Back to Discover

skills_commands_manager

skill

j0ruge

Chewiesoft Marketplace — Claude Code plugin marketplace with skills and commands for development workflows

View on GitHub
8 starsSynced Aug 2, 2026

Install to Claude Code

/plugin marketplace add j0ruge/skills_commands_manager

README

Chewiesoft Marketplace

Plugin marketplace for Claude Code and Cursor — CI/CD, code review, deployments, releases, and more.

Plugins Platform License

Installation · Plugins · Auto-updates · Team Distribution · References


A curated dual-platform plugin marketplace for Claude Code and Cursor by j0ruge. Each plugin packages production-ready skills and commands that integrate directly into your workflow — no configuration needed beyond install.

Platform Compatibility

PluginClaude CodeCursorNotes
ansible-docker-backup-restoreSkill — backup + restore of Dockerized services via Ansible, with a read-only backup-freshness check
cicdSkill — works on both platforms without changes
codereviewSkills — adapted automatically by the installer
dddSkill — works on both platforms
deployCommand (Claude Code) / Skill (Cursor)
dev-scriptSkill — generates dev.sh (bash) + dev.ps1 (PowerShell) per project
dotnet-wpfSkills — works on both platforms
pdf-generationSkill — PDF template design + library selection (pdfmake/pdf-lib/PDFKit/Puppeteer/@react-pdf), modular sections, visual verification
releaseCommand (Claude Code) / Skill (Cursor)
retrofit-skillCommand (Claude Code) / Skill (Cursor)
statuslineClaude Code only (uses the Claude Code status line API)
ticketClaude Code only (/ticket slash command + Jira acli + atlassian MCP)
whisper-preprocessSkill — ffmpeg + OpenAI Whisper offline audio→text pipeline (silence removal, voice enhancement, segmentation, multilingual merge); decoupled stable-gain listening copy (no "picotamento")
zitadel-idpSkill — Zitadel self-hosted OIDC integration field guide (bootstrap, JWT, branding, 43 gotchas with proto-aligned v4.15 examples + CD cutover survival kit + Console UI human-user creation pitfalls + production-cutover v0.7.0 (backend extra_hosts for hairpin-NAT IdP, 3-layer SPA defense vs RT-reuse session revoke) + smoke-e2e CI v0.8.0 (admin.pat bind mount EACCES cascade into unique_constraints_pkey, default password policy 4-class trap, Login UI v2 healthcheck slow on small runners) + real-browser smoke v0.9.0 (seed user grant reconciliation gap on YAML evolution, browser→backend CORS preflight 401 mimicking JWT failure, Playwright self-signed Zitadel recipe) + admin-console Failed to fetch mixed-content v0.10.0 (api http vs issuer https from --tlsMode disabled; recreate, don't docker start) + v2.66→v4 upgrade runbook + API v1→v2 mapping)
wsl-windows-onboardingSkill — onboards a Windows box to WSL2: install the Ubuntu distro + a non-root sudo user, diagnose WSL, install rtk + Claude Code (global rtk hook), migrate projects into the Linux FS (copy→validate→delete, incl. a tight-disk one-repo-at-a-time loop for a nearly-full C: and the reserved-name nul/\\?\ delete trap, CRLF/filemode "whole tree modified" diagnosis), and set up zsh + the Windows Terminal profile (icon + default)

Installation

Claude Code

# Add the marketplace (pick one)
/plugin marketplace add j0ruge/skills_commands_manager          # via GitHub
/plugin marketplace add git@github.com:j0ruge/skills_commands_manager.git  # via SSH

Then install any plugin:

/plugin install codereview    # or: ansible-docker-backup-restore, cicd, ddd, deploy, dev-script, dotnet-wpf, pdf-generation, release, retrofit-skill, statusline, ticket, whisper-preprocess, wsl-windows-onboarding, zitadel-idp

[!TIP] Keep plugins up to date with a single command:

/plugin marketplace update

Cursor

Clone the repo and run the interactive installer:

git clone git@github.com:j0ruge/skills_commands_manager.git
cd skills_commands_manager
python install.py

The installer prompts for platform (Claude Code, Cursor, or Both) and where to place the Cursor skills. It automatically adapts plugin content for Cursor.

[!IMPORTANT] Cursor has no global skills directory — only project-local .cursor/skills/ is auto-loaded by the agent (Cursor docs). Run python install.py from inside each project where you want the skills available, and pick the Project option.

The installer also offers a Staging cache option that copies the converted skills to ~/.cursor/skills/ as a master copy — handy as a source to mirror into projects, but Cursor itself will not pick those up directly.

