digitalocean-app-platform
Lints DigitalOcean App Platform app specs (app.yaml / doctl apps spec JSON / digitalocean_app Terraform) for security, reliability, correctness, and sizing anti-patterns — plaintext secrets, missing health checks, single-instance services, dev databases in production, port mismatches, overlapping ingress routes, conflicting git/image sources, deprecated routes, unknown instance sizes, and app/database region mismatch. Use when working with DigitalOcean App Platform, app.yaml, .do/app.yaml, doctl apps, the digitalocean_app Terraform resource, or reviewing an App Platform deployment for problems.
What this skill does
# DigitalOcean App Platform
Reviews App Platform app specs for the mistakes that cause downtime, leaked
secrets, and broken routing. Ships a stdlib-only validator, `do_app_spec_lint.py`,
that ingests the spec as JSON (recommended), the block-YAML DO emits, or the
`digitalocean_app` Terraform resource, and reports findings with a rule id,
severity, and a one-line fix.
## When to invoke
- Reviewing or authoring an `app.yaml` / `.do/app.yaml` / `digitalocean_app`.
- A service has downtime on deploy or flaps with no warning (health check / HA).
- DigitalOcean warns that `routes` is deprecated.
- A credential may be sitting in an env `value` in plaintext.
- Ingress routing behaves unexpectedly (overlapping prefixes).
## Cross-cutting rules
1. **Prefer JSON input.** `doctl apps spec get <app-id> --format json` is the
most reliable input; the YAML path is a subset parser and rejects anchors,
flow collections, and folded/literal scalars.
2. **Never put a literal secret in an env `value`.** Use `type: SECRET` and a
`${VAR}` substitution. Values containing `${...}` (GitHub secrets, `${db.X}`
bindable refs, `${APP_URL}` app-wide vars) are references, not literals.
3. **The app spec is the source of truth.** App Platform reconciles to the spec
on every deploy; fix the spec, not the running app.
## Running the validator
```bash
# JSON (recommended)
doctl apps spec get <app-id> --format json > spec.json
python3 scripts/do_app_spec_lint.py spec.json
# YAML subset, or Terraform — format auto-detected by extension/content
python3 scripts/do_app_spec_lint.py .do/app.yaml
python3 scripts/do_app_spec_lint.py main.tf
# machine-readable
python3 scripts/do_app_spec_lint.py spec.json --format json
```
Exit 0 = clean or warnings only; 1 = at least one error-severity finding;
2 = unreadable/unparseable input.
## Checks
- **Secrets** — `secret-not-encrypted` (literal secret with type != SECRET),
`secret-build-scope` (SECRET scoped RUN_AND_BUILD_TIME leaks into the build).
- **Reliability** — `no-health-check`, `single-instance` (one instance, no
autoscaling), `dev-db-as-prod` (database with production: false).
- **Correctness** — `port-mismatch`, `route-overlap`, `source-conflict` (both
git and image), `deprecated-routes`.
- **Sizing** — `unknown-instance-slug`, `db-region-mismatch`.
## Proactive triggers
- env `value` is a literal API key/token/password (type != SECRET) → flag
`secret-not-encrypted`; move to `type: SECRET` + `${VAR}`.
- a `service` has `instance_count: 1` and no `autoscaling` → warn single point
of failure.
- a `service` has no `health_check.http_path` → warn deploys can't detect
unhealthy instances.
- both a git source and an `image` on one component → flag `source-conflict`.
- component-level `routes` present → recommend `spec.ingress.rules`.
- `production: false` on a database backing real traffic → warn dev database.
Related in Image & Video
watch
IncludedWatch a video (URL or local path). Downloads with yt-dlp, extracts auto-scaled frames with ffmpeg, pulls the transcript from captions (or Whisper API fallback), and hands the result to Claude so it can answer questions about what's in the video.
physical-ai-defect-image-generation
IncludedUse when the user wants to orchestrate defect image generation, run associated setup, or handle outputs on OSMO. The Day 0 path handles cold-start with USD-to-ROI, image-edit augmentation, and AnomalyGen to create initial PCBA datasets. The Day 1 path performs inference and labeling on real images. This skill helps with first-time asset setup, creation of finetuning checkpoints, and configuring deployment. Trigger keywords: defect image generation, dig workflow, dig pipeline, defect image detection workflow, aoi pipeline, aoi anomalygen, usd2roi anomalygen, day 0 pcba, day 1 pcba, day 1 real-photo alignment, day 1 manual roi, metal surface anomaly, glass defect, anomalygen finetune, setup_pcb, setup_metal, setup_glass, setup_pretrained, dig setup, dig datasets, dig pretrained checkpoint, dig image-edit endpoint.
accelint-react-best-practices
IncludedReact performance optimization and best practices. ALWAYS use this skill when working with any React code - writing components, hooks, JSX; refactoring; optimizing re-renders, memoization, state management; reviewing for performance; fixing hydration mismatches; debugging infinite re-renders, stale closures, input focus loss, animations restarting; preventing remounting; implementing transitions, lazy initialization, effect dependencies. Even simple React tasks benefit from these patterns. Covers React 19+ (useEffectEvent, Activity, ref props). Triggers - useEffect, useState, useMemo, useCallback, memo, inline components, nested components, components inside components, re-render, performance, hydration, SSR, Next.js, useDeferredValue, combined hooks.
elevenlabs-agents
IncludedBuild conversational AI voice agents with ElevenLabs Platform using React, JavaScript, React Native, or Swift SDKs. Configure agents, tools (client/server/MCP), RAG knowledge bases, multi-voice, and Scribe real-time STT. Use when: building voice chat interfaces, implementing AI phone agents with Twilio, configuring agent workflows or tools, adding RAG knowledge bases, testing with CLI "agents as code", or troubleshooting deprecated @11labs packages, Android audio cutoff, CSP violations, dynamic variables, or WebRTC config. Keywords: ElevenLabs Agents, ElevenLabs voice agents, AI voice agents, conversational AI, @elevenlabs/react, @elevenlabs/client, @elevenlabs/react-native, @elevenlabs/elevenlabs-js, @elevenlabs/agents-cli, elevenlabs SDK, voice AI, TTS, text-to-speech, ASR, speech recognition, turn-taking model, WebRTC voice, WebSocket voice, ElevenLabs conversation, agent system prompt, agent tools, agent knowledge base, RAG voice agents, multi-voice agents, pronunciation dictionary, voice speed control, elevenlabs scribe, @11labs deprecated, Android audio cutoff, CSP violation elevenlabs, dynamic variables elevenlabs, case-sensitive tool names, webhook authentication
humanizer
IncludedHumanize AI-generated text by detecting and removing patterns typical of LLM output. Rewrites text to sound natural, specific, and human. Uses 28 pattern detectors, 560+ AI vocabulary terms across 3 tiers, and statistical analysis (burstiness, type-token ratio, readability) for comprehensive detection. Use when asked to humanize text, de-AI writing, make content sound more natural/human, review writing for AI patterns, score text for AI detection, or improve AI-generated drafts. Covers content, language, style, communication, and filler categories.
generating-mermaid-diagrams
IncludedSalesforce architecture diagrams using Mermaid with ASCII fallback. Use this skill when generating text-based diagrams for Salesforce architecture, OAuth flows, ERDs, integration sequences, or Agentforce structure. TRIGGER when: user says "diagram", "visualize", "ERD", or asks for sequence diagrams, flowcharts, class diagrams, or architecture visualizations in Mermaid. DO NOT TRIGGER when: user wants PNG/SVG image output (use generating-visual-diagrams), or asks about non-Salesforce systems.