All skills
harlan-zw avatar

/nuxt-frontend-review

@474ef33

Adversarially review a Nuxt frontend. Run it and verify its contract, UX, and visual behavior. Use for frontend review or testing.

Use this Skill: https://skilld.dev/gh/harlan-zw/harlan-agent-kit/nuxt-frontend-review

This session only. Nothing lands on disk.

referencestoken-checks.md

≈411 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Token Regression Checks

The YAML front matter in DESIGN.md is the machine-readable source of truth for colors, typography, spacing, radii, and component surfaces.

Drift (git-diff based)

HASH=$(jq -r '.git_hash // empty' {JOB_DIR}/build-handoff.json)
git diff "$HASH" -- DESIGN.md | sed -n '/^---$/,/^---$/p'
  • design_system_changes == false in the handoff: any front matter diff is drift. Flag TOKEN DRIFT (hard reject).
  • design_system_changes == true: the diff is expected. Verify it matches the contract's stated design intent.

Structural + contrast lint (preferred)

npx --yes @google/design.md lint DESIGN.md 2>/dev/null

Parse the JSON. Hard rejects:

  • any severity: "error" (broken refs, invalid hex, section-order violations)
  • contrast-ratio warnings on components.* pairs below 4.5:1, unless the decisions log explicitly accepts that pairing (e.g. "button-primary contrast 3.96:1 accepted: large text only, signature purple is theme-defining")

Informational, not rejects: unknown component property warnings (shadow, border, boxShadow, transform), and orphaned-token warnings on palette colors that exist for theming without a specific component reference.

Fallback

Some theme front matter uses rgba() or float alpha values that crash the alpha linter (raw.match is not a function). If the CLI exits nonzero without valid JSON:

grep -oE '\{(colors|rounded|spacing|typography)\.[a-z-]+\}' DESIGN.md

Verify every match resolves to a key in the front matter.

If front matter is absent entirely, note it and skip. The project predates the token schema.

Source: SKILL.md on GitHub

2 warnings1mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub1mo

    The skill performs automated frontend reviews by executing shell commands, running a local development server, and utilizing external Node.js packages. It executes an unverified CLI tool (@ripast/cli) via npx, which introduces a supply chain risk. It also uses dynamic context injection to gather job information and git metadata.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: MEDIUM · 2 issues

Signed by skilld at 474ef33. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 17 hours ago.

Activeupdated 18 hours ago
What it can do
Reads files Runs commands
user_invocable
true
argument-hint
[job-id] [inline]
effort
high
All 4 allowed tools
ReadBashGlobGrep

README badge

README badge for harlan-zw/harlan-agent-kit/nuxt-frontend-review