.claude

agent
Security Audit
Fail
Health Pass
  • License — License: MIT
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Community trust — 32 GitHub stars
Code Fail
  • child_process — Shell command execution capability in bin/prettier-hook.js
  • process.env — Environment variable access in get-shit-done/bin/gsd-tools.cjs
  • fs module — File system access in get-shit-done/bin/gsd-tools.cjs
  • child_process — Shell command execution capability in get-shit-done/bin/lib/commands.cjs
  • exec() — Shell command execution in get-shit-done/bin/lib/commands.cjs
  • fs.rmSync — Destructive file system operation in get-shit-done/bin/lib/commands.cjs
  • process.env — Environment variable access in get-shit-done/bin/lib/commands.cjs
  • fs module — File system access in get-shit-done/bin/lib/commands.cjs
  • network request — Outbound network request in get-shit-done/bin/lib/commands.cjs
  • process.env — Environment variable access in get-shit-done/bin/lib/config.cjs
  • fs module — File system access in get-shit-done/bin/lib/config.cjs
  • child_process — Shell command execution capability in get-shit-done/bin/lib/core.cjs
  • exec() — Shell command execution in get-shit-done/bin/lib/core.cjs
  • spawnSync — Synchronous process spawning in get-shit-done/bin/lib/core.cjs
  • fs.rmSync — Destructive file system operation in get-shit-done/bin/lib/core.cjs
  • process.env — Environment variable access in get-shit-done/bin/lib/core.cjs
  • fs module — File system access in get-shit-done/bin/lib/core.cjs
  • fs module — File system access in get-shit-done/bin/lib/frontmatter.cjs
  • child_process — Shell command execution capability in get-shit-done/bin/lib/init.cjs
  • execSync — Synchronous shell command execution in get-shit-done/bin/lib/init.cjs
  • exec() — Shell command execution in get-shit-done/bin/lib/init.cjs
  • process.env — Environment variable access in get-shit-done/bin/lib/init.cjs
  • fs module — File system access in get-shit-done/bin/lib/init.cjs
Permissions Pass
  • Permissions — No dangerous permissions requested
Purpose
This is a drop-in configuration toolkit for Claude Code that bundles 119+ skills, 67+ agents, and thousands of community marketplace skills. It acts as a zero-config setup that automatically activates resources based on your prompts.

Security Assessment
Overall Risk: High

The tool poses significant security concerns. It heavily utilizes shell command execution across multiple files (`core.cjs`, `commands.cjs`, `init.cjs`, `prettier-hook.js`) via `exec()`, `execSync()`, and `spawnSync`. Destructive file system operations (`fs.rmSync`) are present, which could lead to accidental data loss. Environment variable access is widespread, potentially exposing sensitive system or API key data. Outbound network requests are also made, introducing the risk of data exfiltration. No hardcoded secrets were found, but the combination of arbitrary command execution, file deletion, and network access gives the tool extensive control over your system.

Quality Assessment
Overall Quality: Good

The project is actively maintained (last push was today) and is properly licensed under the permissive MIT license. It has a clear description and detailed documentation. However, community trust is relatively low, sitting at only 32 GitHub stars, which means the codebase has not been widely vetted by a large audience.

Verdict
Use with caution — while actively maintained and open-source, the extensive shell execution, file deletion, and network capabilities require a thorough manual code review before installing on any system with sensitive data.
SUMMARY

The Ultimate Claude Code Toolkit — 119 skills, 67 agents, 103 marketplace repos (6,900+ community skills), 30 commands, 8 hooks. Drop-in ~/.claude config that auto-activates the right resources from your prompt. Zero config required.

README.md
tjn.claude/ — The Ultimate Claude Code Toolkit

v2.11.0
Platform
Website
License
Use Template

Skills
Agents
Commands
GSD
Repos
Marketplace Skills
Hooks
Templates
MCP


🚀 What Is This?

