Marketplaces / vanillagreencom/kendex / workflow
workflow
Orchestration, code review and commit guards in one install, with deep-research and bot-instructions
49 packages
| Package | Kind |
|---|---|
| reviewer-arch Architecture reviewer for design reviews, module boundary validation, spec/proposal review, and technical debt assessment. | agent |
| reviewer-correctness Broad correctness and regression reviewer for behavior breakage, boundary/edge-case predicates, API/CLI/devex regressions, feature-gate leaks, migrations, state semantics, and cross-module side effects. | agent |
| reviewer-doc Documentation accuracy reviewer. Verifies changed doc claims against implementation, re-derives transcribed values, checks citations resolve, audits drift. | agent |
| reviewer-error Silent failure and error handling reviewer. Detects fail-open paths, swallowed errors, wrong-cause diagnostics, and inadequate error propagation. | agent |
| reviewer-perf Performance validation specialist. Latency validation, benchmark execution, percentile analysis, hot-path cost review, regression detection. | agent |
| reviewer-quality Code quality reviewer for maintainability, simplification, abstraction value, type boundaries, helper reuse, decomposition, and god objects. | agent |
| reviewer-safety Memory, thread, and process safety auditor. Unsafe code, data races, lock-free correctness, and file/process races (TOCTOU, PID reuse, shared mutable state). | agent |
| reviewer-security Application security reviewer. Auth logic, input handling, trust/ownership gating, path containment, and secret exposure. | agent |
| reviewer-test Test coverage and quality reviewer. Verifies coverage, detects vacuous tests and missing must-fail controls, audits assertion tightness and test wiring. | agent |
| orch PRIMARY AGENT ONLY. Load to orchestrate a Linear or GitHub work item from preparation through merge. | skill |
| dev Load when implementing an issue or applying review fixes as a dev agent. | skill |
| github Load to work a GitHub pull request: threads, comments, reviews, CI logs, merges. | skill |
| worktree Load to create, list, remove, push, or repair a git worktree. | skill |
| project-management Load to plan a cycle, audit issues, build a roadmap, or decompose research into issues. | skill |
| decider Load to create, search, or supersede an architecture decision record. | skill |
| reviewer Load when reviewing a diff, classifying findings, or returning a verdict. | skill |
| linear Load for any Linear read or write: issues, projects, cycles, milestones, initiatives, labels. | skill |
| review-gate Load to watch pull requests, report the organization standard, or adopt consumer refresh. | skill |
| harness-ci Load to wire, tune, or debug a repo's changed-file CI skip. | skill |
| bot-instructions Load to render, check, or adopt a repo's GitHub review-bot instruction files from the shared doctrine and its effective manifest. | skill |
| second-opinion Load for a cross-model review, challenge, audit, or quick consult. | skill |
| code-quality Load for any coding or development task in any repository: writing, changing, fixing, refactoring, or testing code or scripts in any language. | skill |
| docs-writing Load to write, rewrite, or review repository markdown or documentation HTML: README, DEVELOPMENT, architecture docs, reference docs, SKILL.md and AGENTS.md. | skill |
| deep-research Load for research tasks, architectural investigations, and vendor, library, or technology comparisons. | skill |
| commit-guards Load to add, tune, or debug a commit guard lane, its git hooks, or COMMIT_GUARDS_* settings. | skill |
| doc-limits Load to add, tune, or debug document byte ceilings and DOC_LIMITS_* settings. | skill |
| preflight Load to run, tune, or debug preflight. | skill |
| block-bare-cd Refuse a command with a line that is only a `cd`. Where the shell persists across tool calls (Claude Code) a bare cd re-roots every later command and every hook that judges the working directory, while instruction files and hook paths stay with the launch directory; a cd into a worktree inside the repository, Claude Code's default `.claude/worktrees/<name>/`, also loads that tree's instruction fil | hook |
| block-repo-copy Block a copy (cp, rsync, tar, git clone) whose source names a `.git` or `target` path component and whose destination is under /tmp, /var/tmp or $TMPDIR. Suggests reading the source in place or building a minimal fixture. | hook |
| block-unsafe-rm Block rm on shared directory roots, globs directly under them, child paths with . or .. segments, and paths that start with a variable that may expand empty. Keep a private mktemp directory and remove it in the same shell call. Not run on antigravity: its required command-safety companion does not name antigravity, whose payload is toolCall.args. | hook |
| command-safety On harnesses that execute hooks, refuse shell tool command text matching COMMAND_SAFETY_DENY_PATTERN from project settings. An absent setting applies the shipped host-safety pattern, which refuses a systemd-run memory cap measured in kilobytes or megabytes; an explicit `^$` turns matching off, while unreadable input or settings still refuse. Matching is textual, including quoted text, and does not | hook |
| block-argv-kill Refuse a command that kills processes by name or by argv pattern (`pkill`, `killall`), whatever flags follow. On a machine where several agents share one checkout and its worktrees, a pattern that matches a tool's name matches every lane running that tool, the caller's own shell included when its command line holds the pattern. Names the accepted forms: `kill <pid>` on a PID the caller recorded wh | hook |
| block-worktree-refresh Refuse a `kendex` command that writes the project scope (`refresh`, `apply`, `add`, `remove`, `update-pi`, `updates --apply`, `pin`, `fork`, `adopt`, `drift-hook`, `source add|remove|enable|disable`, `marketplace subscribe|unsubscribe`) when the working directory is a linked git worktree, the command does not name the global scope, and the project the write lands in is not the worktree's own; and | hook |
| pre-commit-check On a git commit, defer to the working directory's armed git hooks — both pre-commit and commit-msg, marked and executable (the tracked commit-guards installer or kendex guard install arms them). Otherwise the commit is refused naming the tracked installer first, then kendex guard install: arming is the local act that says a person wants this repository's committed scripts run on their commits, and | hook |
