review-configuration
louisbrulenaudet/monorepo-template/.agents/skills/review-configuration/SKILL.md
Config, env, wrangler review. USE WHEN: user runs /review-configuration or explicitly asks for this review. DO NOT USE WHEN: implementing features or fixing bugs unless the user asked for a review.
Skill19 starsChanged 6 days ago
- Reads credentials
What's in it
- Review configuration
- Invocation
- Best practices alignment
- Deep technical review
- Environment and secrets
- Cloudflare Workers and wrangler
- Vite (React frontend)
- TypeScript configuration
- OXC (oxfmt / oxlint)
- Build modes and reproducibility
- Anti-patterns to flag
- Steps
- Checklist
- Context usage
- Review checklist
- Output format
--- name: review-configuration description: "Config, env, wrangler review. USE WHEN: user runs /review-configuration or explicitly asks for this review. DO NOT USE WHEN: implementing features or fixing bugs unless the user asked for a review." disable-model-invocation: true context: fork background: true model: sonnet effort: medium --- # Review configuration Run a **configuration-focused** review: environment and secrets handling, Cloudflare/wrangler setup, TypeScript and OXC configs, Vite and Wrangler configuration, build modes, and dev/staging/prod parity. Your reply must be a **plan of suggested changes**: concise, actionable, and structured-not only prose. ## Invocation Text after the slash command is additional scope/focus - narrow the review accordingly. If none given, use the default scope described below. ## Best practices alignment - **Secrets** - Never in repo or client bundle; local values in `apps/<worker>/.env` (never `.dev.vars`) and wrangler secrets; declare every secret name in `secrets.required`. - **Environment** - Clear split: client-exposed keys via Vite (`import.meta.env`, e.g. `VITE_*` if used); server-only secrets and config in Workers; build modes (development/production) consistent across tools. - **TypeScript** - Strict mode everywhere; shared configs from `@repo/typescript-config` (`strict.json` core → runtime presets); per-package `tsc --noEmit` via Turborepo transit (no root solution / project references); no conflicting compiler options between packages. - **OXC (oxfmt / oxlint)** - Single source of truth for format and lint; consistent rules; no conflicting formatters (e.g. Prettier). - **Cloudflare** - Wrangler and Vite build aligned; compatibility date and flags documented; bindings and env match usage; `front-app` assets (SPA) and `worker-api` worker entry configured correctly. Align with root [AGENTS.md](../../../AGENTS.md) and app AGENTS.md for stated config and port allocation. ## Deep technical review Conduct a configuration-only review. Inspect the following and call out violations or improvements. ### Environment and secrets - **Artifacts:** [apps/front-app/wrangler.jsonc](../../../apps/front-app/wrangler.jsonc), [apps/worker-api/wrangler.jsonc](../../../apps/worker-api/wrangler.jsonc), any `.env*` or `import.meta.env` usage in [apps/front-app/src/](../../../apps/front-app/src/), [apps/worker-api/src/](../../../apps/worker-api/src/). - **Checks:** `.env*` / `.dev.vars*` are gitignored; `secrets.required` lists every secret name; no Worker app has a `.dev.vars`; tests give each secret a fake `miniflare.bindings` value. Wrangler `vars` and `[env.*.vars]` only for non-secret config; secrets only in wrangler secret or a local `.env`. No secrets in client-bundled code; only intentionally exposed env keys via Vite (document which prefixes are safe). ### Cloudflare Workers and wrangler - **Artifacts:** [apps/front-app/wrangler.jsonc](../../../apps/front-app/wrangler.jsonc), [apps/front-app/vite.config.ts](../../../apps/front-app/vite.config.ts), [apps/worker-api/wrangler.jsonc](../../../apps/worker-api/wrangler.jsonc). - **Checks:** `compatibility_date` is set and reasonably current. Flags (e.g. `nodejs_compat`) are intentional and documented if non-default. front-app: SPA/static assets configuration (e.g. `assets`, `not_found_handling`) matches Vite build output. worker-api: dev port (e.g. 8725) matches AGENTS.md; production env and routes match deployment. ### Vite (React frontend) - **Artifacts:** [apps/front-app/vite.config.ts](../../../apps/front-app/vite.config.ts), [apps/front-app/tsconfig.json](../../../apps/front-app/tsconfig.json) (extends app config), [apps/front-app/tsconfig.app.json](../../../apps/front-app/tsconfig.app.json), [apps/front-app/tsconfig.node.json](../../../apps/front-app/tsconfig.node.json). - **Checks:** Plugins order (e.g. React, Tailwind, `@cloudflare/vite-plugin`); build target and chunk strategy; no dev-only options in production build. Local dev parity with deployed behavior where relevant. ### TypeScript configuration - **Artifacts:** [packages/typescript-config/](../../../packages/typescript-config/) (`strict.json`, `library.json`, `workers.json`, `vite-react.json`, `vite-node.json`), [apps/front-app/tsconfig.json](../../../apps/front-app/tsconfig.json) + `tsconfig.app.json` / `tsconfig.node.json`, [apps/worker-api/tsconfig.json](../../../apps/worker-api/tsconfig.json), [packages/dtos-common/tsconfig.json](../../../packages/dtos-common/tsconfig.json), [packages/enums-common/tsconfig.json](../../../packages/enums-common/tsconfig.json). - **Checks:** All