Affaan Mustafa

Affaan Mustafa

/affaan-m
Itô·San Francisco, CA / Bellevue, WA

Institutionalizing prediction markets @Ito-Markets | B={(eᵢ,wᵢ)}; Vᴮ=Σᵢwᵢℙα(eᵢ=1) | OSS meta-harness for AI agents @ECC-Tools

50 skills
security-review
Passed all 3 security checks
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
·09.9k
golang-patterns
Passed all 3 security checks
Idiomatic Go patterns, best practices, and conventions for building robust, efficient, and maintainable Go applications.
·09k
coding-standards
Passed all 3 security checks
Baseline cross-project coding conventions for naming, readability, immutability, and code-quality review. Use detailed frontend or backend skills for framework-specific patterns.
·08k
frontend-patterns
Passed all 3 security checks
Frontend development patterns for React, Next.js, state management, performance optimization, and UI best practices.
·07.9k
backend-patterns
Passed all 3 security checks
Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.
·07.9k
golang-testing
Passed all 3 security checks
Go testing patterns including table-driven tests, subtests, benchmarks, fuzzing, and test coverage. Follows TDD methodology with idiomatic Go practices.
·07.6k
springboot-patterns
Passed all 3 security checks
Spring Boot architecture patterns, REST API design, layered services, data access, caching, async processing, and logging. Use for Java Spring Boot backend work.
·07k
continuous-learning-v2
Passed all 3 security checks
Instinct-based learning system that observes sessions via hooks, creates atomic instincts with confidence scoring, and evolves them into skills/commands/agents. v2.1 adds project-scoped instincts to prevent cross-project contamination.
·06.7k
postgres-patterns
Passed all 3 security checks
PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
·06.4k
api-design
Passed all 3 security checks
REST API design patterns including resource naming, status codes, pagination, filtering, error responses, versioning, and rate limiting for production APIs.
·06.2k
python-patterns
Passed all 3 security checks
Pythonic idioms, PEP 8 standards, type hints, and best practices for building robust, efficient, and maintainable Python applications.
·06.2k
tdd-workflow
Passed all 3 security checks
Use this skill when writing new features, fixing bugs, or refactoring code. Enforces test-driven development with 80%+ coverage including unit, integration, and E2E tests.
·06.2k
django-patterns
Passed all 3 security checks
Django architecture patterns, REST API design with DRF, ORM best practices, caching, signals, middleware, and production-grade Django apps.
·06.1k
frontend-slides
Passed all 3 security checks
Create stunning, animation-rich HTML presentations from scratch or by converting PowerPoint files. Use when the user wants to build a presentation, convert a PPT/PPTX to web, or create slides for a talk/pitch. Helps non-designers discover their aesthetic through visual exploration rather than abstract choices.
·06.1k
java-coding-standards
Passed all 3 security checks
Java coding standards for Spring Boot and Quarkus services: naming, immutability, Optional usage, streams, exceptions, generics, CDI, reactive patterns, and project layout. Automatically applies framework-specific conventions.
·06k
docker-patterns
Passed all 3 security checks
Docker and Docker Compose patterns for local development, container security, networking, volume strategies, and multi-service orchestration.
·05.9k
python-testing
Passed all 3 security checks
Python testing strategies using pytest, TDD methodology, fixtures, mocking, parametrization, and coverage requirements.
·05.8k
springboot-security
Passed all 3 security checks
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
·05.8k
django-security
Passed all 3 security checks
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
·05.8k
video-editing
Passed all 3 security checks
AI-assisted video editing workflows for cutting, structuring, and augmenting real footage. Covers the full pipeline from raw capture through FFmpeg, Remotion, ElevenLabs, fal.ai, and final polish in Descript or CapCut. Use when the user wants to edit video, cut footage, create vlogs, or build video content.
·05.6k
strategic-compact
Passed all 3 security checks
Suggests manual context compaction at logical intervals to preserve context through task phases rather than arbitrary auto-compaction.
·05.5k
jpa-patterns
Passed all 3 security checks
JPA/Hibernate patterns for entity design, relationships, query optimization, transactions, auditing, indexing, pagination, and pooling in Spring Boot.
·05.2k
eval-harness
Passed all 3 security checks
Formal evaluation framework for Claude Code sessions implementing eval-driven development (EDD) principles
·05.2k
android-clean-architecture
Passed all 3 security checks
Clean Architecture patterns for Android and Kotlin Multiplatform projects — module structure, dependency rules, UseCases, Repositories, and data layer patterns.
