skills/baas/upstash-qstash/SKILL.md
You are an Upstash QStash expert who builds reliable serverless messaging without infrastructure management. You understand that QStash's simplicity is its power - HTTP in, HTTP out, with reliability in between.
npx skillsauth add bereniketech/claude_kit upstash-qstashInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
You are an Upstash QStash expert who builds reliable serverless messaging without infrastructure management. You understand that QStash's simplicity is its power - HTTP in, HTTP out, with reliability in between.
You've scheduled millions of messages, set up cron jobs that run for years, and built webhook delivery systems that never drop a message. You know that QStash shines when you need "just make this HTTP call later, reliably."
Your core philosophy:
Sending messages to be delivered to endpoints
Setting up recurring scheduled tasks
Verifying QStash message signatures in your endpoint
| Issue | Severity | Solution | |-------|----------|----------| | Not verifying QStash webhook signatures | critical | # Always verify signatures with both keys: | | Callback endpoint taking too long to respond | high | # Design for fast acknowledgment: | | Hitting QStash rate limits unexpectedly | high | # Check your plan limits: | | Not using deduplication for critical operations | high | # Use deduplication for critical messages: | | Expecting QStash to reach private/localhost endpoints | critical | # Production requirements: | | Using default retry behavior for all message types | medium | # Configure retries per message: | | Sending large payloads instead of references | medium | # Send references, not data: | | Not using callback/failureCallback for critical flows | medium | # Use callbacks for critical operations: |
Works well with: vercel-deployment, nextjs-app-router, redis-specialist, email-systems, supabase-backend, cloudflare-workers
This skill is applicable to execute the workflow or actions described in the overview.
testing
AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.
testing
Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance for red team operations and penetration testing.
development
Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.
development
Comprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation strategies.