Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
360 changes: 360 additions & 0 deletions .claude/PRPs/reviews/pr-1-review.md

Large diffs are not rendered by default.

32 changes: 32 additions & 0 deletions .claude/commands/audit.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
description: Audit the project's AI infrastructure (agents, skills, commands, context, rules) for gaps, drift, and security issues
allowed-tools: Bash, Read, Grep, Glob, Task
---

Run a focused audit of the repo's AI-assist infrastructure and report findings — analysis only, no edits.

## Scope

In scope: `.claude/` (agents, commands, settings), `.agents/` (skills, rules), `.github/copilot-instructions.md`, root `SKILL.md`, `AGENTS.md`, `CLAUDE.md`. **Out of scope:** editor-specific `.cursor/**` and Devin agent config.

## Steps

1. **Inventory** — list every in-scope file with line count and git-tracked/ignored status (`git ls-files`, `git check-ignore`). Flag untracked load-bearing config and missing referenced paths (e.g. a rules dir referenced by `AGENTS.md` that does not exist on disk).

2. **Coverage & drift** — check that each tool's context (Claude, Copilot, and any editor-rule mirrors) carries the project invariants from `AGENTS.md`; flag any tool whose context omits them, and any invariant duplicated across files that can drift.

3. **Skills & commands** — flag skills >400 lines (split candidates), skills/commands that duplicate a `~/.claude/` global, and prompts with no stop condition or with phantom commands.

4. **Security** — scan `.claude/settings.local.json` for credential literals (report by location, never reproduce the value), wildcard `Bash(* )` grants, `.env`-copy/home-dir/`/etc` read grants, and machine-absolute or wrong-repo paths.

5. **Report** — findings table `file:line | issue | severity | fix`, severity-ranked. For a deep pass, read the `security-review` skill and dispatch specialist agents (`rag-eval`, `invariant-guard`) when relevant.

## Arguments

$ARGUMENTS — optional surface to focus on (e.g. `skills`, `security`, `context`).

## Guardrails

- Analysis only — never edit infra files; output findings + recommendations.
- Never reproduce secret values; reference by `file:line` only.
- Cite real `path:line` for every finding; drop anything you cannot evidence.
57 changes: 57 additions & 0 deletions .claude/commands/commit-pr.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
---
description: Commit staged changes, push branch, and open a PR in one shot
allowed-tools: Bash, Read
---

Run `/commit` flow then push and open PR. Follows `.agents/rules/git.md`.

## Steps

1. **Commit** — follow `.claude/commands/commit.md` end-to-end (analyze diff, stage specific files, conventional `<type>(<scope>): <subject>`, HEREDOC, no `--no-verify`, no attribution). Abort if nothing to commit.

2. **Push** — parallel:
- `git rev-parse --abbrev-ref HEAD` to get branch
- `git rev-parse --abbrev-ref --symbolic-full-name @{u} 2>/dev/null` to check upstream
- If no upstream: `git push -u origin <branch>`; else `git push`
- Never force-push. Never push to `main`/`master` directly.

3. **PR** — parallel:
- `git log main..HEAD --oneline` for commit list
- `git diff main...HEAD --stat` for scope
- `gh pr view --json url 2>/dev/null` to detect existing PR (skip create if present, return URL)

4. **Draft PR body**:
- Title: same as commit subject (≤ 100 chars). Add `#<issue>` if `$ARGUMENTS` contains issue ref.
- Body sections: `## Summary` (1–3 bullets, why), `## Changes` (key files/modules), `## Test plan` (markdown checklist).

5. **Create PR** against `main` (the project's canonical PR base):

```bash
gh pr create --base main --title "<title>" --body "$(cat <<'EOF'
## Summary
- ...

## Changes
- ...

## Test plan
- [ ] pnpm lint
- [ ] pnpm --filter <app> check-types
- [ ] manual verification
EOF
)"
```

6. Return PR URL.

## Arguments

$ARGUMENTS — optional issue ref / hint (e.g. `#414 flow token`). Used in PR title/body when present.

