Marketplaces / vanillagreencom/kendex
kendex
FeaturedThe official kendex catalog: agents, skills, hooks, commands and Pi extensions for AI coding harnesses
Subscribe
$kendex marketplace subscribe vanillagreencom/kendexIts packages then sit beside everything else you have. Every install is checked on your machine first.
No app yet? Download kendex.
Bundles
6Groups of packages that work well together.
- code-review16 packages
The review agents and the skills that run a review
- command-safety2 packages
Project-defined shell command restrictions
- commit-guards11 packages
Hooks and skills that guard what gets committed
- orchestration19 packages
Multi-agent workflow orchestration and the skills it drives
- research7 packages
Research and planning agents with the deep-research skill
- workflow49 packages
Orchestration, code review and commit guards in one install, with deep-research and bot-instructions
Packages
69| Package | Kind | Tags |
|---|---|---|
| frontend Declarative UI specialist for TypeScript/React web, mobile and terminal views, plus Quickshell QML/JavaScript. Use for view layers and their UI messages, not non-UI runtime logic or Iced. | agent | ui |
| iced Iced UI specialist. Use for Iced widgets, Canvas/Shader rendering, pane_grid layout, Theme system, Subscription-based data flow, or Elm Architecture patterns. | agent | ui |
| maintainer Maintenance specialist for documentation, stale references, links, lint, and file or configuration organization. Use for changes settled by reading. | agent | refactoringdocs |
| planner Planning specialist that explores requirements and code context, weighs architecture trade-offs, and produces ordered implementation plans or plan files. May write planning artifacts; does not edit production code. | agent | planningresearch |
| researcher Exa-powered research specialist for producing evidence-backed findings reports from project research prompts. Use for research issues, technology investigations, vendor/library comparisons, architectural option analysis, and current-state web research. | agent | research |
| reviewer-arch Architecture reviewer for design reviews, module boundary validation, spec/proposal review, and technical debt assessment. | agent | review |
| reviewer-correctness Broad correctness and regression reviewer for behavior breakage, boundary/edge-case predicates, API/CLI/devex regressions, feature-gate leaks, migrations, state semantics, and cross-module side effects. | agent | review |
| reviewer-doc Documentation accuracy reviewer. Verifies changed doc claims against implementation, re-derives transcribed values, checks citations resolve, audits drift. | agent | reviewdocs |
| reviewer-error Silent failure and error handling reviewer. Detects fail-open paths, swallowed errors, wrong-cause diagnostics, and inadequate error propagation. | agent | reviewdebugging |
| reviewer-perf Performance validation specialist. Latency validation, benchmark execution, percentile analysis, hot-path cost review, regression detection. | agent | reviewperformance |
| reviewer-quality Code quality reviewer for maintainability, simplification, abstraction value, type boundaries, helper reuse, decomposition, and god objects. | agent | review |
| reviewer-safety Memory, thread, and process safety auditor. Unsafe code, data races, lock-free correctness, and file/process races (TOCTOU, PID reuse, shared mutable state). | agent | reviewsecurity |
| reviewer-security Application security reviewer. Auth logic, input handling, trust/ownership gating, path containment, and secret exposure. | agent | reviewsecurity |
| reviewer-test Test coverage and quality reviewer. Verifies coverage, detects vacuous tests and missing must-fail controls, audits assertion tightness and test wiring. | agent | reviewtesting |
| runtime Runtime specialist for non-UI shell, Python, TypeScript and Go code. Use for scripts, services, automation and Pi extensions. | agent | automation |
| rust Rust implementation specialist for non-Iced code. Use for domain logic, systems programming, and project-defined performance work. | agent | performance |
| scout Fast reconnaissance agent for exploring codebases, finding files by pattern, searching keywords, answering architecture questions, and returning compressed cited context or report artifacts. Specify thoroughness: quick, medium, or very thorough. | agent | research |
| swift Swift application specialist for SwiftUI and UIKit views, Swift app code, and Xcode and Swift Package Manager builds/tests. Excludes non-UI runtime and data persistence. React Native and Expo go to frontend. | agent | ui |