A drop-in configuration layer for Claude Code that transforms it from a capable AI assistant into an enterprise-grade development powerhouse.

One git clone gives you 123 domain skills, 86 specialist agents, 109 community marketplaces with 11,700+ additional skills, 30 slash commands, 8 lifecycle hooks, 12 MCP server configs, and the GSD (Get Shit Done) project management framework — all auto-activating based on what you're working on. No manual configuration required.

How it works: Describe what you want in plain language. The toolkit's dynamic router detects context from your prompt and loads the right skills, agents, rules, and checklists automatically. No slash commands needed (though they're available if you prefer).

Who it's for: Developers who use Claude Code and want deeper domain expertise, structured workflows, and quality guardrails without manual setup.


⚡ Quick Start

Use as GitHub Template (Recommended)

Click the green "Use this template" button at the top of this repo to create your own copy with a clean commit history. Then clone your new repo to ~/.claude/.

One-Line Install

Or clone directly if you prefer:

git clone --recurse-submodules https://github.com/travisjneuman/.claude.git ~/.claude

Manual Clone (if submodules fail)

git clone https://github.com/travisjneuman/.claude.git ~/.claude
cd ~/.claude
git submodule update --init --recursive

Verify Installation

# Start Claude Code — the toolkit loads automatically
claude

# Run diagnostics
/health-check

# Start a structured project with GSD (flagship workflow tool)
/gsd:new-project

That's it. The toolkit auto-activates from ~/.claude/ on every Claude Code session.


📦 What's Included

Component Count Description
GSD Framework v1.29 Multi-phase project management with 57 commands — the flagship workflow tool
Skills 123 Domain expertise modules (React, security, DevOps, finance, etc.)
Agents 86 Specialist subagents for focused tasks (code review, debugging, etc.)
Commands 94 Slash commands: 30 base + 57 GSD + 7 router
Marketplace Repos 109 Community skill repositories (11,700+ additional skills)
Hooks 9 Lifecycle hooks (session start/stop, pre-commit, safety guards)
Templates 17 Project scaffolding and task templates
MCP Servers 12 Model Context Protocol server configurations
Rules 9 Stack-specific coding guardrails (TypeScript, Python, Go, Rust, etc.)
📋 Skills by Category
Category Skills
Web Development react-native, vue-development, svelte-development, flutter-development, pwa-development, electron-desktop, tauri-desktop, frontend-enhancer
Backend & API api-design, graphql-expert, database-expert, microservices-architecture, event-driven-architecture, websockets-realtime, serverless-development
DevOps & Cloud devops-cloud, monitoring-observability, performance-engineering, mobile-cicd
AI & Data ai-ml-development, llm-app-development, data-science
Security application-security, authentication-patterns
Mobile android-development, ios-development, macos-native, kotlin-multiplatform, react-native, flutter-development
Quality generic-code-reviewer, generic-feature-developer, generic-design-system, generic-ux-designer, test-specialist, tdd-workflow, debug-systematic, tech-debt-analyzer
Business business-strategy, finance, marketing, sales, product-management, hr-talent, legal-compliance, risk-management, operations, innovation
Creative brand-identity, graphic-design, video-production, audio-production, ui-animation, ui-research
Productivity codebase-documenter, document-skills, content-repurposer, status-report-generator, core-workflow
Specialized game-development, i18n-localization, seo-analytics-auditor, email-systems, payment-integration, product-analytics, growth-engineering, monetization-strategy
Blockchain & Web3 blockchain-web3 (Solidity, DeFi, NFTs, Hardhat/Foundry)
Data Engineering data-engineering (ETL, Airflow, dbt, Kafka, BigQuery/Snowflake)
Edge & IoT edge-computing, embedded-iot (Cloudflare Workers, ESP32, FreeRTOS)
XR & Spatial ar-vr-xr (Unity XR, WebXR, ARKit, Vision Pro)
Compliance compliance-engineering (SOC2, HIPAA, GDPR, PCI-DSS)
Developer Tools devex-sdk-design, low-code-platforms (SDK design, Retool, Supabase, n8n)
Non-Tech travel-planner, event-planner, recipe-card-creator, health-wellness, career-path-planner, real-estate-analyzer

See MASTER_INDEX.md for the full listing with descriptions.