## Guardrails

- No `git add -A`/`.`, no `.env`, no secrets.
- No `--no-verify`, no `--force`/`--force-with-lease` unless user explicitly asks.
- No attribution footers.
- If branch is `main`/`master`: abort and tell user to create feature branch first.
- If `pnpm lint` or typecheck obviously broken in diff, warn before pushing (do not auto-run unless asked).
47 changes: 47 additions & 0 deletions .claude/commands/commit.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
---
description: Stage specific files and create a conventional commit following ChatbotX git rules
allowed-tools: Bash, Read
---

Create a git commit for the current changes following the ChatbotX conventions in `.agents/rules/git.md`.

## Steps

1. Run in parallel:
- `git status` (never `-uall`)
- `git diff` (staged + unstaged)
- `git log -n 10 --oneline` for style reference

2. Analyze the diff:
- Determine commit `type`: `feat`, `fix`, `refactor`, `docs`, `style`, `test`, `chore`, `ci`, `perf`, `build`, `revert`
- Determine `scope` from touched package/app/feature when obvious (e.g. `builder`, `worker`, `whatsapp`, `database`)
- Draft subject: `<type>(<scope>): <subject>` — ≤ 100 chars, lowercase after `:`, no trailing period
- Add body only when the _why_ is non-obvious

3. Stage **specific files only** — never `git add -A` or `git add .`.
- Skip `.env*` and any file containing secrets. Warn if user explicitly requests them.

4. Commit using a HEREDOC so formatting is preserved:

```bash
git commit -m "$(cat <<'EOF'
<type>(<scope>): <subject>

<optional body>
EOF
)"
```
- Do **not** pass `--no-verify`. Let `lefthook` commit-msg + pre-commit hooks run.
- If a hook fails, fix the underlying issue and create a **new** commit (do not `--amend`).

5. Run `git status` after commit to confirm clean state.

## Arguments

$ARGUMENTS — optional. Treat as a hint about scope/intent (e.g. `flow token fallback`). Still derive type/scope from the diff.

## Guardrails

- No attribution / `Co-Authored-By` footers (disabled globally).
- No pushing in this command — use `/pr` for that.
- If nothing is staged and there are no changes, abort without creating an empty commit.
157 changes: 157 additions & 0 deletions .claude/commands/implement-plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,157 @@
---
description: Implement approved technical plans with execution-first behavior
---

# Implement Plan

You are in IMPLEMENTATION MODE.

The implementation plan has already been approved.

Your responsibility is execution, not planning.

Follow the shared repository workflow in `.agents/skills/implement-plan/SKILL.md`.

## Core Principles

- Implement code, do not create plans.
- Follow the implementation plan exactly.
- Respect approved architecture decisions.
- Respect approved API contracts.
- Respect approved database schema.
- Reuse existing code whenever possible.
- Keep changes minimal and focused.
- Avoid speculative improvements.
- Avoid unrelated refactoring.
- Do not expand scope.

## Getting Started

When given a plan path:

1. Read the plan completely.
2. Check for completed items (- [x]).
3. Read the original ticket if it is referenced or provided.
4. Read all files referenced by the plan.
5. Read files completely.
6. Understand the surrounding code before making changes.
7. Create an internal task list.
8. Begin implementation immediately.

If no plan path is provided, ask for one.

## Critical Execution Rules

- DO NOT create a new implementation plan.
- DO NOT rewrite the existing implementation plan.
- Only update task checkboxes/status after implementation and verification.
- DO NOT ask for approval before coding.
- DO NOT explain what you intend to do before making changes.
- DO NOT stop to summarize before implementation.
- DO NOT pause unless blocked by ambiguity or a plan mismatch.

Your first action should be reading the plan and relevant files.

Your first response should never be a plan.

## Implementation Process

1. Read the implementation plan.
2. Find the highest-priority unfinished task.
3. Implement that task completely.
4. Verify the implementation.
5. Update task checkbox/status if applicable.
6. Stop after the task is complete.

Only work on ONE task at a time.

Prefer the smallest independently deliverable unfinished task.

Do not automatically continue to the next task.

## Plan Mismatch Handling

If reality differs from the plan:

STOP and explain:

Issue in Phase [N]

Expected:
[what the plan specifies]

Found:
[actual implementation reality]

Why this matters:
[technical impact]

Recommended path:
[best option]

Wait for guidance before proceeding.