| tpm Technical Program Manager for analyzing roadmaps, project lifecycle, and progress. Returns recommendations only. Does not modify project management tools. | agent | planning |
| bot-instructions Load to render, check, or adopt a repo's GitHub review-bot instruction files from the shared doctrine and its effective manifest. | skill | review |
| code-quality Load for any coding or development task in any repository: writing, changing, fixing, refactoring, or testing code or scripts in any language. | skill | review |
| commit-guards Load to add, tune, or debug a commit guard lane, its git hooks, or COMMIT_GUARDS_* settings. | skill | automation |
| decider Load to create, search, or supersede an architecture decision record. | skill | planning |
| deep-research Load for research tasks, architectural investigations, and vendor, library, or technology comparisons. | skill | research |
| dep-radar Load to run or tune a dependency sweep. | skill | release |
| dev Load when implementing an issue or applying review fixes as a dev agent. | skill | automation |
| doc-limits Load to add, tune, or debug document byte ceilings and DOC_LIMITS_* settings. | skill | automation |
| docs-writing Load to write, rewrite, or review repository markdown or documentation HTML: README, DEVELOPMENT, architecture docs, reference docs, SKILL.md and AGENTS.md. | skill | docs |
| github Load to work a GitHub pull request: threads, comments, reviews, CI logs, merges. | skill | gitintegration |
| harness-ci Load to wire, tune, or debug a repo's changed-file CI skip. | skill | automation |
| iced-rs Load whenever building or debugging an Iced UI. | skill | ui |
| linear Load for any Linear read or write: issues, projects, cycles, milestones, initiatives, labels. | skill | integration |
| orch PRIMARY AGENT ONLY. Load to orchestrate a Linear or GitHub work item from preparation through merge. | skill | automation |
| preflight Load to run, tune, or debug preflight. | skill | reviewtesting |
| price-handling Load when comparing, rounding, formatting, or parsing prices, or designing price types. | skill | data |
| project-management Load to plan a cycle, audit issues, build a roadmap, or decompose research into issues. | skill | planning |
| review-gate Load to watch pull requests, report the organization standard, or adopt consumer refresh. | skill | review |
| reviewer Load when reviewing a diff, classifying findings, or returning a verdict. | skill | review |
| second-opinion Load for a cross-model review, challenge, audit, or quick consult. | skill | review |
| slack Load to bind an overseer's mailbox to a private Slack channel, run or check the relay, or post an alert or a file to Slack. | skill | |
| worktree Load to create, list, remove, push, or repair a git worktree. | skill | git |
| xcode-run Load to install or dispatch a macOS GitHub Actions build, test or simulator screenshot run for an Xcode project. | skill | testing |
| block-argv-kill Refuse a command that kills processes by name or by argv pattern (`pkill`, `killall`), whatever flags follow. On a machine where several agents share one checkout and its worktrees, a pattern that matches a tool's name matches every lane running that tool, the caller's own shell included when its command line holds the pattern. Names the accepted forms: `kill <pid>` on a PID the caller recorded wh | hook | |
| block-bare-cd Refuse a command with a line that is only a `cd`. Where the shell persists across tool calls (Claude Code) a bare cd re-roots every later command and every hook that judges the working directory, while instruction files and hook paths stay with the launch directory; a cd into a worktree inside the repository, Claude Code's default `.claude/worktrees/<name>/`, also loads that tree's instruction fil | hook | |
| block-repo-copy Block a copy (cp, rsync, tar, git clone) whose source names a `.git` or `target` path component and whose destination is under /tmp, /var/tmp or $TMPDIR. Suggests reading the source in place or building a minimal fixture. | hook | |
| block-unsafe-rm Block rm on shared directory roots, globs directly under them, child paths with . or .. segments, and paths that start with a variable that may expand empty. Keep a private mktemp directory and remove it in the same shell call. Not run on antigravity: its required command-safety companion does not name antigravity, whose payload is toolCall.args. | hook | |
