复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
106 Cross-Runtime Skills | 7 Claude Code Agents | One Command Install
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md
106 Cross-Runtime Skills | 7 Claude Code Agents | One Command Install
A cross-runtime skill library for Claude Code, Codex, and multi-agent workflows.
Quick Start • Runtime Targets • Pick a Workflow • Skills • Agents • Changelog • Release Status • Contributing • 中文
Rename notice: Spellbook was formerly Claude Arsenal. Claude Code remains a first-class target; the new name reflects the broader roadmap for Claude Code, Codex, and cross-runtime agent skills. See the migration note for details.
Start with one job-shaped workflow. The maintained skills CLI lets you choose
the supported coding agents during installation and installs only these four
skills:
npx skills add majiayu000/spellbook --skill frontend-design --skill app-ui-design --skill ui-design-system --skill figma-to-react
Use npx skills add majiayu000/spellbook --list to inspect the catalog before
installing. See Pick a Workflow for four other focused
starting points.
install.sh remains available when you want explicit Claude Code/Codex target
paths or need to install the repository's Claude Code agents as well as skills.
# Install all skills and supported agents into both maintained runtimes
curl -fsSL https://raw.githubusercontent.com/majiayu000/spellbook/main/install.sh | bash -s -- --target all
# Or clone the repository and select skills explicitly
git clone https://github.com/majiayu000/spellbook.git
cd spellbook
./install.sh --target all --skills typescript-project,python-project,devops-excellence
/ to see your installed skills.~/.agents/skills.Spellbook keeps the skill source in one place and installs it into the runtime you use.
| Target | Installed To | Status |
|---|---|---|
| Claude Code | ~/.claude/skills plus ~/.claude/agents | Skills and agents supported |
| Codex | ~/.agents/skills | Skills supported; agents skipped |
| All | Both Claude Code and Codex paths | Recommended for multi-tool users |
Claude Code remains a first-class target and search entry. The project was formerly known as Claude Arsenal; the new Spellbook name reflects the broader goal: reusable skills that can travel across coding agents.
Older Spellbook versions installed Codex skills under ~/.codex/skills; reinstall with the current installer to use the documented Codex user-level skill path.
Start with a small bundle that matches the job, then add more skills when the workflow sticks.
| Workflow | Install | Good for |
|---|---|---|
| Frontend and UI | npx skills add majiayu000/spellbook --skill frontend-design --skill app-ui-design --skill ui-design-system --skill figma-to-react | Product UI, landing pages, design systems, Figma handoff |
| Code quality | npx skills add majiayu000/spellbook --skill codebase-audit --skill flowguard --skill systematic-debugging --skill review-gate | Audits, guarded delivery, root-cause debugging, pre-landing review |
| Ops and release | npx skills add majiayu000/spellbook --skill release-engineering --skill server-security --skill clash-doctor --skill system-doctor | Release planning, server hardening, and local or network diagnosis |
| Product and docs | npx skills add majiayu000/spellbook --skill product-discovery --skill prd-master --skill technical-spec --skill product-analytics | Discovery, PRDs, technical specs, metrics plans |
| Agent workflows | npx skills add majiayu000/spellbook --skill codex-agent --skill multi-ai-research --skill flowguard --skill vibeguard | Cross-review, multi-AI research, context handoff, anti-hallucination checks |
High-signal individual skills to try first: github-trending, harmonyos-app, app-ui-design, product-discovery, xiaohongshu, codebase-audit, and server-security.
See Showcase for copy-paste prompts and expected outputs. Use the Spellbook Skill Browser for curated first-party skills, or the Claude Skills Registry for broader community discovery. Release history lives in Changelog.
python3 scripts/validate_skills.py --check.references/, templates/, scripts/, and eval files instead of one giant prompt.The generated full skill inventory lives in Skill Registry. Skill layout rules live in Skill Format Policy. Skill authoring quality rules live in Skill Quality Playbook.
# Free-text query (AND semantics across name, description, category, tags)
python3 scripts/validate_skills.py search rust testing
# Filter by tag
python3 scripts/validate_skills.py search --tag agent
# Restrict to a description language
python3 scripts/validate_skills.py search --language zh deploy
# Machine-readable output
python3 scripts/validate_skills.py search --tag react --json
The tag index lives in registry/tags.json for tooling and dashboards. Curated overrides for skills the keyword heuristic cannot infer live in registry/tag_overrides.yml.
