backend-design
Elite Tier Backend standards, including Vertical Slice Architecture, Zero Trust Security, and…
The Foundation Skill. LLM Firewall + 2025 Security + Cross-Skill Coordination. Use for ALL code output - prevents hallucinations, enforces security, ensures quality.
$ npx -y skills add xenitv1/claude-code-maestro --skill clean-code --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/clean-codeContext preview
The summary Claude sees to decide when to auto-load this skill.
The Foundation Skill. LLM Firewall + 2025 Security + Cross-Skill Coordination. Use for ALL code output - prevents hallucinations, enforces security, ensures quality.
name: clean-code description: The Foundation Skill. LLM Firewall + 2025 Security + Cross-Skill Coordination. Use for ALL code output - prevents hallucinations, enforces security, ensures quality.
<domain_overview>
> **Philosophy:** This skill is the FOUNDATION - it applies to ALL other skills. Every piece of code must pass these gates. **ALGORITHMIC ELEGANCE MANDATE (CRITICAL):** Never prioritize "clever" code over readable, intent-revealing engineering. AI-generated code often fails by introducing unnecessary abstractions or using vague naming conventions that obscure logic. You MUST use intent-revealing names for every variable and function. Any implementation that increases cognitive complexity without a proportional gain in performance or scalability must be rejected. Avoid "Hype-Driven Development"—proven patterns trump trending but unstable frameworks. </domain_overview> <iron_laws>
1. NO HALLUCINATED PACKAGES - Verify before import 2. NO LAZY PLACEHOLDERS - Code must be runnable 3. NO SECURITY SHORTCUTS - Production-ready defaults 4. NO OVER-ENGINEERING - Simplest solution first
</iron_laws> <security_protocols>
LLMs hallucinate packages that sound real but don't exist. 1. **Verify before import** - `npm search` or `pip show` for unfamiliar packages 2. **Prefer battle-tested** - lodash, date-fns, zod over obscure alternatives 3. **Check npm audit / pip-audit** before adding new dependencies 4. **Pin versions** in production - no `^` or `~` for critical deps **2025 AI Package Risks:**
**Frontend Security:** | Forbidden | Required | |-----------|----------| | `dangerouslySetInnerHTML` | DOMPurify sanitization | | Inline event handlers | Event delegation | | `eval()`, `new Function()` | Static code only | | Storing tokens in localStorage | httpOnly cookies | **Backend Security:** | Forbidden | Required | |-----------|----------| | `CORS: *` | Explicit origin whitelist | | Raw SQL strings | Parameterized queries | | `chmod 777` | Principle of least privilege | | Hardcoded secrets | Environment variables + validation | **API Security (2025):**
</security_protocols> <modularity_and_placeholder_rules>
**Forbidden Patterns:**
// ❌ BANNED
// TODO: Implement this
// ... logic goes here
function placeholder() { }
throw new Error('Not implemented');**Required:**
**The 50/300 Rule:**
**SOLID Principles:** | Principle | Quick Check | |-----------|-------------| | **S**ingle Responsibility | Does this do ONE thing? | | **O**pen/Closed | Can I extend without modifying? | | **L**iskov Substitution | Can subtypes replace parent? | | **I**nterface Segregation | Are interfaces minimal? | | **D**ependency Inversion | Do I depend on abstractions? | </modularity_and_placeholder_rules> <complexity_and_dependencies>
**Native First:**
// ❌ Don't install is-odd npm install is-odd // ✅ Use native const isOdd = n => n % 2 !== 0;
**Anti-Patterns:**
**YAGNI:** You Aren't Gonna Need It. Build for today's requirements.
**Freshness Check:**
npm outdated # Check for updates npm audit # Check for vulnerabilities
**The CVE Brake:**
**2025 Recommended:** | Category | Recommended | |----------|-------------| | Validation | zod, valibot | | HTTP | ky, ofetch | | State | zustand, jotai | | ORM | drizzle, prisma | | Auth | lucia, better-auth | </complexity_and_dependencies> <ai_era_protocols>
**When Building AI Features:** 1. **Validate AI outputs** - Never trust raw LLM responses 2. **Rate limit AI calls** - Prevent cost explosions 3. **Sanitize before display** - AI can generate malicious content 4. **Log AI interactions** - For debugging and compliance **When AI is Writing Code:** 1. **Verify imports exist** - AI hallucinates packages 2. **Check types are correct** - AI guesses at APIs 3. **Test edge cases** - AI misses boundary conditions 4. **Review security** - AI takes shortcuts </ai_era_protocols> <audit_and_reference>
Before committing ANY code:
---
| When Using... | Clean Code Adds... | |---------------|-------------------| | `@frontend-design` | Security defaults, no eval, CSP awareness | | `@backend-design` | Input validation, no raw SQL, Zero Trust | | `@tdd-mastery` | No placeholders (tests enforce completeness) | | `@planning-mastery` | Modularity guides task breakdown | | `@brainstorming` | SOLID/YAGNI guide architecture decisions | | `@debug-mastery` | Logging standards, no silent failures | </audit_and_reference>
Elite-tier orchestration framework for Claude Code CLI. Supercharges AI development through specialized agents, modular skills, intelligent hooks, and persistent memory systems. Author: xenitV1 • X/Twitter Philosophy: "Why over How.
Repo: xenitv1/claude-code-maestro
Elite Tier Backend standards, including Vertical Slice Architecture, Zero Trust Security, and…
Design-first methodology. Explore user intent, requirements and design before implementation.…
Master specialized skill for building 2025/2026-grade browser extensions. Deep expertise in…
Systematic debugging methodology with 4-phase process, root cause tracing, and elite…
Elite Tier Web UI standards, including pixel-perfect retro aesthetics, immersive layouts, and…
Create isolated git workspaces for feature development. Smart directory selection, safety…