⚙️ How It Works

Dynamic Routing

Every prompt flows through a routing system that loads the best-fit resources on-demand — drawing from 123 built-in skills, 86 agents, 9 rules + 10 checklists, the GSD framework (57 commands), and 11,700+ community marketplace skills across 109 repos:

 Your prompt
     │
     ▼
 ┌──────────────────────────────┐
 │  CLAUDE.md Auto-Routing      │  ← Keyword detection table
 │  (always loaded)             │
 └──────────┬───────────────────┘
            │
   ┌────────┼────────┬──────────┬────────────┐
   ▼        ▼        ▼          ▼            ▼
┌──────┐ ┌──────┐ ┌──────┐ ┌───────┐ ┌────────────┐
│Skills│ │Rules │ │Agents│ │  GSD  │ │ Marketplace│
│(123) │ │& Chk │ │ (86) │ │  (57) │ │  110 repos│
│      │ │      │ │      │ │       │ │ 11,700+ more│
└──────┘ └──────┘ └──────┘ └───────┘ └────────────┘

Example: Type "review this React component for security issues" and the router automatically loads the React/TypeScript stack guide, the security hardening checklist, and spawns the code reviewer agent — without any slash commands.

Auto-Routing Table (from CLAUDE.md)

CLAUDE.md routes to docs and checklists on keyword match. Skills and agents auto-match from their descriptions — no explicit routing needed.

Your prompt mentions... Toolkit loads...
React, TypeScript React/TS stack guide
Security, OWASP Security hardening checklist
Deploy, CI/CD, Docker Deployment workflow
Database, schema, SQL Database design checklist
Performance, speed Performance optimization checklist
UI, visual, CSS UI/visual changes checklist
Research, investigate Research methodology workflow
Monitoring, alerting Monitoring & alerting design checklist
Any specialized domain Best-fit skill + agent auto-matched, marketplace (6,900+)

Hook Lifecycle

Hooks run automatically at key points in every session:

Session Start
  ├── Pull all repos (background, 60s timeout)
  └── Load previous session context

Every Prompt
  └── Inject git branch + status into context

Before Bash Commands
  ├── Block dangerous commands (rm -rf /, force push, etc.)
  └── Update doc counts before git commit

After File Edits
  └── Scan for leaked secrets

Session Stop
  └── Save session summary for next time

Session End (exit/clear/logout)
  └── Final session summary on exit

See hooks/README.md for the full hook reference.


🚢 GSD — Get Shit Done (Flagship)

The GSD Framework is the most powerful component of this toolkit. It transforms Claude Code from a task-runner into a full project management system with multi-phase planning, autonomous execution, verification loops, and session continuity.

Quick start:

/gsd:new-project          # Initialize a new project with deep context gathering
/gsd:plan-phase 1         # Create a detailed plan for phase 1
/gsd:execute-phase 1      # Execute with atomic commits and checkpoints
/gsd:verify-work           # Validate against success criteria
/gsd:next                  # Automatically advance to the next step

What makes it special:

  • 30 slash commands covering the full project lifecycle — from idea capture to PR shipping
  • Autonomous mode (/gsd:autonomous) — runs discuss → plan → execute per phase without interaction
  • Session continuity — pause mid-phase, come back later, /gsd:resume-work picks up exactly where you left off
  • Milestone tracking — multi-milestone projects with requirements tracing and coverage gates
  • Agent orchestration — spawns specialized subagents for research, planning, execution, and verification

Key commands: /gsd:new-project, /gsd:progress, /gsd:next, /gsd:autonomous, /gsd:debug, /gsd:ship, /gsd:fast (quick inline tasks)

See docs/GSD-TUTORIAL.md for the full guide. GSD activates automatically when you describe multi-phase work — no need to invoke it manually.


