CODEBASE.md - project-starter
Comprehensive codebase documentation generated by 10 parallel exploration agents.
Generated: 2026-01-17
Overview
project-starter (formerly claude-workflow) is a universal Claude Code plugin that augments the IDE with specialized AI agents, knowledge skills, automation hooks, and workflow commands for accelerated software development.
Key Capabilities
- 7 Specialized Agents: Autonomous subagents with action-first directives, effort scaling, and adversarial self-review
- 26 Slash Commands: Output styles, git workflows, verification, planning, onboarding, metrics
- 14 Knowledge Skills: Architecture, testing, APIs, performance, git, security, database, devops, error handling — with on-demand context loading
- 14 Automation Hooks: Pre/post tool validation, formatting, security, TypeScript, branch protection, doc suggestions, metrics, notifications
Repository Structure
claude-workflow/
├── .claude-plugin/ # Plugin configuration
│ ├── plugin.json # Plugin manifest (name, version, metadata)
│ └── marketplace.json # Marketplace publishing metadata
├── .github/ # GitHub governance & CI
│ ├── workflows/
│ │ └── validate.yml # Plugin validation CI/CD
│ ├── PULL_REQUEST_TEMPLATE.md
│ └── ISSUE_TEMPLATE/
│ ├── bug_report.md
│ └── feature_request.md
├── .claude/ # Local settings and permissions
│ └── settings.local.json
├── agents/ # 7 specialized AI subagents
│ ├── orchestrator.md # Master coordinator (opus model)
│ ├── code-reviewer.md # Quality and best practices
│ ├── debugger.md # Root cause analysis
│ ├── docs-writer.md # Technical documentation
│ ├── security-auditor.md # OWASP vulnerability detection
│ ├── refactorer.md # Code structure improvements
│ └── test-architect.md # Test strategy design
├── commands/ # 26 slash commands
│ ├── architect.md # System design mode
│ ├── rapid.md # Fast development mode
│ ├── mentor.md # Teaching mode
│ ├── review.md # Strict review mode
│ ├── commit.md # Auto-generate commits
│ ├── commit-push-pr.md # Full PR workflow
│ ├── verify-changes.md # Multi-agent verification
│ ├── validate-build.md # Build validation
│ ├── run-tests.md # Tiered test execution
│ ├── lint-check.md # Linting checks
│ ├── lint-fix.md # Auto-fix linting
│ ├── security-scan.md # Security scanning
│ ├── quick-fix.md # Fast lint/type fixes
│ ├── add-tests.md # Generate tests
│ ├── sync-branch.md # Sync with main
│ ├── summarize-changes.md # Session summaries
│ ├── code-simplifier.md # Post-implementation cleanup
│ ├── parallel-review.md # Multi-directory review
│ ├── parallel-analyze.md # Multi-perspective analysis
│ ├── plan.md # Persistent PLAN.md tracking
│ ├── refactor-guided.md # 4-phase guided refactoring
│ ├── dependency-upgrade.md # Safe dependency upgrades
│ ├── tutorial.md # Interactive plugin tutorial
│ ├── bootstrap-repo.md # 10-agent repo exploration
│ ├── save-session-learnings.md # Persist session discoveries
│ └── metrics.md # View agent metrics
├── skills/ # 14 knowledge domains
│ ├── analyzing-projects/SKILL.md
│ ├── convex-backend/SKILL.md
│ ├── database-design/SKILL.md
│ ├── designing-architecture/SKILL.md
│ ├── designing-apis/SKILL.md
│ ├── designing-tests/SKILL.md
│ ├── devops-infrastructure/SKILL.md
│ ├── error-handling/SKILL.md
│ ├── managing-git/SKILL.md
│ ├── optimizing-performance/SKILL.md
│ ├── parallel-execution/SKILL.md
│ ├── security-patterns/SKILL.md
│ ├── vercel-react-best-practices/SKILL.md
│ └── web-design-guidelines/SKILL.md
├── hooks/ # 14 automation scripts
│ ├── hooks.json # Hook registry
│ ├── protect-files.py # Block sensitive file edits
│ ├── security-check.py # Detect hardcoded secrets
│ ├── format-on-edit.py # Auto-format (prettier/black/gofmt)
│ ├── typescript-check.py # tsc --noEmit on .ts/.tsx edits
│ ├── pre-commit-check.py # Debug statements & temp markers
│ ├── validate-environment.py # Check Node/Python/Git
│ ├── validate-prompt.py # Suggest agents for prompts
│ ├── verify-on-complete.py # Run tests/lint on completion
│ ├── log-commands.sh # Audit bash commands
│ ├── branch-protection.sh # Warn on protected branch ops
│ ├── suggest-doc-updates.py # Suggest doc updates on changes
│ ├── track-metrics.py # Session telemetry logging
│ ├── notify-input.sh # Desktop notification (input needed)
│ └── notify-complete.sh # Desktop notification (complete)
├── examples/ # Multi-agent orchestration examples
