# Admin panel skills

Task playbooks for working on the GCC Admin panel. Each folder holds a
`SKILL.md` with YAML frontmatter (`name`, `description`), matching the
convention used in `app/.claude/skills/`.

These are **procedures**. The reference material they lean on lives in
[`../docs/`](../docs/).

| Skill | Use it when |
|---|---|
| [`admin-api-endpoint`](admin-api-endpoint/SKILL.md) | Adding or changing anything in `api/components/*.cfc` — router registration, the `this.endpoints` allowlist, ACL guards, query binding, response envelope |
| [`admin-ui-view`](admin-ui-view/SKILL.md) | Building or changing a screen — view contract, routes and nav, the UI kit, XSS rules, CSS cascade traps |
| [`admin-acl-section`](admin-acl-section/SKILL.md) | A capability needs its own clearance, or you're splitting view/edit or basic/full tiers |
| [`admin-audit-logging`](admin-audit-logging/SKILL.md) | Recording an action or a view; "why isn't X in the audit log?" |
| [`admin-chat-moderation`](admin-chat-moderation/SKILL.md) | Touching the chat feed, complaint queue, or post removal |
| [`admin-game-integration`](admin-game-integration/SKILL.md) | An admin action must take effect in-game — forced logout, PMs, records, mute flag, game-side CSS |
| [`admin-verify`](admin-verify/SKILL.md) | **Before every commit** — drive the real endpoint, test the gate, clean up |

## Suggested order

Changing the backend → `admin-api-endpoint`, then `admin-audit-logging` if it
should be recorded, then `admin-verify`.

Changing a screen → `admin-ui-view`, then `admin-verify`.

Adding a gated capability → `admin-acl-section` first (it decides the shape of
both sides), then the endpoint/view skills, then `admin-verify`.

## Related skills elsewhere

- `app/.claude/skills/admin-changelog` — update the panel's **What's New** page.
  Owns *all* admin-related history, including admin features that live in game
  files. Run it when admin-visible behaviour changes.
- `app/.claude/skills/game-changelog` — the **public** game changelog. Admin
  changes must never appear there.

## Two standing rules

- **Legacy `edmin/` is defunct and is never documented** — not here, not in
  either changelog.
- **Never commit a verification harness.** `git status --short` before every
  commit; the panel folder should contain only real files.
