Agent skill

Adversarial Tanstack

by pproenca in pproenca/dot-skills

A skill your agent uses to gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff or file set against 22 decidable…

MITAuto-check passedDevelopment

Install Adversarial Tanstack

skills CLI
$ npx skills add pproenca/dot-skills --skill adversarial-tanstack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pproenca/dot-skills adversarial-tanstack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pproenca/dot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.experimental/adversarial-tanstack .claude/skills/adversarial-tanstack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
adversarial-tanstack
GitHub stars
214
Token cost
~1.4k tokens
SKILL.md length
663 words
Files
28 (incl. references, assets)
Skills in repo
182
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses to gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff or file set against 22 decidable…

  • Works in 6 steps: Identify the target. Pin down exactly… → Load the rules. Read… → Compose the reviewer prompt. Fill… → …
  • Gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff
  • SKILL.md covers When to Apply, Review Protocol, Verdict Format and Rule Categories, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Adversarial Tanstack is an agent skill from pproenca/dot-skills. Use this skill to gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff or file set against 22 decidable rules covering client/server boundary leaks, server-function and server-route usage, auth and security, SSR data loading, boundary type safety, and compiler config. Trigger it before merging TanStack Start work, when asked to gate, adversarially review, or pass/fail a Start or TanStack codebase, or as a final check on…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 30 other files, including reference files and assets (for example `assets/templates/verdict.md`, `gotchas.md` and `metadata.json`).

It sits in Development, covering Type safety and Subagents. It works with TanStack and TypeScript. The repository describes itself as: A collection of AI agent skills following the Agent Skills open format. The licence is MIT.

When your agent uses it

  • Gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff
  • File set against 22 decidable rules covering client/server boundary leaks
  • Server-function and server-route usage
  • Auth and security

Example prompts

  • “/adversarial-tanstack”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify the target. Pin down exactly what is under review (a diff, a set of files, a PR) and note the ref/paths so the review runs…
  2. Load the rules. Read references/_sections.md and every rule file in references/ (all boundary-*.md, serverfn-*.md, sec-*.md, ssr-*.md…
  3. Compose the reviewer prompt. Fill references/reviewer-prompt.md with the rules and the target. The composed prompt must be fully…
  4. Dispatch one blind reviewer. Launch a single Task subagent whose entire input is the composed prompt — no conversation context, no…
  5. Render fail-closed. The reviewer's structured output is the verdict — there is no merge step. Overall verdict is PASS only when every rule…
  6. Render the verdict. Fill assets/templates/verdict.md. On FAIL, aggregate the reviewer's "missing for PASS" suggestions into the fix list…

What it can do on your machine

Read from SKILL.md and the folder at commit cf93c57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Adversarial Tanstack loads about 1.4k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 170 tokens; SKILL.md has 663 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~170
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pproenca/dot-skills at commit cf93c57, republished under its MIT licence (© pproenca). 663 words, ~1,433 tokens.

Download SKILL.mdSave it as .claude/skills/adversarial-tanstack/SKILL.md (or your agent's skills folder). This skill also uses 27 other files; get the full folder from GitHub.
name
adversarial-tanstack
description
Use this skill to gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff or file set against 22 decidable rules covering client/server boundary leaks, server-function and server-route usage, auth and security, SSR data loading, boundary type safety, and compiler config. Trigger it before merging TanStack Start work, when asked to gate, adversarially review, or pass/fail a Start or TanStack codebase, or as a final check on agent-authored Start features. It renders verdicts only and never fixes the work; for teaching-style review feedback use a distillation skill instead.

Adversarial TanStack Gate

A merge gate for TanStack Start + TypeScript web-app changes — a pass/fail gate: a single blind reviewer subagent judges the work against this gate's rules with an adversarial mandate, and the work passes only when every rule is PASS or N/A. This skill renders verdicts; it never fixes the work.

Rules are pinned to @tanstack/react-start 1.168+ (v1 RC, July 2026) and TypeScript 5.8–6.x semantics.

When to Apply

  • A TanStack Start feature, route, or server function is about to merge and needs an objective PASS/FAIL, not advisory feedback.
  • An agent (Claude, Codex) authored Start app code and you want an independent check its author bias cannot rubber-stamp.
  • A diff touches the client/server boundary — env vars, loaders, server functions, auth — where a wrong PASS ships secrets or unauthorized data access.
  • Auditing an existing Start codebase file set against the current v1 RC API surface (stale .inputValidator(), removed createServerFileRoute).

Do not apply to non-Start React apps (most serverfn/boundary/ssr rules will return N/A and the gate degenerates to a TypeScript check) or when the user wants explanations and refactors rather than a verdict.

Review Protocol

Follow these steps exactly — the gate's value is that every review runs the same way.