Audit non-blocking skill quality signals:
python3 scripts/audit_skill_quality.py
python3 scripts/audit_skill_quality.py skill-creator
Skills for orchestrating, guarding, and maintaining AI agent workflows — the core of Spellbook's cross-runtime mission.
| Skill | Description |
|---|---|
multi-model-orchestrator | Coordinate multi-agent tasks via a centralized handoff document |
flowguard | Guard long, ambiguous, or stateful agent tasks from drift |
skill-lifeguard | Add reliable-skill contracts, checkpoints, smoke hooks, and drift signals |
review-gate | Produce review packs and require human approval before landing agent changes |
skill-audit | Audit, design, categorize, and measure agent skills |
skill-ecosystem-doctor | Govern canonical sources, projections, retirement, quarantine, and cross-runtime verification |
threads | Codex-native subagents and parallel GitHub queue lanes |
codex-fluent | Codex session hygiene, archive strategy, and handoff discipline |
codex-retrospective | Codex self-review of recent history to improve behavior |
brainstorming | Socratic dialogue for design refinement and architecture exploration |
See docs/agent-reliability-trio.md for the Reliable Skill + Context Engineering + Review Gate workflow.
Build production-ready projects with language-specific best practices.
| Skill | Language | Key Features |
|---|---|---|
typescript-project | TypeScript | ESM, Zod, Biome, Clean Architecture |
python-project | Python | uv, Pydantic, Ruff, FastAPI |
rust-project | Rust | Cargo workspace, error handling, async |
golang-web | Go | Chi/Echo, sqlc, structured logging |
zig-project | Zig | Build system, memory management |
architecture-foundation | Cross-language | Runtime, state ownership, adapters, and convergence specs |
elegant-architecture | Cross-language | Clean architecture with strict 200-line file limits |
End-to-end product development from discovery to deployment.
| Skill | Phase | What You Get |
|---|---|---|
product-discovery | Discovery | JTBD, user interviews, market research |
prd-master | Definition | PRD writing, user stories, RICE prioritization |
technical-spec | Design | Design docs, ADR, C4 diagrams |
product-analytics | Growth | Event tracking, A/B testing, AARRR |
devops-excellence | Deployment | CI/CD, Docker, Kubernetes, GitOps |
observability-sre | Operations | Monitoring, logging, tracing, SLO/SLI |
product-manager-toolkit | Definition | RICE, customer interviews, PRD templates, discovery frameworks |
| Skill | Description |
|---|---|
api-design | REST/GraphQL/gRPC patterns, OpenAPI 3.2 |
auth-security | OAuth 2.1, JWT, security best practices |
database-patterns | PostgreSQL, Redis, migrations, optimization |
codebase-audit | Deep adaptive repository audit with severity-ranked findings and repair roadmap |
structured-logging-lite | Centralized logging, field standards, and distributed tracing |
| Skill | Description | Origin |
|---|---|---|
contributor | End-to-end open source contribution workflow from issue discovery to PR submission | Custom |
repo-agent-context-audit | Audit and scaffold repo agent context across AGENTS, skills, and specs | Custom |
skill-creator | Create, improve, and benchmark reusable skills | Custom |
humanizer | Remove obvious AI writing patterns from user-facing text | External guide + custom adaptation |
Disciplined end-to-end delivery: testing, commits, health checks, and contribution flow.
| Skill | Description |
|---|---|
app-user-story-qa | End-to-end app feature inventory, canonical tracker, user-story testing, fixes, and retest loop |
test-driven-development | Enforce RED-GREEN-REFACTOR TDD discipline |
comprehensive-testing | Test pyramid, unit/integration/E2E/property testing, framework best practices |
git-commit-smart | Generate meaningful conventional commit messages from diff |
push-all | Stage, commit, and push all changes after safety checks |
project-health-auditor | Codebase health, tech debt, dependency, and project risk analysis |
contribution-architect | Move from bug fixes to architectural improvements and debt discovery |
Skills for using multiple coding agents and CLI tools together.
