ssheleg skills → sheleg-dev

integrations: money in, tracking, errors, sign-in, speed

sheleg-dev

The integration layer a product reaches once it has users: Stripe subscription billing reconciled into your own database — checkout, renewals, seats and proration, refunds, claim-first webhook idempotency, reconciliation and price drift; crypto payments that survive under-payment, duplicate webhooks and rate drift; GA4/Ads/Meta/LinkedIn under Consent Mode v2; Google sign-in with the account pre-hijacking guard, and the server-side Google auth surface; Core Web Vitals work that moves the score, and Sentry error tracking wired so it does not forward your own credentials to a third party and so a stack trace names the commit that caused it.

Install this pack on its own, or use it with the ssheleg harness.

v0.13.2pinned in this release of the family
7skills in the pack
1routing rule it owns

What it ships

Each name below is an entry point an agent can be routed to.

Shape: static. Each integration is a fixed sequence of seams; nothing decides its own next step.

stripe-billing

Use when connecting a product to Stripe, fixing a payment bug ( ), or auditing a live integration: checkout, renewals, seats, proration, refunds, cancellation and the cancel-step coupon, the portal, and the webhook that turns a payment into an entitlement. Covers Stripe's agent toolchain, the pinned API version, SDK retries, price resolution, claim-first webhook idempotency, what billing_reason decides, cumulative refunds, the cancellation field flexible billing_mode moved, retention eligibility Stripe cannot express, and write ordering with compensating reverts. Not for choosing between Stripe products (stripe-best-practices) or reading Stripe docs (stripe-docs).

crypto-payments

Use when adding or auditing crypto checkout, crypto top-up, or payment webhooks — where a payer sends the wrong amount, a webhook arrives more than once, and the rate moves between quote and transfer. Covers invoice lifecycle and status mapping, webhook signature verification and the JSON-escaping trap, idempotent processing, IP allowlisting behind a proxy, CSRF exemption for callback routes, the conversion buffer, reconciliation fields, credit waterfalls, refund and AML-hold states, local development with a tunnel and signed mock callbacks, a test matrix and a security checklist. Not for card billing — use stripe-billing.

error-tracking

Use when wiring error tracking into a product — adding Sentry to a service, deciding what a DSN is and where it may live, keeping secrets out of events before they reach a third party, tying releases to commits so a stack trace names the change that caused it, or judging whether a green health check means anything. Covers the Sentry SDK options that matter for a backend, the two different tools both called sentry, the auth-token taxonomy and which kind can create a project, and the MCP server with the config channel it belongs in. NOT for judging an agent's trajectory (agent-evals), triaging tickets in a tracker (your tracker's own triage skill), or choosing an uptime vendor.

ad-tracking

Use when setting up or modifying ad pixel integration, conversion tracking, consent management, purchase event tracking, retargeting audiences, or auditing an existing advertising analytics stack. Covers Google Analytics 4, Google Ads, Meta (Facebook) Pixel and LinkedIn Insight Tag in web applications: Consent Mode v2, standard events, e-commerce tracking, advanced matching, Enhanced Conversions, CSP configuration, user identification, cross-device tracking, and GDPR/DMA compliance. Not for running the ad campaigns themselves.

google-signin

Use when implementing, reviewing or debugging Google login / sign-in / sign-up on a website — wiring the GIS button or One Tap, verifying Google ID tokens on the server, linking Google to existing password accounts, or fixing. Covers GCP OAuth client setup, backend ID-token verification, three-way account linking with the pre- hijacking guard, login-CSRF defense, nonce/replay protection and a mandatory security checklist. For the broader library surface use google-auth instead.

google-auth

Use when a server authenticates to Google in a Node.js or Python application — OAuth 2.0 flows, verifying Google ID tokens server-side, service account authentication and keys, Application Default Credentials, Workload Identity Federation, API keys, or working with google-auth-library (Node.js) or google-auth (Python). Covers server-side ID token verification and security best practices. For end-user web sign-in only, use the google-signin skill instead.

frontend-performance

Use when building or auditing web pages for performance — running PageSpeed Insights, optimizing Lighthouse scores, fixing render-blocking resources, reducing bundle size, improving load times, or diagnosing slow page rendering. Covers Core Web Vitals (LCP, INP, CLS) and the Lighthouse diagnostics beside them (FCP, TBT, Speed Index), font loading strategies, CSS animation compositing, JavaScript bundle optimization, cache headers, code splitting, Content Security Policy, image optimization, and the contrast and heading issues that move a Lighthouse score. Not for visual design or conversion work.