│ ├── README.md
│ └── orchestration/
│ ├── comprehensive-code-review/
│ └── parallel-execution/
├── templates/ # User-copyable configuration
│ ├── CLAUDE.md.template
│ ├── settings.json.template
│ ├── settings.local.json.template
│ └── mcp.json.template
├── CLAUDE.md # Development guidelines
├── README.md # Main documentation
├── CHANGELOG.md # Version history
├── CONTRIBUTING.md # Contribution guidelines
├── CODE_OF_CONDUCT.md # Community guidelines
├── PERMISSIONS.md # Permission framework
└── LICENSE # MIT license
Getting Started
Installation Options
1. Per-Session (Temporary)
git clone https://github.com/CloudAI-X/claude-workflow-v2.git
claude --plugin-dir ./claude-workflow
2. Per-Project (Permanent)
claude plugin install ./claude-workflow
3. Global (Marketplace)
claude plugin install project-starter
4. Agent SDK (Programmatic)
import { query } from "@anthropic-ai/claude-agent-sdk";
for await (const message of query({
plugins: [{ type: "local", path: "./claude-workflow" }],
})) {
// Handle messages
}
Prerequisites
| Tool |
Required |
Purpose |
| Claude Code |
v1.0.33+ |
Plugin host |
| Python 3 |
Yes |
Hook scripts |
| Git |
Recommended |
Version control features |
| Node.js |
Optional |
JS/TS formatting, npm commands |
Validation
claude plugin validate # Validate plugin structure
Architecture
Plugin Architecture Pattern
This plugin uses a metadata-driven, modular architecture with no traditional runtime dependencies:
┌─────────────────────────────────────────────────────────────┐
│ Claude Code IDE │
├─────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Agents │ │ Commands │ │ Skills │ │
│ │ (7 specs) │ │ (19 specs) │ │ (7 domains) │ │
│ └──────┬──────┘ └──────┬──────┘ └──────┬──────┘ │
│ │ │ │ │
│ └────────────────┼────────────────┘ │
│ │ │
│ ┌─────────┴─────────┐ │
│ │ Hook System │ │
│ │ (Event-Driven) │ │
│ └─────────┬─────────┘ │
│ │ │
│ ┌─────────────────────┼─────────────────────┐ │
│ │ │ │ │ │ │
│ ▼ ▼ ▼ ▼ ▼ │
│ PreToolUse PostToolUse Stop SessionStart Notification │
│ │
└─────────────────────────────────────────────────────────────┘
Agent Hierarchy
| Agent |
Model |
Responsibility |
Auto-Trigger Keywords |
| orchestrator |
opus |
Multi-step coordination, parallel execution |
"improve", "enhance", "build", "architecture" |
| code-reviewer |
sonnet |
Quality assessment, best practices |
"review", "PR review", "lint", "standards audit" |
| debugger |
sonnet |
Root cause analysis, bug fixing |
"bug", "error", "crash", "memory leak", "timeout" |
| security-auditor |
sonnet |
Vulnerability detection, OWASP |
"security", "auth", "JWT", "CORS", "secrets" |
| test-architect |
sonnet |
Test strategy, coverage |
"test", "coverage", "mocking", "flaky tests" |
| refactorer |
sonnet |
Code structure, SOLID principles |
"refactor", "tech debt", "code smells", "complexity" |
| docs-writer |
sonnet |
Technical documentation |
"document", "changelog", "migration guide" |
Parallel Execution (v1.1.0)
The orchestrator can spawn N subagents simultaneously for Nx performance:
User Request
│
▼
┌─────────────────┐
│ Orchestrator │
│ (Creates Plan)│
└────────┬────────┘
│
┌───────────┼───────────┬───────────┬───────────┐
│ │ │ │ │
▼ ▼ ▼ ▼ ▼
┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐
│ Task 1 │ │ Task 2 │ │ Task 3 │ │ Task 4 │ │ Task 5 │
└────┬───┘ └────┬───┘ └────┬───┘ └────┬───┘ └────┬───┘
│ │ │ │ │
└──────────┴──────────┴──────────┴──────────┘
│
[TaskOutput]
│
[Synthesize]
Critical Rule: ALL Task calls must be in a SINGLE assistant message for true parallelism.
Data Layer
This plugin has no traditional database layer. Instead, it uses:
Data Sources
| Type |
Location |
Format |
| Plugin Config |
.claude-plugin/plugin.json |
JSON |
| Hook Registry |
hooks/hooks.json |
JSON |
| Agent Definitions |
agents/*.md |
YAML frontmatter + Markdown |
| Command Definitions |
commands/*.md |
YAML frontmatter + Markdown |
| Skill Knowledge |
skills/*/SKILL.md |
YAML frontmatter + Markdown |
YAML Frontmatter Schema
---
name: identifier
description: Purpose. Use PROACTIVELY when [triggers].
tools: Read, Write, Edit, Bash, Glob, Grep
model: opus|sonnet|haiku
permissionMode: default|acceptEdits
skills: skill-name1, skill-name2
---
Hook Input/Output
// stdin (hook receives)
{
"tool_input": {
"file_path": "/path/to/file",
"content": "file contents..."
