.claude
Health Uyari
- License — License: NOASSERTION
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Basarisiz
- rm -rf — Recursive force deletion command in .github/workflows/skills-catalog-release.yml
- fs module — File system access in .github/workflows/skills-catalog-update.yml
Permissions Gecti
- Permissions — No dangerous permissions requested
Bu listing icin henuz AI raporu yok.
Claude Code Toolkit — reproducible skills, agents and hooks for Claude Code, with a security-gated catalog, automated upstream updates and verifiable cross-platform releases (Linux, macOS, Windows, WSL).
Claude Code Toolkit
A reproducible, verifiable Claude Code setup — skills, agents, hooks and provider switching, installed with one command.
Getting started · Setup presets · Providers · Doctor · Security · FAQ
What this is
Claude Code is the upstream harness. This toolkit keeps it that way, then adds
a reproducible skills/configuration layer around it: curated skills, agents,
hooks, MCP starters, provider switching, and the checks that tell you what is
actually active.
It is built for the boring parts that matter in a real setup:
- Install only what you want. Five plugins, installable separately from a
Claude Code marketplace, or the full bootstrap in one command on Linux,
macOS, native Windows or WSL. - Context cost is measured, not hoped for. Claude Code budgets the skill
listing at 2% of your context window and silently drops descriptions past
it, leaving those skills unroutable. This toolkit's entire listing is
CI-enforced at 2,048 characters — half of what a 200k-token context allows. - Every skill is pinned to a reviewed commit SHA, licence-checked, and
recorded with a content digest — so you can see exactly what is on your
machine and where it came from. - Updates never destroy your work. Fast-forward only; an update that would
discard a local change refuses and tells you, rather than resolving it for you. - Upstream updates arrive as reviewed pull requests, not silent overwrites.
Routine changes merge automatically; anything carrying capability surface
(hooks, agents, executables, credentials, network access) is held for a human. - Provider switching without pretending. Claude Code can stay on Anthropic
or route through supported Anthropic-compatible providers. Codex uses the
official Codex CLI/App Server path; tokens stay with their native owner. - No telemetry, no account, no service. Nothing phones home.
Not an official Anthropic project. It packages Anthropic's published
skills alongside third-party and repository-owned ones, each under its own
licence.
Overview video
A 22-second silent overview: install, the implemented provider routes, and
provider switching. The provider marks only identify which routes the
repository supports. This project is not affiliated with, or endorsed by,
Anthropic, OpenAI, NVIDIA or Z.ai. Logo sources are listed in
docs/media/LOGO-PROVENANCE.md.
Quick start
Just the plugins
If you only want the skills and agents, and want them namespaced and
independently updatable:
/plugin marketplace add furkankoykiran/.claude
/plugin install fk-gh-flow@fk-toolkit
| Plugin | What it does | Skill-listing cost |
|---|---|---|
fk-gh-flow |
Find issues worth working on, solve one into a PR, follow up on review feedback, write human-sounding comments | 746 chars |
fk-writing-kit |
Strip AI tells from drafts; build blog posts or LinkedIn copy from a chat, URL or GitHub profile | 819 chars |
fk-eng-agents |
researcher · planner · code-reviewer · debugger subagents | 0 |
fk-toolkit-ops |
Manage toolkit updates, MCP setup, and Codex-native ImageGen boundaries | 233 chars |
Plugins carry no hooks and no executables. fk-toolkit-ops carries the generated no-auth OpenAI Developer Docs MCP manifest; auth-required MCP starters stay disabled in the registry until native host login. Its image skill prefers Codex-native ImageGen when the host exposes it, and never claims ChatGPT-plan API image credits. Everything else with capability surface lives in the bootstrap layer below, where you can see it before it runs.
The whole toolkit
The bootstrap additionally installs the upstream skill packs, the provider
switcher, the safety hooks and the updater.
Linux · macOS · WSL · Git Bash
curl -fsSL https://raw.githubusercontent.com/furkankoykiran/.claude/main/install.sh | bash
Windows (native PowerShell)
irm https://raw.githubusercontent.com/furkankoykiran/.claude/main/install.ps1 | iex
Native Windows requires Git for Windows — it
bundles Git Bash, which runs the shell hooks.
Re-running is safe. The installer is idempotent and fail-soft: it never
overwrites an existing config.json or settings.json, and a component that
fails to install does not abort the rest.
Required: git, curl, bash (or PowerShell 7+ on Windows).
Bootstrapped if missing: bun, rtk, gstack, Chromium for browser
skills. Optional components can be skipped — see
installer flags.
