CtrlK
BlogDocsLog inGet started
Tessl Logo

Discover rules

Discover rules to enhance your AI agent's capabilities.

AllSkillsDocsRules
NameContainsScore

g14wxz/storage-path-validation

v0.1.0

Prevents directory traversal in Supabase Storage via path validation functions and storage RLS.

Contains:

storage-path-validation

Creates Postgres functions to validate storage path payloads and prevent directory traversal. Enforces tenant-safe file paths via storage RLS bucket policies. Use when configuring Supabase storage buckets, writing storage RLS policies, or implementing tenant-scoped file uploads.

SkillsDocsRules

77

Enforces strict isolation of service_role key to server-side contexts only.

Contains:

service-role-boundary

Enforces that service_role key is never exposed to client-side code. Validates admin client isolation, privileged operations routing, and server-only key usage. Use when implementing admin operations, server-side Supabase clients, or auditing service_role key usage.

SkillsDocsRules

77

Injects tenant ID and RBAC permissions into JWT via Postgres Auth Hooks during token issuance.

Contains:

custom-access-token-hook

Generates Postgres Auth Hook that injects tenant_id and serialized permissions into JWT app_metadata using jsonb_set. Use when implementing RBAC, multi-tenant JWT claims, custom access token hooks, or permission injection into Supabase auth tokens.

SkillsDocsRules

77

Database architecture skills, docs, and rules for high-demand multi-tenant commerce platforms (PostgreSQL source of truth, Neo4j as derived GraphRAG projection, transactional outbox, RLS-based tenant isolation). Includes live schema introspection workflow via explicit Supabase MCP/read-only schema sources.

Contains:

adr-drafting

Use when the user proposes — or the agent detects — a deviation from constitutional defaults that requires an Architecture Decision Record. Triggered by proposals to extract microservices, drop foreign keys, denormalize without measured evidence, store transactional truth in Neo4j, skip Row Level Security, skip the transactional outbox, run destructive migrations, use database-per-service, or any explicit override of a constitutional principle. Drafts a structured ADR with context, decision, consequences, alternatives rejected, migration path, validation criteria, and constitutional sections affected — and refuses to proceed with the underlying work until the ADR is at least Proposed status.

commerce-database-architecture

Use when designing or reviewing database architecture for high-demand multi-tenant commerce platforms — including PostgreSQL schema design, foreign keys, indexes, JSONB usage, multi-tenant isolation with Row Level Security, transactional outbox, Neo4j GraphRAG projections, event sourcing decisions, audit logging, partitioning, expand/contract migrations, and product/inventory/order modeling for restaurants, boutiques, drugstores, retailers, distributors, grocery, hardware, or appliance businesses. Triggered by any request to design tables, design schemas, create migrations, model products/variants/inventory/orders/payments, choose between monolith and microservices, choose between PostgreSQL and Neo4j as source of truth, model multi-tenant data, design event flows, or review an ER diagram.

graph-rag-boundary-review

Use when reviewing or designing how Neo4j and GraphRAG interact with PostgreSQL transactional truth — including any feature involving recommendations, semantic product search, ingredient relationships, substitution suggestions, complementary products, AI-assisted discovery, vector search combined with graph traversal, or any proposal that puts orders, inventory, payments, prices, or tenant access rules into Neo4j. Evaluates architectural proposals for data boundary violations, identifies sync pattern errors between Neo4j and PostgreSQL, produces structured design review feedback with severity-ranked findings, counter-proposals with Mermaid diagrams, eventing changes, and re-projection plans. Triggered by mentions of GraphRAG, Neo4j, knowledge graph, recommendations engine, semantic search, vector + graph hybrid search, AI product discovery, or any design that crosses the PostgreSQL ↔ Neo4j boundary.

SkillsDocsRules

77

Teaches coding agents how to build TUIs with TamboUI correctly: API-level selection, render-thread discipline, display-width safety, CSS-aware element authoring, and JFR conventions.