Available Plugins

PluginVersionCategoryDescription
cicd2.19.1DevelopmentCI/CD troubleshooting for GitHub Actions, Docker, GHCR, and self-hosted runners (systemd-on-host e containerizado via myoung34/github-runner) — cobre CMD-herdado-zerado, env LABELS vs RUNNER_LABELS, EPHEMERAL+restart:always loop, gpg --dearmor em buildkit, deploy keys per-repo unique, .env leading whitespace + sed silenciando, monorepo workspace hoisting diagnosis, vitest jsdom→happy-dom recipe pra msw v2. (NEW v2.12.0) troubleshooting-shared.md §1a — GHCR net/http: TLS handshake timeout no docker login do deploy job self-hosted é bug DISTINTO de §1 unauthorized (TCP conectou mas handshake não completou — credencial é irrelevante); isolation key é build-and-push em ubuntu-latest passar enquanto deploy em self-hosted falha; causa raiz típica é MTU mismatch em VPN/overlay ou TLS-inspection proxy; Fix A bash retry wrapper 3x backoff 10s/20s ao redor de docker login (20 linhas, sem nick-fields/retry); Fix B mtu: 1400 em /etc/docker/daemon.json + restart. Reference dedicada cd-pipeline-pitfalls.md cobre 7 classes de bugs de cutover/CI prod: (1) VITE/CRA/Next build args bake'd no image, frontend rebuild mandatory; (2) operator clone reconciliando stack stale; (3) docker compose --profile X run reconciliando containers de outros services; (4) compose run --rm orphan + nginx-proxy upstream poisoning (~50% intermittent 401s); (5) container scripts que escrevem upward de __dirname batem ENOENT em prod (Dockerfile só copia packages/<self>/) — fix canônico é try/catch best-effort, v2.11.0 refinement narrow catch para ENOENT/ENOTDIR e propagar EACCES/ENOSPC/EROFS preserva visibilidade de problemas reais em dev (especialmente importante quando bootstrap.json é consumido por sanity check downstream); v2.11.0 §6 — GHA bind mount uid mismatch: container vendorado roda uid 1000 (Postgres, Zitadel, vários), runner GHA ubuntu-latest é uid 1001 com pasta 0755 → EACCES no init/setup, e o estado parcial deixado para trás cascata em erros DIFERENTES nas retries (constraint violation, already-exists), burying the real cause; cura é pre-create do bind mount com chmod 0777; v2.11.0 §7docker compose up -d --wait espera TODOS os serviços com healthcheck por default; um sibling lento (Next.js/Vite ~90s+ no runner pequeno) estoura --wait-timeout da stack inteira; cura é passar service names explícitos no up --wait + companion sempre dumpar logs do serviço lento no on-failure (`
codereview1.17.1QualityPre-PR code review with model routing (haiku/sonnet/opus), TOCTOU detection, accessibility, deterministic hardcoded secrets detection via Python regex script + optional ggshield/gitleaks (GitGuardian-equivalent, blocks PRs with leaked credentials), and multi-reviewer PR resolver (CodeRabbit, Copilot, Gemini, Codex) with baseline-aware regression testing, verify-before-trust validation of reviewer-cited references, and byte-exact verification (od -c / xxd) when reviewers cite NUL bytes, BOM, zero-width chars, or other invisible/control characters — Read renders those bytes as plain whitespace and silently induces false-positive verdicts. v1.12.0 hardens Phase A output discipline (literal return template + END_OF_PHASE_A_REPORT end-marker) and adds a mandatory orchestrator-side fallback so the F-grade secrets gate never silently degrades when the haiku agent under-reports (running 9 tool calls but final-messaging only "results returned above"). v1.13.0 adds detection pass 6.5.3 "Contract Drift in Tests" — when the diff modifies an exported constant (export const X = [...] as const, Zod/Yup/literal-union schemas) and a test file in the codebase asserts that constant literally (expect(X).toEqual([...]) / toStrictEqual / toMatchObject / deepEqual), cross-check the asserted shape against the current export and flag mismatches as HIGH (public contract) / MEDIUM (internal). Same release also forces the final report's ### Overall Grade table and ### Recommended Actions block to ALWAYS render — even on zero-findings happy path, focus-area runs, or token-tight reviews where the model would otherwise collapse them into prose. v1.14.0 adds detection pass 6.9 "Dead Code & Unused Symbols" plus a dedicated parallel Dead Code Sweep agent (Phase B2) — because the per-file analysis agents each see only one file and structurally cannot tell whether an exported symbol is referenced elsewhere, dead code (unused exports, orphaned files, unreachable code, dead deps) needs a whole-repo reference sweep. It runs a hybrid scope (code morto introduced or orphaned by this PR first, then a capped pre-existing project-health summary) using the repo's own tooling when present (knip / ts-prune / vulture / depcheck / Roslyn / staticcheck, read-only) and a grep reference deepsearch otherwise, with strong false-positive guardrails (public API, framework/DI/reflection wiring, non-code references, barrels, test-only utils) and a per-finding Confidence. Dead code is hygiene: MEDIUM/LOW only, never blocks the PR, and feeds the new 🧹 Dead Code & Cleanup report section + Recommended Actions → Consider Fixing. v1.15.0 calibrates pass 6.9's reading of knip/ts-prune output with two false-positive guardrails learned from a real run: over-export (a symbol used only WITHIN its own file is reported as an "unused export" but isn't dead — recommend dropping the export, not deleting it) and regenerable scaffolding (shadcn components/ui/** / **/generated/** surfaced in bulk → keep in Bucket B, capped, never an actionable app finding). v1.16.0 splits that over-export guardrail into two opposite fixes — pure in-file plumbing → drop the export; a symbol that's part of an exported type-surface/API (e.g. an interface typing an exported hook's return, like AuthUser in UseAuthReturn) → keep the export and mark @public/@internal, never delete (dropping it can break tsc -b/declaration emit with "uses private name") — and makes the within-file/exported-signature grep a mandatory per-symbol check on every "unused export". v1.17.0 makes coderabbit_pr's mechanical phases deterministic and self-cleaning: reviewer detection, comment extraction and thread resolution now run inline as fixed gh api/--jq/GraphQL commands instead of prose-prompted subagents (a delegated batch that silently skips a thread is indistinguishable from a clean run), with Phase 5 ending on an unresolved: 0 assertion that gates completion; extraction is separated from interpretation via a --jq projection that drops diff_hunk/URLs before they reach any context (delegating to sonnet only above a size threshold) and encodes two non-obvious traps — .line // .original_line (null once a comment's diff goes stale) and select(.body != "") (empty approval bodies became phantom findings); a new Phase 6 deletes the {reviewer}-review.md checklists on the success path, since a stale checklist from an earlier PR is read by the cross-reviewer check as if it were current (opt out with --keep-checklists). Also fixes two real defects: fixes were applied to whatever branch was checked out rather than the PR's headRefName (silently landing them on unrelated work), and a reviewer that never ran — e.g. Copilot returning "unable to review — quota limit" — was recorded as "approved without issues", burying a coverage gap. v1.17.1 closes four coherence defects that a live run of v1.17.0 exposed: the zero-findings checklist is no longer written just for Phase 6 to delete moments later (the determination goes into the final report unless --keep-checklists is passed); the "no review comments → stop" error no longer collides with Phase 2's zero-findings path (stop means no bot posted anything at all — a reviewer that posted but found nothing, or reported it could not run, must still be reported); Phase 4 is skipped when Phase 3 changed no files, since a before/after comparison with no "after" only burns minutes and makes pre-existing failures look like this run caused them; and Phase 6's cleanup drops its hardcoded filename list plus an unexecutable "plus any {bot-login}-review.md" comment in favour of matching the header this skill writes — which covers unknown reviewers while leaving unrelated project docs like security-review.md untouched, where a bare rm -f *-review.md would not.
deploy1.4.0DevelopmentAutomated staging deployment with pre-flight checks and pipeline monitoring
release1.3.0DevelopmentGitHub Release creation with categorized notes, multi-stack and monorepo support
statusline1.5.2CustomizationInteractive status line setup — cross-platform (Bash + PowerShell), 12 sections incl. 5h/weekly usage limits + PR state, optional effort-level badge
dotnet-wpf1.6.1DevelopmentWPF toolkit — project audit, Fluent Design guide (90+ controls, form spacing, height clipping, Grid row separators, multi-column layouts, ContentDialog confirmation for destructive actions), MVVM migration, E2E testing
ddd0.4.1ArchitectureDomain-Driven Design toolkit — analyzes codebases for DDD violations, guides strategic design (event storming, context mapping, bounded-context canvas), generates legacy→DDD migration specs. Language-agnostic; synthesizes Evans + Vernon + modular-monolith practice