| Skill | Description |
|---|---|
codex | Invoke Codex CLI sessions from another agent workflow |
codex-agent | Optional second-opinion review, cross-verification, and alternatives through Codex CLI |
sol-luna-router | Keep GPT-5.6 Sol as commander/reviewer while GPT-5.6 Luna performs bounded implementation |
ask-opencli | Ask Grok or Gemini through opencli and an existing browser session |
multi-ai-research | Parallel research across multiple AI tools and internal agents |
| Skill | Description |
|---|---|
app-ui-design | iOS/Android UI design, Material Design 3, HIG |
product-ux-expert | UX evaluation, heuristics, accessibility |
frontend-design | Web frontend design patterns |
ui-designer | Extract design systems from UI screenshots and references |
ui-design-system | Design system toolkit and design-dev handoff support |
web-artifacts-builder | Claude.ai HTML artifacts |
react-best-practices | React and Next.js performance patterns distilled from Vercel guidance |
react-hooks-best-practices | React hooks, effects, refs, and component design patterns |
slides | Speech-friendly slide deck and background slide generation |
ui-ux-pro-max | Compact UI/UX tables for product patterns, landing pages, charts, and 9 stacks |
figma-to-code | Figma designs to production React/Next.js with TypeScript and Tailwind |
css-debug | Diagnose CSS/layout issues, Tailwind conflicts, z-index stacking |
playwright-automation | Browser automation and testing with Playwright |
| Skill | Description |
|---|---|
web-asset-generator | Favicons, app icons, OG images |
github-trending | GitHub trending analysis |
vibeguard | Task contracts, finding scoring, and lightweight anti-hallucination reviews |
clash-doctor | Clash proxy & network diagnostics |
clash-routes | Inspect active proxy routes for specific processes via Mihomo API |
optimize-network | Safe local network speed, latency, DNS, Wi-Fi, and bufferbloat diagnostics with VPN/proxy guardrails |
disk-cleaner | Scan and reclaim disk space with interactive cleanup guidance |
system-doctor | Diagnose CPU, memory, and process-level system slowdowns |
codex-log-guard | Diagnose and mitigate excessive Codex local SQLite diagnostic log writes |
server-security | Audit and harden Linux server SSH, firewall, and exposed services |
cliproxy-newapi-stack | Add a loopback-first NewAPI metering layer to an independently verified CLIProxyAPI upstream |
Deploy models and diagnose local and remote environments.
| Skill | Description |
|---|---|
gemma4-local-deploy | Deploy Gemma 4 12B locally on Mac/Apple Silicon via llama.cpp or Ollama |
gpu-use | Inspect remote server GPU usage (per-card VRAM, processes, containers) |
rustdesk-doctor | Diagnose RustDesk connection issues |
vscode-doctor | Diagnose slow or freezing VS Code-compatible editors |
| Skill | Description |
|---|---|
xiaohongshu | Xiaohongshu content creation & publishing |
trip-planner | Travel itinerary planning |
weekly | Weekly report from Git, Claude Code, and Codex sessions |
xiaohongshu-netfeel-guardian | Remove translation-tone from Claude's Chinese content for native readability |
| Skill | Description |
|---|---|
harmonyos-app | HarmonyOS with ArkTS, ArkUI, Stage Model |
| Skill | Description |
|---|---|
rust-best-practices | Microsoft Rust guidelines, error handling |
Specialized agents for complex tasks.
| Agent | Expertise | Use Case |
|---|---|---|
tech-lead-orchestrator | Coordination | Multi-step tasks, delegation |
code-archaeologist | Exploration | Legacy codebase documentation |
backend-typescript-architect | Architecture | Bun/Node.js, API design |
senior-code-reviewer | Review | Security, performance, architecture |
kubernetes-specialist | Infrastructure | K8s, Helm, GitOps |
security-auditor | Security | OWASP Top 10, SAST |
opensource-contributor | Contribution | Open source workflow |
Spellbook is also a Claude Code plugin marketplace. Install the repo as a marketplace, then install plugins from it:
/plugin marketplace add majiayu000/spellbook
/plugin install idea-coach
/plugin install rust-dev
| Plugin | Description |
|---|---|
idea-coach | Opinionated product coach (idea -> PRD -> clickable HTML prototype) + multi-role idea group chat; plugin commands are /idea-coach:idea and /idea-coach:idea-team |
rust-dev | Rust best practices, code review, performance, and async patterns |
Plugin skills are packaged copies of catalog skills; the catalog (installed by
install.sh) remains the cross-runtime source of truth.
