frontend-development — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited frontend-development (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Project-specific patterns for React/Next.js/TypeScript frontend work.
Start with Server Components. Only add 'use client' when you need interactivity, state, or browser APIs. Extract only the interactive leaf — not the entire page or section.
Types, hooks, and utilities that serve one feature live in that feature's directory. Only truly shared code goes in global directories.
Compose existing components rather than adding props/variants. shadcn/ui components are meant to be copied and modified. Build up from primitives.
Server fetches data and passes it as props. Client components handle interactions and call server actions. Never fetch in client components what could be fetched on the server.
'use client' does NOT mean "runs only in the browser" — it runs on the server during SSR too. It means "include in the client bundle." Putting secrets or DB calls in a 'use client' file will leak them.children props instead.useEffect with empty deps fires AFTER paint — use useLayoutEffect for DOM measurements that affect layout, but never in Server Components.fetch() caches by default in App Router. Add { cache: 'no-store' } or revalidate: 0 for data that must be fresh. Forgetting this causes stale data bugs that only appear in production. bg-${color}-500 ` will be missing. Use complete class names or safelist them.key prop on mapped elements must be stable and unique. Using array index as key causes subtle bugs when list items are reordered, inserted, or deleted.useSearchParams() requires a <Suspense> boundary in Next.js App Router or the entire page becomes client-rendered.npx shadcn-ui add, the component lives in YOUR codebase — modify it directly, don't wrap it.register() returns a ref — don't also pass your own ref to the same input without merging them.async Server Components that throw redirect() or notFound() must NOT be wrapped in try/catch — these work by throwing special errors that Next.js catches upstream.'use client' when you hit a walllogin-form.tsx not form.tsx. Must be grep-findable.| When you need... | Read |
|---|---|
| File naming, imports, exports | conventions.md |
| Next.js App Router patterns | overview.md |
| React component patterns | overview.md |
| TypeScript project patterns | typescript.md |
| shadcn/ui + Dice UI usage | shadcn.md |
| Tailwind configuration | tailwind.md |
| Data fetching (tRPC, TanStack, axios) | overview.md |
| Biome/linter config | biome.md |
For general framework docs beyond project-specific patterns, consult:
| Framework | URL |
|---|---|
| Next.js | https://nextjs.org/docs |
| React | https://react.dev |
| TypeScript | https://www.typescriptlang.org/docs |
| Tailwind CSS | https://tailwindcss.com/docs |
| shadcn/ui | https://ui.shadcn.com/docs |
| Dice UI | https://www.diceui.com/docs |
| TanStack Query | https://tanstack.com/query/latest/docs |
| tRPC | https://trpc.io/docs |
| Zustand | https://zustand.docs.pmnd.rs |
| React Hook Form | https://react-hook-form.com |
| Zod | https://zod.dev |
| Biome | https://biomejs.dev |
| nuqs | https://nuqs.47ng.com |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.