dev-script0.5.0DevelopmentGenerates dev.sh (bash) + dev.ps1 (PowerShell) launchers tailored to the current project — detects compose/monorepo/IdP/mkcert, emits idempotent script with healthchecks, two-strategy port handling (find-next-free discovery with peer-coordination env vars for foreign-owned service ports / kill-and-reclaim with pgrep fallback for own orphans), trap cleanup, HTTPS-on-LAN via mkcert + Caddy when the SPA does OIDC PKCE, Playwright LAN-HTTPS testing recipe, monorepo kill_known_dev_servers regex gotcha (path appears before tsx in cmdline), tsx watch --include=.env so launcher-patched env actually reaches runtime, the boot-time sanity-check pattern (app warns LOUD when runtime config diverges from launcher's source-of-truth file), and v0.4.0 P17 — foreign port owner + strictPort: true silent-hang cascade (kill silently fails → Vite hard-fails → parent wait keeps tracking surviving backend = looks like a hang; fix is pre-flight port discovery with peer-coordination env vars instead of trying to kill foreign processes). v0.5.0 adds three Windows↔WSL migration pitfalls: P18 — CRLF .env silently appends \r to values read with grep|cut (docker exec "$name\r"No such container, healthcheck times out while every log line looks correct; fix is a tr -d '\r' read helper); P19 — node_modules built on another platform crashes Vite/swc/esbuild with Failed to load native binding (missing platform-optional binary; re-install inside the target OS); P20 — yarn resolves to Debian's cmdtest impostor (Parsing scenario file …) when Corepack isn't enabled (corepack enable shadows it; resolve the package manager Corepack-aware)
retrofit-skill0.2.3DevelopmentApply non-obvious session lessons to a target skill in two modes — full (marketplace skill: bumps version, updates CHANGELOG/marketplace.json/README, commits and pushes) or lean (local skill in another repo: edits files + CHANGELOG and commits there, no bump or marketplace changes)
pdf-generation1.5.0DevelopmentPDF generation design toolkit — analyzes reference templates, recommends libraries (pdfmake/pdf-lib/PDFKit/Puppeteer/@react-pdf), designs modular section architecture with conditional columns, auto-generated observations and revision control. v1.2.0 adds three production-proven pdfmake pitfalls: cell padding NOT discounted from widths (last column silently cuts on A4 with 8+ cols, most painful pdfmake gotcha); Roboto bundled fi/fl/ffi ligatures drop the f (fiscalfscal) — v1.2.1 corrects the cause: pdfkit applies the liga substitution but fails to embed the glyph (bundled font is current, not old; confirm via SFNT parse; @fontsource-variable/* ships only .woff2, unusable by pdfmake); addFonts() silently rejects AFM (errors 500 on getBuffer). Plus Phase 6 Visual Verification (NON-NEGOTIABLE) — render bugs only surface in the rendered PDF, never in automated tests. v1.3.0 adds three visual-verification lessons: render/inspect EVERY page — header/footer in content[] (vs the header/footer slots) vanish on page 2+ (invisible in 1-page tests); conditional/optional field absence ≠ bug (populate the data to verify); hash-by-input revision cache doesn't regenerate on layout/code change (bust the cache). v1.4.0 adds vector-logo (SVG) handling: pdfmake renders SVG natively via { svg, width } (no svg-to-pdfkit dependency — the "pdfmake can't do SVG" belief is wrong); an SVG whose fills come from a <style>/class block renders with NO color unless each class is inlined to a fill= attribute (silent — only the visual render reveals it); ship a small default vector as a .ts string constant so it survives tsc → dist builds (which don't copy non-.ts files) and gitignored runtime asset dirs (which don't exist on fresh deploy)
zitadel-idp0.10.0DevelopmentZitadel v4.x self-hosted OIDC integration field guide — captures 43 high-friction quirks with proto-aligned examples verified against raw GitHub Zitadel v4.15.0 (FirstInstance env placement, volume perms, v1/v2 API split, tenant→orgId mapping, JWT validation over self-signed HTTPS via NODE_EXTRA_CA_CERTS + JWKS, loginV2 instance flag, silent-renew redirect URI byte-match, idempotent bootstrap No changes 400, TLS-terminating reverse proxy, secure-context PKCE on LAN, boot-time signinSilent recursion, StrictMode closure trap, post_logout_redirect_uri invalid, Login UI v1 branding via privateLabelingSetting / custom_login_text / LANG-lg4DP, F5 with InMemoryWebStorage, 401 storm post --reset-zitadel from tsx watch zombies, multi-app YAML refactor regression vs dynamic env, Zitadel v2.66.x --masterkey flag fix, v0.3.0: Login UI v2 as a separate Next.js container (zitadel-login) with reverse-proxy split, API v2 idempotence via deterministic IDs, contextual orgId moved from header into body, v0.4.0: proto-aligned payloads (CreateApplication discriminator = oidcConfiguration top-level com applicationType / developmentMode internos, NÃO oidc com appType / devMode); per-service ListResponse field names (projects[] / projectRoles[] / applications[] / authorizations[] vs result[]); CreateAuthorization exige organizationId, Update/Delete usam id (não authorizationId); Authorization shape nested (project.id, user.id); AlreadyExisting no matcher; quirk 28 — Login UI v2 auto-provisioning quebrado em v4.15.0 (zitadel/zitadel#8910 + #9293 — LOGINCLIENT_MACHINE_* envs causa unique_constraints_pkey em 03_default_instance migration; sem essas envs zitadel-login fica em loop Awaiting file and reading token eternamente; mitigação Path B loginV2.required: false); v0.5.0 — CD cutover survival kit: quirk 29 OIDC client_id é o numeric clientId do oidcConfiguration (gerado pelo Zitadel) NÃO o applicationId UUID determinístico que você passou em CreateApplicationRequest — frontend VITE_OIDC_CLIENT_ID wired no UUID retorna 400 Errors.App.NotFound em todo /oauth/v2/authorize; quirk 30 ZITADEL_BOOTSTRAP_ENV (ou qualquer env-driven dev/prod ID selector) silently defaultando pra dev em CD cria entidades com IDs do ambiente errado, mismatch silent contra secrets prod, mesmo sintoma Errors.App.NotFound; quirk 31 ZITADEL_DEFAULTINSTANCE_FEATURES_LOGINV2_REQUIRED=false no FirstInstance time quebra a chicken-and-egg dos quirks 25 + 28 — instância nasce com Login UI v1 ativo, operador loga no console post-wipe sem precisar PAT, sem precisar bootstrap rodar primeiro; quirk 32 nginx-proxy ignora silently containers sem VIRTUAL_PATH quando sibling tem VIRTUAL_PATH=/<algo> (todas as rotas fora do prefix retornam 404, sintoma é trailing "-" upstream nos logs nginx) — fix é declarar VIRTUAL_PATH=/ + VIRTUAL_DEST=/ no container "default"; ListUsers per-item field é userId não id (proto-confirmed v4.15.0 — code que lê result[0].id returns undefined e fallback bogus → CreateAuthorization 404 User could not be found); eventstore SQL pra diagnose password.check.failed (SELECT created_at, event_type FROM eventstore.events2 WHERE aggregate_type='user' AND aggregate_id=... mostra timeline completa de attempts + change events); idp-bootstrap Dockerfile pitfalls (precisa COPY src/ pra tsx imports + audit do path do YAML em cada release)); v0.6.0 — Console UI human-user creation pitfalls (manual operator flow only, NOT triggered by API/bootstrap): quirk 33 Console v4 "Add Human User" form auto-truncates Username to email's local-part on auto-fill — combined with userLoginMustBeDomain=false default, loginName drops the @domain and end users get "O usuário não pôde ser encontrado" / "User could not be found" when typing their full email; quirk 34 userLoginMustBeDomain=true (Settings → Domain settings → "Add Organization Domain as suffix to loginnames") stamps loginNames irreversibly on existing users, disabling + Reset to Instance default does NOT undo, doubly hostile in self-hosted because org primaryDomain auto-generates as <orgSlug>.<externalDomain> (not the company email domain) so toggling without a custom domain produces nonsensical or double-suffixed loginNames; quirk 35 Console "Add Human User" leaves "E-mail Verificado" / "Email verified" unchecked by default, first login then stalls on SMTP code prompt that never arrives in self-hosted setups where SMTP is deferred); v0.7.0 — Production-cutover quirks (validade_bateria_estoque PR #9): quirk 36 backend container that validates JWT needs extra_hosts: idp.<domain>:host-gateway when IdP is co-located on a VPS with unreliable hairpin NAT — jose.createRemoteJWKSet reload after the 600s cacheMaxAge TTL silently fails the network fetch, causing 401-storm starting at ~10min uptime with JWT iss/aud/exp/kid all verifiable by hand (third documented cause of "401-storm with apparently-valid JWT" alongside quirks 12 and 13); fix is extra_hosts mapping to docker bridge (same path external traffic takes), apply to ANY co-located container (bootstrap, observability, runners); also covers logging tip — use pino.warn not console.error for JOSEError because the same path fires for malformed tokens from clients (log-spam vector at error level); quirk 37 frontend defense-in-depth against 401-storm-revokes-session requires THREE coordinated layers, not just dedupe: L1 dedupe lives in ApiClient with pendingRenew instance field cleared in .finally() + public refreshToken() method shared between 401-retry path AND addAccessTokenExpiring handler (provider-level useRef dedupe alone leaves the expiring path leaking — same RT used by both sides → Zitadel detects reuse → revokes session); L2 TanStack Query retry predicate filters ApiError 401 because 401 is not transient (retrying amplifies the storm); L3 listener for apiclient:unauthorized CustomEvent in <AuthProvider> with isAuthRoute() early-return guard + state: { returnTo: location.pathname+search+hash } on signinRedirect (without guard a 401 from /auth/callback triggers another redirect → loop; without state.returnTo user lands on / after re-auth instead of where they were); each layer addresses a different race and skipping any one leaves a known leak path. v0.8.0 — smoke-e2e CI quirks: quirk 38 ZITADEL_FIRSTINSTANCE_PATPATH bind mount EACCES cascading into misleading unique_constraints_pkey; quirk 39 default password policy 4-class trap (openssl rand -hex is lowercase-only, dies with COMMA-VoaRj); quirk 