contentstack/kickstart-next-ssg · Archived

code-review

Pull-request checklist for security, Contentstack credentials, sanitization, and image configuration.

First seen Jul 16, 2026

Installation

$ npx skills add contentstack/kickstart-next-ssg --skill code-review

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from contentstack/kickstart-next-ssg.

npx skills add contentstack/kickstart-next-ssg

Browse all from contentstack/kickstart-next-ssg

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

License LICENSE
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,546 B
  • docs SUMMARY.md 120 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2 installs

SKILL.md

Code review – kickstart-next-ssg

When to use

  • Before approving or merging a pull request
  • Auditing changes that touch env vars, CMS integration, or user-facing HTML

Instructions

Secrets and configuration

  • No real .env values or delivery/preview tokens committed; use placeholders in docs only.
  • New NEXTPUBLIC* keys are exposed to the browser—avoid putting sensitive server-only secrets behind that prefix.

Contentstack

  • Token scopes and preview settings stay aligned with [README.md](../../README.md) (preview-capable delivery token, Live Preview environment).

Security and dependencies

  • PRs trigger SCA ([.github/workflows/sca-scan.yml](../../.github/workflows/sca-scan.yml)); be explicit about new dependencies and known advisories.
  • Public repos: SECURITY.md and license file expectations per [.github/workflows/policy-scan.yml](../../.github/workflows/policy-scan.yml).

HTML and XSS

  • Rich text and block copy use dangerouslySetInnerHTML only after isomorphic-dompurify in [pages/index.tsx](../../pages/index.tsx); preserve or improve sanitization when changing markup.

Images

  • New remote image domains must be reflected in [next.config.mjs](../../next.config.mjs) images.remotePatterns (or env-driven hostname) so next/image does not break at runtime.

Quality

  • Run npm run lint locally for substantive TS/React changes.