Contains:

add-jfr-event

Add a new Java Flight Recorder event to a TamboUI module following project conventions — `dev.tamboui.AREA.THING` naming, `enabled()` guards, static `commit(...)` helper, and `compileOnly(libs.jfr.polyfill)` for Java 8 modules. Use when the user says "add a JFR event", "trace X with JFR", "instrument Y for flight recorder", or "emit a JFR event for Z".

build-log-style-list

Build a log-style or chat-style scrollable pane in a TamboUI Toolkit app — `ListElement` configured with no selection highlight, sticky scroll, scrollbar, mouse-wheel capture, focus chain integration, and a pre-wrap helper for long content. Use when the user says "build a log pane", "add a chat pane", "make a scrollable list", "trace pane that auto-scrolls", "tail-style output", or asks how to display many lines of streamed text in a TUI.

multi-pane-focus

Wire keyboard and mouse focus across multiple panes in a TamboUI Toolkit app — assign stable ids, set the initial focus in `onStart()`, and add a visible focused-pane border via `focusManager.focusedId()`. Use when the user says "add multi-pane focus", "set initial focus on the input", "highlight the focused pane", "tab between panes", "make the prompt focused by default", or asks how to manage focus across panels.

SkillsRules

76

Guardrails for Vue 2.7 + Vuetify 2.7 frontends built with Vite 7, with exact version pins, a working Vite and Axios setup, and Vuetify 2 component patterns that avoid Vue 3 and Vuetify 3 idioms.

Contains:

vue2-vuetify2-vite-setup

Scaffolds and configures a Vue 2.7 + Vuetify 2.7 frontend built with Vite 7 and Axios, with pinned versions, the vite.config.js alias and dedupe for Vue, the main.js bootstrap with new Vue and new Vuetify, MDI icons, VITE_ environment variables and an axios API module. Use when creating a frontend with Vite for a project that requires Vue 2 or Vuetify 2, migrating a Vue 2 app from Vue CLI to Vite, adding or upgrading dependencies in a Vue 2 project, setting up ESLint for Vue 2, or fixing errors such as Multiple instances of Vue detected, Vuetify is not properly initialized, or an npm peer conflict on vite.

vuetify2-components

Builds Vue 2.7 + Vuetify 2 screens with the correct v2 props, slots and events and with Vue 2 reactivity, for example a point-of-sale screen with product search, a table of editable sale lines, a total, a confirmation dialog, forms and snackbars. Covers v-data-table headers and item slots, v-autocomplete with server search, v-dialog activators, v-form validation, v-snackbar, custom v-model with value and input, and array updates with splice or $set. Use when writing or reviewing .vue components in a Vue 2 or Vuetify 2 project, when a Vuetify prop or slot seems to do nothing, when a table does not update after a change, or when porting a Vue 3 or Vuetify 3 example to Vue 2.

SkillsRules

76

Write professional, persuasive complaint letters to US airlines emphasizing loyalty status, DOT regulations, and airline commitments.

Contains:

frequent-flyer-advocate

Write professional, persuasive complaint letters to US airlines on behalf of passengers. Emphasizes loyalty status, DOT regulations, and the airline's own published commitments. Use when: user wants to complain to an airline, request compensation, write a complaint letter, dispute an airline's response, escalate an airline issue, file a DOT complaint, or mentions a bad flight experience they want to act on. Also trigger when user describes: flight delay, cancellation, lost baggage, damaged baggage, denied boarding, downgrade, poor service, broken amenities, tarmac delay, missed connection, or any airline service failure they want addressed.

using-travel-credits

How an LLM agent reads and updates the shared travel-credits inventory at ~/.claude/travel-credits/ — flight credits, vouchers, upgrade certificates, and airline or hotel compensation, tracked for a whole family across every carrier and brand. Actions: check store readiness and bootstrap it; migrate the store to the current record shape; list credits; show what is expiring; match credits against a booking scenario; show compensation history; add a credit; update one; mark one used; handle errors. Use whenever a question turns on what credits, vouchers, or certificates are on hand — before searching flights, when presenting an itinerary, after a booking, or when an airline grants compensation.

SkillsRules

76

Lenguaje ubicuo para agentes de código: explicaciones cortas, directas y sin jerga, y un glosario compartido (docs/lenguaje-ubicuo.md) cuyas palabras se usan igual en la conversación, el código, los tests y la base de datos.

Contains:

glosario-lenguaje-ubicuo

Crea, actualiza y revisa el glosario de lenguaje ubicuo del proyecto (docs/lenguaje-ubicuo.md), el vocabulario compartido entre la persona usuaria y el agente que se usa igual en la conversación, el código, los tests y la base de datos. Úsala al empezar un proyecto desde un documento de requisitos, al nombrar tablas, modelos, funciones o rutas, cuando aparece un término nuevo o ambiguo, cuando hay dos palabras para lo mismo (por ejemplo "tile" y "plugin"), o cuando piden revisar si el código habla igual que el negocio.