Every skill in Spellbook follows these principles:
FORBIDDEN / REQUIRED markers| Document | Description |
|---|---|
| Changelog | Release history and current release status |
| Installation Guide | Detailed setup instructions |
| Runtime Targets | Claude Code and Codex installation targets |
| Showcase | Copy-paste workflow demos |
| Spellbook Operating Contract | Agent behavior rules for autonomy, escalation, pushback, feedback loops, and done-when checks |
| Skill Format Policy | Directory vs file skill layout rules |
| Skill Quality Playbook | Trigger descriptions, gotchas, progressive disclosure, and verification |
| Skill Testing Guide | How to validate skills work |
| Creating Plugins | Build your own skills |
| Product Lifecycle (EN) | Full lifecycle coverage |
| Product Lifecycle (中文) | 产品生命周期覆盖 |
Spellbook is in pre-1.0 release-readiness mode. No numbered GitHub release tag
has been cut yet; the current install path uses the repository main branch.
See Changelog for release history.
Current limitations:
Support paths:
Built on the shoulders of giants:
Contributions welcome! Please read our Contributing Guide first.
This project is one layer of an open-source stack for running coding agents (Claude Code, Codex) as serious infrastructure. Every piece works standalone; together they close the loop:
spellbook sits in the Extend layer — the authoring side of the skill story: write once, run on Claude Code and Codex. Discovery and distribution live in claude-skill-registry.
| Layer | Project | What it does |
|---|---|---|
| Extend | claude-skill-registry | Discover and search community Claude Code skills |
| Extend | spellbook ◀ you are here | Cross-runtime skills for Claude Code, Codex, and multi-agent workflows |
| Trust | argus | Static install-time scanner for supply-chain attacks (npm / PyPI / crates.io) |
| Trust | vibeguard | Rules, hooks, and guards against hallucinated or unverified agent changes |
| Remember | remem | Local-first persistent memory for Claude Code and Codex sessions |
| Orchestrate | harness | Rust agent orchestration platform — rules, skills, GC, observability |
| Route | litellm-rs | High-performance Rust AI gateway — 100+ LLM APIs via OpenAI format |
| Keep | keepline | Session command center — monitor, recover, never lose agent work |
MIT License - Use freely in your projects.
If this helps you, consider giving it a ⭐
Made for builders using Claude Code, Codex, and multi-agent workflows
name: codex-agent
description: Use when you want a second-opinion review via Codex CLI, cross-verification after another agent implements changes, debugging help, or alternative implementation proposals. Requires Codex CLI to be installed and authenticated.
compatibility: {runtimes: [claude_code]}
allowed-tools:
- Bash(REPORT=*)
- Bash(DIFF_REPORT=*)
- Bash(codex:*)
- Bash(mktemp:*)
- Bash(cat:*)
- Bash(git diff:*)
- Read
- Edit
- Grep
- GlobThis skill enables Claude Code to collaborate with OpenAI's Codex CLI agent for second-opinion review, cross-verification, debugging analysis, and alternative implementation proposals.
Default posture: Codex reviews in read-only; the primary agent applies changes only when the user asked for fixes or approved them after reading the review.
Use this workflow when the user asks for Codex review, wants a second opinion, or needs cross-verification from a separate coding agent.
REPORT="$(mktemp -t codex-review.XXXXXX.md)"
codex exec -C <project_path> -s read-only -o "$REPORT" \
"Review the code in <file_or_directory>. Check for:
- Security vulnerabilities
- Performance issues
- Code quality and best practices
- Potential bugs and edge cases
- Naming and readability
Provide specific, actionable feedback with file paths and line numbers."
cat "$REPORT"
Keep the write and read in the same Bash call, or pass a concrete report path between calls; shell variables do not persist across tool calls.