}
}
// Exit codes
// 0 = Allow operation
// 2 = Block with message
Core Logic
Orchestrator Workflow
Phase 1: UNDERSTAND
└─ Read requirements, explore codebase, identify affected systems
Phase 2: PLAN
└─ Create TodoWrite list, group parallelizable tasks, identify dependencies
Phase 3: DELEGATE
└─ Spawn specialists (sequential or parallel via Task tool)
Phase 4: INTEGRATE
└─ Synthesize outputs, resolve conflicts, ensure consistency
Phase 5: VERIFY
└─ Run tests/lint, quality checks
Phase 6: DELIVER
└─ Summarize changes, create PRs, update documentation
Security Check Algorithm
SECRET_PATTERNS = [
r'api[_-]?key.*[a-zA-Z0-9_-]{20,}', # API keys
r'ghp_[a-zA-Z0-9]{36}', # GitHub PATs
r'sk-ant-[a-zA-Z0-9-]{90,}', # Anthropic keys
r'AKIA[0-9A-Z]{16}', # AWS credentials
r'-----BEGIN.*PRIVATE KEY-----', # Private keys
]
SKIP_FILES = ['.env.example', 'package-lock.json', '*test*']
# Exit 2 (block) if secret found, 0 (allow) otherwise
Verification Pipeline
verify-changes command spawns 5 parallel subagents:
1. Syntax & Type Check (tsc, mypy, go vet)
2. Test Runner (affected → unit → integration)
3. Lint & Style Check (eslint, ruff, golangci-lint)
4. Security Scan (secrets, dependencies, OWASP)
5. Build Validator (compile, artifacts)
+ 3 Adversarial subagents:
- False Positive Filter
- Missing Issues Finder
- Context Validator
API Reference
Commands (26 total)
Output Styles
| Command |
Description |
/project-starter:architect |
System design mode - architecture before code |
/project-starter:rapid |
Fast development - minimal ceremony |
/project-starter:mentor |
Teaching mode - explains concepts |
/project-starter:review |
Strict code review mode |
Git Workflow
| Command |
Description |
/project-starter:commit |
Auto-generate conventional commit |
/project-starter:commit-push-pr |
Full workflow: commit → push → PR |
/project-starter:quick-fix |
Fast lint/type error fixes |
/project-starter:add-tests |
Generate tests for changes |
/project-starter:lint-fix |
Auto-fix all linting issues |
/project-starter:sync-branch |
Sync with main (rebase/merge) |
/project-starter:summarize-changes |
Generate standup/PR summaries |
Verification
| Command |
Description |
/project-starter:verify-changes |
Multi-agent adversarial verification |
/project-starter:validate-build |
Build process validation |
/project-starter:run-tests |
Tiered test execution |
/project-starter:lint-check |
Code quality checks |
/project-starter:security-scan |
Vulnerability detection |
/project-starter:code-simplifier |
Post-implementation cleanup |
/project-starter:parallel-review |
Multi-directory parallel review |
/project-starter:parallel-analyze |
Multi-perspective analysis |
Planning & Refactoring
| Command |
Description |
/project-starter:plan |
Persistent PLAN.md phase tracking |
/project-starter:refactor-guided |
4-phase systematic refactoring |
/project-starter:dependency-upgrade |
Safe dependency upgrades |
Onboarding & Knowledge
| Command |
Description |
/project-starter:tutorial |
Interactive guided tutorial |
/project-starter:bootstrap-repo |
10-agent parallel repo exploration |
/project-starter:save-session-learnings |
Persist session discoveries |
/project-starter:metrics |
View agent performance metrics |
Hook Events
| Event |
Trigger |
Scripts |
| PreToolUse |
Before Edit/Write |
protect-files.py, security-check.py |
| PreToolUse |
Before Bash |
log-commands.sh, branch-protection.sh, pre-commit-check.py |
| PostToolUse |
After Edit/Write |
format-on-edit.py, typescript-check.py |
| SessionStart |
Plugin load |
validate-environment.py |
| UserPromptSubmit |
User prompt |
validate-prompt.py |
| Stop |
Task complete |
verify-on-complete.py, suggest-doc-updates.py, notify-complete.sh, track-metrics.py |
| Notification |
Input needed |
notify-input.sh |
Testing
Test Strategy (Testing Pyramid)
/\
/ \ E2E Tests (10%)
/----\ - Critical user journeys
/ \ - Slow but comprehensive
/--------\ Integration Tests (20%)
/ \ - Component interactions
/ \ - API contracts
/ \ Unit Tests (70%)
/________________\ - Fast, isolated
- Business logic focus
Framework Detection
| Language |
Unit |
Integration |
E2E |
| JavaScript/TypeScript |
Jest, Vitest |
Vitest + MSW |
Playwright |
| Python |
pytest |
pytest + httpx |
Playwright |
| Go |
testing + testify |
testing + httptest |
chromedp |
| Rust |
cargo test |
cargo test --features |
- |
Tiered Execution
# Tier 1: Affected tests only (fast)
npm test -- --findRelatedTests [changed files]
pytest [specific files] -x --tb=short
# Tier 2: Full unit suite
npm test
pytest tests/unit/
# Tier 3: Integration tests
npm run test:integration
pytest tests/integration/
Coverage Targets
- Global: 80%+ branches, functions, lines
- Core business logic: 95%+
- API contracts: 100%
Deployment
Agent-Based Operations
This plugin uses intelligent agents instead of traditional CI/CD:
| Traditional |
project-starter Equivalent |
| GitHub Actions |
/project-starter:verify-changes |
| Build pipeline |
/project-starter:validate-build |
| Test runner |
/project-starter:run-tests |
| Security scanner |
/project-starter:security-scan |
| Linter |
/project-starter:lint-check |
| PR creation |
/project-starter:commit-push-pr |
Hook Automation
| Operation |
Automation |
| File edit |
Auto-format (prettier/black/gofmt) |
| Commit |
Secret detection, file protection |
| Task complete |
Auto-verification, notifications |
| Session start |
Environment validation |
Cross-Platform Notifications
- macOS:
osascript native notifications
- Linux:
notify-send (graceful fallback if missing)
- Windows: PowerShell toast notifications
Dependencies
Zero Runtime Dependencies
This plugin has no npm/pip dependencies. It's pure metadata + scripts.
Tool Dependencies (Auto-detected)
| Tool |
File Types |
Required |
| Prettier |
JS, TS, JSON, CSS, MD, YAML |
Optional |
| Black |
Python |
Optional |
| gofmt |
Go |
Built-in with Go |
| rustfmt |
Rust |
rustup component |
| ESLint |
JS, TS |
Optional |
| Ruff |
Python |
Optional |
Graceful Degradation
All tools are optional. Missing tools result in warnings, not failures.