40 zitadel-login healthcheck slow on small CI runners. v0.9.0 — real-browser smoke from sales_quote T150: quirk 41 idempotent bootstrap creates initial user grants but does NOT reconcile existing ones when YAML evolves — adding a new app + role leaves pre-existing seed user grants stuck at day-0 roleKeys, JWT ships missing the new role, symptom collides with quirks 11/12/13/36/28 family but a brand-new user via the same bootstrap works fine (that asymmetry is the diagnostic); cure is search-then-PUT via Quirk 8 pattern. Quirk 42 browser SPA → backend Express needs CORS or every preflight OPTIONS hits authJwt and 401s, mimicking the 401-storm family; key diagnostic asymmetry is curl -H "Authorization: Bearer <JWT>" returns 200 (no Origin → no preflight) while the browser fails 100%; MSW/supertest integration tests miss this entirely; cure is minimal CORS middleware as FIRST app-level middleware, short-circuiting OPTIONS with 204 + headers. Plus a new spa-recipes.md recipe — 'E2E browser tests (Playwright) against self-signed Zitadel' — covering ignoreHTTPSErrors: true (browser-side counterpart of Quirk 12's NODE_EXTRA_CA_CERTS), conditional username fill for login_hint-prefilled flows in Login UI v1, and the storageState+InMemoryWebStorage reuse caveat. v0.10.0 — admin-console mixed-content (quirk 43): Zitadel's own Console shows [unknown] Failed to fetch when the generated environment.json renders api: http:// while issuer: https:// — mixed content on the HTTPS page; root cause is --tlsMode disabled (the binary doesn't trust the proxy's X-Forwarded-Proto), compounded by docker start reviving a stale container's create-time args; cure is the full Quirk 15 triad + up -d --force-recreate (never docker start). References: migration-v2-to-v4.md (full upgrade runbook — pre-flight, schema migration, validation matrix, rollback) and api-v1-to-v2-mapping.md (Connect protocol mapping). Bundles working docker-compose.zitadel.yml, idempotent bootstrap-zitadel.ts (annotated with // v2 equivalent comments) and reset-zitadel.sh
ticket1.0.1DevelopmentJira ticket lifecycle for JRC Brasil projects integrated with Git — /ticket start | split | close | status. Per-repo project detection via .jira-project (PROJECT/BOARD/BRANCH_PREFIX, optional BASE_BRANCH) — no hardcoded project. Prefers acli + atlassian MCP (markdown comments, story-points/sprint custom fields acli can't write). v1.0.0 initial packaging, capturing two production-proven lessons: (1) transitions are PROJECT-SPECIFIC — discover via getTransitionsForJiraIssue and transition by id (RS: Em andamento→Aprovação→Finished; SQ: Em andamento→Concluído via id 31, no Aprovação), and acli --status matches the DESTINATION STATUS name so --status "Concluído" works (the transition name "Itens concluídos" fails) → MCP transition-by-id stays a robust alternative; (2) base branch is project-specific (optional BASE_BRANCH, default = repo's detected default branch) — don't assume develop (SQ/sales_quote uses main). v1.0.1 corrects the acli transition guidance (the v1.0.0 corollary was inverted)
whisper-preprocess1.0.0DevelopmentAudio→text pipeline (ffmpeg + OpenAI Whisper), 100% offline — extract, silence-removal, voice enhancement, segmentation, transcription (optional 2-language pass + auto-merge). v1.0.0 initial packaging of the local skill, capturing the anti-"picotamento" (choppy/pumping voice) lessons proven against a real 65-min recording with a low-volume, impaired (dysarthric) speaker: (1) the listenable *_enhanced.opus is now decoupled from the transcription chain — it used to inherit silenceremove + a fast-release acompressor + single-pass dynamic loudnorm AGC (three stacked gain-modulation/chopping sources); build_listenable() builds the listening copy from the original file at 48 kHz with no silence removal (continuous audio) and stable gain only (slow-release compressor + makeup + true-peak alimiter), no dynamic AGC; (2) a 2-pass loudnorm linear=true is not reliable — on a clipping source it silently reverts to Normalization Type: Dynamic (verified via print_format=summary), reintroducing the pump; (3) Opus adds inter-sample overshoot above the limiter ceiling (a -1.5 dBFS sample limit measured +1.3 dBTP after Opus) so the limiter needs headroom (--listen-limit 0.6) to keep the decoded true-peak below 0 dBFS — the old recipe clipped at +0.7 dBFS; (4) gentler silenceremove (detection=rms, window=0.025, stop_silence=0.5, stop_duration=2.0) helps Whisper on slow/quiet speakers while the -30dB threshold lesson is kept; afftdn stays opt-in/off (musical-noise risk, arnndn preferred). Listening copy now encoded -application audio 48k/64k (was narrowband voip)
ansible-docker-backup-restore1.2.0DevelopmentBackup and restore of a Linux server's Docker services with Ansible. Restore half: the silent compose-project-name trap (wrong prefix ⇒ brand-new empty volume, containers up, no error), an 8-step anti-overwrite guard that never deletes before the replacement is on disk and verified, SQL-dump guards that count rows instead of trusting schema presence, and a reverse-proxy/TLS gate — a config directory that is a volume survives a disk swap while a sibling that is not one dies, leaving an orphan directive that takes down every HTTPS vhost on the host the moment a container claims the domain. Backup half: the four ways a nightly backup dies without a sound — ignore_errors + no_log on the same task, the same root cause on a task without ignore_errors (aborts the play, looks like slowness), set -euo pipefail meeting tar rc=1 on a live database datadir (alphabetical volume order makes it look intermittent), and a fixed path that stopped existing after a restore. Ships a read-only freshness check (gaps in the date sequence, one dump per database, undersized dumps, volume coverage, retention arithmetic vs real free space). v1.1.0 adds the edges found bringing a sibling server that never had a backup online, with three stacked blockers: the SSH push path is a per-host prerequisite that can silently not exist (verify from each client, don't generalize) and must be granted least-privilege (a dedicated rrsync -wo key proven to open no shell, so the backup host can't become a lateral-movement pivot); a preflight that checks docker ps vs the inventory both ways (running-but-undeclared DB is dumped by no one and errors nowhere); bind mounts escape docker volume ls (DB dumps present gives false coverage while a bind-mounted datadir is missed); delegate_to on a shared authorized_keys from parallel hosts races (throttle: 1); and history rewrites can't scrub a weak password equal to a public identifier — only rotation can. v1.2.0 adds the lessons from a service everyone believed restored for four days that was in fact broken in two places, both of which passed a green playbook: a restored MySQL datadir carries each user's authentication plugin, not just the password, so caching_sha2_password refuses old clients (DBD::mysql, older mysqli, old JDBC) with the entirely correct password — and the compose flag --default-authentication-plugin does not fix it, since it only governs users created after it; the failure shows in one client and not another (the PHP UI stayed up while the Perl agent endpoint was down for a week), so verify every entry plane, because the one still standing masks the one that fell; proof-of-content is promoted from advice to role contract (verify_body_contains, empty by default) after the very domain cited in the reference spent four more days serving the web server's default page; a log error pointing at teardown code (rollback, finally, a destructor) is usually the error handler failing on top of the real fault, which is typically suppressed by default — raise verbosity before theorizing, and revert it in the same script; and lineinfile whose regexp matches nothing silently appends the line at end of file, landing outside every config block, inert, and reports changed
wsl-windows-onboarding0.4.0DevelopmentEnd-to-end onboarding of a Windows machine to WSL2 — diagnose/enable WSL, install rtk (rtk-ai/rtk), and safely migrate dev projects from C:\…\repos into the Linux filesystem. Built from a real migration and encodes the non-obvious gotchas: Docker users already have WSL2 and the docker-desktop distro is NOT your workspace; rtk is a zero-dependency Rust binary whose installer drops it in ~/.local/bin but does not add it to PATH (the #1 "rtk not found" cause), and one global install serves every project; git clone drops gitignored .env so migration uses rsync (keep .git and .env, exclude only rebuildable dirs); /mnt/c is slow and du over it hangs (use df, run rsync in background); validate by diffing file PATHS not counts (a .env inside node_modules/psl is a harmless false positive); copy → validate → delete, with the irreversible delete last via PowerShell Remove-Item; and after migrating a repo git status may show the whole tree modified with zero untracked files — a CRLF/LF + filemode artifact (autocrlf, 0777 from /mnt/c), diagnosed with git diff --ignore-cr-at-eol --stat + core.fileMode=false and fixed by renormalization, not panic. Bundles wsl-diagnose.sh (read-only) and migrate-repos.sh (rsync + validation, never deletes). v0.2.0 adds an optional Phase 4 shell setup (references/shell-setup.md, deep-research-validated): zsh + oh-my-zsh, default shell via chsh (wsl.conf can't set it), the ~/.bashrc config doesn't carry to ~/.zshrc trap (rtk PATH/aliases must be re-added; Ubuntu's empty /etc/zsh/zprofile makes the explicit export required), the Docker _docker completion warning fix, and JetBrains Mono Nerd Font + ligatures on Windows Terminal (font.features { liga: 1 })

