frontend-production-engineer v1.24.1
Patch release. The skill is installed on its own by engineers who never install another skill from the same author. It named two of those skills by name at fifty-six sites, and each name was a dangling reference for those engineers. Every site now states the same rule in self-contained words. No domain is added, and the router, the domain roster, and the frontmatter description are unchanged.
What changed
- Fifty-five sites in
SKILL.md,AGENTS.md, and twenty-four reference files handed a server-side subject to a named backend security skill. Each now hands it to "the backend's security review". The subject each site hands over is unchanged: the DRF permission class, the server-side CSRF rule, the rate limit, the cookie attributes, the upload scan, the stored file's name, the secret storage, the password hash, the server-side injection sink, and the never-log guarantee on a response body. references/openapi-schema-and-codegen.mdhanded the reconciliation of two OpenAPI documents to a named FastAPI skill. It now hands that reconciliation to the backend, which owns one error shape, one authentication scheme, and one schema dialect across both surfaces. The frontend keeps what it generates from each document.
Verification
Both repository workflows pass on the finished tree: 73 reference files, every link resolving, no orphan, balanced code fences, SKILL.md at 211,632 of the 215,040 bytes allowed, and the frontmatter description at 1013 characters. A grep for either skill name over the repository returns nothing.