  1. Identify the target. Pin down exactly what is under review (a diff, a set of files, a PR) and note the ref/paths so the review runs against an unambiguous, fixed target. Always include tsconfig.json, src/router.tsx, and src/start.ts (if present) in the target paths — several rules are decided by those files even when the diff does not touch them.
  2. Load the rules. Read references/_sections.md and every rule file in references/ (all boundary-*.md, serverfn-*.md, sec-*.md, ssr-*.md, types-*.md, tscfg-*.md files).
  3. Compose the reviewer prompt. Fill references/reviewer-prompt.md with the rules and the target. The composed prompt must be fully self-contained — a reviewer sees no conversation history, so nothing may refer to context outside the prompt.
  4. Dispatch one blind reviewer. Launch a single Task subagent whose entire input is the composed prompt — no conversation context, no commentary alongside it.
  5. Render fail-closed. The reviewer's structured output is the verdict — there is no merge step. Overall verdict is PASS only when every rule is PASS or N/A; any single FAIL fails the gate. Never average, weigh severity, or waive a rule — a "minor" FAIL is a FAIL.
  6. Render the verdict. Fill assets/templates/verdict.md. On FAIL, aggregate the reviewer's "missing for PASS" suggestions into the fix list, each with its location, ordered by category importance. Every rule whose final result is FAIL must appear in the fix list with a change concrete enough to apply as written — if the reviewer's suggestion only restates the violation, derive the fix from the rule's Correct example before rendering.

If the same rule flips verdicts across re-reviews of an unchanged target, or a human reads the evidence and overrides the verdict, that is a decidability bug in the rule — record it in gotchas.md and sharpen the rule; do not override the gate.

Show full SKILL.md (170 more words)Show less

Verdict Format

The reviewer returns, per rule: PASS | FAIL | N/A, evidence (file:line or a quote — required for PASS as well as FAIL), and for every FAIL, the fix that flips the rule to PASS once applied — the named change plus its location, never a restatement of the violation. The final report follows assets/templates/verdict.md.

Rule Categories

#CategoryPrefixCovers
1Client/Server Boundaryboundary-Env vars in server contexts only, loader isomorphism, public-prefix discipline
2Server Functions & Routesserverfn-Input validators, POST for mutations, current v1 RC APIs, static imports
3Auth & Securitysec-Auth at the handler, CSRF with custom start config, cache privacy, cookie flags, enumeration
4SSR & Data Loadingssr-Per-request router/QueryClient, useSuspenseQuery for loader data, deterministic render
5Type Safety at Boundariestypes-Schema-parse external data, exhaustive switches, escape-hatch audit, non-null assertions
6Compiler Configurationtscfg-strict + noUncheckedIndexedAccess, erasableSyntaxOnly, verbatimModuleSyntax off (Start-specific)

Reference Files

FileDescription
references/reviewer-prompt.mdSelf-contained prompt template for the blind reviewer
assets/templates/verdict.mdVerdict report template
references/_sections.mdCategory definitions and ordering
metadata.jsonVersion and source references

© pproenca, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 27 other files (references, assets) in skills/.experimental/adversarial-tanstack of pproenca/dot-skills.

  • SKILL.md
  • assets/templates/verdict.md
  • gotchas.md
  • metadata.json
  • references/_sections.md
  • references/boundary-client-env-prefix.md
  • references/boundary-env-server-context.md
  • references/boundary-loader-no-secrets.md
  • references/reviewer-prompt.md
  • references/sec-auth-at-handler.md
  • references/sec-csrf-with-custom-start.md
  • references/sec-no-account-enumeration.md
  • references/sec-private-cache-control.md
  • references/sec-session-cookie-flags.md
  • references/serverfn-current-api.md
  • references/serverfn-post-mutations.md
  • references/serverfn-static-imports.md
  • references/serverfn-validate-input.md
  • … and 10 more

Open the folder on GitHubat commit cf93c57

Compare with similar skills

Adversarial Tanstack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Adversarial Tanstack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Adversarial Tanstack this skillpproenca/dot-skills214—~1.4kAutomated safety check: PassMIT
Wagmi Feature Developmentwevm/wagmi6.8k—~3.8kAutomated safety check: PassMIT
Tanstack Routersecondsky/claude-skills227—~1.9kAutomated safety check: NotesMIT
React Devdavila7/claude-code-templates32k2 repos~2.6kAutomated safety check: PassMIT
React Frontend Development Guidelinesdiet103/claude-code-infrastructure-showcase10k2 repos~2.9kAutomated safety check: PassMIT
Olore Tanstack Form Latestolorehq/olore103—~1.1kAutomated safety check: PassMIT

Similar skills

  • Walks through adding a Wagmi feature across its layers: a Viem-based core action, TanStack Query options, and React and Vue bindings.