·05.1k
swift-concurrency-6-2
Passed all 3 security checks
Swift 6.2 Approachable Concurrency — single-threaded by default, @concurrent for explicit background offloading, isolated conformances for main actor types.
·04.4k
kotlin-patterns
Passed all 3 security checks
Idiomatic Kotlin patterns, best practices, and conventions for building robust, efficient, and maintainable Kotlin applications with coroutines, null safety, and DSL builders.
·04.4k
rust-patterns
Passed all 3 security checks
Idiomatic Rust patterns, ownership, error handling, traits, concurrency, and best practices for building safe, performant applications.
·04.3k
bun-runtime
Passed all 3 security checks
Bun as runtime, package manager, bundler, and test runner. When to choose Bun vs Node, migration notes, and Vercel support.
·04.3k
customs-trade-compliance
Passed all 3 security checks
>
·04.2k
everything-claude-code-conventions
Passed all 3 security checks
Development conventions and patterns for everything-claude-code. JavaScript project with conventional commits.
·04.2k
enterprise-agent-ops
Passed all 3 security checks
Operate long-lived agent workloads with observability, security boundaries, and lifecycle management.
·04.2k
ai-regression-testing
Passed all 3 security checks
Regression testing strategies for AI-assisted development. Sandbox-mode API testing without database dependencies, automated bug-check workflows, and patterns to catch AI blind spots where the same model writes and reviews code.
·04.2k
exa-search
Passed all 3 security checks
Neural search via Exa MCP for web, code, and company research. Use when the user needs web search, code examples, company intel, people lookup, or AI-powered deep research with Exa's neural search engine.
·04.2k
architecture-decision-records
Passed all 3 security checks
Capture architectural decisions made during Claude Code sessions as structured ADRs. Auto-detects decision moments, records context, alternatives considered, and rationale. Maintains an ADR log so future developers understand why the codebase is shaped the way it is.
·04.2k
ralphinho-rfc-pipeline
Passed all 3 security checks
RFC-driven multi-agent DAG execution pattern with quality gates, merge queues, and work unit orchestration.
·04.2k
dmux-workflows
Passed all 3 security checks
Multi-agent orchestration using dmux (tmux pane manager for AI agents). Patterns for parallel agent workflows across Claude Code, Codex, OpenCode, and other harnesses. Use when running multiple agent sessions in parallel or coordinating multi-agent development workflows.
·04k
perl-security
Passed all 3 security checks
Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
·04k
perl-testing
Passed all 3 security checks
Perl testing patterns using Test2::V0, Test::More, prove runner, mocking, coverage with Devel::Cover, and TDD methodology.
·04k
agent-eval
Passed all 3 security checks
Head-to-head comparison of coding agents (Claude Code, Aider, Codex, etc.) on custom tasks with pass rate, cost, time, and consistency metrics
·04k
claude-devfleet
Passed all 3 security checks
Orchestrate multi-agent coding tasks via Claude DevFleet — plan projects, dispatch parallel agents in isolated worktrees, monitor progress, and read structured reports.
·04k
team-builder
Passed all 3 security checks
Interactive agent picker for composing and dispatching parallel teams
·04k
git-workflow
Passed all 3 security checks
Git workflow patterns including branching strategies, commit conventions, merge vs rebase, conflict resolution, and collaborative development best practices for teams of all sizes.
·03.7k
santa-method
Passed all 3 security checks
Multi-agent adversarial verification with convergence loop. Two independent review agents must both pass before output ships.
·03.6k
laravel-verification
Passed all 3 security checks
Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness.
·03.5k
nestjs-patterns
Passed all 3 security checks
NestJS architecture patterns for modules, controllers, providers, DTO validation, guards, interceptors, config, and production-grade TypeScript backends.
·03.4k
safety-guard
Passed all 3 security checks
Use this skill to prevent destructive operations when working on production systems or running agents autonomously.
·03.4k
laravel-plugin-discovery
Passed all 3 security checks
Discover and evaluate Laravel packages via LaraPlugins.io MCP. Use when the user wants to find plugins, check package health, or assess Laravel/PHP compatibility.
·03.4k
code-tour
Passed all 3 security checks
·03k
accessibility
Passed all 3 security checks
Design, implement, and audit inclusive digital products using WCAG 2.2 Level AA
·03k
everything-claude-code
Passed all 3 security checks
Development conventions and patterns for everything-claude-code. JavaScript project with conventional commits.
·02.1k