跳到主要内容
知仓学习社ZHICANG

saas-scaffolder

>

读凭据写文件读文件严重 11 · 高危 2borghei/Claude-Skills

它会碰到什么

扫了多少7 个文本文件,67 KB
它会碰到什么读凭据写文件读文件
命中总数18 处
命中统计严重 11 · 高 2 · 中 5 · 低 0
逐条看命中(13 条严重或高危)
  • 严重 references/project-structure-and-schema.md:80cred-paths
    ├── .env.example
  • 严重 references/project-structure-and-schema.md:153cred-paths
    # .env.example
  • 严重 references/workflow-and-quality.md:14cred-paths
    5. Create `.env.example`
  • 严重 references/workflow-and-quality.md:84cred-paths
    | Stripe test mode charges succeed but live mode fails | Live mode price IDs differ from test mode IDs | Use separate environment variables for test vs. live St
  • 严重 references/workflow-and-quality.md:94cred-paths
    - All environment variables are documented in `.env.example` with descriptions, and the app fails fast with clear error messages when required variables are mis
  • 严重 scripts/saas_scaffolder.py:218cred-paths
    ".env.example": None,
  • 严重 scripts/saas_scaffolder.py:268cred-paths
    ".env.example": ENV_EXAMPLE,
  • 严重 scripts/saas_scaffolder.py:377cred-paths
    key_files = [f for f in files_written if f in (".env.example", "middleware.ts", "db/schema.ts", "package.json")]
  • 严重 SKILL.md:37cred-paths
    - Generating a baseline `.env.example`, schema, and API routes for a Next.js stack.
  • 严重 SKILL.md:62cred-paths
    - **[references/project-structure-and-schema.md](references/project-structure-and-schema.md)** — input spec format, the full generated file tree, the multi-tena
  • 严重 SKILL.md:88cred-paths
    | `env-secrets-manager` | Audits and secures the environment variable configuration | Scaffolder generates `.env.example`; secrets manager validates no secrets 
  • scripts/saas_scaffolder.py:186identity-config-write
    "webhooks": {"stripe": {"route.ts": None}},
  • scripts/saas_scaffolder.py:215identity-config-write
    "hooks": {"use-subscription.ts": None, "use-current-user.ts": None},

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

SaaS Scaffolder

Generate a complete, production-ready SaaS application boilerplate including authentication (NextAuth, Clerk, or Supabase Auth), database schemas with multi-tenancy, billing integration (Stripe or Lemon Squeezy), API routes with validation, dashboard UI with shadcn/ui, and deployment configuration. Produces a working application from a product specification in under 30 minutes.

Core Capabilities

  • Spec-driven scaffolding — produce a full Next.js App Router + TypeScript + Tailwind + shadcn/ui file tree from a short product spec (auth/db/payments/tenancy/features).
  • Multi-tenant database schema — Drizzle ORM schema with workspaces (tenancy boundary), users, members, OAuth accounts, and sessions, with proper indexes and cascade rules.
  • Authentication — NextAuth v5 with Drizzle adapter, OAuth (Google/GitHub) and magic-link (Resend) providers, route-protection middleware.
  • Stripe billing — checkout session, customer portal, and signature-verified webhook handler keeping subscription state in sync.
  • Multi-tenancy patterns — workspace-scoped queries and plan-based feature gating (free/pro/enterprise).
  • Phased build + quality bar — 5 ordered scaffolding phases with per-phase validation, pitfalls, best practices, troubleshooting, and success criteria.

Keywords: SaaS, boilerplate, scaffolding, Next.js, authentication, Stripe, billing, multi-tenancy, subscription, starter template, NextAuth, Drizzle ORM, shadcn/ui

When to Use

  • Starting a new SaaS product, subscription app, or multi-tenant platform.
  • Standing up auth + billing + tenancy boilerplate quickly before building product features.
  • Adding workspace/organization tenancy with role-based access and plan gating.
  • Generating a baseline .env.example, schema, and API routes for a Next.js stack.