| block-worktree-refresh Refuse a `kendex` command that writes the project scope (`refresh`, `apply`, `add`, `remove`, `update-pi`, `updates --apply`, `pin`, `fork`, `adopt`, `drift-hook`, `source add|remove|enable|disable`, `marketplace subscribe|unsubscribe`) when the working directory is a linked git worktree, the command does not name the global scope, and the project the write lands in is not the worktree's own; and | hook | |
| cloud-git-hooks Runs the commit-guards installer and its read-only check only when CLAUDE_CODE_REMOTE=true and HEAD commits this hook's project SessionStart registration in .claude/settings.json. A global install reaches no repository without that committed registration. Reports an arming gap as session context without refusing startup. Not run on codex: its SessionStart environment supplies no CLAUDE_CODE_REMOTE | hook | |
| command-safety On harnesses that execute hooks, refuse shell tool command text matching COMMAND_SAFETY_DENY_PATTERN from project settings. An absent setting applies the shipped host-safety pattern, which refuses a systemd-run memory cap measured in kilobytes or megabytes; an explicit `^$` turns matching off, while unreadable input or settings still refuse. Matching is textual, including quoted text, and does not | hook | |
| critical-path-deny Answers Claude Code's critical-path check prompt for a Bash call with deny at once, inside a launched orch lane only, so an unattended lane is not held two minutes per prompt and does not trip the three-prompt circuit breaker. The deny message gives the rewrite the permission-modes page gives for each form the check flags: `${NAME:?}` or a literal path for a glob or trailing slash under a variable | hook | |
| dev-stop-check Blocks a subagent's stop while a validation run it started is still going, naming the `dev-validate-run --wait --run-dir <run dir>` command to run next, because a subagent whose turn has ended is not woken when the run ends and its round is left with a verdict on disk and no commit. The worktrees are those the subagent's transcript names as `dev-validate-run ... --worktree <absolute path>` in a co | hook | |
| doc-drift-check Retired: runs no check and exits 0. `kendex remove doc-drift-check --scope project --sweep` removes the declaration and its files in one change; a hand deletion is swept by the next rolling refresh. Not run on gemini: it has no Stop event. Not run on antigravity: its Stop payload carries no `stop_hook_active`. | hook | |
| lane-mail-check Blocks a lane's turn end while its overseer mailbox holds unread lines, so a directive or a ruling reaches the lane without a keystroke, a pane or a question tool. The lane is the work item `LANE_MAIL_ITEM` names, or the one directory under `<repo>/tmp/lane-mail/` whose name lowercases to the current branch; a session with neither is not a lane; a lane whose mailbox holds no unread line passes sil | hook | |
| lane-mail-compact Flags a Copilot lane's or overseer's automatic compaction, so its next turn end holds it until it writes its handoff record, the backstop for a turn that crossed into the compaction before its context reading reached a turn end. A Copilot session is handed off before its compaction by its context reading: the orch `copilot-lane-context` Copilot extension hands the lane-mail-check hook the tokens i | hook | |
| lane-mail-deliver Hands a lane the lines its overseer mailbox holds unread once a tool call finishes, so a directive reaches a working lane at its next tool call rather than at its turn end. The judgement is the lane-mail-check hook's, run from beside this one with the argument `deliver`: it exits 0 with `{"hookSpecificOutput":{"hookEventName":"PostToolUse","additionalContext":...}}` on stdout, the context opening | hook | |
| lane-mail-halt Refuses every tool call in a lane while its overseer mailbox holds an unread directive sent with `lane-mail send --halt`, so a halted lane stops at its next tool call. The judgement is the lane-mail-check hook's, run from beside this one with the argument `halt`: its refusal opens `lane-mail-check: halt=<id>` and carries the directive and the one `lane-mail inbox` command that reads it. That comma | hook | |
| lane-mail-prompt Hands a Copilot lane the lines its overseer mailbox holds unread each time it is handed a prompt, so a lane idle at its prompt reads its mail with the next prompt rather than at its first tool call or turn end. The judgement is the lane-mail-check hook's, run from beside this one with the argument `prompt`: it exits 0 with `{"additionalContext":...}` on stdout, the context opening `lane-mail-check | hook | |
