Skip to content
Back to skills

Stack Rules

ASecurity

Enforces this kit's standards for Next.js, React, Supabase and Vercel work. Use when writing or reviewing UI components, API routes, database schemas or queries, deployment config, styling, animations, accessibility, performance, state management or tests, or when running a pre-ship audit. Covers shadcn/ui patterns, Zod-validated App Router routes, RLS policies, Core Web Vitals budgets and WCAG contrast.

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentstypescriptpythonreactnextjsawstestinggitapidatabasesecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 14 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add calebnewtonusc/Chewbacca --skill stack-rules --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Stack Rules?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Stack Rules
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/calebnewtonusc-stack-rules/badge)](https://www.skillsdirectory.com/skills/calebnewtonusc-stack-rules)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: stack-rules
description: "Enforces this kit's standards for Next.js, React, Supabase and Vercel work. Use when writing or reviewing UI components, API routes, database schemas or queries, deployment config, styling, animations, accessibility, performance, state management or tests, or when running a pre-ship audit. Covers shadcn/ui patterns, Zod-validated App Router routes, RLS policies, Core Web Vitals budgets and WCAG contrast."
---

# Stack rules

Twelve standards files for the stack this kit assumes. They load only when the
work actually touches the relevant area, which is the point: importing all of
them on every session costs roughly 12,500 tokens, and a Python service that
will never render a button should not pay for the Tailwind rules.

The six genuinely universal standards (git, security, writing, naming,
typescript, review-discipline) are not here. Those are `@`-imported by
`CLAUDE.md` and always in context, at about 3,700 tokens.

## Which file to read

Read the specific file before writing code in its area. Do not read all twelve.

| Working on                                        | Read                           |
| ------------------------------------------------- | ------------------------------ |
| React components, shadcn/ui, loading/empty states | `references/components.md`     |
| API routes, Zod validation, error shapes          | `references/api.md`            |
| Supabase schema, RLS, migrations, queries         | `references/database.md`       |
| Vercel deploys, env vars, pre-deploy checks       | `references/deployment.md`     |
| Color, typography, spacing, the visual system     | `references/design.md`         |
| Images, fonts, bundle size, Core Web Vitals       | `references/performance.md`    |
| React Query, URL state, Zustand, form state       | `references/state.md`          |
| Semantic HTML, focus, ARIA, WCAG contrast         | `references/accessibility.md`  |
| Scroll animations, parallax, reveal effects       | `references/scroll-effects.md` |
| Unit, integration, and E2E tests                  | `references/testing.md`        |
| Hick's, Fitts's, Miller's, layout decisions       | `references/ux-laws.md`        |
| Pre-ship audit across all six lenses              | `references/audit.md`          |

## How to apply them

These are standards, not suggestions. When a file says "never build a custom
button, use shadcn/ui," that is the expected output, not one option among
several. If a rule genuinely does not fit the project, say so and explain why
rather than quietly ignoring it.

When a task spans areas, read each relevant file. Building a settings page that
saves to Supabase means `components.md`, `state.md`, and `database.md`, plus
`accessibility.md` before it ships.

Files in this skill

  • SKILL.md2.7 KB
  • evals/evals.json833 B
  • references/accessibility.md3 KB
  • references/api.md3.1 KB
  • references/audit.md3.2 KB
  • references/components.md4.7 KB
  • references/database.md3.5 KB
  • references/deployment.md2.4 KB
  • references/design.md6 KB
  • references/performance.md3.7 KB
  • references/scroll-effects.md7.5 KB
  • references/state.md4.3 KB
  • references/testing.md1.9 KB
  • references/ux-laws.md5.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…