When the user asked to apply fixes, handle each issue identified by Codex:
If the user only asked for a review or second opinion, report findings without editing files.
codex exec -C <project_path> -s read-only \
"Verify the fixes applied to <files>. Confirm issues are resolved."
# Step 1: Get Codex review
REPORT="$(mktemp -t codex-review.XXXXXX.md)"
codex exec -C /project -s read-only -o "$REPORT" \
"Review src/auth/login.ts for security vulnerabilities and code quality issues. Provide specific line numbers and fixes."
# Step 2: Read the feedback
cat "$REPORT"
Then the primary agent reads the feedback, applies fixes with Edit tool, and optionally re-verifies.
# Get diff of recent changes
DIFF_REPORT="$(mktemp -t recent-changes.XXXXXX.diff)"
git diff HEAD~1 > "$DIFF_REPORT"
# Step 1: Have Codex review the diff
REPORT="$(mktemp -t codex-review.XXXXXX.md)"
codex exec -C /project -s read-only -o "$REPORT" \
"Review the changes saved at $DIFF_REPORT. Check for bugs, security issues, and improvements needed."
# Step 2: Read and apply fixes
cat "$REPORT"
# Step 1: Comprehensive review
REPORT="$(mktemp -t codex-review.XXXXXX.md)"
codex exec -C /project -s read-only -o "$REPORT" \
"Perform a comprehensive code review of src/. Focus on:
1. Security vulnerabilities (OWASP Top 10)
2. Error handling patterns
3. Performance bottlenecks
4. Code duplication
Prioritize issues by severity (critical/high/medium/low)."
# Step 2: Read prioritized feedback
cat "$REPORT"
When asking Codex for review, include:
Review <target_files_or_directory>.
Context:
- Project type: <TypeScript/Python/etc>
- Framework: <Express/React/etc>
- Focus areas: <security/performance/quality>
Check for:
1. Security vulnerabilities
2. Performance issues
3. Error handling
4. Code quality
5. Edge cases
Output format:
For each issue:
- File: <path>
- Line: <number>
- Severity: critical/high/medium/low
- Issue: <description>
- Fix: <specific code change>
After receiving Codex feedback, apply fixes systematically:
Codex CLI must be installed and authenticated:
# Install via npm
npm install -g @openai/codex
# Or via Homebrew (macOS)
brew install --cask codex
# Authenticate
codex login
codex exec [options] "<task_description>"
| Option | Description |
|---|---|
"<task>" | Task description (positional, must be quoted) |
-C <dir> | Working directory (use absolute path) |
-s read-only | Read-only sandbox (use for reviews) |
-o <path> | Save output to file |
--json | Output as JSON Lines |
When communicating with Codex, PRIORITIZE ACCURACY AND PRECISION:
codex exec -C /project -s read-only \
"Verify the implementation in src/feature/. Check correctness and edge cases."
REPORT="$(mktemp -t codex-alternative.XXXXXX.md)"
codex exec -C /project -s read-only -o "$REPORT" \
"Propose an alternative implementation for the caching in src/cache/manager.ts"
cat "$REPORT"
codex exec -C /project -s read-only \
"Debug: tests in tests/auth.test.ts failing with timeout. Analyze root cause."
For multi-turn reviews:
# Initial review
codex exec -C /project -s read-only "Review src/api/ for security issues"
# Note session ID from output
# Follow-up after fixes
codex exec resume <session_id> "I've applied the fixes. Please re-verify."
scripts/check-codex.sh checks whether the Codex CLI is installed and authenticated.scripts/codex-wrapper.sh is optional. Use it only when you need a small CLI wrapper; it executes Codex through shell arrays and must not use eval./tmp/codex-review.md; use mktemp or a project-specific private report path so concurrent projects cannot overwrite or read stale feedback.read-only unless the user explicitly asked Codex itself to edit.danger-full-access, --dangerously-bypass-approvals-and-sandbox, --dangerously-bypass-hook-trust, and --skip-git-repo-check as high-impact flags. Ask before using them.codex logout
codex login
codex --version
which codex
评论 (0)
暂无评论,成为第一个评论者吧!