits your site's certificates, TLS versions and HTTPS settings, flags common problems and generates a secure Cloudflare and origin configuration.
- [Secure webhook receiver (/networking--webhook-endpoint)](https://skills.sgomez.dev/en/s/networking--webhook-endpoint.md): Builds an endpoint that receives webhooks with signature verification, duplicate handling and retries, in whichever framework your project uses.
- [Cloudflare Zero Trust access (/networking--zero-trust)](https://skills.sgomez.dev/en/s/networking--zero-trust.md): Designs Cloudflare Zero Trust access policies to protect internal apps, and generates the code that validates user identity in your application.
- [Low-noise alerting rules (/observability--alerting-rules)](https://skills.sgomez.dev/en/s/observability--alerting-rules.md): Audits your current alerts and replaces them with a few symptom-based rules, with thresholds, severity and routing, for your monitoring stack.
- [Incident response process (/observability--incident-response)](https://skills.sgomez.dev/en/s/observability--incident-response.md): Creates an incident response process with a severity matrix, roles and communication templates, sized to your team's real scale.
- [Structured logging strategy (/observability--logging-strategy)](https://skills.sgomez.dev/en/s/observability--logging-strategy.md): Audits your project's logging and migrates it to JSON logs with levels, correlation IDs, PII redaction and a retention policy.
- [Application metrics setup (/observability--metrics-setup)](https://skills.sgomez.dev/en/s/observability--metrics-setup.md): Adds a small set of application metrics to your app using the RED and USE methods, exported via Prometheus or OpenTelemetry, with cardinality kept in check.
- [Blameless postmortem (/observability--postmortem)](https://skills.sgomez.dev/en/s/observability--postmortem.md): Turns chat logs, alerts and notes from an incident into a postmortem with a timeline, contributing factors and owned action items.
- [Operational runbooks (/observability--runbook-gen)](https://skills.sgomez.dev/en/s/observability--runbook-gen.md): Generates runbooks by reading your code and infrastructure, with symptoms, diagnosis commands, remediation ordered by safety, and escalation.
- [SLO and SLI definition (/observability--slo-sli)](https://skills.sgomez.dev/en/s/observability--slo-sli.md): Defines SLIs and SLOs from your users' key journeys, with error budgets and multi-window burn-rate alerts.
- [Distributed tracing setup (/observability--tracing-setup)](https://skills.sgomez.dev/en/s/observability--tracing-setup.md): Instruments your service with OpenTelemetry so one request can be followed across services, with auto and manual spans and context propagation.
- [JavaScript bundle analysis (/performance--bundle-analyze)](https://skills.sgomez.dev/en/s/performance--bundle-analyze.md): Analyzes your project's JavaScript bundle size and proposes specific code changes to shrink it, with estimated savings for each.
- [Caching strategy (/performance--cache)](https://skills.sgomez.dev/en/s/performance--cache.md): Designs and implements a caching strategy for API responses, database queries or expensive computations, including invalidation.
- [Database performance tuning (/performance--db-performance)](https://skills.sgomez.dev/en/s/performance--db-performance.md): Finds your slowest database queries from real data and applies fixes such as indexes, rewritten queries and connection pool changes.
- [Lazy loading for faster pages (/performance--lazy-load)](https://skills.sgomez.dev/en/s/performance--lazy-load.md): Applies lazy loading to routes, components, images and modules so your site loads faster on first visit.
- [Finding memory leaks (/performance--memory-leak)](https://skills.sgomez.dev/en/s/performance--memory-leak.md): Scans your frontend and backend code for memory leaks, explains why each one leaks and proposes the fix.
- [Performance audit (/performance--perf-audit)](https://skills.sgomez.dev/en/s/performance--perf-audit.md): Audits your backend and frontend code for bottlenecks and lists each finding with its location, estimated impact and a specific fix.
- [Core Web Vitals improvement (/performance--web-vitals)](https://skills.sgomez.dev/en/s/performance--web-vitals.md): Measures your site's LCP, INP and CLS, diagnoses their causes in the code and applies fixes to reach the recommended thresholds.
- [Browser automation (/playwright-cli)](https://skills.sgomez.dev/en/s/playwright-cli.md): Drives a browser from the terminal with playwright-cli to open pages, fill forms, take screenshots and extract data.
- [Complete UI component (/scaffold--component)](https://skills.sgomez.dev/en/s/scaffold--component.md): Generates a React, Vue or Svelte component following your project's conventions, with types, styles, tests and a Storybook story.
- [3D component for the web (/scaffold--component-3d)](https://skills.sgomez.dev/en/s/scaffold--component-3d.md): Generates a 3D component with React Three Fiber, Three.js or Babylon.js, including types, animations and controls, matched to your project.
- [Full-stack feature scaffold (/scaffold--fullstack)](https://skills.sgomez.dev/en/s/scaffold--fullstack.md): Builds a feature end to end: migration, model, API, typed client, UI screens and tests, following your project's conventions.
- [Custom React hook (/scaffold--hook)](https://skills.sgomez.dev/en/s/scaffold--hook.md): Generates a custom React hook with types, effect cleanup, error handling, tests and a usage example.
