code-review

tarafından contentstack

Pull-request checklist for security, Contentstack credentials, sanitization, and image configuration.

npx skills add https://github.com/contentstack/kickstart-next-ssg --skill code-review

Code review – kickstart-next-ssg

When to use

  • Before approving or merging a pull request
  • Auditing changes that touch env vars, CMS integration, or user-facing HTML

Instructions

Secrets and configuration

  • No real .env values or delivery/preview tokens committed; use placeholders in docs only.
  • New NEXT_PUBLIC_* keys are exposed to the browser—avoid putting sensitive server-only secrets behind that prefix.

Contentstack

  • Token scopes and preview settings stay aligned with README.md (preview-capable delivery token, Live Preview environment).

Security and dependencies

HTML and XSS

  • Rich text and block copy use dangerouslySetInnerHTML only after isomorphic-dompurify in pages/index.tsx; preserve or improve sanitization when changing markup.

Images

  • New remote image domains must be reflected in next.config.mjs images.remotePatterns (or env-driven hostname) so next/image does not break at runtime.

Quality

  • Run npm run lint locally for substantive TS/React changes.

contentstack tarafından daha fazla skill

brand-kit-assistant
contentstack
Advise users on Contentstack Brand Kit concepts, setup, governance, and on-brand AI generation. Route API-specific tasks to the right Brand Kit capability or…
official
cms-assets
contentstack
Advise developers on organizing, delivering, and transforming assets in Contentstack. Cover folder structure, Image Delivery API transformations, publishing…
official
cms-branches-aliases
contentstack
Advise developers on using Contentstack branches for isolated content development and aliases for zero-downtime content deployments. Cover branch strategy,…
official
cms-data-modeling-best-practices
contentstack
Guide developers to model content in Contentstack using the simplest reusable structure. The skill explains when to use content types, references, global…
official
cms-entries
contentstack
Advise developers on querying, localizing, versioning, publishing, and structuring Contentstack entries for efficient delivery. Focus on CDA usage, reference…
official
cms-environments-publishing
contentstack
Geliştiricilere ortam yapılandırma, içerik yayınlama, dağıtım ve önizleme token'larını kullanma, Sync API'den yararlanma ve CDN'i anlama konularında danışmanlık yapın ve…
official
cms-live-preview-visual-builder-support-assistant
contentstack
Contentstack Live Preview ve Visual Builder uygulamalarını teşhis edin ve yönlendirin. Önizleme bağlamını izleyin, bozuk sözleşmeyi belirleyin ve öneride bulunun…
official
cms-localization
contentstack
Advise developers on Contentstack localization: language setup, fallback chains, localized vs unlocalized entries, non-localizable fields, and multi-locale…
official