Domain Glossary
Core Entities
| Term |
Definition |
| Agent |
Specialized subagent spawned by Claude for specific domains |
| Skill |
Knowledge domain applied automatically when relevant |
| Command |
Slash command (/project-starter:<name>) for workflows |
| Hook |
Automation script triggered on specific events |
| Orchestrator |
Master coordinator that delegates to specialist agents |
Execution Patterns
| Term |
Definition |
| Parallel Execution |
N tasks spawned simultaneously using Task tool with run_in_background: true |
| Sequential Workflow |
Tasks executed one after another with dependencies |
| Task Synthesis |
Combining outputs from multiple parallel agents |
| Adversarial Review |
Using multiple agents to validate findings |
Code Quality
| Term |
Definition |
| Code Smell |
Surface indicator of deeper structural problem |
| Technical Debt |
Cost of rework from choosing expedient solutions |
| Root Cause |
Why an error occurred, not just what/where |
| Regression Test |
Test ensuring bug doesn't reoccur after fix |
Security
| Term |
Definition |
| OWASP Top 10 |
Most critical web application security risks |
| Secret Detection |
Pattern matching for hardcoded credentials |
| File Protection |
Blocking edits to sensitive files (.env, locks) |
Documentation Index
| Document |
Purpose |
| README.md |
Main documentation, quick start |
| CLAUDE.md |
Development guidelines for contributors |
| CONTRIBUTING.md |
How to contribute |
| CHANGELOG.md |
Version history |
| PERMISSIONS.md |
Permission framework reference |
| CODE_OF_CONDUCT.md |
Community guidelines |
| examples/ |
Multi-agent orchestration examples |
| templates/ |
User-copyable configuration templates |
Agent Documentation
| Agent |
File |
| Orchestrator |
agents/orchestrator.md |
| Code Reviewer |
agents/code-reviewer.md |
| Debugger |
agents/debugger.md |
| Security Auditor |
agents/security-auditor.md |
| Test Architect |
agents/test-architect.md |
| Refactorer |
agents/refactorer.md |
| Docs Writer |
agents/docs-writer.md |
Skill Documentation
| Skill |
File |
| Analyzing Projects |
skills/analyzing-projects/SKILL.md |
| Convex Backend |
skills/convex-backend/SKILL.md |
| Database Design |
skills/database-design/SKILL.md |
| Designing Architecture |
skills/designing-architecture/SKILL.md |
| Designing APIs |
skills/designing-apis/SKILL.md |
| Designing Tests |
skills/designing-tests/SKILL.md |
| DevOps Infrastructure |
skills/devops-infrastructure/SKILL.md |
| Error Handling |
skills/error-handling/SKILL.md |
| Managing Git |
skills/managing-git/SKILL.md |
| Optimizing Performance |
skills/optimizing-performance/SKILL.md |
| Parallel Execution |
skills/parallel-execution/SKILL.md |
| Security Patterns |
skills/security-patterns/SKILL.md |
| Vercel React Best Practices |
skills/vercel-react-best-practices/SKILL.md |
| Web Design Guidelines |
skills/web-design-guidelines/SKILL.md |
Version History
v1.2.0 (2026-02-14)
- Agent Upgrades: All 7 agents enhanced with action-first directives, effort scaling, adversarial self-review, paired WRONG/CORRECT examples
- 4 New Skills:
database-design, devops-infrastructure, error-handling, security-patterns
- On-Demand Context Loading: All 14 skills now have "When to Load" sections for optimized context usage
- 7 New Commands:
plan, refactor-guided, dependency-upgrade, tutorial, bootstrap-repo, save-session-learnings, metrics
- 5 New Hooks:
pre-commit-check.py, branch-protection.sh, typescript-check.py, suggest-doc-updates.py, track-metrics.py
- Improved Hook Messages: All hooks now include actionable remediation suggestions
- CI/CD: GitHub Actions plugin validation workflow
- Rewritten:
web-design-guidelines skill now self-contained (was external URL dependency)
v1.1.0 (2025-01-07)
- Parallel Execution Support: Orchestrator can spawn N subagents simultaneously
- New Commands:
parallel-review, parallel-analyze
- New Skill:
parallel-execution with patterns and best practices
- Performance: ~Nx faster execution for N independent tasks
v1.0.0 (2025-01-01)
- Initial release with 7 agents, 6 skills, 17 commands, 9 hooks
- Full multi-agent orchestration support
- Cross-platform desktop notifications
- Comprehensive security scanning
This document was generated by the /bootstrap-repo command using 10 parallel exploration agents.
1---2name: codebase-md-project-starter3description: This plugin has no npm/pip dependencies. It's pure metadata + scripts.4---5# CODEBASE.md - project-starter67> Comprehensive codebase documentation generated by 10 parallel exploration agents.8> Generated: 2026-01-17910---1112## Overview1314**project-starter** (formerly claude-workflow) is a universal Claude Code plugin that augments the IDE with specialized AI agents, knowledge skills, automation hooks, and workflow commands for accelerated software development.1516| Attribute | Value |17| ---------------- | ----------------------------------------------- |18| **Name** | project-starter |19| **Version** | 1.2.0 |20| **Type** | Claude Code Plugin |21| **License** | MIT |22| **Author** | CloudAI-X |23| **Repository** | https://github.com/CloudAI-X/claude-workflow-v2 |24| **Requirements** | Claude Code v1.0.33+, Python 3, Git |2526### Key Capabilities2728- **7 Specialized Agents**: Autonomous subagents with action-first directives, effort scaling, and adversarial self-review29- **26 Slash Commands**: Output styles, git workflows, verification, planning, onboarding, metrics30- **14 Knowledge Skills**: Architecture, testing, APIs, performance, git, security, database, devops, error handling — with on-demand context loading31- **14 Automation Hooks**: Pre/post tool validation, formatting, security, TypeScript, branch protection, doc suggestions, metrics, notifications3233---3435## Repository