- [Backend middleware (/scaffold--middleware)](https://skills.sgomez.dev/en/s/scaffold--middleware.md): Generates middleware for authentication, authorization, validation, logging, rate limiting or error handling in your project's web framework.
- [Data model with validation (/scaffold--model)](https://skills.sgomez.dev/en/s/scaffold--model.md): Generates a data model with validation, relationships, serialization, a migration and test fixtures, using whichever ORM your project has.
- [Project scaffold from scratch (/scaffold--scaffold)](https://skills.sgomez.dev/en/s/scaffold--scaffold.md): Generates the full structure of a new project, with config files, Docker, CI and an environment variable template.
- [Startup business plan deck (/scaffold--startup-generator)](https://skills.sgomez.dev/en/s/scaffold--startup-generator.md): Runs 10 parallel agents on your SaaS idea and consolidates market, product, finance and pricing analysis into an investor-ready PowerPoint.
- [Login and permissions review (/security--auth-review)](https://skills.sgomez.dev/en/s/security--auth-review.md): Reviews your app's login, sessions, tokens and access rules and returns severity-rated findings, each with a specific fix.
- [CORS configuration review (/security--cors-review)](https://skills.sgomez.dev/en/s/security--cors-review.md): Reviews your CORS setup in Express, FastAPI, Django or Nginx, tightens overly permissive origins and headers, and verifies them with curl.
- [Content Security Policy generator (/security--csp-gen)](https://skills.sgomez.dev/en/s/security--csp-gen.md): Analyzes the scripts, styles, images and connections your app uses and generates a Content Security Policy as a header and a meta tag.
- [Dependency vulnerability check (/security--dependency-vuln)](https://skills.sgomez.dev/en/s/security--dependency-vuln.md): Runs your package manager's audit and lists each vulnerable dependency with its CVE, severity, fixed version and a remediation plan.
- [Environment and headers hardening (/security--env-hardening)](https://skills.sgomez.dev/en/s/security--env-hardening.md): Reviews .env files, server settings and HTTP security headers, then generates a hardened configuration with a before and after comparison.
- [Pentest preparation (/security--pentest-prep)](https://skills.sgomez.dev/en/s/security--pentest-prep.md): Prepares you for a penetration test: sweeps for easy fixes, documents the scope and delivers a pentest-prep.md with a checklist and known risks.
- [Rate limiting design (/security--rate-limiting)](https://skills.sgomez.dev/en/s/security--rate-limiting.md): Designs and adds rate limiting: picks an algorithm, sets per-route budgets, returns 429 with Retry-After and adds tests.
- [Input sanitization review (/security--sanitize)](https://skills.sgomez.dev/en/s/security--sanitize.md): Traces where user input enters your code and where it ends up, flags SQL injection, XSS and similar flaws, and proposes the fix.
- [Leaked secrets scan (/security--secrets-scan)](https://skills.sgomez.dev/en/s/security--secrets-scan.md): Scans your code, config files and recent git history for API keys, tokens, passwords and private keys, and explains how to remediate each.
- [OWASP security audit (/security--security-audit)](https://skills.sgomez.dev/en/s/security--security-audit.md): Audits your codebase against the OWASP Top 10 and returns each finding with severity, file and line, a description and a fix.
- [STRIDE threat model (/security--threat-model)](https://skills.sgomez.dev/en/s/security--threat-model.md): Analyzes your repo's architecture and writes threat-model.md with a data-flow diagram, rated STRIDE threats and a top-5 action list.
- [Website SEO audit (/seo-audit)](https://skills.sgomez.dev/en/s/seo-audit.md): Audits your site's technical, on-page and content SEO and delivers a report with issues, impact, fixes and a prioritized action plan.
- [Contract tests between services (/testing--contract-testing)](https://skills.sgomez.dev/en/s/testing--contract-testing.md): Sets up consumer-driven contract tests (Pact by default) so breakages between services are caught at build time without running both together.
- [Load testing setup (/testing--load-testing)](https://skills.sgomez.dev/en/s/testing--load-testing.md): Sets up load tests with k6, Locust or Artillery: realistic scenarios, pass/fail thresholds and a lightweight smoke gate in CI.
- [Mutation testing setup (/testing--mutation-testing)](https://skills.sgomez.dev/en/s/testing--mutation-testing.md): Sets up mutation testing to measure whether your tests would catch real bugs, then turns surviving mutants into stronger tests.
- [Browser automation with Playwright (/testing--playwright-mcp)](https://skills.sgomez.dev/en/s/testing--playwright-mcp.md): Drives a real browser through Playwright MCP to navigate, click, fill forms, debug pages and take screenshots.
- [Test snapshot updates (/testing--snapshot-update)](https://skills.sgomez.dev/en/s/testing--snapshot-update.md): Reviews failing test snapshots and decides whether each is an intended change, a real bug or a flaky test before updating anything.
- [Test coverage gaps (/testing--test-coverage)](https://skills.sgomez.dev/en/s/testing--test-coverage.md): Finds which code your tests don't cover, ranks the gaps by risk and generates tests for the highest-priority ones.