🔑 Key Features

🏪 Marketplace — 109 repos, 11,700+ skills

The toolkit aggregates 109 community skill repositories as git submodules in plugins/marketplaces/. All are read-only (fetch but never push). Skills span security (Trail of Bits), full-stack development, scientific computing, SAP/enterprise, Elixir, Terraform, creative writing, and more. Some marketplace repos are installed as plugins, making their agents, commands, and skills fully active in the routing system alongside built-in resources. Non-installed repos contribute discoverable skills via keyword search.

# Search marketplace skills
find ~/.claude/plugins/marketplaces -name "SKILL.md" | xargs grep -li "kubernetes"

# Update all marketplace repos
bash ~/.claude/_pull-all-repos.sh

See docs/MARKETPLACE-GUIDE.md for the full catalog.

🛡️ Safety Guards

The guard-dangerous.sh hook blocks dangerous commands before execution:

Blocked Pattern Risk
rm -rf / / rm -rf ~ Filesystem destruction
git push --force Overwrite remote history
DROP TABLE / TRUNCATE TABLE Database destruction
git reset --hard origin Discard all local changes
git clean -fd Delete untracked files
curl ... | sh Pipe-to-shell (RCE)
npm publish Accidental package publication
chmod -R 777 Overly permissive permissions
docker system prune -a Destroy all Docker resources

Additional safety: pre-write-validate.sh blocks writes to .env, .ssh, .gnupg, *.pem, and *.key files. secret-scan.sh scans every file edit for leaked API keys and tokens.

🖥️ Cross-Platform

All hooks use a Node.js-based runner (hooks/run-hook.js) that resolves paths via os.homedir(). This avoids WSL path issues on Windows where ~ resolves to /root/ instead of the Windows user home.

On Windows, the runner explicitly prefers Git Bash (C:\Program Files\Git\usr\bin\bash.exe) over WSL bash to prevent drive mount failures on network drives.

Platform Shell Notes
macOS /bin/bash Standard bash via Git or Homebrew
Linux /bin/bash Standard bash
Windows Git Bash (preferred) Avoids WSL drive mount errors
🤖 Agent Teams

For complex tasks, spawn multiple specialist agents to work in parallel:

  • Code review from multiple angles — security, performance, tests
  • Cross-layer features — frontend + backend + database agents
  • Competing hypotheses — debug with parallel investigation

Agent types include architecture analysts, debugging specialists, performance optimizers, security auditors, test generators, and 50+ more. See agents/README.md.

🔌 MCP Servers

12 MCP server configurations available (all disabled by default for token efficiency):

Server Purpose
sequential-thinking Structured reasoning chains
playwright Browser testing & automation
memory Persistent memory across sessions
sqlite / postgres Database operations
github / git Enhanced GitHub/git operations
chrome-devtools Browser debugging & profiling
context7 Enhanced context retrieval

Enable on-demand via /mcp. See docs/MCP-SERVERS.md.

🔄 Session Continuity

The toolkit maintains context between sessions automatically:

  1. Session stopsession-stop-summary.sh saves working directory, branch, recent commits, active tasks, and pending todos to ~/.claude/last-session.md
  2. Session startsession-start-context.sh injects the previous session context (if < 72 hours old)
  3. Repo syncsession-start-pull.sh pulls all repos in the background on startup

🛠️ Configuration

Key Files

File Purpose
CLAUDE.md Core rules, auto-routing table, code standards
settings.json Claude Code settings, hook registrations, permissions
.mcp.json MCP server definitions
counts.json Resource counts (source of truth)
plugin.json Plugin metadata

Common Customizations

Add your own project directories to auto-pull:

cp ~/.claude/.env.example ~/.claude/.env.local
# Edit CUSTOM_PROJECT_DIRS="/path/to/your/projects"

Switch action mode between proactive (default) and conservative — see docs/reference/workflows/action-policy.md.

