framework-compliance-t…
Make a cloud account compliant with a security or industry framework using Prowler Cloud.
Keeps product-tour definitions aligned with the UI features they describe. Trigger: When modifying UI components that have associated tours, editing tour definition files, or renaming data-tour-id attributes.
$ npx -y skills add prowler-cloud/prowler --skill prowler-tour --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/prowler-tourContext preview
The summary Claude sees to decide when to auto-load this skill.
Keeps product-tour definitions aligned with the UI features they describe. Trigger: When modifying UI components that have associated tours, editing tour definition files, or renaming data-tour-id attributes.
name: prowler-tour
description: >
Keeps product-tour definitions aligned with the UI features they describe.
Trigger: When modifying UI components that have associated tours, editing tour
definition files, or renaming data-tour-id attributes.
license: Apache-2.0
metadata:
author: prowler-cloud
version: "1.0"
scope: [root, ui]
auto_invoke:
- "Editing a UI file containing data-tour-id attributes"
- "Adding, updating, or removing a tour definition (*.tour.ts)"
- "Renaming or removing a data-tour-id attribute value"
- "Changing button labels or section headings on a tour-covered page"
- "Restructuring routes or layouts covered by a tour"
allowed-tools: Read, Glob, Grep**Report-only.** This skill never edits tour files or UI files; it inspects the change, reports drift it finds between tours and the covered UI, and recommends actions for the developer to apply.
Run this check first. Most UI edits are not tour-related — exit cheaply.
1. Glob `ui/lib/tours/*.tour.ts`. 2. For each tour, check whether any `coversFiles` glob pattern matches any file in the current change. 3. If no tour matches, respond **exactly**:
> No tour affected — skipping alignment check
and exit. Do not proceed to the checklist. 4. If at least one tour matches, continue to "Drift checklist" for that tour.
For each affected tour, evaluate every item. Skip items that obviously do not apply, but list explicitly which items were checked.
1. **Orphan selectors** — every step's `target` (which composes to `data-tour-id="<tour-id>-<step.target>"`) must resolve to a real element in the codebase. Grep `ui/` for the expected attribute value; report any step whose target is missing. 2. **Renamed selectors** — a `data-tour-id` attribute was edited in this change. Match it back to any tour step referencing the old value. 3. **Outdated copy** — a popover `title`/`description` references a button label, heading, or term that no longer exists on the covered page. 4. **Obsolete steps** — a step describes a section, panel, or workflow that was removed. 5. **Missing steps** — a new feature was added on the covered surface without a corresponding step (e.g. a new panel, a new primary action, a new wizard stage). 6. **Reordered flow** — the user's path through the feature changed (e.g. query builder moved before scan selection) and the step order no longer reflects it.
Apply per tour after listing drift:
copy, rename a `data-tour-id` selector while keeping the same step, swap one screenshot for another, tighten wording.
Examples: a new step was added or removed; the order changed; an anchored target was retargeted to a different panel; the tour now covers a new feature on the surface.
When in doubt, ask: "Would a user who already saw the previous version miss something useful by not seeing this one?" If yes, bump.
When emitting a report, follow the exact structure in `references/output-format.md`. The structure is mandatory because the report is consumed downstream and tolerates no field reordering.
decision — the developer makes it, not the skill.
in the current change. Stick to the early-exit rule.
emitting a report).
under `ui/lib/tours/`.
Prowler is the world’s most widely used Open-Source Cloud Security Platform that automates security and compliance across any cloud environment.
Repo: prowler-cloud/prowler
Make a cloud account compliant with a security or industry framework using Prowler Cloud.
Vercel AI SDK 5 patterns. Trigger: When building AI features with AI SDK v5 (chat, streaming, tools/function calling, UIMessage parts), including migration…
Django REST Framework patterns. Trigger: When implementing generic DRF APIs (ViewSets, serializers, routers, permissions, filtersets). For Prowler API…
Reviews Django migration files for PostgreSQL best practices specific to Prowler. Trigger: When creating migrations, running makemigrations/pgmakemigrations,…
Create and maintain GitHub Agentic Workflows (gh-aw) for Prowler. Trigger: When creating agentic workflows, modifying gh-aw frontmatter, configuring…
Strict JSON:API v1.1 specification compliance. Trigger: When creating or modifying API endpoints, reviewing API responses, or validating JSON:API compliance.