# Agent Skills for Cursor

A collection of [Agent Skills](https://agentskills.io) for the Cursor coding agent. Skills are loaded from `.cursor/skills/` and teach the agent domain-specific workflows and best practices.

**Stack focus:** Laravel 12+, Vue 3, Inertia.js. Includes Npontu Technologies security standards and performance patterns (ROCI caching).

---

## Repository

- **GitLab:** [gitlab.npontutechnologies.com/okafor/cursor-skills](https://gitlab.npontutechnologies.com/okafor/cursor-skills)

```bash
git clone https://gitlab.npontutechnologies.com/okafor/cursor-skills.git
```

---

## Skills

### Stack & expertise

| Skill | Description |
|-------|-------------|
| [senior-laravel-engineer](.cursor/skills/senior-laravel-engineer/) | Expert Laravel 12+ development: Eloquent, Artisan, Blade, APIs, testing, queues, and best practices. |
| [vue-expert](.cursor/skills/vue-expert/) | Expert Vue 3 with Composition API, reactivity optimization, Nuxt 3, and Laravel + Inertia + Vue integration. |

### Conversion (internal frontend)

| Skill | Description |
|-------|-------------|
| [html-to-vue-inertia](.cursor/skills/html-to-vue-inertia/) | Senior expert: convert raw HTML template folders (e.g. ThemeForest) to Vue 3 + Laravel Inertia. Analysis, layout/components/pages, asset migration, jQuery→Vue, Inertia patterns. |

### Npontu security & standards

| Skill | Description |
|-------|-------------|
| [npontu-security-standards](.cursor/skills/npontu-security-standards/) | Single-doc Npontu Security Framework (always-on rule for .php, .vue, .js, .ts). Enforces secrets, auth, DB, multi-tenancy, validation, API security. |
| [npontu-security](.cursor/skills/npontu-security/) | Npontu security standards: env/config, auth, authorization, SQL safety, validation, error handling. Includes `scripts/check-secrets.sh` for pre-commit. |
| [npontu-auth](.cursor/skills/npontu-auth/) | Secure auth & session: login/registration, rate limiting, session config, Sanctum, password policy, logout other devices. |
| [npontu-database](.cursor/skills/npontu-database/) | Database performance: N+1 prevention, eager loading, indexing, pagination, chunking, lazy-load prevention. |
| [npontu-multitenancy](.cursor/skills/npontu-multitenancy/) | Multi-tenant isolation: HasTenant trait, TenantScope, migrations, policies, FormRequest uniqueness, tenant tests. |

### Performance

| Skill | Description |
|-------|-------------|
| [roci-cache-pattern](.cursor/skills/roci-cache-pattern/) | ROCI (Redis Observer Cache Invalidation): cache forever + model observers for automatic invalidation. Cache services, observers, key conventions, search TTL exception. |

---

## Usage

### In Cursor

- **Automatic:** Cursor discovers skills from `.cursor/skills/` and applies them when relevant.
- **Manual:** Type `/` in Agent chat and search for the skill name (e.g. `senior-laravel-engineer`).

### Use in your project

Copy the `.cursor` folder (or only the skills/rules you need) into your Laravel or Vue project root so Cursor loads them there:

```bash
# From this repo
cp -r .cursor /path/to/your-project/
```

Or clone this repo and copy:

```bash
git clone https://gitlab.npontutechnologies.com/okafor/cursor-skills.git
cp -r cursor-skills/.cursor /path/to/your-project/
```

---

## Rules (always-on by file type)

Rules in `.cursor/rules/` are applied when matching files are in context:

| Rule | Applies to |
|------|------------|
| [npontu-security-standards.mdc](.cursor/rules/npontu-security-standards.mdc) | `**/*.php`, `**/*.vue`, `**/*.js`, `**/*.ts` (and always in session) |

The Npontu Security Framework is both a rule (always apply for those file types) and a skill (`npontu-security-standards`). The four Npontu skills (`npontu-security`, `npontu-auth`, `npontu-database`, `npontu-multitenancy`) are more detailed and activate by context (e.g. auth code → npontu-auth, tenant models → npontu-multitenancy).

---

## our-skills (Npontu source)

If present, the [our-skills/](our-skills/) folder is the **canonical source** for Npontu security skills. It may contain:

- **skills-README.md** – Overview, installation, pre-commit hook setup.
- **npontu-*-SKILL.md** – Source SKILL content (synced into `.cursor/skills/<name>/SKILL.md`).
- **check-secrets.sh** – Pre-commit secret scanner (also at `.cursor/skills/npontu-security/scripts/check-secrets.sh`).

Keep `our-skills/` and `.cursor/skills/` in sync when updating Npontu skills.

---

## Adding skills

Each skill is a folder under `.cursor/skills/` with:

- **SKILL.md** – Required. YAML frontmatter (`name`, `description`) and markdown instructions.
- **references/** – Optional. Extra docs loaded on demand.
- **scripts/** – Optional. Executable scripts the agent can run.
- **assets/** – Optional. Templates, configs, or other static files.

See [Agent Skills](https://agentskills.io) for the full format and conventions.
