A collection of powerful extensions for Claude Code including autonomous agents, slash commands, global configurations, and GitHub Actions workflows.
Security Auditor (agents/security-auditor.md)
- Elite Application Security Engineer with 15+ years of simulated expertise
- Comprehensive vulnerability scanning (OWASP Top 10, CVE databases)
- Static Application Security Testing (SAST) and dependency analysis
- Generates structured security audit reports with remediation guidance
- Use for pre-release audits, dependency checks, and security reviews
Project Architect (agents/project-architect.md)
- Elite Software Architect that analyzes any project's tech stack
- Automatically detects languages, frameworks, build tools, testing infrastructure
- Generates custom Claude Code agents, skills, and commands tailored to the project
- Creates workflow-specific extensions (test-runner, build-manager, linter-helper, etc.)
- Updates existing documentation (CLAUDE.md, README.md) to document new tools
- Use when setting up Claude Code for a new project or after major tech stack changes
Repository Maintenance Agents (.claude/agents/)
- markdown-linter - Validates agent and command files for proper YAML frontmatter and structure
- doc-sync-manager - Synchronizes documentation across README.md and CLAUDE.md
- template-validator - Ensures templates follow Claude Code best practices
- release-manager - Manages versioning, changelog generation, and releases
Project Setup Command
/setup-project-tools- Automatically analyze project and generate tailored agents, skills, and commands
Security Audit Command
/security-audit- Perform comprehensive security audit of the project (invokes security-auditor agent)
Repository Maintenance Commands
/validate-agents- Validate all agent files for proper structure and syntax/validate-commands- Validate all command files for proper structure and syntax/sync-docs- Synchronize documentation after adding/modifying agents or commands/test-workflows- Validate GitHub Actions workflow syntax and best practices/new-agent- Scaffold a new agent file with proper template/new-command- Scaffold a new command file with proper template
Session Finalization Command
/finalize- Review session changes and run quality actions (tests, translations, docs)
Release Command
/release-gh-prepare- Cut a new version: update CHANGELOG, commit, push, and create a GitHub draft release. Mandatory user approval of the proposed version.
Commit Workflow Commands
/commit-prepare- Review changes and draft commit messages following best practices/commit-do- Create commits with proper formatting using a safe temp-file +git commit -Fflow
Both commit commands enforce strict commit message standards:
- Subject line: max 50 chars, imperative mood
- Body: wrapped at 72 chars, explains what and why
- Clean messages without AI attribution footers
Located in global/ directory - copy these to your ~/.claude/ directory:
global/CLAUDE.md
- Strict git workflow rules (no automatic commits/pushes)
- Commit message formatting standards
- Platform-specific command compatibility (macOS/Linux)
- Permission file management guidelines
global/settings.json
- Custom status line showing project, git branch, and model
- Always-thinking mode enabled
- Template for team-wide settings
global/commands/ - Global slash command templates
finalize.md- Review session changes and run quality actions (tests, translations, docs)release-gh-prepare.md- Cut a new version: update CHANGELOG, commit, push, and create a GitHub draft release
global/skills/ - Skills in the shared Agent Skills format, usable by Claude Code and Codex from one directory
pr-fix/- Repair automated pull-request review findings (chatgpt-codex-connector, Claude review) in at most two fix pushes: collect unresolved threads, triage each (FIX / REJECT / DEFER / DUP), apply minimal fixes, run the same Codex reviewer locally before pushing, push once, close every thread./pr-fix <PR>in Claude Code,$pr-fix <PR>in Codex.- The P2 rule: a P2 finding gets a one-line fix or a reply, never a rewrite