Structure3637```38claude-workflow/39├── .claude-plugin/ # Plugin configuration40│ ├── plugin.json # Plugin manifest (name, version, metadata)41│ └── marketplace.json # Marketplace publishing metadata42├── .github/ # GitHub governance & CI43│ ├── workflows/44│ │ └── validate.yml # Plugin validation CI/CD45│ ├── PULL_REQUEST_TEMPLATE.md46│ └── ISSUE_TEMPLATE/47│ ├── bug_report.md48│ └── feature_request.md49├── .claude/ # Local settings and permissions50│ └── settings.local.json51├── agents/ # 7 specialized AI subagents52│ ├── orchestrator.md # Master coordinator (opus model)53│ ├── code-reviewer.md # Quality and best practices54│ ├── debugger.md # Root cause analysis55│ ├── docs-writer.md # Technical documentation56│ ├── security-auditor.md # OWASP vulnerability detection57│ ├── refactorer.md # Code structure improvements58│ └── test-architect.md # Test strategy design59├── commands/ # 26 slash commands60│ ├── architect.md # System design mode61│ ├── rapid.md # Fast development mode62│ ├── mentor.md # Teaching mode63│ ├── review.md # Strict review mode64│ ├── commit.md # Auto-generate commits65│ ├── commit-push-pr.md # Full PR workflow66│ ├── verify-changes.md # Multi-agent verification67│ ├── validate-build.md # Build validation68│ ├── run-tests.md # Tiered test execution69│ ├── lint-check.md # Linting checks70│ ├── lint-fix.md # Auto-fix linting71│ ├── security-scan.md # Security scanning72│ ├── quick-fix.md # Fast lint/type fixes73│ ├── add-tests.md # Generate tests74│ ├── sync-branch.md # Sync with main75│ ├── summarize-changes.md # Session summaries76│ ├── code-simplifier.md # Post-implementation cleanup77│ ├── parallel-review.md # Multi-directory review78│ ├── parallel-analyze.md # Multi-perspective analysis79│ ├── plan.md # Persistent PLAN.md tracking80│ ├── refactor-guided.md # 4-phase guided refactoring81│ ├── dependency-upgrade.md # Safe dependency upgrades82│ ├── tutorial.md # Interactive plugin tutorial83│ ├── bootstrap-repo.md # 10-agent repo exploration84│ ├── save-session-learnings.md # Persist session discoveries85│ └── metrics.md # View agent metrics86├── skills/ # 14 knowledge domains87│ ├── analyzing-projects/SKILL.md88│ ├── convex-backend/SKILL.md89│ ├── database-design/SKILL.md90│ ├── designing-architecture/SKILL.md91│ ├── designing-apis/SKILL.md92│ ├── designing-tests/SKILL.md93│ ├── devops-infrastructure/SKILL.md94│ ├── error-handling/SKILL.md95│ ├── managing-git/SKILL.md96│ ├── optimizing-performance/SKILL.md97│ ├── parallel-execution/SKILL.md98│ ├── security-patterns/SKILL.md99│ ├── vercel-react-best-practices/SKILL.md100│ └── web-design-guidelines/SKILL.md101├── hooks/ # 14 automation scripts102│ ├── hooks.json # Hook registry103│ ├── protect-files.py # Block sensitive file edits104│ ├── security-check.py # Detect hardcoded secrets105│ ├── format-on-edit.py # Auto-format (prettier/black/gofmt)106│ ├── typescript-check.py # tsc --noEmit on .ts/.tsx edits107│ ├── pre-commit-check.py # Debug statements & temp markers108│ ├── validate-environment.py # Check Node/Python/Git109│ ├── validate-prompt.py # Suggest agents for prompts110│ ├── verify-on-complete.py # Run tests/lint on completion111│ ├── log-commands.sh # Audit bash commands112│ ├── branch-protection.sh # Warn on protected branch ops113│ ├── suggest-doc-updates.py # Suggest doc updates on changes114│ ├── track-metrics.py # Session telemetry logging115│ ├── notify-input.sh # Desktop notification (input needed)116│ └── notify-complete.sh # Desktop notification (complete)117├── examples/ # Multi-agent orchestration examples118│ ├── README.md119│ └── orchestration/120│ ├── comprehensive-code-review/121│ └── parallel-execution/122├── templates/ # User-copyable configuration123│ ├── CLAUDE.md.template124│ ├── settings.json.template125│ ├── settings.local.json.template126│ └── mcp.json.template127├── CLAUDE.md # Development guidelines128├── README.md # Main documentation129├── CHANGELOG.md # Version history130├── CONTRIBUTING.md # Contribution guidelines131├── CODE_OF_CONDUCT.md # Community guidelines132├── PERMISSIONS.md # Permission framework133└── LICENSE # MIT license134```135136---137138## Getting Started139140### Installation Options141142**1. Per-Session (Temporary)**143144```bash145git clone https://github.com/CloudAI-X/claude-workflow-v2.git146claude --plugin-dir ./claude-workflow147```148149**2. Per-Project (Permanent)**150151```bash152claude plugin install ./claude-workflow153```154155**3. Global (Marketplace)**156157```bash158claude plugin install project-starter159```160161**4. Agent SDK (Programmatic)**162163```typescript164import { query } from "@anthropic-ai/claude-agent-sdk";165166for await (const message of query({167 plugins: [{ type: "local", path: "./claude-workflow" }],168})) {169 // Handle messages170}171```172173### Prerequisites174175| Tool | Required | Purpose |176| ----------- | ----------- | ------------------------------ |177| Claude Code | v1.0.33+ | Plugin host |178| Python 3 | Yes | Hook scripts |179| Git | Recommended | Version control features |180| Node.js | Optional | JS/TS formatting, npm commands |181182### Validation183184```bash185claude plugin validate # Validate plugin structure186```187188---189190## Architecture191192### Plugin Architecture Pattern193194This plugin uses a **metadata-driven, modular architecture** with no traditional runtime dependencies:195196```197┌─────────────────────────────────────────────────────────────┐198│ Claude Code IDE │199├─────────────────────────────────────────────────────────────┤200│ │201│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │202│ │ Agents │ │ Commands │ │ Skills │ │203│ │ (7 specs) │ │ (19 specs) │ │ (7 domains) │ │204│ └──────┬──────┘ └──────┬──────┘ └──────┬──────┘ │205│ │ │ │ │206│ └────────────────┼────────────────┘ │207│ │ │208│ ┌─────────┴─────────┐ │209│ │ Hook System │ │210│ │ (Event-Driven) │ │211│ └─────────┬─────────┘ │212│ │ │213│ ┌─────────────────────┼─────────────────────┐ │214│ │ │ │ │ │ │215│ ▼ ▼ ▼ ▼ ▼ │216│ PreToolUse PostToolUse Stop SessionStart Notification │217│ │218└─────────────────────────────────────────────────────────────┘219```220221### Agent Hierarchy222223| Agent | Model | Responsibility | Auto-Trigger Keywords |224| -------------------- | ------ | ------------------------------------------- | ---------------------------------------------------- |225| **orchestrator** | opus | Multi-step coordination, parallel execution | "improve", "enhance", "build", "architecture" |226| **code-reviewer** | sonnet | Quality assessment, best practices | "review", "PR review", "lint", "standards audit" |227| **debugger** | sonnet | Root cause analysis, bug fixing | "bug", "error", "crash", "memory leak", "timeout" |228| **security-auditor** | sonnet | Vulnerability detection, OWASP | "security", "auth", "JWT", "CORS", "secrets" |229| **test-architect** | sonnet | Test strategy, coverage | "test", "coverage", "mocking", "flaky tests" |230| **refactorer** | sonnet | Code structure, SOLID principles | "refactor", "tech debt", "code smells", "complexity" |231| **docs-writer** | sonnet | Technical documentation | "document", "changelog", "migration guide" |232233### Parallel Execution (v1.1.0)234235The orchestrator can spawn N subagents simultaneously for Nx performance:236237```238 User Request239 │240 ▼241 ┌─────────────────┐242 │ Orchestrator │243 │ (Creates Plan)│244 └────────┬────────┘245 │246 ┌───────────┼───────────┬───────────┬───────────┐247 │ │ │ │ │248 ▼ ▼ ▼ ▼ ▼249┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐ ┌────────┐250│ Task 1 │ │ Task 2 │ │ Task 3 │ │ Task 4 │ │ Task 5 │251└────┬───┘ └────┬───┘ └────┬───┘ └────┬───┘ └────┬───┘252 │ │ │ │ │253 └──────────┴──────────┴──────────┴──────────┘254 │255 [TaskOutput]256 │257 [Synthesize]258```259260**Critical Rule**: ALL Task calls must be in a SINGLE assistant message for true parallelism.261262---263264## Data Layer265266This plugin has **no traditional database layer**. Instead, it uses:267268### Data Sources269270| Type | Location | Format |271| ----------------------- | ---------------------------- | --------------------------- |272| **Plugin Config** | `.claude-plugin/plugin.json` | JSON |273| **Hook Registry** | `hooks/hooks.json` | JSON |274| **Agent Definitions** | `agents/*.md` | YAML frontmatter + Markdown |275| **Command Definitions** | `commands/*.md` | YAML frontmatter + Markdown |276| **Skill Knowledge** | `skills/*/SKILL.md` | YAML frontmatter + Markdown |277278### YAML Frontmatter Schema279280```yaml281---282name: identifier283description: Purpose. Use PROACTIVELY when [triggers].284tools: Read, Write, Edit, Bash, Glob, Grep285model: opus|sonnet|haiku286permissionMode: default|acceptEdits287skills: skill-name1, skill-name2288---289```290291### Hook Input/Output292293```json294// stdin (hook receives)295{296 "tool_input": {297 "file_path": "/path/to/file",298 "content": "file contents..."299 }300}301302// Exit codes303// 0 = Allow operation304// 2 = Block with message305```306307---308309## Core Logic310311### Orchestrator Workflow312313```314Phase 1: UNDERSTAND315 └─ Read requirements, explore codebase, identify affected systems316317Phase 2: PLAN318 └─ Create TodoWrite list, group parallelizable tasks, identify dependencies319320Phase 3: DELEGATE321 └─ Spawn specialists (sequential or parallel via Task tool)322323Phase 4: INTEGRATE324 └─ Synthesize outputs, resolve conflicts, ensure consistency325326Phase 5: VERIFY327 └─ Run tests/lint, quality checks328329Phase 6: DELIVER330 └─ Summarize changes, create PRs, update documentation331```332333### Security Check Algorithm334335```python336SECRET_PATTERNS = [337 r'api[_-]?key.*[a-zA-Z0-9_-]{20,}', # API keys338 r'ghp_[a-zA-Z0-9]{36}', # GitHub PATs339 r'sk-ant-[a-zA-Z0-9-]{90,}', # Anthropic keys340 r'AKIA[0-9A-Z]{16}', # AWS credentials341 r'-----BEGIN.*PRIVATE KEY-----', # Private keys342]343344SKIP_FILES = ['.env.example', 'package-lock.json', '*test*']345346# Exit 2 (block) if secret found, 0 (allow) otherwise347```348349### Verification Pipeline350351```352verify-changes command spawns 5 parallel subagents:3533541. Syntax & Type Check (tsc, mypy, go vet)3552. Test Runner (affected → unit → integration)3563. Lint & Style Check (eslint, ruff, golangci-lint)3574. Security Scan (secrets, dependencies, OWASP)3585. Build Validator (compile, artifacts)359360+ 3 Adversarial subagents:361 - False Positive Filter362 - Missing Issues Finder363 - Context Validator364```365366---367368## API Reference369370### Commands (26 total)371372#### Output Styles373374| Command | Description |375| ---------------------------- | --------------------------------------------- |376| `/project-starter:architect` | System design mode - architecture before code |377| `/project-starter:rapid` | Fast development - minimal ceremony |378| `/project-starter:mentor` | Teaching mode - explains concepts |379| `/project-starter:review` | Strict code review mode |380381#### Git Workflow382383| Command | Description |384| ------------------------------------ | --------------------------------- |385| `/project-starter:commit` | Auto-generate conventional commit |386| `/project-starter:commit-push-pr` | Full workflow: commit → push → PR |387| `/project-starter:quick-fix` | Fast lint/type error fixes |388| `/project-starter:add-tests` | Generate tests for changes |389| `/project-starter:lint-fix` | Auto-fix all linting issues |390| `/project-starter:sync-branch` | Sync with main (rebase/merge) |391| `/project-starter:summarize-changes` | Generate