extend from `@repo/typescript-config` where appropriate. `strict` enabled via `strict.json` inheritance. No root solution `tsconfig.json` and no TypeScript Project References - `check-types` is `tsc --noEmit` with Turborepo transit. Worker apps set `compilerOptions.types` for `worker-configuration.d.ts`. React apps use split layout: `vite-react.json` for `src/**`, `vite-node.json` for `vite.config.ts`. Presets keep `isolatedDeclarations` off (schema-first `z.infer` in `@repo/dtos-common`). `erasableSyntaxOnly` on - no `export enum`; use `as const` objects in `@repo/enums-common`. Each package running `check-types` declares `typescript` in devDependencies. ### OXC (oxfmt / oxlint) - **Artifacts:** [.oxfmtrc.json](.oxfmtrc.json), [.oxlintrc.json](.oxlintrc.json). - **Checks:** Single OXC config at root; apps/packages don't override unless necessary (and documented). Format: spaces, double quotes, line width 80 per AGENTS.md. Lint: rules in `.oxlintrc.json`; no disabled rules that hide real issues without a reason. Ignore patterns exclude build outputs and generated files. No Prettier (or other formatter) in use to avoid conflicts. ### Build modes and reproducibility - **Artifacts:** Root and app [package.json](../../../package.json) scripts, [turbo.json](../../../turbo.json). - **Checks:** `build` uses production mode (e.g. `NODE_ENV=production` or equivalent). Dev and build use same Node version (engines field). Lockfile is committed; CI uses `--frozen-lockfile`. packageManager in package.json matches pnpm version. pnpm policy in `pnpm-workspace.yaml` is intentional and documented. ### Anti-patterns to flag - Secrets in repo, in client bundle, or in wrangler.jsonc as plain text. - A secret read by code but missing from `secrets.required`; a `.dev.vars` in a Worker app. - TypeScript strict disabled or `any` encouraged by config. - Multiple formatters or conflicting lint configs. - Wrangler compatibility_date very old; or flags that are deprecated/removed. - Vite build output path and wrangler `assets` / SPA settings mismatch. ## Steps 1. **Gather scope** - All config or specific area (env, wrangler, TS, OXC, Vite). Default to full configuration review. 2. **Read conventions** - Root and app AGENTS.md for env, ports, and tooling. 3. **Inspect env and secrets** - `secrets.required`, wrangler vars, codebase for env usage; confirm no secrets in client or repo. 4. **Inspect wrangler and Vite** - Both wrangler.jsonc files; front-app vite.config.ts; alignment between build output and deployment. 5. **Inspect TypeScript** - All tsconfig files and typescript-config package; strict and extends chain. 6. **Inspect OXC** - `.oxfmtrc.json` and `.oxlintrc.json`; format/lint rules and ignore patterns. 7. **Inspect build and lockfile** - package.json scripts, turbo.json, pnpm-workspace.yaml, engines; reproducibility and build mode. 8. **Compose plan** - Critical / Improvements / Optional; each item: **what**, **where**, **why**. One-line "no issues" per sub-area if none. ## Checklist - [ ] Scope clear - [ ] Root and app AGENTS.md consulted - [ ] Env and secrets handling reviewed (`secrets.required`, `.env`, wrangler, Vite env) - [ ] Both wrangler.jsonc and front-app vite.config.ts reviewed - [ ] All tsconfig and typescript-config reviewed - [ ] `.oxfmtrc.json` and `.oxlintrc.json` reviewed - [ ] Build mode and reproducibility (scripts, turbo, pnpm-workspace.yaml, lockfile) reviewed - [ ] Plan structured as Critical / Improvements / Optional with what/where/why ## Context usage - Use `@file` for config files (wrangler.jsonc, vite.config.ts, tsconfig.json, .oxfmtrc.json, .oxlintrc.json). - Use `@code` for env or config snippets when suggesting changes. - Use `@docs` for Cloudflare/OXC/TypeScript when checking correct options. If context is insufficient, suggest which config files or @ references to add. ## Review checklist - **Correctness:** Config options are valid and consistent; no secrets exposed. - **Conventions:** Matches AGENTS.md (ports, env, TypeScript strict, OXC). - **Quality:** Reproducible builds; clear env contract; strict typing. - **Actionability:** Every suggestion is implementable (e.g. "add X to secrets.required", "set strict: true in Y"). - **Trade-offs:** Note any (e.g. nodejs_compat vs bundle size). - **Scope:** Configuration only; defer security or performance to their reviews. ## Output format Respond with a **plan** only (no implementation unless the user asks): 1. **Critical** – Must-fix (secrets in repo/client, broken build, strict disabled, wrangler/Vite mismatch). 2. **Improvements** – Worthwhile (documentation of env, clearer TS/OXC rules, compatibility date update). 3. **Optional** – Nice-to-haves (comments in config, minor tidy). Prefix with **Nit:** for non-blocking polish. For each item: **what** to change, **where** (file/area), and **why**. If a sub-area has no findings, state it in one line.
