JustHandled Labs
// practical agent and app guides

Choose the workflow. Verify the work.

Short, specific guidance for buyers and teams choosing SKILL.md packages or shipping AI-built software. Recommendations separate observed evidence from confident claims.

GITHUB CLI GUIDE · 8 MIN

Install agent skills safely with GitHub CLI

Preview the whole package, choose the correct host and scope, pin the reviewed release, preserve provenance, and check updates without applying them.

Use the gh skill workflow →
BUYER GUIDE · 7 MIN

Which agent skill should I install first?

Match the problem in front of you to a focused free or paid workflow, using real install and purchase evidence from the JustHandled Labs catalog.

Choose a starting skill →
SECURITY GUIDE · 9 MIN

How to audit a SKILL.md package before installation

Review provenance, instructions, scripts, permissions, network access, outputs, and updates with a practical nine-step checklist.

Use the security checklist →
PRE-LAUNCH GUIDE · 11 MIN

How to audit an AI-built app before launch

Replace a convincing demo with evidence for completeness, real data paths, failures, authorization, production behavior, and recovery.

Build the release evidence →
PAYMENTS GUIDE · 9 MIN

Stripe webhook works locally but not in production

Separate missing events from delivery failures and business-logic errors, then fix live-mode secrets, raw-body handling, retries, idempotency, and subscription state.

Trace the production failure →
DATABASE SECURITY GUIDE · 10 MIN

Supabase RLS audit checklist before launch

Prove table coverage, policy semantics, cross-user denial, elevated-key boundaries, view and storage behavior, and migration state before production traffic arrives.

Build the RLS evidence →
TEST QUALITY GUIDE · 10 MIN

Audit AI-generated tests before trusting coverage

Check assertion execution, expected-value provenance, mocks, snapshots, and deliberate falsification before a passing suite becomes release evidence.

Test the tests →
BROWSER TESTING GUIDE · 10 MIN

How to test a web app before launch with Playwright

Select the activation and payment journeys that matter, then run them with resilient locators, protected auth state, mobile projects, console capture, screenshots, and traces.

Build the browser evidence →
CI TROUBLESHOOTING GUIDE · 9 MIN

GitHub Actions failed? Find the first real error

Start with the first failing job and step, separate the root error from cascades, check repository context, and verify one bounded fix.

Diagnose the failed run →
CODE REVIEW GUIDE · 8 MIN

Write a pull request description from the git diff

Choose the correct staged or three-dot diff, separate intent from evidence, report changed files exactly, and keep unrun tests honest.

Build the reviewer map →
RELEASE NOTES GUIDE · 8 MIN

Generate a changelog from git commits

Choose the exact Git range, preserve both breaking-footer spellings, keep malformed commits visible, and review the SemVer signal before publishing.

Build the release notes →
ACCOUNT MAPPING GUIDE · 9 MIN

How to identify a sales champion in an account

Separate authority, engagement, and demonstrated influence; label inferred relationships; and choose one evidence-seeking next action per stakeholder.

Build the champion map →
SOCIAL PREVIEW GUIDE · 7 MIN

LinkedIn link preview image not showing?

Check the final Open Graph tags, image URL and dimensions, crawler access, redirects, and cache state in the order that isolates the real failure.

Fix the preview path →
QR PAYLOAD GUIDE · 7 MIN

Audit a QR code payload before printing it

Decode the final candidate, verify its scheme and domain, expose shorteners and credentials, test the intended action, and preserve a fallback.

Run the payload preflight →
ENGINEERING PLANNING GUIDE · 10 MIN

Turn a PRD into a coding-agent implementation plan

Extract the product contract, isolate ambiguities, map dependencies, write observable acceptance criteria, and preview GitHub issues before anything is created.

Build the execution contract →
CREATOR STOREFRONT GUIDE · 8 MIN

Make a Gumroad cover and thumbnail with AI

Use the right cover and square-thumbnail dimensions, constrain text and claims, compare real composition variants, and review the result at storefront size.

Build the cover set →
LOCAL DEBUGGING GUIDE · 9 MIN

App won't run locally? Check the environment before the code

Preserve the first useful error, then check runtimes, dependencies, environment-variable names, ports, Docker, and required services in a fixed order.

Diagnose the startup failure →
SEO GUIDE · 8 MIN

How to fix robots.txt and sitemap.xml before indexing

Align crawl rules, sitemap URLs, canonicals, noindex controls, and live responses before asking Google to discover the site.

Run the crawlability preflight →
REPOSITORY GUIDE · 10 MIN

How to remove commented-out code safely

Classify dead code, preserve comments that carry intent, preview the exact diff, and verify the repository after cleanup.

Clean the comments without guessing →
DATA SAFETY GUIDE · 9 MIN

How to scan a codebase for PII before sharing it

Inventory schemas, seeds, samples, configuration, logs, and generated artifacts; triage matches without copying sensitive values into a second leak.

Run the personal-data preflight →

How these guides are written

Recommendations separate verified marketplace behavior from judgment calls, avoid calling a clean scan proof of safety, and send readers to individual detail pages before any marketplace handoff. Prices and purchase options remain on Agensi, where they are current.

Already know the job?

Search all 98 focused skills by task, category, or platform.

Browse the complete catalog