- Before approval or publication, the author verifies changed behavior with failure/normal scenarios and affected consumer traces. See behavior verification. Baseline test counts, a clean review, and the runner's
status=readysupplement this evidence; they do not establish its coverage. scripts/pr-fix.sh- runner withcollect,triage,check,review,status,close,record-push,pre-push; state in<repo>/.audit/pr-<N>/references/- triage rules and reply templates, developer instructions for the local reviewer, a## Code Review Rulesblock for a target repository's AGENTS.md, and a paragraph for~/.codex/AGENTS.md
global/hooks/ - Git hooks for commit and push protection
pre-commit- Prevents Claude Code from committing without explicit user approval- Blocks all automated commits in non-interactive mode
- Requires typing "YES" to approve commits in interactive mode
pre-push- Thepr-fixpush gate: armed once a findings round has started, refuses a push whose commit was not the tree the local review saw or that would exceed two fix pushes, records allowed pushes, fails open, chains to the repository's own hook- Can be installed per-repo, globally, or across all existing repos
- See
global/hooks/README.mdfor installation instructions
global/tests/ - Self-contained shell tests for global configuration
statusline-cwd-test.sh- Verifies the status linecwdvalidation: accepts paths with shell metacharacters and Unicode, rejects control-character injection attempts and missing pathspr-fix-test.sh- 206 offline assertions for thepr-fixrunner and thepre-pushgate, using stubgh/codexbinaries and fixtures infixtures/pr-fix/- Run with
sh global/tests/statusline-cwd-test.shandsh global/tests/pr-fix-test.sh(requirejqandgit)
Automated PR Reviews (.github/workflows/claude-code-review.yml)
- Runs on PR open/synchronize events
- Reviews code quality, security, performance, and test coverage
- Posts feedback as PR comments
@claude Mention Response (.github/workflows/claude.yml)
- Triggers when
@claudeis mentioned in issues or PRs - Responds to requests with full repository access
- Supports issue comments, PR reviews, and new issues
Located in stacks/ directory - copy these to your project's .claude/ directory:
Go (stacks/go/)
- Pre-configured hooks, agents, and commands for Go development
validate-go-toolchain.sh- Blocks builds when Go version mismatches compilervalidate-go-test.sh- Recommends race detection for test commandscode-quality-auditoragent - Comprehensive code quality scanning/code-quality,/commit-prepare, and/fly-deploycommands
Swift/Xcode (stacks/swift/)
- Pre-configured hooks for Xcode project development
validate-xcodebuild.sh- Ensures xcodebuild commands use correct simulator (iPhone 17 Pro)- Prevents build failures from incorrect simulator targets
Kotlin/Android (stacks/kotlin/)
- Pre-configured agents and commands for Android/Kotlin development
android-quality-auditoragent - Comprehensive Android code quality scanning (SDK, Gradle, dependencies, lint, Compose)kotlin-refactoreragent - Kotlin refactoring and best practicescompose-developeragent - Jetpack Compose UI development/code-quality,/lint,/detekt,/clean,/test-instrumentedcommandstemplates/detekt.yml- Ready-to-use Detekt configuration for Android/Compose projects
PHP (stacks/php/)
- Pre-configured agents, commands, and hooks for PHP development
composer-manageragent - Dependency management with Composersecurity-revieweragent - PHP security scanning and code reviewphp-refactoreragent - PHP refactoring and modern best practices/phpstan,/update-deps,/security-scancommandsskills/security-review- Security review skill for PHP projectshooks/validate-php-syntax.sh- Validates PHP syntax before executionhooks/validate-composer-lock.sh- Ensures composer.lock stays in sync
Drupal (stacks/drupal/)
- Pre-configured agents, commands, skills, hooks, and templates for Drupal development
drupal-debuggeragent - Debug errors, test failures, configuration issuesdrush-helperagent - Drush commands and system administrationconfig-revieweragent - Configuration safety and deployment readinessperformance-tuneragent - Redis, caching, database optimizationtest-creatoragent - Generate PHPUnit tests for modulesapi-developeragent - REST/JSON:API development, external integrationsmigration-expertagent - Content migrations, CRM sync, data transformationscode-quality-auditoragent - Scan PHPStan/PHPCS/deprecation issues and offer fixes (read-only)- 24 commands:
