skills/team/qrspi-questions/SKILL.md
QRSPI Questions phase -- surface what the agent does not know before any research or design begins. Use for "/qrspi-questions <feature>", "what don't we know about X", "surface unknowns for X", "open technical questions for X". Do NOT use to answer a question or for general Q&A -- this phase ASKS questions, it does not answer them. Do NOT use for the deprecated RPI workflow.
npx skillsauth add michaelalber/ai-toolkit qrspi-questionsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
"Judge a person by their questions rather than their answers." -- Adapted from Voltaire
The Questions phase is the first alignment gate of QRSPI. Before any codebase research or design,
the agent surfaces every unknown as a targeted technical question and STOPS for the human to
answer. A skipped question becomes a wrong assumption; a wrong assumption cascades into wrong
code. This phase makes the unknowns explicit and cheap to correct -- one edit in questions.md,
not a rewrite later.
Non-Negotiable Constraints:
questions.md -- the human answers inline before Research beginsquestions.md with progress and
tell the user to start a fresh session.PRE-FLIGHT
[ ] Determine the feature slug (kebab-case) and today's date
[ ] Feature folder = thoughts/shared/qrspi/YYYY-MM-DD-{slug}/ (create if absent)
[ ] If an ANSWERED questions.md already exists here, this phase is DONE -> route to /qrspi-research
SURFACE
Enumerate unknowns across every area the feature could touch:
data model · API contract · UI/UX · integration points · auth · testing · edge cases · migration
For each unknown, write a specific, answerable question -- never a vague prompt
Group questions by area; mark any that BLOCK design as [BLOCKING]
WRITE
Create thoughts/shared/qrspi/YYYY-MM-DD-{slug}/questions.md
Use references/questions-template.md
Set status: awaiting-answers
STOP
Tell the user: answer the questions inline in questions.md, then start a NEW session
and run /qrspi-research. Do NOT proceed to Research yourself.
Exit criteria: questions.md written with status awaiting-answers; questions cover all
relevant areas with blocking items flagged; user told to answer inline and start a fresh Research
session.
<qrspi-questions-state>
phase: PRE-FLIGHT | SURFACE | WRITE | STOP | COMPLETE
feature_slug: [kebab-slug]
feature_folder: thoughts/shared/qrspi/YYYY-MM-DD-{slug}/
areas_covered: [data | api | ui | integration | auth | testing | edge-cases | migration]
question_count: [count]
blocking_count: [count]
context_budget: under-40 | approaching-60 | checkpoint-now
status: awaiting-answers | complete
</qrspi-questions-state>
See references/questions-template.md for the full questions.md structure and frontmatter.
| Skill | Relationship |
|-------|-------------|
| qrspi-research | Next phase. Consumes the ANSWERED questions.md as its neutral topic source. |
| qrspi-spec | Downstream. Design decisions trace back to the answers captured here. |
| spec-coach | Use instead when you want an interactive design conversation, not a one-shot question dump. |
| grill-me | Use instead to be quizzed and challenged; qrspi-questions surfaces unknowns FOR the human to answer. |
development
Interviews the user relentlessly about a plan, decision, or idea — one question at a time, each with a recommended answer. Shared engine behind "grill-me" and "grill-with-docs". Use on any "grill" trigger phrase or to stress-test thinking. Do NOT use to build the plan; it ends at shared understanding, not implementation.
testing
Runs a relentless interview to sharpen a plan or design, capturing the decisions as ADRs and a glossary along the way. Use when the user wants to be grilled AND wants the session to leave durable domain documentation behind. Do NOT use for a throwaway stress-test with no artifacts; use grill-me instead.
tools
OWASP-based security review of Vue/TypeScript front-ends. Detects framework (Vite/Vue CLI/Nuxt), entry points, and data flows; scans the OWASP Top 10 (2025) mapped to Vue client-side risks (raw-HTML XSS via v-html, URL/protocol injection, bundled secrets, insecure token storage, dependency CVEs, missing CSP, open redirects, router guard bypass); emits an exec summary plus graded findings. Use to audit Vue for vulnerabilities. Not for architecture grading (vue-architecture-checklist).
tools
Analyzes legacy Vue codebases and produces actionable modernization plans. Primary migration paths include Options API to Composition API, Vue 2 to Vue 3, Vue CLI to Vite, JavaScript to TypeScript, Vue Test Utils/Karma/Mocha to Vitest + Vue Testing Library, legacy Vuex to Pinia, and removed-in-Vue-3 pattern cleanup (filters, event bus, `$listeners`). Does NOT perform the migration — assesses, quantifies risk, and plans.