    6.8k GitHub stars~3.8k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Tanstack Router

    secondsky/claude-skills

    TanStack Router type-safe file-based routing for React. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    DevelopmentAuto-check: notes
  • React Dev

    davila7/claude-code-templates

    This skill should be used when building React components with TypeScript, typing hooks, handling events, or when React TypeScript, React 19, Server Components are mentioned.

    32k GitHub starsUsed in 2 repos~2.6k tokens
    Frontend & DesignAuto-check passed
  • React Frontend Development Guidelines

    diet103/claude-code-infrastructure-showcase

    Guidelines for React 18 and TypeScript apps covering Suspense data fetching, lazy loading, feature folders, MUI v7 styling, TanStack Router and performance.

    10k GitHub starsUsed in 2 repos~2.9k tokens
    Frontend & DesignAuto-check passed
  • Local TanStack Form documentation reference (latest, v1.33.5).

    103 GitHub stars~1.1k tokensUpdated today
    MobileAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 24 repos~4.2k tokens
    DevelopmentAuto-check passed

More from pproenca/dot-skills

All 182 skills in this repo
  • Audio Voice Recovery

    pproenca/dot-skills

    Audio forensics and voice recovery guidelines for CSI-level audio analysis.

    214 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Codemod React Pipeline

    pproenca/dot-skills

    Guided, scripted pipeline for running JSX/TSX/React codemods safely across large legacy codebases.

    214 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Dev Rfc

    pproenca/dot-skills

    Create well-structured RFCs and technical proposals for software projects.

    214 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Dx Harness

    pproenca/dot-skills

    Developer-experience friction auditing and fixing — slow onboarding, repeated manual setup steps, missing bootstrap/reset/seed scripts, undiscoverable conventions.

    214 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Language Spec Author

    pproenca/dot-skills

    Turn a rough idea for a language into a complete, implementable specification — a DSL, query, config/data, template, or protocol language — by interviewing the author dimension by dimension until…

    214 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Python Pep Author

    pproenca/dot-skills

    Drafting Python Enhancement Proposals (PEPs) — proposing a Python language feature, a standard library change, an interoperability standard, or an informational/process document for the Python…

    214 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Adversarial Tanstack

What does Adversarial Tanstack do?

A skill your agent uses to gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff or file set against 22 decidable…. Adversarial Tanstack is an agent skill from pproenca/dot-skills. Use this skill to gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff or file set against 22 decidable rules covering client/server boundary leaks, server-function and server-route usage, auth and security, SSR data loading, boundary type safety, and compiler config.

When should I use Adversarial Tanstack?

Adversarial Tanstack fits situations like: gate TanStack Start plus TypeScript web-app changes with a pass/fail adversarial review — a single blind reviewer subagent judges a diff; file set against 22 decidable rules covering client/server boundary leaks; server-function and server-route usage; auth and security.

How do I install Adversarial Tanstack in Claude Code?

Run `npx skills add pproenca/dot-skills --skill adversarial-tanstack -a claude-code`. Or copy the skill folder (skills/.experimental/adversarial-tanstack in pproenca/dot-skills) into .claude/skills/adversarial-tanstack in your project. Claude Code loads it when a task matches its description.

How do I install Adversarial Tanstack in Codex?

Run `npx skills add pproenca/dot-skills --skill adversarial-tanstack -a codex`. Or copy the skill folder (skills/.experimental/adversarial-tanstack in pproenca/dot-skills) into .agents/skills/adversarial-tanstack in your project. Codex loads it when a task matches its description.

Can I use Adversarial Tanstack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pproenca/dot-skills --skill adversarial-tanstack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/adversarial-tanstack, .gemini/skills/adversarial-tanstack, .github/skills/adversarial-tanstack and .opencode/skills/adversarial-tanstack in your project.

What does Adversarial Tanstack need to run?

SKILL.md names no scripts, command-line tools or credentials: Adversarial Tanstack is instructions for the agent only.

Does Adversarial Tanstack access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Adversarial Tanstack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Adversarial Tanstack use?

Adversarial Tanstack is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Adversarial Tanstack use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.4k tokens, read only when the agent opens those files.

What are the alternatives to Adversarial Tanstack?

Skills that share tags, products or a category with Adversarial Tanstack: Wagmi Feature Development (wevm/wagmi, 6.8k stars), Tanstack Router (secondsky/claude-skills, 227 stars), React Dev (davila7/claude-code-templates, 32k stars) and React Frontend Development Guidelines (diet103/claude-code-infrastructure-showcase, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Adversarial Tanstack?

pproenca (a GitHub user) maintains it in pproenca/dot-skills, which has 214 GitHub stars. The repository holds 182 skills in this directory. The repository was last updated on August 15, 2026.

Source: pproenca/dot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.