/backup-db,/cache-clear,/code-quality,/config-diff,/config-export,/config-import,/content-audit,/cron-status,/db-query,/db-update,/deploy-check,/drush,/feature-revert,/health-check,/logs,/maintenance,/module-status,/queue-status,/scaffold,/test-coverage,/test-create,/test-run,/translate-check,/user-info - 8 skills: api-development, config-management, database-operations, drupal-drush, drupal-hooks, drupal-migrations, drupal-testing, performance-optimization
hooks/validate-drush.sh- Validates drush command execution contexthooks/validate-drupal-root.sh- Ensures commands run from Drupal roottemplates/phpunit.xml.dist- Standard PHPUnit configuration for custom module testingtemplates/phpstan.neon- Base PHPStan configuration for Drupal projects
Security Policy (SECURITY.md)
- Vulnerability disclosure via GitHub Security Advisories
- 48-hour response SLA for security reports
- Token rotation policy (90 days for OAuth tokens)
- Incident response procedures
Threat Model (.github/THREAT_MODEL.md)
- Attack scenarios (expression injection, prompt injection, supply chain)
- Trust boundaries and security assumptions
- Implemented controls (preventive, detective, corrective)
- Residual risks and user recommendations
Supply Chain Security (.github/SUPPLY_CHAIN_SECURITY.md)
- GitHub Actions dependency inventory with pinned SHAs
- Verification process for adding new dependencies
- Incident response for supply chain compromises
Copy agent files to your project's .claude/agents/ directory:
cp agents/security-auditor.md /path/to/your/project/.claude/agents/Then invoke in Claude Code:
# In Claude Code conversation
Please use the security-auditor agent to audit this codebaseCopy command files to your project's .claude/commands/ directory:
# Project setup command
cp commands/setup-project-tools.md /path/to/your/project/.claude/commands/
# Commit workflow commands
cp .claude/commands/commit-prepare.md /path/to/your/project/.claude/commands/
cp .claude/commands/commit-do.md /path/to/your/project/.claude/commands/Then use in Claude Code:
/setup-project-tools
/commit-prepare
/commit-doCopy global files to your ~/.claude/ directory:
# Create directory if it doesn't exist
mkdir -p ~/.claude
# Copy global configuration
cp global/CLAUDE.md ~/.claude/
cp global/settings.json ~/.claude/These will apply to all your Claude Code sessions across all projects.
Copy global command templates to your ~/.claude/commands/ directory:
mkdir -p ~/.claude/commands
cp global/commands/finalize.md ~/.claude/commands/These commands will be available as slash commands in all Claude Code sessions.
Skills follow the Agent Skills format that both Claude Code and Codex read, so one checkout serves both tools. Symlink instead of copying so updates to this repository apply immediately:
mkdir -p ~/.claude/skills ~/.codex/skills
ln -s "$PWD/global/skills/pr-fix" ~/.claude/skills/pr-fix
ln -s "$PWD/global/skills/pr-fix" ~/.codex/skills/pr-fixClaude Code then offers /pr-fix <PR>; Codex offers $pr-fix <PR>. The runner needs gh (authenticated), jq, git and the codex CLI on PATH. Add the paragraph from global/skills/pr-fix/references/codex-agents-md-snippet.md to ~/.codex/AGENTS.md so Codex routes findings work to the skill.
Install the pre-commit hook to prevent Claude Code from committing without your approval, and the pre-push hook to enforce the pr-fix two-push workflow:
# Option 1: Install to current repository only
cp global/hooks/pre-commit .git/hooks/pre-commit
chmod +x .git/hooks/pre-commit
# Option 2: Install globally for all future repositories
mkdir -p ~/.git-hooks
cp global/hooks/pre-commit ~/.git-hooks/pre-commit
chmod +x ~/.git-hooks/pre-commit
ln -s "$PWD/global/hooks/pre-push" ~/.git-hooks/pre-push
git config --global core.hooksPath ~/.git-hookscore.hooksPath makes git skip each repository's .git/hooks; the pre-push wrapper chains to a repository's own pre-push hook so nothing is lost. See global/hooks/README.md for detailed installation instructions and additional options.