Disable a hook — edit settings.json and remove the hook entry.


🖥️ Multi-Machine Setup

The toolkit uses a two-layer architecture:

  1. This repo (~/.claude/) — Shared configuration, cloned on every machine
  2. Machine-specific (.env.local, known_marketplaces.json) — Gitignored, per-device

New Device Setup

git clone --recurse-submodules https://github.com/travisjneuman/.claude.git ~/.claude
cp ~/.claude/.env.example ~/.claude/.env.local
# Edit .env.local with machine-specific paths
bash ~/.claude/scripts/fix-marketplace-paths.sh

See docs/NEW-DEVICE-SETUP.md for the full walkthrough.


💻 Platform Support

Platform Status Shell Notes
macOS Full support bash/zsh Notifications via osascript
Linux Full support bash Notifications via notify-send
Windows 11 Full support Git Bash Hooks use Node.js runner to avoid WSL issues
WSL Works bash Native Linux behavior inside WSL

Requirements: Node.js (comes with Claude Code), Git, bash (Git Bash on Windows).


🆕 What's New

March 2026 — Comprehensive audit, GSD promotion, new repos, full domain coverage

  • GSD (Get Shit Done) promoted: Now the flagship feature with dedicated README section, Quick Start integration, and routing diagram inclusion. 57 commands for full project lifecycle management.
  • 6 new marketplace repos: blader/humanizer (11.4K stars), phuryn/pm-skills (8.3K stars, 100+ PM skills), Lum1104/Understand-Anything (6.6K stars), SawyerHood/dev-browser (4.9K stars), slavingia/skills (4.5K stars), millionco/expect (2.3K stars). Now 109 repos total.
  • Submodule cleanup: Fixed orphaned directories, standardized all .gitmodules naming, verified no_push protection on 100% of marketplace repos
  • Full domain coverage: New skills and agents for blockchain/Web3, data engineering, embedded/IoT, edge computing, compliance, and more
  • New stack rules: Added Go, Rust, Java/Kotlin, C/C++, Swift/iOS, Flutter/Dart rules — path-scoped for zero token cost when not relevant
  • Count synchronization: All counts now accurate across README, plugin.json, counts.json (127 skills, 86 agents, 94 commands, 110 repos)

Earlier in March 2026:

  • Marketplace routing: All repos now surface naturally by domain — routing coverage went from 23% to 100%
  • CLAUDE.md condensed: Auto-routing table reduced from 72 to 29 rows, saving ~600 tokens per conversation
  • start-task trimmed: 156 → 82 lines, removed duplication with CLAUDE.md

See CHANGELOG.md for the full history.


📚 Documentation

Document Description
CLAUDE.md Core rules and auto-routing table
GSD Tutorial Get Shit Done framework — project lifecycle management
CHANGELOG.md Version history
Architecture System design and component interactions
Setup Guide First-time installation walkthrough
New Device Setup Multi-machine configuration
Workflow Guide Development workflow patterns
Marketplace Guide Community skill catalog
Agent Teams Multi-agent coordination
Auto-Claude Guide Autonomous coding framework
MCP Servers MCP server reference
Configuration Full settings.json reference
Folder Structure Directory layout and purpose
Skills Index All 123 skills with descriptions
Agents Index All 86 agents with descriptions

💡 Philosophy

This toolkit follows three core principles:

  1. Everything activates dynamically. Describe what you want — the system loads what's needed. No memorizing commands.
  2. Token efficiency over completeness. Domain content loads on-demand, not upfront. Unused skills cost zero tokens.
  3. Safety by default. Dangerous commands are blocked, secrets are scanned, protected files are guarded — all before you make a mistake.

Maintained by Travis Neuman · claude.travisjneuman.com · MIT License

Reviews (0)

No results found