Production Full Stack
Design, scaffold, implement, review, and verify production-grade full-stack applications and substantial backend or frontend features. Use when creating an app, API, backend, frontend, dashboard, service, worker, queue, database-backed feature, or production deployment. Enforce scalable API/worker architecture, bounded concurrency, queues, caching, pagination, audit logging, rate limits, Docker a…
Adopt Existing Project
Safely adopt, audit, production-harden, restructure, or refactor an existing application after Engineering Baseline is installed. Use on first run when `.engineering-baseline-lock.json` has `adoption.status: pending`, and whenever a user asks to make an existing repository production-ready, apply all baseline/security frameworks, correct its directory structure, reduce complexity with Ponytail, o…
Engineering Baseline
Apply a risk-proportionate engineering baseline to software planning, implementation, debugging, review, and verification in any language or stack. Use for coding tasks, project changes, bug fixes, refactoring, and code review; route to installed Ponytail, Superpowers, Impeccable, and Security Review skills when their narrower triggers match.
Security Review
Perform mandatory feature-level threat modeling and security verification using STRIDE, OWASP ASVS 5.0.0 Level 2, OWASP Top 10:2025, NIST CSF 2.0, and NIST SP 800-207 Zero Trust. Use for every new feature and material behavior change, and for reviews involving authentication, authorization, trust boundaries, APIs, untrusted input, sensitive data, secrets, cryptography, files, external URLs, depen…