standup/PR summaries |392393#### Verification394395| Command | Description |396| ----------------------------------- | ------------------------------------ |397| `/project-starter:verify-changes` | Multi-agent adversarial verification |398| `/project-starter:validate-build` | Build process validation |399| `/project-starter:run-tests` | Tiered test execution |400| `/project-starter:lint-check` | Code quality checks |401| `/project-starter:security-scan` | Vulnerability detection |402| `/project-starter:code-simplifier` | Post-implementation cleanup |403| `/project-starter:parallel-review` | Multi-directory parallel review |404| `/project-starter:parallel-analyze` | Multi-perspective analysis |405406#### Planning & Refactoring407408| Command | Description |409| ------------------------------------- | --------------------------------- |410| `/project-starter:plan` | Persistent PLAN.md phase tracking |411| `/project-starter:refactor-guided` | 4-phase systematic refactoring |412| `/project-starter:dependency-upgrade` | Safe dependency upgrades |413414#### Onboarding & Knowledge415416| Command | Description |417| ----------------------------------------- | ---------------------------------- |418| `/project-starter:tutorial` | Interactive guided tutorial |419| `/project-starter:bootstrap-repo` | 10-agent parallel repo exploration |420| `/project-starter:save-session-learnings` | Persist session discoveries |421| `/project-starter:metrics` | View agent performance metrics |422423### Hook Events424425| Event | Trigger | Scripts |426| -------------------- | ----------------- | ------------------------------------------------------------------------------------------- |427| **PreToolUse** | Before Edit/Write | `protect-files.py`, `security-check.py` |428| **PreToolUse** | Before Bash | `log-commands.sh`, `branch-protection.sh`, `pre-commit-check.py` |429| **PostToolUse** | After Edit/Write | `format-on-edit.py`, `typescript-check.py` |430| **SessionStart** | Plugin load | `validate-environment.py` |431| **UserPromptSubmit** | User prompt | `validate-prompt.py` |432| **Stop** | Task complete | `verify-on-complete.py`, `suggest-doc-updates.py`, `notify-complete.sh`, `track-metrics.py` |433| **Notification** | Input needed | `notify-input.sh` |434435---436437## Testing438439### Test Strategy (Testing Pyramid)440441```442 /\443 / \ E2E Tests (10%)444 /----\ - Critical user journeys445 / \ - Slow but comprehensive446 /--------\ Integration Tests (20%)447 / \ - Component interactions448 / \ - API contracts449 / \ Unit Tests (70%)450/________________\ - Fast, isolated451 - Business logic focus452```453454### Framework Detection455456| Language | Unit | Integration | E2E |457| --------------------- | ----------------- | --------------------- | ---------- |458| JavaScript/TypeScript | Jest, Vitest | Vitest + MSW | Playwright |459| Python | pytest | pytest + httpx | Playwright |460| Go | testing + testify | testing + httptest | chromedp |461| Rust | cargo test | cargo test --features | - |462463### Tiered Execution464465```bash466# Tier 1: Affected tests only (fast)467npm test -- --findRelatedTests [changed files]468pytest [specific files] -x --tb=short469470# Tier 2: Full unit suite471npm test472pytest tests/unit/473474# Tier 3: Integration tests475npm run test:integration476pytest tests/integration/477```478479### Coverage Targets480481- **Global**: 80%+ branches, functions, lines482- **Core business logic**: 95%+483- **API contracts**: 100%484485---486487## Deployment488489### Agent-Based Operations490491This plugin uses **intelligent agents** instead of traditional CI/CD:492493| Traditional | project-starter Equivalent |494| ---------------- | --------------------------------- |495| GitHub Actions | `/project-starter:verify-changes` |496| Build pipeline | `/project-starter:validate-build` |497| Test runner | `/project-starter:run-tests` |498| Security scanner | `/project-starter:security-scan` |499| Linter | `/project-starter:lint-check` |500| PR creation | `/project-starter:commit-push-pr` |501502### Hook Automation503504| Operation | Automation |505| ------------- | ---------------------------------- |506| File edit | Auto-format (prettier/black/gofmt) |507| Commit | Secret detection, file protection |508| Task complete | Auto-verification, notifications |509| Session start | Environment validation |510511### Cross-Platform Notifications512513- **macOS**: `osascript` native notifications514- **Linux**: `notify-send` (graceful fallback if missing)515- **Windows**: PowerShell toast notifications516517---518519## Dependencies520521### Zero Runtime Dependencies522523This plugin has **no npm/pip dependencies**. It's pure metadata + scripts.524525### Tool Dependencies (Auto-detected)526527| Tool | File Types | Required |528| ------------ | --------------------------- | ---------------- |529| **Prettier** | JS, TS, JSON, CSS, MD, YAML | Optional |530| **Black** | Python | Optional |531| **gofmt** | Go | Built-in with Go |532| **rustfmt** | Rust | rustup component |533| **ESLint** | JS, TS | Optional |534| **Ruff** | Python | Optional |535536### Graceful Degradation537538All tools are optional. Missing tools result in warnings, not failures.539540---541542## Domain Glossary543544### Core Entities545546| Term | Definition |547| ---------------- | ----------------------------------------------------------- |548| **Agent** | Specialized subagent spawned by Claude for specific domains |549| **Skill** | Knowledge domain applied automatically when relevant |550| **Command** | Slash command (`/project-starter:<name>`) for workflows |551| **Hook** | Automation script triggered on specific events |552| **Orchestrator** | Master coordinator that delegates to