Plugin Details

cicd — CI/CD Troubleshooting & Configuration

Unified troubleshooting and pipeline configuration for GitHub Actions, Docker, GHCR, and self-hosted runners. Auto-detects backend (Prisma/Biome) or frontend (Vite) projects and routes to specific references.

SkillDescription
/cicdTroubleshoots and configures CI/CD pipelines — 30+ scenarios, 50+ lessons learned (incl. dedicated self-hosted-runner-docker.md reference for myoung34/github-runner setups com §7 cobrindo o cenário deadlock-em-prod por RUNNER_REGISTRATION_TOKEN estática + a migração ACCESS_TOKEN in-place como fix durável (lesson 46), + §8/§9 (lessons 47–49) cobrindo crashloops ortogonais ao token — versão de binário deprecada e config stale reaproveitada, e cd-pipeline-pitfalls.md cobrindo 5 classes de cutover-prod bugs incluindo upstream pool poisoning por compose run orphans e §5 sobre container scripts escrevendo paths fora do WORKDIR — ENOENT mascarado por soft-failure que pinta yellow warning ambiente em todo deploy)

Highlights: project-type detection, tagged troubleshooting ([S] shared / [B] backend / [F] frontend), Jest OOM fixes, Biome 2.x migration, stale Docker image cache handling.

codereview — Automated Code Review

Stack-agnostic pre-PR code review built on The Zen of Python as a universal analysis framework. Five principles — readability, explicitness, simplicity, flatness, and error handling — applied as analysis lenses to any codebase. Now with model routing for 76-86% Opus token savings.

SkillDescription
/codereviewFull pre-PR review — diffs against base branch, severity-rated findings (CRITICAL → LOW), final grade (A-F). Uses haiku for git context, sonnet for per-file analysis, opus for cross-file review and report.
/codereview:coderabbit_prResolves AI review bot comments (CodeRabbit, Copilot, Gemini, Codex) on a GitHub PR — auto-detects reviewers, creates per-reviewer checklists, triages with severity recalibration, applies fixes, runs regression tests, resolves all GitHub conversations

Analysis layers: Bug Detection · Security · Secrets Detection (deterministic regex script + optional ggshield/gitleaks, always-on, blocks grade F) · Performance · Type Safety · Test Coverage · Documentation Sync · Race Conditions (TOCTOU) · Accessibility · Data Integrity

Model routing: Haiku (git/CLI) → Sonnet (per-file analysis, parallel) → Opus (cross-file review, report)

Framework presets: react (default) · vue · angular · node · dotnet · generic

deploy — Automated Deployments

Automated deployment commands for staging and production pipelines via CD.

CommandDescription
/deploy:stagingSyncs main ↔ develop, merges current branch, pushes to trigger CD Staging pipeline

Highlights: auto-detects branch flow (develop vs feature), pre-flight checks (ESLint, TypeScript, Jest), pipeline monitoring via gh run watch.

release — GitHub Release Automation

Auto-generates categorized release notes from git history and creates a GitHub Release via gh CLI.

CommandDescription
/release:release [VERSION] [--path DIR]Generates release notes and creates a GitHub Release

Multi-stack: C#/.NET · Node.js · Go · Rust · Python Monorepo: --path filter scopes commits to subdirectories Contributors: resolved via GitHub API with org membership cross-reference

statusline — Status Line Customization

Interactive wizard to configure Claude Code's status line — model info, context bar, git branch/PR state, cost, and 5h/weekly usage limits.

CommandDescription
/statusline:setupInteractive setup wizard — sections, colors, emojis, separator

12 composable sections: Model name · Context bar · Git branch · Project folder · Session cost · Duration · Lines changed · Token counts · Vim mode · 5h usage window · Weekly usage · PR state

Sections 10-12 (5h/weekly usage limits, PR state) are part of the recommended default set and degrade gracefully — usage limits appear only for Pro/Max subscribers, PR state only when the branch has an open PR.

Effort-level badge (v1.4.0): when effortLevel is set in ~/.claude/settings.json, the Model section shows it inline (e.g., 🤖 Opus 4.7 [high]). Re-read on every invocation — no regeneration needed when you toggle the value.

Cross-platform: Bash + PowerShell, no jq dependency, Windows/Git Bash compatible.

dotnet-wpf — .NET WPF Development Toolkit

Complete development toolkit for C#/.NET WPF desktop applications — from project setup to E2E testing.

SkillDescription
/dotnet-wpf:dotnet-desktop-setupConfigures and audits .NET desktop projects for Claude Code
/dotnet-wpf:dotnet-wpf-designFluent Design guide — layout patterns, typography, 90+ WPF-UI controls catalog, date validation traps, Grid row separators (FORM-004), multi-column form layouts, ContentDialog confirmation for destructive actions (CTRL-008)
/dotnet-wpf:dotnet-wpf-mvvmWinForms → WPF MVVM migration with CommunityToolkit.Mvvm and WPF-UI
/dotnet-wpf:dotnet-wpf-e2e-testingFlaUI + xUnit E2E testing — Page Objects, AutomationId patterns, CI/CD setup
dev-script — Local Dev Stack Launcher Generator

Generates a single-command development launcher for any project — dev.sh (bash, Linux/macOS) and dev.ps1 (PowerShell 5.1/7+, Windows). Detects the stack (compose files, monorepo workspaces, frontend/backend dev servers, IdP, mkcert posture, existing launcher) and emits an idempotent script that brings up Postgres, the IdP, the backend(s), and the frontend with colored per-service prefixes, per-component healthchecks, two-strategy port handling (find-next-free port discovery with per-subshell peer-coordination env vars for ports a foreign process might legitimately own, kill-and-reclaim with fuserlsofsspgrep fallback chain for orphans the script itself spawned), trap cleanup, and HTTPS-on-LAN via mkcert + Caddy when the SPA does OIDC PKCE.