Clarify First

Before scaffolding, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • [ ] Auth provider — NextAuth / Clerk / Supabase Auth (--auth; changes the auth config and middleware generated)
  • [ ] Payments provider — Stripe / Lemon Squeezy / none (--payments; determines the billing + webhook handler)
  • [ ] Tenancy model — workspace / organization / single-tenant (--tenancy; shapes the entire database schema and scoped queries)
  • [ ] Database — Neon / Supabase / other Postgres (--db; sets the Drizzle adapter and connection config)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Tools

| Tool | Purpose | Command |

|------|---------|---------|

| saas_scaffolder.py | Generate a production-ready SaaS project structure (auth, billing, tenancy) | python scripts/saas_scaffolder.py --name my-saas --auth nextauth --db neondb --payments stripe --tenancy workspace |

| feature_flag_manager.py | CRUD + evaluate feature flags on a JSON store | python scripts/feature_flag_manager.py evaluate --key dark-mode --environment production --plan pro |

| tenant_config_validator.py | Validate multi-tenant config and scan source for missing tenant scoping / isolation issues | python scripts/tenant_config_validator.py --config tenant_config.json --src ./app |

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • [references/project-structure-and-schema.md](references/project-structure-and-schema.md) — input spec format, the full generated file tree, the multi-tenant Drizzle schema, and the .env.example variables. Read when defining the spec, laying out files, or writing the schema/env config.
  • [references/auth-billing-and-tenancy.md](references/auth-billing-and-tenancy.md) — complete NextAuth config, Stripe checkout + webhook handlers, route-protection middleware, and workspace-scoped query / plan-gating code. Read when wiring auth, billing, or tenancy.
  • [references/workflow-and-quality.md](references/workflow-and-quality.md) — the 5 ordered scaffolding phases with per-phase validation, common pitfalls, best practices, the troubleshooting table, and success criteria. Read before scaffolding and before shipping.

Scope & Limitations

This skill covers:

  • Full-stack SaaS scaffolding with Next.js App Router, TypeScript, Tailwind, and shadcn/ui
  • Authentication setup with NextAuth v5, Clerk, or Supabase Auth including OAuth and magic link providers
  • Stripe and Lemon Squeezy billing integration with checkout, webhooks, and customer portal
  • Multi-tenancy patterns (workspace/organization) with role-based access and plan-based feature gating

This skill does NOT cover:

  • Ongoing Stripe billing logic beyond initial integration (metered billing, usage-based pricing, invoicing customization) — see stripe-integration-expert
  • Database schema design decisions beyond the core tenancy model (complex relational modeling, indexing strategies) — see database-schema-designer
  • CI/CD pipeline configuration, deployment automation, or infrastructure provisioning — see ci-cd-pipeline-builder
  • API design standards, versioning, or OpenAPI specification generation — see api-design-reviewer

Integration Points

| Skill | Integration | Data Flow |

|-------|-------------|-----------|

| stripe-integration-expert | Extends the scaffolded Stripe setup with advanced billing patterns (metered, tiered, usage-based) | Scaffolder outputs base Stripe config and webhook handler; Stripe expert refines pricing models and adds invoice customization |

| database-schema-designer | Designs extended schemas beyond the core tenancy tables | Scaffolder provides baseline users/workspaces/members schema; schema designer adds domain-specific entities and optimizes indexes |

| api-design-reviewer | Reviews and improves the generated API routes for consistency and standards compliance | Scaffolder generates initial API routes; reviewer audits naming, error handling, and response formats |

| ci-cd-pipeline-builder | Creates deployment pipelines for the scaffolded project | Scaffolder outputs the application code; pipeline builder adds GitHub Actions, preview deployments, and production release workflows |

| env-secrets-manager | Audits and secures the environment variable configuration | Scaffolder generates .env.example; secrets manager validates no secrets are hardcoded and recommends vault integration |

| observability-designer | Adds logging, tracing, and monitoring to the scaffolded application | Scaffolder provides the application structure; observability designer instruments API routes, webhooks, and auth flows |

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。