- [End-to-end workflow tests (/testing--test-e2e)](https://skills.sgomez.dev/en/s/testing--test-e2e.md): Generates end-to-end tests for a user workflow in Playwright, Cypress or similar, covering happy path, error paths and data cleanup.
- [Edge case tests (/testing--test-edge-cases)](https://skills.sgomez.dev/en/s/testing--test-edge-cases.md): Generates tests for boundaries, nulls, concurrency, Unicode and state in your code, explaining which bug each one would catch.
- [Fixing failing tests (/testing--test-fix)](https://skills.sgomez.dev/en/s/testing--test-fix.md): Runs your test suite, works out whether each failure is in the test, the code or the environment, fixes it and re-runs to confirm.
- [Unit tests for your code (/testing--test-gen)](https://skills.sgomez.dev/en/s/testing--test-gen.md): Reads a file and writes unit tests covering normal use, edge cases and errors in your existing framework, then runs them to check they pass.
- [Integration tests (/testing--test-integration)](https://skills.sgomez.dev/en/s/testing--test-integration.md): Generates integration tests that exercise real interactions between components, APIs and databases, including partial failures and retries.
- [Mocks and test fixtures (/testing--test-mock)](https://skills.sgomez.dev/en/s/testing--test-mock.md): Creates mocks, stubs, spies, fakes and realistic fixture data for your code's dependencies, following Jest, Vitest, pytest or Go conventions.
- [Visual regression tests (/testing--visual-regression)](https://skills.sgomez.dev/en/s/testing--visual-regression.md): Sets up screenshot comparison against approved baselines to catch unintended UI changes, with CI integration and flakiness control.
- [Reliable code benchmarks (/utils--benchmark)](https://skills.sgomez.dev/en/s/utils--benchmark.md): Builds a benchmark with warmup, repetition and statistics to measure or compare performance, optionally with a CI regression gate.
- [Data format conversion (/utils--convert)](https://skills.sgomez.dev/en/s/utils--convert.md): Converts data between JSON, YAML, TOML, XML, CSV and ENV, or into TypeScript interfaces, JSON Schema or Zod, and validates the output.
- [Cron expressions explained (/utils--cron-explain)](https://skills.sgomez.dev/en/s/utils--cron-explain.md): Turns a schedule description into a cron expression, or explains an existing one in plain English, with the next 5 run times and common pitfalls.
- [Safe dependency updates (/utils--dep-update)](https://skills.sgomez.dev/en/s/utils--dep-update.md): Lists outdated dependencies, sorts them into patch, minor and major, checks breaking changes and updates in batches, running tests.
- [Environment variables setup (/utils--env-setup)](https://skills.sgomez.dev/en/s/utils--env-setup.md): Finds every environment variable your code uses and generates a .env.example, a validation schema and a config module that fails fast.
- [ESLint setup (/utils--eslint-config)](https://skills.sgomez.dev/en/s/utils--eslint-config.md): Generates or tunes your ESLint config for TypeScript, React or Node, with rules, ignores, lint scripts and a pre-commit hook.
- [Code explanation (/utils--explain)](https://skills.sgomez.dev/en/s/utils--explain.md): Reads the code you point to and explains it in layers: summary, purpose, step-by-step flow, key concepts, dependencies and gotchas.
- [Tailored .gitignore file (/utils--gitignore)](https://skills.sgomez.dev/en/s/utils--gitignore.md): Detects your project languages, frameworks and tools, then writes a commented .gitignore, merging with any existing one.
- [JSON toolkit (/utils--json-tools)](https://skills.sgomez.dev/en/s/utils--json-tools.md): Validates, diffs, queries with jq, flattens or infers a schema for JSON, and returns the result on screen or in a file.
- [Monorepo setup (/utils--monorepo)](https://skills.sgomez.dev/en/s/utils--monorepo.md): Sets up or tunes a monorepo with workspaces, shared configs, cached builds and tests that run only on affected packages.
- [package.json cleanup (/utils--package-json)](https://skills.sgomez.dev/en/s/utils--package-json.md): Reviews and tidies your package.json: scripts, dependencies, metadata and config, and flags risks such as postinstall scripts.
- [Regular expressions (/utils--regex)](https://skills.sgomez.dev/en/s/utils--regex.md): Writes, explains and tests regular expressions in your language, with test cases and warnings about ReDoS and flavor differences.
- [Code translation between languages (/utils--translate)](https://skills.sgomez.dev/en/s/utils--translate.md): Translates code from one programming language to another, keeping the logic, using target idioms and noting what has no direct equivalent.
- [tsconfig.json setup (/utils--tsconfig)](https://skills.sgomez.dev/en/s/utils--tsconfig.md): Generates or tunes tsconfig.json for a backend, frontend, library or monorepo, with strict mode and an explanation of the settings.
- [Modern Swift writing guide (/write-swift)](https://skills.sgomez.dev/en/s/write-swift.md): A guide for writing, reviewing or migrating Swift 6: value types, data-race-safe concurrency, protocols, performance and Swift Testing.