SkillDescription
/dev-scriptWalks the project, confirms the plan, generates dev.sh and/or dev.ps1, updates .gitignore, prints onboarding for LAN clients

What it encodes (the gotchas painfully learned in JRC projects):

  • Vite ≥ 5 allowedHosts blocks non-localhost — wrap config without editing vite.config.ts
  • Node backend can't validate JWKS over self-signed HTTPS without NODE_EXTRA_CA_CERTS
  • Zitadel persists externalDomain on init — drift detection + --reset flag
  • Bootstrap idempotency vs 400 COMMAND-1m88i "No changes"
  • --tlsMode external triad (env vars + start flag) for TLS-terminating proxies
  • crypto.subtle outside secure contexts → signinRedirect silently fails
  • Process-group cleanup (setsid + kill -- -PGID) so Ctrl+C doesn't orphan children
  • Re-derive projectId/clientId from bootstrap.json on every boot — never hardcode
  • v0.4.0 Foreign port owner + strictPort silent-hang cascade (P17) — kill_stale_ports against a process the script can't kill silently fails, downstream Vite with strictPort: true hard-fails, parent wait keeps tracking surviving children → visually identical to a hang. Fix is port discovery + peer coordination instead of port reclaim
  • v0.5.0 CRLF .env reads (P18) — Windows/WSL CRLF appends \r to grep|cut values, so docker exec "$name\r" fails No such container and the healthcheck times out while every log line looks correct; fix is a tr -d '\r' read helper
  • v0.5.0 Cross-platform node_modules (P19) — a tree installed on Windows then run on WSL crashes Vite/swc/esbuild with Failed to load native binding (missing platform-optional binary); re-install on the target OS
  • v0.5.0 yarncmdtest collision (P20) — Corepack off by default → apt install yarn installs Debian's cmdtest (Parsing scenario file …); corepack enable shadows the impostor and the script resolves the package manager Corepack-aware

Cross-platform: Linux/macOS bash and Windows/cross-platform PowerShell — same flags, same semantics, idiomatic primitives in each.

zitadel-idp — Zitadel Self-Hosted OIDC Field Guide

Captures patterns and pitfalls discovered while integrating Zitadel v4.x self-hosted as the IdP for the JRC Brasil ERP. Read this skill BEFORE drafting Zitadel compose files, writing a Management API bootstrap, validating Zitadel JWTs, customizing the Login UI v1, or wiring an SPA via OIDC PKCE — it averages 1–3 hours saved per integration.

SkillDescription
zitadel-idpField guide with 43 documented quirks (v4-first with proto-aligned v4.15.0 examples, v2.66.x masterkey edge case, full v2.66→v4 upgrade runbook, Login UI v2 deploy bug + Path B mitigation, CD cutover survival kit, Console UI human-user creation pitfalls, production 401-storm hairpin NAT + 3-layer SPA defense, smoke-e2e CI plumbing checklist, real-browser smoke E2E gaps — seed user grant reconciliation + CORS preflight 401 + Playwright self-signed Zitadel recipe), drill-down references, and bundled working assets

Bundled references (references/): api-cheatsheet.md, api-v1-to-v2-mapping.md (NEW v0.3.0), branding.md, docker-compose-bootstrap.md, migration-v2-to-v4.md (NEW v0.3.0), spa-recipes.md, tenant-org-mapping.md, token-validation.md, troubleshooting.md.

Bundled assets: docker-compose.zitadel.yml (working FirstInstance + volume perms), bootstrap-zitadel.ts (idempotent Management API bootstrap with multi-app applications[] and env > YAML > hardcoded precedence for dynamic dev hosts), scripts/reset-zitadel.sh.

Highlights of the gotchas encoded:

  • FirstInstance env placement; v1/v2 API split; tenant → orgId mapping
  • JWT validation over self-signed HTTPS — NODE_EXTRA_CA_CERTS, createRemoteJWKSet traps, tlsMode external, x-zitadel-orgid
  • Silent-renew byte-match on redirect URIs; signinSilent boot-time recursion; StrictMode + closure cancelled flag locking SPA in "Verifying session…"
  • post_logout_redirect_uri invalid; InMemoryWebStorage + F5 trap; crypto.subtle PKCE secure-context requirement on LAN
  • Login UI v1 branding via privateLabelingSetting, custom_login_text, LANG-lg4DP, 405 on /assets/v1/orgs/me/policy/label/...
  • Idempotent bootstrap COMMAND-1m88i "No changes" and Org-8nfSr "Private Label Policy has not been changed"
  • 401 storm post --reset-zitadel from orphaned tsx watch / nodemon processes holding stale env+JWKS in heap
  • Multi-app YAML refactor: env vars from dev.sh must dominate static YAML when LAN host is dynamic (.sslip.io)

Scope: Zitadel v4.x self-hosted, OIDC-only (Login UI v1 primary; Login UI v2 deploy bug + Path B mitigation also covered). Out of scope: Zitadel Cloud, v3, SAML, federation IdPs.

ddd — Domain-Driven Design Toolkit

Language-agnostic DDD toolkit that audits a codebase for tactical/strategic violations and guides design. Synthesizes Evans, Vernon and modular-monolith practice.

SkillDescription
/dddAnalyzes the codebase for DDD violations, guides strategic design (event storming, context mapping, bounded-context canvas), and generates legacy→DDD migration specs

References: bounded-context-canvas.md (DDD Crew v5), ddd-crew-process.md (6-phase canonical sequence: Big Picture → Domain Message Flow → BC Canvas → Context Map → Design Level → ADRs), plus tactical/strategic pattern guides.

retrofit-skill — Apply Session Lessons to a Skill

Captures non-obvious lessons from the current session and applies them to a target skill, in one of two modes so the workflow matches where the skill lives.

CommandDescription
/retrofit-skill <skill>Lists session lessons, filters to the target skill, previews the diff, then applies it

Full mode (skill published in this marketplace): bumps plugin.json + marketplace.json, updates CHANGELOG and README, commits and pushes. Lean mode (local skill in another repo, e.g. <repo>/.claude/skills/<name>/): edits the files + a CHANGELOG entry and commits in that repo — no version bump or marketplace changes.

pdf-generation — PDF Template Design Toolkit

Designs PDF generation from reference templates — maps dynamic vs fixed fields, recommends a library with trade-offs, and architects modular sections with conditional columns and revision control.

SkillDescription
/pdf-generationAnalyzes a reference template (PDF/Excel), recommends a library (pdfmake, pdf-lib, PDFKit, Puppeteer, @react-pdf), and designs the section architecture

Production-proven pitfalls encoded: cell padding not discounted from widths (last column cut off on A4 with 8+ columns); Roboto fi/fl ligatures drop the f; addFonts() rejects AFM; header/footer in content[] vanish on page 2+; revision cache stale on layout change; SVG fills from a <style> block render blank unless inlined. Phase 6 Visual Verification (NON-NEGOTIABLE) — render and inspect every page, not just page 1.

ticket — Jira Ticket Lifecycle (Claude Code only)

Jira ticket lifecycle integrated with Git for JRC Brasil projects. Per-repo project detection via a .jira-project file (PROJECT/BOARD/BRANCH_PREFIX, optional BASE_BRANCH) — no hardcoded project. Prefers acli + the atlassian MCP.

CommandDescription
/ticket start | split | close | statusCreate issues/sub-issues + branches, split work, and close with an auto-generated summary

Encoded lessons: transitions are project-specific (discover via getTransitionsForJiraIssue, transition by id; acli --status matches the destination status name, not the transition name); the base branch is project-specific (optional BASE_BRANCH, don't assume develop).

whisper-preprocess — Offline Audio→Text Pipeline

Audio preprocessing + transcription pipeline (ffmpeg + OpenAI Whisper), 100% offline — extract, silence removal, voice enhancement, segmentation, and transcription (optional two-language pass + auto-merge).

SkillDescription
/whisper-preprocessRuns the full pipeline from a media file (MKV/MP4/WAV/M4A) to text

Anti-"picotamento" lessons (proven on a 65-min low-volume, dysarthric recording): the listenable *_enhanced.opus is decoupled from the transcription chain (stable gain only — no dynamic AGC or silence removal); a 2-pass loudnorm linear=true silently reverts to dynamic on clipping sources (compressor + limiter used instead); Opus inter-sample overshoot needs limiter headroom (--listen-limit 0.6) to keep the decoded true-peak below 0 dBFS.

ansible-docker-backup-restore — Backup & Restore of Dockerized Services via Ansible

Field guide for recovering a Linux server's Docker services from backup, and for keeping the backup that protects them actually alive. Both halves live in one skill because the incident that closes the loop is born on the seam: a restore renamed a container, the backup inventory did not follow in the same commit, and the nightly backup stopped completing — for days, with no alert.