Copy stack-specific tools to your project:
# For Go projects
cp stacks/go/settings.json /path/to/your/project/.claude/
mkdir -p /path/to/your/project/.claude/hooks
cp stacks/go/hooks/*.sh /path/to/your/project/.claude/hooks/
chmod +x /path/to/your/project/.claude/hooks/*.sh
# Optional: Copy agents and commands
cp -r stacks/go/agents /path/to/your/project/.claude/
cp -r stacks/go/commands /path/to/your/project/.claude/
# For Swift/Xcode projects
cp stacks/swift/settings.json /path/to/your/project/.claude/
mkdir -p /path/to/your/project/.claude/hooks
cp stacks/swift/hooks/validate-xcodebuild.sh /path/to/your/project/.claude/hooks/
chmod +x /path/to/your/project/.claude/hooks/validate-xcodebuild.sh
# For Kotlin/Android projects
cp -r stacks/kotlin/agents /path/to/your/project/.claude/
cp -r stacks/kotlin/commands /path/to/your/project/.claude/
# For PHP projects
cp stacks/php/settings.json /path/to/your/project/.claude/
mkdir -p /path/to/your/project/.claude/hooks
cp stacks/php/hooks/*.sh /path/to/your/project/.claude/hooks/
chmod +x /path/to/your/project/.claude/hooks/*.sh
# Optional: Copy agents, commands, and skills
cp -r stacks/php/agents /path/to/your/project/.claude/
cp -r stacks/php/commands /path/to/your/project/.claude/
cp -r stacks/php/skills /path/to/your/project/.claude/
# For Drupal projects
cp stacks/drupal/settings.json /path/to/your/project/.claude/
mkdir -p /path/to/your/project/.claude/hooks
cp stacks/drupal/hooks/*.sh /path/to/your/project/.claude/hooks/
chmod +x /path/to/your/project/.claude/hooks/*.sh
# Optional: Copy agents, commands, skills, and templates
cp -r stacks/drupal/agents /path/to/your/project/.claude/
cp -r stacks/drupal/commands /path/to/your/project/.claude/
cp -r stacks/drupal/skills /path/to/your/project/.claude/
cp -r stacks/drupal/templates /path/to/your/project/.claude/-
Generate Claude Code OAuth Token
- Visit Claude Code settings
- Generate a new OAuth token for GitHub Actions
-
Add Secret to Repository
- Go to your repository Settings > Secrets and variables > Actions
- Add new secret:
CLAUDE_CODE_OAUTH_TOKEN - Paste your OAuth token
-
Copy Workflow Files
mkdir -p .github/workflows cp .github/workflows/claude-code-review.yml .github/workflows/ cp .github/workflows/claude.yml .github/workflows/
-
Customize as Needed
- Edit
claude_argsto restrict or expand allowed tools - Modify triggers and filters for your workflow
- Adjust review prompts and criteria
- Edit
Security Note: These workflows include security hardening (pinned actions, tool restrictions, trusted user checks). Before deploying, review SECURITY.md for token rotation requirements and best practices.
# In Claude Code - Option 1: Use slash command
/setup-project-tools
# Option 2: Invoke agent directly
Use the project-architect agent to analyze this project and generate
tailored Claude Code extensions for my tech stack.The agent will:
- Analyze your project (languages, frameworks, build tools, testing, etc.)
- Generate custom agents in
.claude/agents/(e.g., test-runner, build-manager) - Generate slash commands in
.claude/commands/(e.g., /test, /build, /lint) - Create skills in
.claude/skills/if needed - Update existing documentation (CLAUDE.md, README.md, etc.) with new tools
- Provide quick start guide for using the generated extensions
# In Claude Code
Use the security-auditor agent to perform a comprehensive security audit
of this codebase, focusing on authentication and API endpoints.The agent will generate multiple markdown reports:
security-audit-application-code.mdsecurity-audit-dependencies.mdsecurity-audit-authentication.mdsecurity-audit-api.mdsecurity-audit-summary.md
# Step 1: Review changes and prepare message
/commit-prepare
# Step 2: Create the commit
/commit-doWhen a review bot (chatgpt-codex-connector, Claude review) leaves findings on a pull request:
# In Claude Code
/pr-fix 170
# In Codex
$pr-fix 170The skill collects the unresolved threads, triages each one (FIX / REJECT / DEFER / DUP), applies minimal fixes (a P2 gets a one-line fix or a reply, never a rewrite), verifies the changed behavior and affected consumers, and runs codex exec review --base locally. Its approval report separates direct evidence, baseline checks, review results, and gaps. Once both the evidence and recorded-state gates pass, it commits and pushes once after your approval, replies to and resolves every thread, and stops after two fix pushes. Round three and later are triage-only unless you say override. State and reports live in .audit/pr-<N>/ (gitignored).