More agent context in louisbrulenaudet/monorepo-template
68 other files this repository gives its agents, the first 60 shown.
CLAUDE.md
Cursor rule
- .cursor/rules/backend/hono-gateway.mdc
- .cursor/rules/backend/ports.mdc
- .cursor/rules/backend/workers-cache.mdc
- .cursor/rules/backend/workers-config.mdc
- .cursor/rules/contracts/contracts.mdc
- .cursor/rules/contracts/type-inference.mdc
- .cursor/rules/core/boundaries.mdc
- .cursor/rules/core/guardrails.mdc
- .cursor/rules/core/turborepo.mdc
- .cursor/rules/core/worktrees.mdc
- .cursor/rules/frontend/frontend-architecture.mdc
- .cursor/rules/frontend/react-doctor.mdc
- .cursor/rules/frontend/react.mdc
- .cursor/rules/frontend/tailwind.mdc
- .cursor/rules/frontend/tanstack-query.mdc
- .cursor/rules/frontend/tanstack-router.mdc
- .cursor/rules/frontend/vite-config.mdc
- .cursor/rules/ops/cd.mdc
- .cursor/rules/ops/ci.mdc
- .cursor/rules/ops/previews.mdc
- .cursor/rules/ops/release.mdc
- .cursor/rules/quality/code-style.mdc
- .cursor/rules/quality/comments.mdc
- .cursor/rules/quality/knip.mdc
- .cursor/rules/quality/markdown-style.mdc
- .cursor/rules/quality/naming.mdc
- .cursor/rules/quality/testing.mdc
- .cursor/rules/quality/typescript-config.mdc
- .cursor/rules/quality/vitest-config.mdc
- .cursor/rules/tests/front-react.mdc
- .cursor/rules/tests/hono-workers.mdc
- .cursor/rules/tests/vitest.mdc
Skill
- front-vitest.agents/skills/front-vitest/SKILL.md
- git-commit.agents/skills/git-commit/SKILL.md
- hono.agents/skills/hono/SKILL.md
- monorepo-agent-setup.agents/skills/monorepo-agent-setup/SKILL.md
- playwright-cli.agents/skills/playwright-cli/SKILL.md
- pnpm.agents/skills/pnpm/SKILL.md
- privileged-legal-data.agents/skills/privileged-legal-data/SKILL.md
- react-doctor.agents/skills/react-doctor/SKILL.md
- review-architecture.agents/skills/review-architecture/SKILL.md
- review-ci.agents/skills/review-ci/SKILL.md
- review-code-quality.agents/skills/review-code-quality/SKILL.md
- review-performance.agents/skills/review-performance/SKILL.md
- review-security.agents/skills/review-security/SKILL.md
- review-seo.agents/skills/review-seo/SKILL.md
- review.agents/skills/review/SKILL.md
- review-stack.agents/skills/review-stack/SKILL.md
- review-tests.agents/skills/review-tests/SKILL.md
- review-ui.agents/skills/review-ui/SKILL.md
- run-app.agents/skills/run-app/SKILL.md
- security-audit.agents/skills/security-audit/SKILL.md
- skills-update.agents/skills/skills-update/SKILL.md
- tanstack-config.agents/skills/tanstack-config/SKILL.md
- tanstack-devtools.agents/skills/tanstack-devtools/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