SkillDescription
ansible-docker-backup-restore11 inviolable rules, a routing table into 7 references, and two mandatory gates — audit the vhost before any VIRTUAL_HOST, and no restore is done until the backup ran end to end with failed=0

Highlights: silent compose-project-name trap (wrong prefix creates an empty volume and the service comes up clean); 8-step anti-overwrite guard that fetches and verifies the replacement before deleting anything; find returning files: [] on an unreadable path being read as "empty, safe to overwrite"; generic service key becoming a shared-network DNS alias that resolves round-robin between two different databases; certificate PEMs surviving without the ACME client state; the four silent-death patterns of a backup pipeline; and a read-only check-backup-freshness.sh that flags gaps in the date sequence — the cheapest signal there is, and the one that would have caught the original incident on day one.

Agnostic by construction: no server, domain, container, volume or network address from any specific environment — the real cases are told by mechanism, with placeholders.

Auto-updates

For private repo auto-updates at startup, set a GitHub token with repo scope:

export GITHUB_TOKEN=ghp_xxxxxxxxxxxxxxxxxxxx

[!IMPORTANT] Generate a token at github.com/settings/tokens with the repo scope.

Team Distribution

Projects that clone this repo get automatic marketplace discovery via .claude/settings.json. When team members trust the folder, Claude Code prompts them to install the marketplace — no manual setup needed.

Modo de Utilizacao

Modo Cursor

Use este modo quando quiser trabalhar com as skills no Cursor (ativacao por contexto).

  1. Instale via python install.py e escolha Cursor ou Both.
  2. Escolha o destino:
    • ~/.cursor/skills/ (uso pessoal em todos os projetos), ou
    • .cursor/skills/ (uso compartilhado no projeto).
  3. Abra o projeto no Cursor e descreva a tarefa em linguagem natural.
  4. O agente aplicara automaticamente a skill mais adequada.

Exemplos de pedidos no chat:

Faz um code review das minhas alteracoes antes do PR.
Resolve os comentarios do CodeRabbit no PR #49.
Deploy para staging da branch atual.
Cria a release 2.1.0 com notas de versao.

Observacao: o plugin statusline e exclusivo do Claude Code.

Modo Claude Code

Use este modo quando quiser utilizar comandos e skills diretamente no Claude Code.

  1. Adicione o marketplace:
/plugin marketplace add j0ruge/skills_commands_manager
  1. Instale os plugins desejados:
/plugin install ansible-docker-backup-restore
/plugin install cicd
/plugin install codereview
/plugin install ddd
/plugin install deploy
/plugin install dev-script
/plugin install dotnet-wpf
/plugin install pdf-generation
/plugin install release
/plugin install retrofit-skill
/plugin install statusline
/plugin install ticket
/plugin install whisper-preprocess
/plugin install wsl-windows-onboarding
/plugin install zitadel-idp
  1. Execute os comandos/skills no Claude Code:
/deploy:staging
/release:release 2.1.0
/statusline:setup
/codereview
/codereview:coderabbit_pr 49

Para atualizar plugins instalados:

/plugin marketplace update

References

Claude Code

Cursor support (used to design install.py and the platforms field)


Proprietary — j0ruge. All rights reserved.

Rendered live from j0ruge/skills_commands_manager's GitHub README — not stored, always reflects the source repo.

