future. The same principles (unit, integration) will apply, using Go's native testing packages.
- **Frontend**: Tests will be added in the future, likely using a framework like Jest for unit
local Docker Compose setup.
- **`docker-compose.yml`**: The main file that defines all the services (backend, frontend, databases, etc.) and how they connect.
- **`docker/`**: Contains the specific Docker configurations for each service
from the task file exactly; match **`input/tech/stack.md`**; write tests as the task requires; **no** frontend files; **no** tables/columns not evidenced in `schema.json` without flagging.
**Code shape examples** (NestJS/Prisma, etc.) live
files and produces a structured
design specification (`design-spec.md`) that the specification-agent and
frontend-agent use to generate accurate, on-brand UI code.
If no PNGs resolve for the target
uses different permission model; restrictions documented in the role body and the master rule).
# Frontend Agent
> **Phase:** Step 3 — DEV Phase (runs in parallel with backend-agent)
> **Trigger:** Task files
Meta-orchestrator that classifies tasks and routes to the right combination of installed skills across caveman (output compression), superpowers (dev workflow), anthropic-skills (business/domain expertise), and wired tactical libraries (wshobson, davila7, impeccable, anthropic-official). 26 routing categories including whole-codebase analysis via repomix-pack, LLM/AI app dev, a live task dashboard, meta skill discovery, and curated tactical skill libraries (wshobson, davila7) for backend/security/CI-CD/database depth. Also scaffolds the canonical project-doc spine (README/AGENTS.md/CLAUDE.md/PROJECTLOG.md) in new projects via `/agent-master scaffold`. Invoke with /agent-master. Use as default entry point for ambiguous or multi-domain requests.
Security auditing skill for web applications and codebases. Scans for OWASP Top 10, dependency vulnerabilities, secrets exposure, XSS/CSRF/injection flaws, auth weaknesses, and misconfigurations. Use when task involves security scan, vulnerability assessment, pen test review, threat modeling, or hardening a codebase.