| lane-mail-start Hands a Copilot lane the lines its overseer mailbox holds unread when its session starts, so a lane launched or resumed onto waiting mail reads it before its first tool call rather than at its first tool call or turn end. The judgement is the lane-mail-check hook's, run from beside this one with the argument `start`: it exits 0 with `{"additionalContext":...}` on stdout, the context opening `lane- | hook | |
| pre-commit-check On a git commit, defer to the working directory's armed git hooks — both pre-commit and commit-msg, marked and executable (the tracked commit-guards installer or kendex guard install arms them). Otherwise the commit is refused naming the tracked installer first, then kendex guard install: arming is the local act that says a person wants this repository's committed scripts run on their commits, and | hook | |
| reviewer-read-only For a subagent whose agent_type starts with `reviewer-`, refuses every Edit, MultiEdit and NotebookEdit call; a Write whose path lies inside a git work tree unless it is the review artifact, `<dir>/tmp/review-*.json`; and a Bash command that runs `git commit`, `push`, `checkout`, `restore`, `stash`, `clean`, `reset` or `switch` (options between `git` and the verb allowed). Any other agent, and a p | hook | |
| reviewer-stop-check Blocks a reviewer subagent's stop once when it leaves no readable review artifact or leaves files behind in the worktree it reviewed. The worktree is the one the artifact path in the subagent's transcript names (`<worktree>/tmp/review-<agent>-*.json`, the newest mention), the transcript being the payload's `agent_transcript_path` where the payload carries that key (Claude Code and Codex, whose `tr | hook | |
| session-drift-check On a fresh session start (not resume or compact), runs `kendex check --quiet --report-only` and surfaces kendex drift to the agent — outdated items (`kendex refresh`), items removed upstream (`kendex remove --kind <kind> <name>`, `--global` in a global section), unreachable sources, and packages not yet evaluated against their sources (a background refresh settles them). Outside a lane, prints not | hook | |
| session-end-row Records that a session ended, as one JSON row the fleet's overseer judgement reads instead of the session's pane: `oversee-watch` judges an overseer whose last row is a SessionEnd for any reason but `clear` or `resume` as exited only where its pane's process is a bare shell with nothing under it, and as live over a running process, whatever its screen shows. The row is written by the lane-mail-che | hook | |
| session-start-row Records that a session started, as one JSON row the fleet's overseer judgement reads instead of the session's pane. The row is written by the lane-mail-check hook, run from beside this one with the argument `row`, through the orch skill's `lib/session-rows.sh` from that hook's own install: it carries the time, the event, the harness this hook's install directory names, the payload's `session_id`, | hook | |
| stop-failure-row Records that a turn ended on an API error, as one JSON row the fleet's overseer judgement reads instead of the session's pane: `oversee-watch` judges an overseer whose last row is a StopFailure with error `rate_limit` as walled, Claude Code's own word for a usage limit, or on Pi, which names no error kind, one whose `message` the orch skill's `lane_limit_banner` reads as the account's limit, whate | hook | |
| task-completed-check Before a task is marked complete, runs `cargo clippy --workspace --all-targets -- -D warnings` against the repository's Cargo.toml, or the nearest one above a changed file when the root has none, whenever a Rust file changed in the working tree, the index or as an untracked file, and refuses the completion naming the first error lines, or the output tail when there are none. Rust only. Not run on | hook | |
| worktree-session-claim Claims the linked git worktree a session starts in when the tree carries the worktree skill's `kendex-issue` record; what a lease protects against, and its limits, are the worktree skill's `references/session-guard.md`. Every tree `worktree create` returns carries that record in its private git dir, a tree it adopted through `--reuse` or `--restack` included; the hook reads that one file and runs | hook | |
| code-scrub Audit merged pull requests over a user-specified number of days. | command | |
| STE Simplified Technical English for a reader with moderate technical knowledge | output-style |