15 Plugins

NameDescriptionCategorySource
ansible-docker-backup-restoreBack up and restore a Linux server's Docker services with Ansible — volume tars, pg_dump/mysqldump, snapshot-guarded overwrite, and proof the nightly backup still runs. Catches restores that look green but are broken: 200s serving the wrong page, auth-plugin drift in restored datadirs, silently dead backups. Triggers — ansible, playbook, backup, restore, disaster recovery, volume snapshot, mysqldump, retention.development./plugins/ansible-docker-backup-restore
wsl-windows-onboardingEnd-to-end onboarding of a Windows machine to WSL2 — diagnose/enable WSL, install rtk (rtk-ai/rtk), migrate dev projects from C:\Users\...\repos into the Linux filesystem with rsync that keeps .git and .env and validates before deleting, and optionally set up zsh + JetBrains Mono. Built from a real migration, so it knows the traps: rtk 'not found' because ~/.local/bin isn't on PATH, /mnt/c being slow, the whole git tree looking modified after migration (CRLF/filemode), and ~/.bashrc config not carrying to ~/.zshrc. Triggers — install rtk on Windows, move or migrate projects to WSL, set up WSL for development, access Windows files from Ubuntu, slow WSL builds, rtk not on PATH, zsh on WSL, JetBrains Mono ligatures, migrate repos with C: nearly full, one-repo-at-a-time copy-validate-delete, resume an interrupted WSL migration, Remove-Item nul Incorrect function.development./plugins/wsl-windows-onboarding
cicdGitHub Actions / Docker / GHCR pipeline troubleshooting and config — auto-routes by stack: backend Node (Prisma/Biome) or Django (gunicorn), plus frontend Vite. Deep self-hosted runner runbook (containerized myoung34 + systemd): registration-token chicken-and-egg, ACCESS_TOKEN/PAT migration, deprecated-binary & deleted-registration crashloops, stacked failures, silently-queued deploys. Also GHCR auth/TLS-handshake-timeout, reverse-proxy upstream poisoning, Django ALLOWED_HOSTS healthcheck-400. Triggers — CI/CD, GitHub Actions, GHCR auth, self-hosted runner, runner crashloop, registration token expired, runner version deprecated, compose run orphan, deploy queued, Django gunicorn.development./plugins/cicd
deployAutomated deployment commands — staging and production pipelines via CDdevelopment./plugins/deploy
codereviewPre-PR review with severity grading and model routing (haiku/sonnet/opus). Detects TOCTOU races, accessibility gaps, hardcoded secrets (GitGuardian-equivalent regex), docs/OpenAPI sync, contract drift in tests (exported const grew without its assertion updated), and **dead code** via a parallel whole-repo sweep — unused exports, orphaned files, unreachable code (knip/ts-prune/vulture or grep) — with cleanup recs. Final report always includes the Overall Grade table + Recommended Actions. Stack-agnostic with TypeScript/React defaults, dotnet preset. Triggers — code review, pre-PR, secrets scan, accessibility audit, contract drift, dead code, unused exports, cleanup, code health.quality./plugins/codereview
statuslineInteractive wizard to configure Claude Code status line — model (+ effort badge), context bar, git branch/PR, cost, and 5h/weekly usage limits. Cross-platform (Bash + PowerShell). Triggers — statusline, status bar, footer, rate limit, usage window, PR state.customization./plugins/statusline
releaseAutomated GitHub Release creation with categorized release notes from git history. Multi-stack (C#/.NET, Node.js, Go, Rust, Python) with --path filter for monorepo component releases. Contributor resolution via org membership cross-reference.development./plugins/release
dotnet-wpfC#/.NET WPF toolkit — project setup/audit, Fluent Design guide (90+ controls, layout troubleshooting, dark theme, branding), WinForms→WPF MVVM migration, and FlaUI E2E testing.development./plugins/dotnet-wpf
dddDomain-Driven Design toolkit — analyzes codebases for DDD violations, guides strategic design (event storming, context mapping), generates legacy→DDD migration specs. Language-agnostic. Synthesizes Evans + Vernon + modular-monolith practice.architecture./plugins/ddd
retrofit-skillApply non-obvious session lessons to a target skill in two modes — full (marketplace skill: bumps version, updates CHANGELOG/marketplace.json/README, commits and pushes) or lean (local skill in another repo: edits files + CHANGELOG and commits there, no bump or marketplace changes). Triggers — retrofit, skill-maintenance, session-lessons, lean-retrofit, local-skill.development./plugins/retrofit-skill
dev-scriptGenerates idempotent dev.sh / dev.ps1 launchers for the current stack — Compose orchestration, healthchecks, two-strategy port handling (find-next-free discovery with peer-coordination env vars for foreign-owned service ports / kill-and-reclaim with pgrep fallback for own orphans), HTTPS-on-LAN via mkcert+Caddy, boot-time sanity check. Encodes the gotchas learned in JRC projects (Vite allowedHosts, JWKS over self-signed HTTPS, --tlsMode external, runtime drift detection, P17 foreign-port-owner + strictPort silent-hang cascade, plus v0.5.0 Windows↔WSL migration traps — P18 CRLF .env reads corrupt grep|cut values, P19 cross-platform node_modules native-binding crash, P20 yarn↔cmdtest name collision / Corepack-aware package-manager resolution).development./plugins/dev-script
zitadel-idpSelf-hosted Zitadel v4 OIDC field guide — 43 documented quirks + working docker-compose, idempotent TypeScript bootstrap, and reset script. High-friction traps: FirstInstance env placement, JWT/JWKS over self-signed HTTPS, TLS-terminating reverse proxy (`--tlsMode external`) and the admin-console `Failed to fetch` mixed-content trap, Login UI v1/v2, v2.66→v4 upgrade, API v1→v2 mapping, silent-renew, 401-storm defenses, smoke-e2e CI. Triggers — zitadel, oidc self-hosted, silent-renew, JWKS, masterkey, v2.66→v4, api v1→v2, login-ui-v2, tlsMode external, console Failed to fetch, mixed content, smoke-e2e CI, Playwright self-signed Zitadel.development./plugins/zitadel-idp
pdf-generationPDF generation design toolkit — analyzes reference templates (PDF/Excel), maps dynamic vs fixed fields with browser preview, recommends libraries (pdfmake, pdf-lib, PDFKit, Puppeteer, @react-pdf) with trade-offs, designs modular section architecture with conditional columns, auto-generated observations, bold markup, and revision control. v1.2.0: three new production-proven pitfalls — cell padding NOT discounted from `widths` (last column silently cuts off A4 with 8+ cols, the most painful pdfmake gotcha); Roboto bundled fi/fl/ffi ligatures drop the f (fiscal→fscal) — v1.2.1 corrects the cause: pdfkit applies the `liga` substitution but fails to embed the glyph (bundled font is current, not old; confirm via SFNT parse; `@fontsource-variable/*` ships only .woff2, unusable by pdfmake); `addFonts()` silently rejects AFM (Helvetica AFM via pdfkit looks like it works but errors 500 on getBuffer). Plus Phase 6 Visual Verification (NON-NEGOTIABLE) — render bugs only surface in the rendered PDF, never in automated tests. v1.3.0: render and inspect EVERY page, not just page 1 — header/footer in `content[]` (vs the `header`/`footer` slots) render once and silently vanish on page 2+ (invisible in a 1-page test); conditional/optional field absence ≠ bug (populate the data to verify it renders); hash-by-input revision cache does NOT regenerate on layout/code changes (bust the cache before re-rendering). v1.4.0: vector-logo (SVG) handling — pdfmake renders SVG natively via the `{ svg, width }` node (no svg-to-pdfkit dependency; the common belief that pdfmake can't do SVG is wrong); an SVG whose fills come from a `<style>`/class block renders with NO color (black/blank) unless each `class` is inlined to a `fill=` attribute — silent, build and unit tests pass, only the visual render reveals it; ship a small default vector as a `.ts` string constant (not an `.svg` file) so it survives `tsc → dist` builds (which don't copy non-`.ts` files) and gitignored runtime asset dirs (which don't exist on a fresh deploy). Triggers — PDF generation, generate PDF, PDF template, PDF layout, pdfmake, commercial proposal PDF, invoice PDF, report PDF, pdfmake column overflow, pdfmake widths padding, Roboto ligature bug, pdfmake AFM rejection, pdfmake header not repeating, PDF multipage verification, PDF revision cache stale, pdfmake SVG logo, vector logo PDF, SVG logo blank/black, SVG fills not rendering, embed SVG as constant.development./plugins/pdf-generation
ticketJira ticket lifecycle for JRC Brasil projects, integrated with Git — create issues/sub-issues, branches, and close with an auto-generated summary. Commands: /ticket start, /ticket split, /ticket close, /ticket status. Project is detected per-repo via a `.jira-project` file (PROJECT/BOARD/BRANCH_PREFIX, optional BASE_BRANCH) — no hardcoded project. Prefers `acli` (Jira CLI) + the atlassian MCP. v1.0.0: initial packaging of the local skill, capturing two production-proven lessons — (1) transitions are PROJECT-SPECIFIC, not universal: discover them with `getTransitionsForJiraIssue` and transition by id; RS goes Em andamento→Aprovação→Finished while SQ goes Em andamento→Concluído (transition id 31, no Aprovação), and `acli --status` matches the DESTINATION STATUS name — `--status "Concluído"` works, while the transition name "Itens concluídos" fails (MCP transition-by-id stays a robust alternative; corrected in v1.0.1); (2) the base branch is project-specific (new optional `BASE_BRANCH`, default = repo's detected default branch) — do NOT assume `develop` (SQ/sales_quote uses `main`). Triggers — ticket, /ticket, Jira, criar issue, abrir ticket, fechar ticket, sub-issue, branch da issue, transição Jira, No allowed transitions found, story points, sprint, acli, projeto SQ, projeto RS.development./plugins/ticket
whisper-preprocessAudio preprocessing + transcription pipeline (ffmpeg + OpenAI Whisper), 100% offline — extract, silence-removal, voice enhancement, segmentation, transcription (optional 2-language pass + auto-merge). **v1.0.0** initial packaging of the local skill, capturing the anti-"picotamento" (choppy/pumping voice) lessons proven against a real 65-min recording with a low-volume, impaired (dysarthric) speaker: (1) the listenable `*_enhanced.opus` must be DECOUPLED from the transcription chain — it used to inherit `silenceremove` + a fast-release `acompressor` + single-pass dynamic `loudnorm` AGC, three stacked gain-modulation/chopping sources that flutter the voice; `build_listenable()` now builds the listening copy from the ORIGINAL file at 48 kHz with NO silence removal (continuous audio) and STABLE gain only (slow-release compressor + makeup + true-peak `alimiter`), no dynamic AGC; (2) a 2-pass `loudnorm linear=true` is NOT reliable — on a clipping source it silently reverts to `Normalization Type: Dynamic` (verified via `print_format=summary`), reintroducing the pump, so compressor+limiter is used instead; (3) Opus adds inter-sample overshoot ABOVE the limiter ceiling (a -1.5 dBFS sample limit measured +1.3 dBTP after Opus), so the limiter needs headroom (`--listen-limit 0.6`) to keep the decoded true-peak below 0 dBFS — the old recipe clipped at +0.7 dBFS; (4) gentler `silenceremove` (`detection=rms`, `window=0.025`, `stop_silence=0.5`, `stop_duration=2.0`) helps Whisper on slow/quiet speakers while the long-standing -30dB threshold lesson is kept, and `afftdn` stays opt-in/off (musical-noise risk; `arnndn` preferred when denoise is wanted). Also encodes the listening copy as `-application audio` 48k/64k (was narrowband `voip`). Triggers — transcribe audio/video, transcricao, Whisper, speech-to-text, remove silence, enhance audio, voz picotando/choppy in enhanced.opus, pumping/breathing audio, low-volume or impaired speaker, MKV/MP4/WAV/M4A to text.development./plugins/whisper-preprocess

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.