
Register runnable project commands with documented side effects and exit codes.
PostgreSQL schema, Liquibase with rollback, indexing, backups, RLS, pooling, and query tuning.
Author and wire Cursor hook scripts with documented exit codes and JSON contracts.
L1 child skill under security-reviewer: OWASP Top 10 checklist and Spring/Thymeleaf secure patterns. Auto-load with security-reviewer when Java/Spring files are in scope; used by security-auditor for Spring-deep reviews.
Manage .cursor/rules/*.mdc frontmatter, globs, alwaysApply, and deduplicated policy text.
Agent metrics, review learning, controlled prompt experiments, monthly reports, and human-gated pattern rollout.
Spring Boot coding standards, patterns, and conventions for this project. Uses SLF4J API with Log4j2 as the logging implementation. Loaded dynamically when implementing Java/Spring Boot code.
Maintain AGENTS.md roster and disabled.txt without deleting agent files without explicit approval.
Thymeleaf + Spring Boot UI conventions, fragment patterns, form handling, and accessibility standards for this project.
Read-only checklist for Jakarta Bean Validation on Spring API models (DTOs, request bodies). Produces a markdown report with PASS/FAIL; does not modify source files.
Architect playbook to scaffold Architecture Decision Records under docs/adr/ with consistent headings aligned to tasks/decisions.md and mermaid-diagrams ADR convention.
Correlated log analysis, safe auto-fixes, profiling, dumps, slow queries, and confidence-scored remediation.
springdoc/OpenAPI sync, runbooks, changelogs, migration guides, and architecture diagram updates.
Zeus-oriented read of tasks/lessons.md: cluster themes, surface duplicate prevention rules, and suggest consolidations. Default read-only; appends digest only with explicit user consent.
Mermaid diagram generation rules and patterns for the Architect agent. Covers flowcharts, sequence diagrams, ERDs, use case diagrams, and C4-style views for Spring Boot projects.
User stories, Given/When/Then acceptance criteria, edge cases, dependencies, estimates, debt prioritisation, and Jira linkage before dev handoff.
Parent security skill (workspace-wide): OWASP-oriented controls, secrets, deps, CI/Docker, auth, logging. Child skill: owasp-checklist (Spring/Java depth). Load this first whenever security-review rule or /cmd-review-project-security applies.
Create and maintain Cursor SKILL.md files under .cursor/skills with valid frontmatter and scoped updates.
QA-oriented playbook for verifying test coverage on new or changed code (JaCoCo / Maven Gradle) against project quality gate expectations. Read-only analysis instructions unless user authorizes runs.
Contract-first OpenAPI 3.0, DTOs, standard errors, pagination, filtering, versioning, rate limits, auth docs, Postman, and consumer contract tests.