## Verification

After implementation:

- Run relevant tests.
- Run lint.
- Run typecheck.
- Fix all issues introduced by your changes.
- Ensure the project builds successfully.
- Verify success criteria defined in the plan.

## Manual Verification

Only pause for manual verification when:

- The plan explicitly requires manual testing.
- The implementation cannot be fully validated automatically.
- User interaction is required.

Otherwise continue implementation.

Do not mark manual verification items complete until confirmed by the user.

## Resuming Work

If checkmarks already exist:

- Trust completed work unless it blocks the current task, conflicts with current code, or verification fails.
- Resume from the first unfinished item.
- Only revisit completed work if necessary.

## Output Format

### Task Implemented

- What was implemented
- Why it was required

### Files Changed

- File path
- Reason for change

### Validation

- Tests executed
- Test results
- Lint status
- Typecheck status
- Build status

### Remaining Work

- Remaining unfinished tasks from the implementation plan

## Important

- Implementation first.
- Code first.
- No planning.
- No redesign.
- No scope expansion.

Your first code-changing action should be implementation, not replanning.
41 changes: 41 additions & 0 deletions .claude/commands/release-check.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
---
description: Run the full pre-release verification gate (lint, types, tests, coverage) and report readiness
allowed-tools: Bash, Read, Grep
---

Verify the repo is release-ready by running the gate sequence from the `testing-workflow` skill. CI only builds Docker images, so this gate is your real safety net — run it before tagging a release or opening a release PR.

## Steps

1. **Scope** — determine what changed: `git diff main...HEAD --stat` (or the given range). Identify the touched workspaces.

2. **Lint** — `pnpm lint`. If it fails, stop and report; suggest `pnpm fix` for auto-fixable issues.

3. **Types** — for each touched workspace: `pnpm --filter <workspace> check-types`. Report the first failure per workspace.

4. **Tests + coverage** — run the affected packages' Vitest suites. Do **not** set `VITEST_SKIP_COVERAGE_THRESHOLDS`; the 80% threshold must hold (`packages/vitest-config/src/node.ts`). Report any suite below threshold.

5. **Invariant scan** — dispatch the `invariant-guard` agent on the diff to catch the non-lintable invariants.

6. **Secret scan** — grep the diff for credential patterns (`PGPASSWORD`, `DATABASE_URL=`, API keys); confirm no `.env`/secret is staged.

## Output

A readiness checklist:

```
RELEASE CHECK
- lint: PASS / FAIL (<detail>)
- types: PASS / FAIL (<workspace>)
- tests: PASS / FAIL (<suite>)
- coverage: >=80% / BELOW (<package> <n>%)
- invariants: PASS / <n> violations
- secrets: CLEAN / FOUND (<file:line>)
=> READY / NOT READY
```

## Guardrails

- Read-only verification — do not edit code to make a gate pass; report the failure and let the owner fix it.
- Never report READY on a gate you did not actually run; say which gate was skipped and why.
- Never bypass coverage with the skip env var.
6 changes: 6 additions & 0 deletions .claude/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
{
"enabledPlugins": {
"expo@claude-plugins-official": true,
"ui-ux-pro-max@ui-ux-pro-max-skill": true
}
}
5 changes: 5 additions & 0 deletions .codegraph/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# CodeGraph data files — local to each machine, not for committing.
# Ignore everything in .codegraph/ except this file itself, so transient
# files (the database, daemon.pid, sockets, logs) never show up in git.
*
!.gitignore
6 changes: 6 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Base URL of the ChatbotX builder app (oRPC + REST API + OpenAPI spec host).
# Defaults to the builder app's standard local dev URL when unset.
API_BASE_URL=http://localhost:3123

# PartyKit realtime server URL. Defaults to the local `partykit dev` port when unset.
WS_URL=http://localhost:1999
37 changes: 37 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: CI

on:
push:
branches: [main]
pull_request:

jobs:
ci:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: pnpm/action-setup@v4

- uses: actions/setup-node@v4
with:
node-version: 22
cache: pnpm

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Typecheck
run: pnpm typecheck

- name: Lint
run: pnpm lint

- name: Format check
run: pnpm format:check

- name: Test
run: pnpm test

- name: Expo config/dependency doctor
run: npx expo-doctor
Loading
Loading