Verify the install:
bun install --frozen-lockfile && bun run catalog:check
fkt doctor
Then choose how much the toolkit should configure for you. Start with a preview:
fkt setup --dry-run --preset recommended --profile balanced
Apply only the choices you mean to apply. For example, this keeps setup
non-interactive, selects Codex as the provider, uses GPT-5.5 medium effort, and
leaves manual /compact available while turning off automatic compaction:
fkt setup --yes --provider codex --model gpt-5.5 --effort medium --permission-mode manual --compaction off
ccs login codex
ccs codex
ccs status
Codex support is deliberately native-first: authentication stays in codex,
models come from the live Codex App Server catalog, Claude-side MCP tools stay
owned by Claude Code in bridge mode, and ImageGen is used only when the current
host exposes native ImageGen. The optional OpenAI API image path is a separate
API-key fallback, not a ChatGPT-plan credit claim.
Updating
fkt check # is there an update? (cached; no network on a cache hit)
fkt update # fast-forward, then run migrations
fkt never runs reset --hard, never runs clean, and never stashes on your
behalf. If your checkout has uncommitted changes or local commits, it refuses and
prints the command to inspect them — this directory holds your settings and your
memory, and only you can decide what happens to work you did in it.
Two channels: stable (the default) follows tagged releases and installs
third-party packs at reviewed SHAs, so two machines get byte-identical skills;edge follows main and upstream HEAD.
Plugins update through Claude Code itself: /plugin marketplace update fk-toolkit.
Full detail — migrations, snoozing, opting out, security advisories — in
Updates. Uninstall instructions are in
Getting started.
What you get
| Component | Location | What it does |
|---|---|---|
| Plugins | skills/fk-* |
The fk-toolkit marketplace: fk-gh-flow, fk-writing-kit, fk-eng-agents, fk-toolkit-ops |
| Skill packs | skills/ |
Installer-fetched upstream packs, pinned to reviewed commits |
| Hooks | hooks/ |
Format on edit, secret scan on commit, pre-push verify, Docker volume protection, update notice |
| Updater | bin/fkt |
Fast-forward-only bootstrap updates on a stable or edge channel |
| Providers | providers/, bin/cc-provider |
Switch Claude Code between Anthropic, Codex, NVIDIA, DeepSeek, Kimi, MiniMax, OpenRouter, Z.ai |
| Utilities | utils/ |
Shared Python helpers and profile-aware config |
| Catalog | catalog/ |
Deterministic resolver + generator producing the verifiable skills catalog |
Runtime architecture
flowchart LR
U["developer"] --> CC["Claude Code upstream CLI"]
CC --> S["skills, agents, hooks"]
CC --> MCP["Claude-owned MCP servers"]
CC --> P{"active provider"}
P --> A["Anthropic"]
P --> C["Codex loopback gateway"]
P --> O["other Anthropic-compatible providers"]
C --> APP["official Codex App Server"]
APP --> CHATGPT["ChatGPT/Codex entitlement"]
C -. "no token copying" .-> MCP
Claude Code remains the executable you run. The toolkit changes configuration,
not the harness. Provider adapters, MCP registry output, and setup presets are
kept as generated or documented layers so you can inspect them before they touch
your local credentials.
See the provider capability matrix,
Codex mode parity, and
Codex skill parity for the tested boundaries.
Catalog architecture
flowchart LR
M["skills-sources.toml<br/>declarative manifest"] --> RES
G["git sources"] --> RES["resolver<br/>pin, fetch, verify licence"]
R["runtime sources"] -. metadata only .-> RES
RES --> L["skills-source.lock.json<br/>catalog/cache"]
L --> GEN["generator"]
GEN --> OUT["catalog/generated/<br/>catalog, index, digests"]
GEN --> D["docs/skills/"]
OUT --> PR["automation pull request"]
PR --> GATE{"policy gate"}
GATE -- routine --> AM["squash auto-merge<br/>after required checks"]
GATE -- capability surface --> HUMAN["manual-review-required<br/>held for a human"]
AM --> REL["tagged release<br/>with SHA256SUMS"]
The catalog
Every skill is resolved from a declared source, pinned to an immutable revision,
licence-checked, and recorded with a content digest. Generation is
deterministic — two runs produce byte-identical output — so the committed
catalog is verifiable rather than trusted.
How sources are selected:
| Mode | Meaning | New upstream skills |
|---|---|---|
all-skills |
every <dir>/SKILL.md under a root |
ingested automatically |
named |
only the listed skills | never — reported, not added |
subpath |
one skill at a fixed path | never — siblings reported |
repo-owned |
committed in this repository | n/a |
runtime |
resolved by the claude CLI, PyPI or an installer |
metadata only |
metadata-only sources publish name, description, digest and an immutable
link but never the body — either upstream grants no redistribution right, or the
component cannot be resolved from files.
bun run catalog:coverage # what each source contributes, and what is curated out
See Catalog coverage and
Catalog architecture.
Safety model
Skills are instructions Claude reads; they are not sandboxed. Adding a source is
a supply-chain decision, so the automation treats it as one.