| session-drift-check On a fresh session start (not resume or compact), runs `kendex check --quiet --report-only` and surfaces kendex drift to the agent — outdated items (`kendex refresh`), items removed upstream (`kendex remove --kind <kind> <name>`, `--global` in a global section), unreachable sources, and packages not yet evaluated against their sources (a background refresh settles them). Outside a lane, prints not | hook |
| task-completed-check Before a task is marked complete, runs `cargo clippy --workspace --all-targets -- -D warnings` against the repository's Cargo.toml, or the nearest one above a changed file when the root has none, whenever a Rust file changed in the working tree, the index or as an untracked file, and refuses the completion naming the first error lines, or the output tail when there are none. Rust only. Not run on | hook |
| reviewer-read-only For a subagent whose agent_type starts with `reviewer-`, refuses every Edit, MultiEdit and NotebookEdit call; a Write whose path lies inside a git work tree unless it is the review artifact, `<dir>/tmp/review-*.json`; and a Bash command that runs `git commit`, `push`, `checkout`, `restore`, `stash`, `clean`, `reset` or `switch` (options between `git` and the verb allowed). Any other agent, and a p | hook |
| reviewer-stop-check Blocks a reviewer subagent's stop once when it leaves no readable review artifact or leaves files behind in the worktree it reviewed. The worktree is the one the artifact path in the subagent's transcript names (`<worktree>/tmp/review-<agent>-*.json`, the newest mention), the transcript being the payload's `agent_transcript_path` where the payload carries that key (Claude Code and Codex, whose `tr | hook |
| dev-stop-check Blocks a subagent's stop while a validation run it started is still going, naming the `dev-validate-run --wait --run-dir <run dir>` command to run next, because a subagent whose turn has ended is not woken when the run ends and its round is left with a verdict on disk and no commit. The worktrees are those the subagent's transcript names as `dev-validate-run ... --worktree <absolute path>` in a co | hook |
| lane-mail-check Blocks a lane's turn end while its overseer mailbox holds unread lines, so a directive or a ruling reaches the lane without a keystroke, a pane or a question tool. The lane is the work item `LANE_MAIL_ITEM` names, or the one directory under `<repo>/tmp/lane-mail/` whose name lowercases to the current branch; a session with neither is not a lane; a lane whose mailbox holds no unread line passes sil | hook |
| lane-mail-deliver Hands a lane the lines its overseer mailbox holds unread once a tool call finishes, so a directive reaches a working lane at its next tool call rather than at its turn end. The judgement is the lane-mail-check hook's, run from beside this one with the argument `deliver`: it exits 0 with `{"hookSpecificOutput":{"hookEventName":"PostToolUse","additionalContext":...}}` on stdout, the context opening | hook |
| lane-mail-halt Refuses every tool call in a lane while its overseer mailbox holds an unread directive sent with `lane-mail send --halt`, so a halted lane stops at its next tool call. The judgement is the lane-mail-check hook's, run from beside this one with the argument `halt`: its refusal opens `lane-mail-check: halt=<id>` and carries the directive and the one `lane-mail inbox` command that reads it. That comma | hook |
| session-start-row Records that a session started, as one JSON row the fleet's overseer judgement reads instead of the session's pane. The row is written by the lane-mail-check hook, run from beside this one with the argument `row`, through the orch skill's `lib/session-rows.sh` from that hook's own install: it carries the time, the event, the harness this hook's install directory names, the payload's `session_id`, | hook |
| session-end-row Records that a session ended, as one JSON row the fleet's overseer judgement reads instead of the session's pane: `oversee-watch` judges an overseer whose last row is a SessionEnd for any reason but `clear` or `resume` as exited only where its pane's process is a bare shell with nothing under it, and as live over a running process, whatever its screen shows. The row is written by the lane-mail-che | hook |
| stop-failure-row Records that a turn ended on an API error, as one JSON row the fleet's overseer judgement reads instead of the session's pane: `oversee-watch` judges an overseer whose last row is a StopFailure with error `rate_limit` as walled, Claude Code's own word for a usage limit, or on Pi, which names no error kind, one whose `message` the orch skill's `lane_limit_banner` reads as the account's limit, whate | hook |
| lane-mail-start Hands a Copilot lane the lines its overseer mailbox holds unread when its session starts, so a lane launched or resumed onto waiting mail reads it before its first tool call rather than at its first tool call or turn end. The judgement is the lane-mail-check hook's, run from beside this one with the argument `start`: it exits 0 with `{"additionalContext":...}` on stdout, the context opening `lane- | hook |
| lane-mail-prompt Hands a Copilot lane the lines its overseer mailbox holds unread each time it is handed a prompt, so a lane idle at its prompt reads its mail with the next prompt rather than at its first tool call or turn end. The judgement is the lane-mail-check hook's, run from beside this one with the argument `prompt`: it exits 0 with `{"additionalContext":...}` on stdout, the context opening `lane-mail-check | hook |
| lane-mail-compact Flags a Copilot lane's or overseer's automatic compaction, so its next turn end holds it until it writes its handoff record, the backstop for a turn that crossed into the compaction before its context reading reached a turn end. A Copilot session is handed off before its compaction by its context reading: the orch `copilot-lane-context` Copilot extension hands the lane-mail-check hook the tokens i | hook |
| critical-path-deny Answers Claude Code's critical-path check prompt for a Bash call with deny at once, inside a launched orch lane only, so an unattended lane is not held two minutes per prompt and does not trip the three-prompt circuit breaker. The deny message gives the rewrite the permission-modes page gives for each form the check flags: `${NAME:?}` or a literal path for a glob or trailing slash under a variable | hook |