Simply open a PR and the review workflow will automatically:
- Analyze the changed lines
- Report high-confidence correctness and security problems with
file:lineand a failing scenario - Post a review comment with findings
In any issue or PR comment:
@claude can you add unit tests for the new authentication module?
Claude will respond and complete the task with full repository access.
.
├── agents/ # Autonomous agent definitions
│ ├── security-auditor.md # Security vulnerability scanning
│ └── project-architect.md # Project analysis & tool generation
├── .claude/
│ ├── agents/ # Repository-specific agents
│ │ ├── markdown-linter.md # Validate agent/command files
│ │ ├── doc-sync-manager.md # Synchronize documentation
│ │ ├── template-validator.md # Validate template quality
│ │ └── release-manager.md # Manage releases and versioning
│ └── commands/ # Repository-specific slash commands
│ ├── commit-prepare.md # Review changes
│ ├── commit-do.md # Create commits
│ ├── finalize.md # Session finalization
│ ├── security-audit.md # Security audit command
│ ├── validate-agents.md # Validate agent files
│ ├── validate-commands.md # Validate command files
│ ├── sync-docs.md # Update documentation
│ ├── test-workflows.md # Validate workflows
│ ├── new-agent.md # Scaffold new agent
│ └── new-command.md # Scaffold new command
├── commands/ # Template commands for copying to projects
│ ├── setup-project-tools.md
│ └── no-ticket/ # Alternative command structures
├── stacks/ # Stack-specific configurations
│ ├── go/ # Go project tools
│ │ ├── settings.json # Hook configuration for Go commands
│ │ ├── hooks/
│ │ │ ├── validate-go-toolchain.sh # Toolchain version validation
│ │ │ └── validate-go-test.sh # Test command recommendations
│ │ ├── agents/
│ │ │ └── code-quality-auditor.md # Code quality scanning agent
│ │ └── commands/
│ │ ├── code-quality.md # Run quality checks
│ │ ├── commit-prepare.md # Commit with test gate + quality checks
│ │ └── fly-deploy.md # Deploy Go app to Fly.io
│ ├── swift/ # Swift/Xcode project tools
│ │ ├── settings.json # Hook configuration for xcodebuild
│ │ └── hooks/
│ │ └── validate-xcodebuild.sh # Simulator validation hook
│ ├── kotlin/ # Kotlin/Android project tools
│ │ ├── agents/
│ │ │ ├── android-quality-auditor.md # Android code quality auditor
│ │ │ ├── kotlin-refactorer.md # Kotlin refactoring agent
│ │ │ └── compose-developer.md # Jetpack Compose development
│ │ ├── commands/
│ │ │ ├── code-quality.md # Run quality checks
│ │ │ ├── lint.md # Run Android Lint
│ │ │ ├── detekt.md # Run Detekt static analysis
│ │ │ ├── clean.md # Clean build artifacts
│ │ │ └── test-instrumented.md # Run instrumented tests
│ │ └── templates/
│ │ └── detekt.yml # Detekt config for Android/Compose
│ ├── php/ # PHP project tools
│ │ ├── settings.json # Hook configuration for PHP commands
│ │ ├── hooks/
│ │ │ ├── validate-php-syntax.sh # PHP syntax validation
│ │ │ └── validate-composer-lock.sh # Composer lock sync check
│ │ ├── agents/
│ │ │ ├── composer-manager.md # Composer dependency management
│ │ │ ├── security-reviewer.md # PHP security scanning
│ │ │ └── php-refactorer.md # PHP refactoring agent
│ │ ├── commands/
│ │ │ ├── phpstan.md # Run PHPStan static analysis
│ │ │ ├── update-deps.md # Update Composer dependencies
│ │ │ └── security-scan.md # PHP security scanning
│ │ └── skills/
│ │ └── security-review/ # PHP security review skill
│ │ └── SKILL.md
│ └── drupal/ # Drupal project tools
│ ├── settings.json # Hook configuration for Drupal commands
│ ├── hooks/
│ │ ├── validate-drush.sh # Drush command validation