SkillsRules

76

MySQL 8.4 stored procedures with Sequelize 6 and mysql2: procedures created by sequelize-cli migrations without DELIMITER, multi-line data passed as JSON and read with JSON_TABLE, transactions owned by the procedure, CALL from Express with correct result reading and HTTP error mapping, and money kept as DECIMAL(10,2).

Contains:

mysql-stored-procedure-authoring

Writes MySQL 8.4 stored procedures and the sequelize-cli migration that creates them, for Node backends on Sequelize 6 and mysql2. Covers a .sql script that also runs with the mysql client through DELIMITER, a migration that sends DROP and only the CREATE PROCEDURE block in separate queries, a JSON parameter read with JSON_TABLE for header-plus-lines data such as a sale and its items, an EXIT HANDLER with ROLLBACK and RESIGNAL, SIGNAL SQLSTATE 45000 for business rules, totals computed in SQL as DECIMAL(10,2), and exactly one final SELECT. Use when asked to create or change a stored procedure, to save a sale with its items (or any header with lines) in one call, when a migration fails with ER_PARSE_ERROR 1064 near DELIMITER, when deciding between docker-entrypoint-initdb.d and migrations, or when a procedure must validate input and roll back.

sequelize-call-procedure

Calls MySQL stored procedures from Node with Sequelize 6 and mysql2 and turns their errors into HTTP responses in Express. Covers CALL with named replacements and JSON.stringify for lists, reading rows[0], why QueryTypes.SELECT, OUT parameters and sequelize.transaction() break a CALL, errno mapping (1644, 1452, 3140, 1062) to 422, 404, 400 and 409, money kept as DECIMAL strings, and safe name or barcode search with Op symbols. Use when writing a service or route that runs CALL, when a CALL returns nested arrays, objects with numeric keys or undefined, when adding status codes for procedure errors, when someone wants to wrap a procedure call in a transaction, or when searching products by name or barcode.

SkillsRules

75

Eight-skill presentation system: ingest talks into a rhetoric vault, run interactive clarification, generate a speaker profile, create presentations that match your documented patterns, produce the deck illustrations + thumbnail visual layer, create and publish talk-content Agent Skills with talk pages to a Jekyll shownotes site, verify a recorded screencast against its storyboard, and edit a Camtasia screencast into a speaker-first video with corrected captions and chapters, all informed by a 113-entry Presentation Patterns taxonomy (83 observable: 64 patterns + 19 antipatterns; 30 unobservable: 21 patterns + 9 antipatterns) for scoring, brainstorming, and go-live preparation.

Contains:

illustrations

Generates the visual layer of a talk: deck illustrations (FULL / IMG+TXT slides with a shared style anchor), progressive-reveal build chains, and YouTube thumbnails. Owns style-strategy collaboration (informed by the speaker's visual_style_history in the vault), prompt safety, edit-vs-regenerate asymmetry, build chaining, title-safe-zone composition, and thumbnail composition with a real speaker photo. Invoked by presentation-creator during illustration strategy (Phase 2), illustration generation and application to the deck (Phase 5), and the post-event YouTube thumbnail (Phase 7). Triggers: "illustrate the deck", "generate illustrations", "create slide visuals", "design the visual style", "make a thumbnail", "build a YouTube thumbnail", "add visuals to my talk", "regenerate slide image", "fix the thumbnail", "generate progressive reveals", "build sequence for a slide".

presentation-creator

Creates presentations grounded in the speaker's documented rhetoric patterns, using a personal rhetoric-knowledge-vault as a constitutional style guide. Interactive and spec-driven: distill intent, jointly select rhetorical instruments from the vault catalog, architect the talk, develop content with speaker notes, run guardrail checks, generate a .pptx deck, publish per the speaker's workflow. Use whenever the user wants to create a presentation, build a talk, write a conference submission, design a slide deck, prepare for a speaking engagement, describe a topic to present on, or adapt an existing talk for a new audience. Also handles CFP abstracts; the sessions catalog of submission-ready titles, abstracts, and outlines; and single post-authoring tasks on an existing talk — QR code, deck export, shownotes page, YouTube thumbnail, linking a recording. Not a generic slide-deck tool — requires a populated rhetoric-knowledge-vault and follows the speaker's established style.

screencast-editor

Edit a talk-to-camera or demo screencast recorded in Camtasia for Mac (screen, camera and mic in one take) into a speaker-first video: plan cuts on sentence boundaries from Camtasia's own word timings, frame and zoom the screen evidence, audit the framing against the recorded pointer, generate the Camtasia project, correct the dynamic captions, time the YouTube chapters, and compose the thumbnail from frames of the take. Use when the user has a new Camtasia recording to edit, wants captions fixed, zooms adjusted, chapters or a description with time marks, or asks how to produce a screencast like a previous one.