specialist agents |553554### Execution Patterns555556| Term | Definition |557| ----------------------- | ----------------------------------------------------------------------------- |558| **Parallel Execution** | N tasks spawned simultaneously using Task tool with `run_in_background: true` |559| **Sequential Workflow** | Tasks executed one after another with dependencies |560| **Task Synthesis** | Combining outputs from multiple parallel agents |561| **Adversarial Review** | Using multiple agents to validate findings |562563### Code Quality564565| Term | Definition |566| ------------------- | ------------------------------------------------ |567| **Code Smell** | Surface indicator of deeper structural problem |568| **Technical Debt** | Cost of rework from choosing expedient solutions |569| **Root Cause** | Why an error occurred, not just what/where |570| **Regression Test** | Test ensuring bug doesn't reoccur after fix |571572### Security573574| Term | Definition |575| -------------------- | ----------------------------------------------- |576| **OWASP Top 10** | Most critical web application security risks |577| **Secret Detection** | Pattern matching for hardcoded credentials |578| **File Protection** | Blocking edits to sensitive files (.env, locks) |579580---581582## Documentation Index583584| Document | Purpose |585| ---------------------------------------- | --------------------------------------- |586| [README.md](README.md) | Main documentation, quick start |587| [CLAUDE.md](CLAUDE.md) | Development guidelines for contributors |588| [CONTRIBUTING.md](CONTRIBUTING.md) | How to contribute |589| [CHANGELOG.md](CHANGELOG.md) | Version history |590| [PERMISSIONS.md](PERMISSIONS.md) | Permission framework reference |591| [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md) | Community guidelines |592| [examples/](examples/) | Multi-agent orchestration examples |593| [templates/](templates/) | User-copyable configuration templates |594595### Agent Documentation596597| Agent | File |598| ---------------- | -------------------------------------------------------- |599| Orchestrator | [agents/orchestrator.md](agents/orchestrator.md) |600| Code Reviewer | [agents/code-reviewer.md](agents/code-reviewer.md) |601| Debugger | [agents/debugger.md](agents/debugger.md) |602| Security Auditor | [agents/security-auditor.md](agents/security-auditor.md) |603| Test Architect | [agents/test-architect.md](agents/test-architect.md) |604| Refactorer | [agents/refactorer.md](agents/refactorer.md) |605| Docs Writer | [agents/docs-writer.md](agents/docs-writer.md) |606607### Skill Documentation608609| Skill | File |610| --------------------------- | ------------------------------------------------------------------------------------------ |611| Analyzing Projects | [skills/analyzing-projects/SKILL.md](skills/analyzing-projects/SKILL.md) |612| Convex Backend | [skills/convex-backend/SKILL.md](skills/convex-backend/SKILL.md) |613| Database Design | [skills/database-design/SKILL.md](skills/database-design/SKILL.md) |614| Designing Architecture | [skills/designing-architecture/SKILL.md](skills/designing-architecture/SKILL.md) |615| Designing APIs | [skills/designing-apis/SKILL.md](skills/designing-apis/SKILL.md) |616| Designing Tests | [skills/designing-tests/SKILL.md](skills/designing-tests/SKILL.md) |617| DevOps Infrastructure | [skills/devops-infrastructure/SKILL.md](skills/devops-infrastructure/SKILL.md) |618| Error Handling | [skills/error-handling/SKILL.md](skills/error-handling/SKILL.md) |619| Managing Git | [skills/managing-git/SKILL.md](skills/managing-git/SKILL.md) |620| Optimizing Performance | [skills/optimizing-performance/SKILL.md](skills/optimizing-performance/SKILL.md) |621| Parallel Execution | [skills/parallel-execution/SKILL.md](skills/parallel-execution/SKILL.md) |622| Security Patterns | [skills/security-patterns/SKILL.md](skills/security-patterns/SKILL.md) |623| Vercel React Best Practices | [skills/vercel-react-best-practices/SKILL.md](skills/vercel-react-best-practices/SKILL.md) |624| Web Design Guidelines | [skills/web-design-guidelines/SKILL.md](skills/web-design-guidelines/SKILL.md) |625626---627628## Version History629630### v1.2.0 (2026-02-14)631632- **Agent Upgrades**: All 7 agents enhanced with action-first directives, effort scaling, adversarial self-review, paired WRONG/CORRECT examples633- **4 New Skills**: `database-design`, `devops-infrastructure`, `error-handling`, `security-patterns`634- **On-Demand Context Loading**: All 14 skills now have "When to Load" sections for optimized context usage635- **7 New Commands**: `plan`, `refactor-guided`, `dependency-upgrade`, `tutorial`, `bootstrap-repo`, `save-session-learnings`, `metrics`636- **5 New Hooks**: `pre-commit-check.py`, `branch-protection.sh`, `typescript-check.py`, `suggest-doc-updates.py`, `track-metrics.py`637- **Improved Hook Messages**: All hooks now include actionable remediation suggestions638- **CI/CD**: GitHub Actions plugin validation workflow639- **Rewritten**: `web-design-guidelines` skill now self-contained (was external URL dependency)640641### v1.1.0 (2025-01-07)642643- **Parallel Execution Support**: Orchestrator can spawn N subagents simultaneously644- **New Commands**: `parallel-review`, `parallel-analyze`645- **New Skill**: `parallel-execution` with patterns and best practices646- **Performance**: ~Nx faster execution for N independent tasks647648### v1.0.0 (2025-01-01)649650- Initial release with 7 agents, 6 skills, 17 commands, 9 hooks651- Full multi-agent orchestration support652- Cross-platform desktop notifications653- Comprehensive security scanning654655---656657_This document was generated by the `/bootstrap-repo` command using 10 parallel exploration agents._