Install just this one

Every pack installs standalone. The whole family is one command.

any agent the skills CLI supports
$
npx skills add ssheleg/sheleg-dev
claude code, as a plugin
$
claude plugin marketplace add ssheleg/sheleg-dev && claude plugin install sheleg-dev@sheleg-dev

When the agent reaches for it

These are the rules the family writes into your agent's own instruction file — verbatim. Each one states the rule, the boundary in both directions, and the phrase that declines it.

/sheleg-dev — what it runs on to charge, track and sign in

  • when: money, tracking, errors, sign-in or speed is being wired
  • decline it: no wiring

If sheleg-dev is installed, WIRING integrations goes through it — cards (stripe-billing), crypto (crypto-payments), pixels/server events (ad-tracking), errors (error-tracking), sign-in (google-signin, google-auth), speed (frontend-performance). The webhook proves payment; the redirect only a browser. Share one event_id across both event channels or count revenue twice.

The boundary. NOT through it: paywall behavior/tiers (super-ux), checkout look (sheleg-design), words (copywriting), price (a business decision, never a skill's).

Refusal phrase: "no wiring" or «без обвязки» — avoid «без интеграций»: интеграция triggers task-pipeline.

Among the routers: super-ux owns the payment step; sheleg-dev its charge.


The rest of the family

super-ux v0.59.1

what the interface must do

Scenario-driven UI development: a versioned design chain in docs/ux/ — the product vision, personas and jobs, user flows and the paid-acquisition funnel among them, a screens-and-states map with Figma frames…

7 skills/super-ux

task-pipeline v1.90.2

how a change reaches the repository

Full-cycle delivery orchestrator: an intake grill turns the request into a complete brief, then ten gated stages carry it from docs to acceptance, refusing to advance until each gate passes.

3 skills/task-pipeline

agent-sync v1.21.5

who is holding this file right now

Coordination plane for concurrent agents: leases with a TTL so two agents cannot claim the same work, race-free id reservation, a run journal and a generated board, over a pluggable knowledge cloud.

1 skill/agent-sync

make-skill v0.29.2

how the skill or plugin itself is built

A skill that builds skills: create, retrofit, audit and publish agent skills and Claude Code plugins

1 skill/make-skill

sheleg-design v1.64.0

how it looks and moves

The taste layer: cinematic scroll-driven landing pages (one scroll clock, motion that degrades to calm, WebGL particle formations), product-UI style packs with a ready token layer each, and the Figma border

1 skill · a catalogue of its own/sheleg-design

seo-aeo-audit v0.26.3

whether a machine will find it

Evidence-first website audit for search and answer engines: ten tracks from crawl access to AI citation mechanics, every finding backed by an observation and every recommendation tiered, ending in…

1 skillRead →

agent-stack v0.25.5

orchestration, prompts, evals, protocols, and the LLM wallet

Production patterns for AI agent systems, in four skills. The orchestrator: tool-calling loops that survive context pressure, pipelines with human checkpoints and resume, provider routing with fallback…

4 skills/agent-stack

telegram-dev v0.2.2

which Telegram API each surface speaks, and what each one costs

Telegram, split by the API each surface actually speaks, in three skills. telegram-bots covers the official HTTP Bot API

3 skills/telegram-dev

xr-dev v0.3.2

how a Quest product moves from platform choice to launch and operation

Quest product delivery from platform choice to launch and operation, with stage owners, evidence gates and next actions.

7 skills · a catalogue of its own/xr-dev

web3d-dev v0.1.2

how realtime 3D on the web runs, ships its assets and moves

Realtime 3D on the web with three.js and React Three Fiber, in three skills split by the question. web3d-runtime owns how the scene runs

3 skills/web3d-dev