│ │ └── validate-drupal-root.sh # Drupal root directory check
│ ├── agents/
│ │ ├── drupal-debugger.md # Debug errors and config issues
│ │ ├── drush-helper.md # Drush commands and sysadmin
│ │ ├── config-reviewer.md # Configuration safety review
│ │ ├── performance-tuner.md # Redis, caching, DB optimization
│ │ ├── test-creator.md # PHPUnit test generation
│ │ ├── api-developer.md # REST/JSON:API development
│ │ └── migration-expert.md # Content migrations and data sync
│ ├── commands/
│ │ ├── cache-clear.md # Clear all caches
│ │ ├── config-diff.md # Config differences
│ │ ├── config-export.md # Export Drupal configuration
│ │ ├── config-import.md # Import Drupal configuration
│ │ ├── backup-db.md # Create database backup
│ │ ├── db-query.md # Safe SELECT queries
│ │ ├── db-update.md # Run database updates
│ │ ├── drush.md # Execute drush command
│ │ ├── feature-revert.md # Revert feature configuration
│ │ ├── health-check.md # Site health check
│ │ ├── logs.md # View watchdog logs
│ │ ├── module-status.md # Module status information
│ │ └── test-run.md # Run PHPUnit tests
│ ├── skills/
│ │ ├── api-development/ # REST/JSON:API skill
│ │ ├── config-management/ # Features workflow and config splits
│ │ ├── database-operations/ # PostgreSQL backup/restore
│ │ ├── drupal-drush/ # Comprehensive Drush reference
│ │ ├── drupal-hooks/ # Hook and event subscriber patterns
│ │ ├── drupal-migrations/ # Migration YAMLs and plugins
│ │ ├── drupal-testing/ # PHPUnit tests and mocking
│ │ └── performance-optimization/ # Redis, caching, tuning
│ └── templates/
│ ├── phpunit.xml.dist # PHPUnit config for custom modules
│ └── phpstan.neon # PHPStan config for Drupal projects
├── global/ # User-level configuration templates
│ ├── CLAUDE.md
│ ├── settings.json
│ ├── commands/ # Global slash command templates
│ │ ├── finalize.md # Session finalization command
│ │ └── release-gh-prepare.md # Draft GitHub release with CHANGELOG update
│ ├── skills/ # Shared Claude Code + Codex skills
│ │ └── pr-fix/ # Repair PR review findings in ≤ 2 pushes
│ │ ├── SKILL.md
│ │ ├── scripts/pr-fix.sh # collect/triage/check/review/status/close/pre-push
│ │ └── references/ # triage rules, reviewer instructions, AGENTS.md blocks
│ ├── hooks/ # Git hooks for commit and push protection
│ │ ├── README.md # Installation instructions
│ │ ├── pre-commit # Prevents automated commits
│ │ └── pre-push # pr-fix push gate
│ └── tests/ # POSIX shell tests
│ ├── statusline-cwd-test.sh
│ ├── pr-fix-test.sh
│ └── fixtures/pr-fix/ # stub gh/codex data
├── .github/
│ ├── workflows/ # GitHub Actions workflows
│ │ ├── claude.yml
│ │ └── claude-code-review.yml
│ ├── THREAT_MODEL.md # Security threat model
│ └── SUPPLY_CHAIN_SECURITY.md # Supply chain security policy
└── SECURITY.md # Vulnerability disclosure policy
This repository has no runtime dependencies. It consists entirely of:
- Markdown documentation and agent definition files
- YAML configuration files for GitHub Actions
- JSON configuration files
If dependencies are added in the future, they must:
- Use lockfiles (package-lock.json, go.sum, etc.)
- Be scanned for vulnerabilities with Dependabot
- Follow semantic versioning
- Have versions pinned in production
Feel free to add your own:
- Agents - Create specialized agents for different domains (testing, refactoring, documentation, etc.)
- Commands - Build workflow-specific slash commands
- Workflows - Share GitHub Actions configurations for different use cases
Copyright (C) 2025-2026 Oleg Ivanchenko
GNU General Public License v3.0 - see LICENSE file for details.