Discoverability shim for the Retail-Agentic-Commerce CVE remediation Codex skill. Use for CVE, BDSA, GHSA, OSV, Dependabot, Black Duck, Snyk, npm, PyPI, or package advisory remediation.
日本語の概要は準備中です。原文の説明を表示しています。
Pre-commit implementation analysis for Retail-Agentic-Commerce. Use before commits, after significant changes, or when validating Apps SDK tools, mock data, MCP communication, widget isolation, or implementation quality.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Use this skill before committing significant changes or when the user asks for implementation-quality validation.
If multi-agent tools are available, run the analysis areas in parallel. If not, perform the same checks directly with local commands.
Files to inspect:
src/apps_sdk/tools/*.pysrc/apps_sdk/main.pyRed flags:
src/data/product_catalog.py.Commands:
rg "MOCK_PRODUCTS|mock_products" src/apps_sdk/
rg "from src.data.product_catalog import" src/apps_sdk/
rg "httpx|requests|fetch" src/apps_sdk/tools/
Expected patterns:
from src.data.product_catalog import PRODUCTS
async with httpx.AsyncClient() as client:
response = await client.get(f"{merchant_url}/products/{id}")
Files to inspect:
src/apps_sdk/web/src/**/*.tsxsrc/apps_sdk/web/src/**/*.tssrc/apps_sdk/web/package.jsonRed flags:
window.parent usage except for postMessage.Commands:
rg "from ['\"]\\.\\./\\.\\./\\.\\." src/apps_sdk/web/src/
rg "localhost:8000|localhost:8001" src/apps_sdk/web/src/
rg "postMessage|window\\.parent" src/apps_sdk/web/src/
Expected pattern:
window.parent.postMessage({ type: "GET_RECOMMENDATIONS" }, "*");
const result = await window.openai.callTool("add-to-cart", args);
Files to inspect:
src/data/product_catalog.pysrc/ui/data/mock-data.tssrc/apps_sdk/tools/recommendations.pyRed flags:
Commands:
rg '"id": "prod_' src/data/product_catalog.py | wc -l
rg "CATALOG_PRODUCTS|from src.data.product_catalog" src/apps_sdk/
Files to inspect:
src/ui/components/agent/MerchantIframeContainer.tsxsrc/ui/hooks/useMCPClient.tssrc/apps_sdk/web/src/App.tsxsrc/apps_sdk/web/src/main.tsxMessage types to verify:
| Direction | Message Type | Purpose |
|---|---|---|
| Widget to Parent | GET_RECOMMENDATIONS | Request product recommendations |
| Parent to Widget | RECOMMENDATIONS_RESULT | Return recommendation data |
| Widget to Parent | CHECKOUT_COMPLETE | Notify checkout success |
| Widget to Parent | CALL_TOOL | MCP tool invocation through the bridge |
Commands:
rg "message\\.type.*==|case.*:" src/ui/components/agent/MerchantIframeContainer.tsx
rg "postMessage.*type:" src/apps_sdk/web/src/
Track these before committing:
Pre-Commit Analysis:
- [ ] MCP tools use shared catalog data where applicable.
- [ ] MCP tools make real API calls where needed.
- [ ] Apps SDK web has no forbidden parent imports.
- [ ] Widget uses postMessage for parent communication.
- [ ] Widget makes no direct backend API calls.
- [ ] Mock data is synced with product catalog expectations.
- [ ] Agent fallbacks exist when services are unavailable.
- [ ] Message types match between sender and receiver.
- [ ] Relevant tests pass.
- [ ] Relevant linter and type checks pass.
Run relevant checks for the changed areas:
uv run pytest tests/apps_sdk/ -v
uv run ruff check src/apps_sdk/
uv run pyright src/apps_sdk/
cd src/apps_sdk/web && pnpm build
Broaden to the full quality gates from skills/features/SKILL.md and skills/ui/SKILL.md when shared backend or frontend behavior changed.
## Pre-Commit Analysis Report
### MCP Tools
- Status: PASS/FAIL
- Issues: [list any issues]
### Apps SDK Isolation
- Status: PASS/FAIL
- Issues: [list any issues]
### Mock Data
- Status: PASS/FAIL
- Product count: X/17
- Issues: [list any issues]
### Communication Flow
- Status: PASS/FAIL
- Issues: [list any issues]
### Recommendations
1. [High priority fixes]
2. [Medium priority improvements]
3. [Low priority enhancements]
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Discoverability shim for the Retail-Agentic-Commerce CVE remediation Codex skill. Use for CVE, BDSA, GHSA, OSV, Dependabot, Black Duck, Snyk, npm, PyPI, or package advisory remediation.
日本語の概要は準備中です。原文の説明を表示しています。
Dependency vulnerability remediation workflow for this repository. Use when fixing CVE, BDSA, GHSA, OSV, npm, PyPI, Dependabot, Black Duck, Snyk, or other package vulnerability findings, especially when the user asks for minimal package-only updates, validation, commits, branches, or pull requests.
日本語の概要は準備中です。原文の説明を表示しています。
Discoverability shim for the Retail-Agentic-Commerce backend feature Codex skill. Use when writing or modifying Python backend code, routes, services, models, tests, or protocol logic.
日本語の概要は準備中です。原文の説明を表示しています。
Python backend development standards for FastAPI, SQLModel, pytest, Ruff, and Pyright. Use when writing or modifying backend code in src/merchant, src/payment, src/apps_sdk, agents, tests, API routes, services, models, or protocol logic.
日本語の概要は準備中です。原文の説明を表示しています。
Discoverability shim for the Retail-Agentic-Commerce pre-commit analysis Codex skill. Use before commits, after significant changes, or for implementation-quality validation.
日本語の概要は準備中です。原文の説明を表示しています。
Discoverability shim for the Retail-Agentic-Commerce setup Codex skill. Use when the user asks to setup, install, start, launch, or run the project stack.
日本語の概要は準備中です。原文の説明を表示しています。