saas-scaffolder
>
它会碰到什么
逐条看命中(13 条严重或高危)
- 严重
references/project-structure-and-schema.md:80cred-paths├── .env.example
- 严重
references/project-structure-and-schema.md:153cred-paths# .env.example
- 严重
references/workflow-and-quality.md:14cred-paths5. Create `.env.example`
- 严重
references/workflow-and-quality.md:84cred-paths| Stripe test mode charges succeed but live mode fails | Live mode price IDs differ from test mode IDs | Use separate environment variables for test vs. live St
- 严重
references/workflow-and-quality.md:94cred-paths- All environment variables are documented in `.env.example` with descriptions, and the app fails fast with clear error messages when required variables are mis
- 严重
scripts/saas_scaffolder.py:218cred-paths".env.example": None,
- 严重
scripts/saas_scaffolder.py:268cred-paths".env.example": ENV_EXAMPLE,
- 严重
scripts/saas_scaffolder.py:377cred-pathskey_files = [f for f in files_written if f in (".env.example", "middleware.ts", "db/schema.ts", "package.json")] - 严重
SKILL.md:37cred-paths- Generating a baseline `.env.example`, schema, and API routes for a Next.js stack.
- 严重
SKILL.md:62cred-paths- **[references/project-structure-and-schema.md](references/project-structure-and-schema.md)** — input spec format, the full generated file tree, the multi-tena
- 严重
SKILL.md:88cred-paths| `env-secrets-manager` | Audits and secures the environment variable configuration | Scaffolder generates `.env.example`; secrets manager validates no secrets
- 高
scripts/saas_scaffolder.py:186identity-config-write"webhooks": {"stripe": {"route.ts": None}}, - 高
scripts/saas_scaffolder.py:215identity-config-write"hooks": {"use-subscription.ts": None, "use-current-user.ts": None},
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
SaaS Scaffolder
Generate a complete, production-ready SaaS application boilerplate including authentication (NextAuth, Clerk, or Supabase Auth), database schemas with multi-tenancy, billing integration (Stripe or Lemon Squeezy), API routes with validation, dashboard UI with shadcn/ui, and deployment configuration. Produces a working application from a product specification in under 30 minutes.
Core Capabilities
- Spec-driven scaffolding — produce a full Next.js App Router + TypeScript + Tailwind + shadcn/ui file tree from a short product spec (auth/db/payments/tenancy/features).
- Multi-tenant database schema — Drizzle ORM schema with workspaces (tenancy boundary), users, members, OAuth accounts, and sessions, with proper indexes and cascade rules.
- Authentication — NextAuth v5 with Drizzle adapter, OAuth (Google/GitHub) and magic-link (Resend) providers, route-protection middleware.
- Stripe billing — checkout session, customer portal, and signature-verified webhook handler keeping subscription state in sync.
- Multi-tenancy patterns — workspace-scoped queries and plan-based feature gating (free/pro/enterprise).
- Phased build + quality bar — 5 ordered scaffolding phases with per-phase validation, pitfalls, best practices, troubleshooting, and success criteria.
Keywords: SaaS, boilerplate, scaffolding, Next.js, authentication, Stripe, billing, multi-tenancy, subscription, starter template, NextAuth, Drizzle ORM, shadcn/ui
When to Use
- Starting a new SaaS product, subscription app, or multi-tenant platform.
- Standing up auth + billing + tenancy boilerplate quickly before building product features.
- Adding workspace/organization tenancy with role-based access and plan gating.
- Generating a baseline
.env.example, schema, and API routes for a Next.js stack.
Clarify First
Before scaffolding, confirm these inputs. If any is unknown or vague, ASK — do not assume:
- [ ] Auth provider — NextAuth / Clerk / Supabase Auth (
--auth; changes the auth config and middleware generated) - [ ] Payments provider — Stripe / Lemon Squeezy / none (
--payments; determines the billing + webhook handler) - [ ] Tenancy model — workspace / organization / single-tenant (
--tenancy; shapes the entire database schema and scoped queries) - [ ] Database — Neon / Supabase / other Postgres (
--db; sets the Drizzle adapter and connection config)
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
Tools
| Tool | Purpose | Command |
|------|---------|---------|
| saas_scaffolder.py | Generate a production-ready SaaS project structure (auth, billing, tenancy) | python scripts/saas_scaffolder.py --name my-saas --auth nextauth --db neondb --payments stripe --tenancy workspace |
| feature_flag_manager.py | CRUD + evaluate feature flags on a JSON store | python scripts/feature_flag_manager.py evaluate --key dark-mode --environment production --plan pro |
| tenant_config_validator.py | Validate multi-tenant config and scan source for missing tenant scoping / isolation issues | python scripts/tenant_config_validator.py --config tenant_config.json --src ./app |
References
Load the reference that matches the task — keep this file lean and pull detail on demand:
- [references/project-structure-and-schema.md](references/project-structure-and-schema.md) — input spec format, the full generated file tree, the multi-tenant Drizzle schema, and the
.env.examplevariables. Read when defining the spec, laying out files, or writing the schema/env config. - [references/auth-billing-and-tenancy.md](references/auth-billing-and-tenancy.md) — complete NextAuth config, Stripe checkout + webhook handlers, route-protection middleware, and workspace-scoped query / plan-gating code. Read when wiring auth, billing, or tenancy.
- [references/workflow-and-quality.md](references/workflow-and-quality.md) — the 5 ordered scaffolding phases with per-phase validation, common pitfalls, best practices, the troubleshooting table, and success criteria. Read before scaffolding and before shipping.
Scope & Limitations
This skill covers:
- Full-stack SaaS scaffolding with Next.js App Router, TypeScript, Tailwind, and shadcn/ui
- Authentication setup with NextAuth v5, Clerk, or Supabase Auth including OAuth and magic link providers
- Stripe and Lemon Squeezy billing integration with checkout, webhooks, and customer portal
- Multi-tenancy patterns (workspace/organization) with role-based access and plan-based feature gating
This skill does NOT cover:
- Ongoing Stripe billing logic beyond initial integration (metered billing, usage-based pricing, invoicing customization) — see
stripe-integration-expert - Database schema design decisions beyond the core tenancy model (complex relational modeling, indexing strategies) — see
database-schema-designer - CI/CD pipeline configuration, deployment automation, or infrastructure provisioning — see
ci-cd-pipeline-builder - API design standards, versioning, or OpenAPI specification generation — see
api-design-reviewer
Integration Points
| Skill | Integration | Data Flow |
|-------|-------------|-----------|
| stripe-integration-expert | Extends the scaffolded Stripe setup with advanced billing patterns (metered, tiered, usage-based) | Scaffolder outputs base Stripe config and webhook handler; Stripe expert refines pricing models and adds invoice customization |
| database-schema-designer | Designs extended schemas beyond the core tenancy tables | Scaffolder provides baseline users/workspaces/members schema; schema designer adds domain-specific entities and optimizes indexes |
| api-design-reviewer | Reviews and improves the generated API routes for consistency and standards compliance | Scaffolder generates initial API routes; reviewer audits naming, error handling, and response formats |
| ci-cd-pipeline-builder | Creates deployment pipelines for the scaffolded project | Scaffolder outputs the application code; pipeline builder adds GitHub Actions, preview deployments, and production release workflows |
| env-secrets-manager | Audits and secures the environment variable configuration | Scaffolder generates .env.example; secrets manager validates no secrets are hardcoded and recommends vault integration |
| observability-designer | Adds logging, tracing, and monitoring to the scaffolded application | Scaffolder provides the application structure; observability designer instruments API routes, webhooks, and auth flows |
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。