SkillsRules

75

Configures database INSERT triggers that offload document chunking and embedding to Edge Functions.

Contains:

rag-ingestion-trigger-pipeline

Creates Postgres INSERT triggers that fire Edge Functions for document chunking and embedding generation. Configures the ingestion pipeline from raw document insert to vector storage. Use when building RAG ingestion, embed-on-insert pipelines, database-driven document ingestion, or automated embedding workflows.

SkillsDocsRules

75

Provides EXPLAIN ANALYZE workflow for identifying missing indexes, sequential scans, and query plan issues.

Contains:

query-explain-plan-debugging

Executes EXPLAIN ANALYZE via MCP to debug slow queries, identify missing indexes, detect sequential scans, and optimize query plans. Use when debugging slow SQL, analyzing query plans, finding unused indexes, optimizing Postgres queries, or investigating index-not-used issues.

SkillsDocsRules

75

Configures server-side session synchronization via secure HTTP-only cookies for SSR frameworks.

Contains:

ssr-auth-session-management

Implements server-side auth session management with HTTP-only cookie synchronization for Next.js, SvelteKit, and other SSR frameworks. Depends on PKCE auth flow. Use when implementing SSR authentication, server-side session sync, HTTP-only auth cookies, Next.js Supabase auth, or SvelteKit Supabase auth.

SkillsDocsRules

75

Context for developing and debugging Hubitat Elevation apps, drivers, and hub environment — sandbox constraints, lifecycle idioms, capability contracts, plus grounded deploy/log-tail/lint mechanisms.

Contains:

debug

Tail a Hubitat hub's live log or event websocket, filtered, and interpret it against the code to diagnose an app or driver. Use when the user wants to debug, watch logs, tail the log stream, see live events, or figure out why a Hubitat app/driver misbehaves.

deploy

Deploy a Hubitat app or driver's Groovy source to a hub and confirm it saved and runs by watching the log stream. Use when the user wants to deploy, push, upload, or install app/driver code onto a Hubitat hub, or iterate the edit-deploy-check loop.

device-command

Run a command on a Hubitat device over HTTP and confirm it landed — turn a switch or plug on/off, set a dimmer level, refresh a sensor, start an irrigation zone, or run a driver's custom command. Use when the user wants to command, control, operate, or exercise a device, test that a device responds, or run a device command and verify it took effect. Not for deleting a device (that is device-removal).

SkillsRules

74

FastAPI framework with Pydantic v2 patterns, PII sanitisation, and practical workflows

Contains:

run-check-server

Start a FastAPI dev server, verify docs and OpenAPI schema, test endpoints, and run pytest. Use when running, checking, or debugging a FastAPI application.

scaffold-project

Scaffold a new FastAPI project with an opinionated directory layout, pydantic-settings config, and starter files. Use when creating a new FastAPI application from scratch.

SkillsDocsRules

74

Empirical calibration for DJL face_feature (ArcFace/FaceNet 512-d) embeddings: cosine distance bands, piecewise confidence formula, enrollment quality targets. Replaces the dlib-based jbaruch/face-recognition-calibration tile for Kotlin/JVM pipelines.

Contains:

face-recognition-confidence-djl

Compute perceptually-correct confidence from DJL face_feature cosine distances using piecewise mapping (d ≤ 0.30 → 1.0, d ≥ 0.65 → 0.0, linear between). Includes enrollment averaging, L2 normalization, and the "textbook formula compresses strong matches" anti-pattern. Use when mapping FaceNet/ArcFace cosine distance to a user-facing confidence score, driving a confidence display (semaphore, progress bar, gauge), or diagnosing why a strong-looking recognition still reads as "yellow" or "weak" downstream.

SkillsRules

74

Automatically monitor GitHub Actions workflows after git push operations. Tracks workflow progress and reports pass/fail results.

