code-review

Pull-request checklist for security, Contentstack credentials, sanitization, and image configuration.

npx skills add https://github.com/contentstack/kickstart-next-ssg --skill code-review

Code review – kickstart-next-ssg

When to use

  • Before approving or merging a pull request
  • Auditing changes that touch env vars, CMS integration, or user-facing HTML

Instructions

Secrets and configuration

  • No real .env values or delivery/preview tokens committed; use placeholders in docs only.
  • New NEXT_PUBLIC_* keys are exposed to the browser—avoid putting sensitive server-only secrets behind that prefix.

Contentstack

  • Token scopes and preview settings stay aligned with README.md (preview-capable delivery token, Live Preview environment).

Security and dependencies

HTML and XSS

  • Rich text and block copy use dangerouslySetInnerHTML only after isomorphic-dompurify in pages/index.tsx; preserve or improve sanitization when changing markup.

Images

  • New remote image domains must be reflected in next.config.mjs images.remotePatterns (or env-driven hostname) so next/image does not break at runtime.

Quality

  • Run npm run lint locally for substantive TS/React changes.

Lebih banyak skill dari contentstack

brand-kit-assistant
contentstack
Memberikan saran kepada pengguna tentang konsep Contentstack Brand Kit, pengaturan, tata kelola, dan pembuatan konten AI sesuai merek. Mengarahkan tugas khusus API ke kemampuan Brand Kit yang tepat atau…
official
cms-assets
contentstack
Advise developers on organizing, delivering, and transforming assets in Contentstack. Cover folder structure, Image Delivery API transformations, publishing…
official
cms-branches-aliases
contentstack
Advise developers on using Contentstack branches for isolated content development and aliases for zero-downtime content deployments. Cover branch strategy,…
official
cms-data-modeling-best-practices
contentstack
Guide developers to model content in Contentstack using the simplest reusable structure. The skill explains when to use content types, references, global…
official
cms-entries
contentstack
Advise developers on querying, localizing, versioning, publishing, and structuring Contentstack entries for efficient delivery. Focus on CDA usage, reference…
official
cms-environments-publishing
contentstack
Advise developers on configuring environments, publishing content, using delivery and preview tokens, leveraging the Sync API, and understanding CDN and…
official
cms-live-preview-visual-builder-support-assistant
contentstack
Diagnose and guide Contentstack Live Preview and Visual Builder implementations. Trace preview context, identify the broken contract, and recommend the…
official
cms-localization
contentstack
Advise developers on Contentstack localization: language setup, fallback chains, localized vs unlocalized entries, non-localizable fields, and multi-locale…
official