A change is held for human review when it introduces a credential reference,
executable or binary, hooks, MCP/LSP config, agents, dynamic shell, Bash or
PowerShell, network access or hidden files — or when an existing skill gains
any of those, when a skill that already carries a severe capability has its
content rewritten, when files appear or disappear beside SKILL.md, when the
tool surface grows, when redistribution or licence changes, when the source
repository changes, when a skill is removed or renamed, or when the batch is
unusually large.
The gate is a strong filter, not a proof of safety: it reasons about capability
surface and provenance, not intent. A rewrite of a skill carrying no severe
capability still merges as routine. Read the diff on anything you care about.
Detection does not rely on the content digest: the same bytes re-pointed at a
different repository or re-licensed is still a change. Auto-merge state is torn
down and re-proven on every run, so a merge request enabled by an earlier
routine update cannot carry into a later sensitive one.
API keys live only in git-ignored files; a commit hook scans staged content.
Full detail in Security model.
Privacy
There is no telemetry, no analytics, no account and no service of ours anywhere.
The toolkit makes exactly three kinds of outbound request, all of them to
public endpoints you can see in the source:
| Request | When | What it carries |
|---|---|---|
git ls-remote / git fetch against this repository and the pinned upstreams |
install, and fkt check at most every 12 hours |
what git sends |
one GET of security-advisories.tsv |
alongside an update check | nothing identifying — it is a static file, and the matching happens on your machine |
whatever you install (bun, rtk, gstack, pip packages) |
first install | their own business; each is named in Provenance |
fkt disable stops update checks. FKT_OFFLINE=1 forbids all network access.
Security advisories deliberately survive fkt disable — turning off "there is a
new version" should not turn off "the version you are on has a known problem" —
and have their own switch.
Context cost
Claude Code injects name + description for every model-discoverable skill at
session start, budgeted at 2% of your context window. Past that it drops
descriptions without a warning, and a skill listed by name alone cannot be
routed to by the model.
Before this toolkit's plugin split, its install put 54,529 characters into that
listing — 13× the budget of a 200k-token context. Roughly fifty skills were
unroutable and nothing said so.
bun run catalog:budget
is CI-enforced at 2,048 characters with a per-plugin, per-skill breakdown.
Measurement, method and the full before/after in
Skill context economy.
Repository layout
.claude-plugin/ generated marketplace manifest
AGENTS.md shared cross-agent repository instructions
bin/ executables on PATH (cc-provider, fkt)
catalog/ catalog toolchain (src, tests, cache, generated)
docs/ documentation — start at docs/README.md
hooks/ git and Claude Code hooks
memory/ persistent memory files
migrations/ versioned bootstrap migrations run by `fkt`
providers/ API provider definitions
scripts/ maintenance and test scripts
skills/ repo-owned plugins (fk-*) and installer-fetched packs
utils/ shared Python helpers
install.sh installer for Linux/macOS/WSL — public URL, do not move
install.ps1 installer for native Windows — public URL, do not move
marketplace.toml plugin marketplace source of truth
mcp-registry.toml curated portable MCP registry
skills-sources.toml declarative source manifest
skills-source.lock.json pinned revisions and digests
security-advisories.tsv advisory feed consumed by `fkt`
VERSION single version source of truth
package.json catalog toolchain scripts
tsconfig.json TypeScript configuration
bun.lock dependency lock
CLAUDE.md repository instructions for Claude Code
README.md this file
docs/ documentation, including the release process and archive
CONTRIBUTING.md contribution guide
CODE_OF_CONDUCT.md community standards
SECURITY.md vulnerability reporting
LICENSE MIT, for this repository's own code
config.json.example template seeded to config.json on install
settings.json.example optional settings, merged with settings.base.json on install
settings.base.json repo-owned safety config merged in on every provider switch
PSScriptAnalyzerSettings.psd1 PowerShell lint configuration
Generated artifacts live in catalog/generated/ and are rebuilt bybun run catalog:generate — never edit them by hand. Published release asset
names stay stable regardless of where their sources sit in the tree.
Contributing
Contributions are genuinely welcome — this is more useful the more people shape
it. Especially valuable:
- New source adapters and skill sources, with a clear upstream licence
- Platform support — macOS, native Windows and WSL edge cases
- Tests, particularly around the resolver and the policy gate
- Documentation — if something here was unclear, that is a bug
- Bug reports including the failing command's output
Before opening a pull request:
bun install --frozen-lockfile
bun run typecheck
bun test catalog
bun run catalog:check
bun run docs:check
See CONTRIBUTING.md and the
Code of Conduct.
Security
Report vulnerabilities privately — see SECURITY.md. Please do not
open a public issue for security reports.
Licence and acknowledgements
This repository's own code is MIT. Cataloged and vendored content
keeps its upstream licence; the resolver verifies each and withholds bodies it
may not republish.
Built on the work of gstack,
Anthropic's skills,
impeccable,
marketing skills,
taste-skill,
Karpathy guidelines and
rtk. Thank you to their authors.
Yorumlar (0)
Yorum birakmak icin giris yap.
Yorum birakSonuc bulunamadi