Contains:

github-action-monitor

Monitors GitHub Actions workflow runs and reports pass/fail results. Use when git push has been executed, code has been pushed to a remote, or when the user asks about CI status.

SkillsRules

74

Coding policy for Viktor Gamov's AI agents: language-agnostic quality rules, autonomous shipping discipline, and stack defaults for JVM, Swift, TypeScript, and Python

Contains:

herdr-standup

Hold a daily standup with the named Herdr agents and print a table the operator can find while scrolling back through a long session: ask each idle worker for four lines (DONE / PLAN / BLOCKED / REPORT), fill the busy ones from the round log, and render a banner-topped fixed-width block plus a Markdown record. Use when the user wants a standup, a daily status round, a summary of what each agent is doing, "what is everyone working on", or a status table for the team. Requires HERDR_ENV=1.

herdr-teamlead

Run Herdr rounds with on-demand specialists, qualified tiers, bounded briefs, report verification, and release gates. Use for requests to dispatch the Herdr team, balance worker usage, collect reports, run or retrieve retrospectives, catch up on outstanding user attention, curate team lessons, or save and resume lead handoffs. Live rounds require HERDR_ENV; saved memory and attention work offline. Other standalone tasks skip this skill.

onboard-repo

Bootstrap a consumer repo onto gamussa/coding-policy: install the plugin at `latest`, gitignore tessl's generated artifacts, scaffold the Codex policy-review workflow plus the Copilot lane charter, set the CODEX_AUTH_JSON secret, then commit and ship via the release skill. Use when the user wants to add, install, enable, scaffold, set up, wire up, or enroll coding-policy / an automated policy review / a PR reviewer in a repo. Also use to upgrade or refresh the reviewer files in a repo that already has them (override mode: "upgrade", "update", "refresh", "--override").

SkillsRules

74

Kotlin/coroutines patterns for driving rate-limited IoT actuators from real-time producers: debounce controller, target quantization, bottom-up progress-bar rendering.

Contains:

debounce-controller-kotlin

One-coroutine-per-device debounce controller for rate-limited IoT APIs in Kotlin. Min-interval throttle, 2-tick stability filter, send-latest semantics. Min-interval is 0.2s for LAN devices, 1.2s for cloud APIs. Dispatches on Dispatchers.IO. Use when a real-time producer (camera loop, sensor feed, Flow<T>) drives a cloud or LAN IoT device that can't keep up with per-frame updates, or when you see flicker / HTTP 429 errors from hammering an actuator.

render-progress-bar-kotlin

Render a segmented LED progress bar that fills bottom-up with red/yellow/green gradient — thermometer pattern, not falling-bar. Handles top-indexed hardware (where segment[0] is physically at the top) and bottom-indexed hardware. Use when wiring a quantised level (0..N) into an LED bar, especially Govee H6056, Hue Lightstrip, or similar segmented devices where fill direction and gradient matter.

target-quantization-kotlin

Discretise continuous producer signals (Float, Double) into Int targets so the debounce controller's stability filter can actually commit. Without quantization, a noisy 0.42-vs-0.43-vs-0.42 signal blocks every commit and the actuator stays dark. Use when wiring a continuous producer (confidence score, sensor reading, audio level) into a debounce controller, or debugging "I call submit() but onApply() never fires".

SkillsRules

73

1.63x

Rules for trusted NanoClaw groups. Shared memory, session bootstrap, cross-group memory updates. Loaded for trusted and main containers only.

Contains:

google-ops

Native Google Calendar and Tasks reads over the OneCLI gateway, for trusted-tier ground-truth verification. Gmail is intentionally excluded. Use when a trusted agent must verify a calendar event or a task/todo status, or otherwise read the owner's Calendar or Tasks.

status

Quick read-only health check — session context, workspace mounts, tool availability, and task snapshot. Use when the user asks for system status, health check, diagnostics, system info, check environment, what tools are available, or runs /status.

system-status

Read-only system-status probe for trusted-tier NanoClaw containers — surfaces stuck scheduled tasks, DB size, and recent task-run failures from the orchestrator's SQLite at `/workspace/store/messages.db`. Use as part of heartbeat or standalone. Triggers on "system status", "check tasks", "stuck tasks", "database size", "task failures".

SkillsRules

73

Can't find what you're looking for? Evaluate a missing skill.