复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
Essays and writing behind this toolkit live at vexjoy.com.
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md
Essays and writing behind this toolkit live at vexjoy.com.
VexJoy Agent connects plain-English requests to specialist agents, skills, and workflows. /do selects the knowledge and tools needed for your task. Hooks enforce specific checks, and scripts handle repeatable work.
The aim is to give capable models useful domain knowledge without making you learn the toolkit's catalog.
43 domain agents, 59 workflow skills, 78 hooks, 153 scripts. Agents carry knowledge, skills enforce methodology, hooks block incomplete work, scripts handle determinism.
Works across Claude Code (/do), Codex ($do), Factory (/do), Reasonix (/do).
$ claude
> /do debug this Go test
Routing: go-engineer + systematic-debugging
Phase 1/4: Reproduce: running test, capturing failure...
Phase 2/4: Hypothesize: 3 candidates from stack trace...
Phase 3/4: Verify: isolated root cause in connection pool timeout
Phase 4/4: Fix: patch applied, test passing, PR opened
✓ Delivered: PR #847, fix connection pool timeout in health check
The router pairs a Go agent with a debugging skill, then follows the task through verification and delivery.
ROUTE PLAN EXECUTE VERIFY DELIVER RECORD
┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐
│ /do │───▶│ Task │───▶│Agent │───▶│Tests │───▶│ PR │───▶│Route │
│Router│ │ Plan │ │+Skill│ │Gates │ │Branch│ │Result│
└──────┘ └──────┘ └──────┘ └──────┘ └──────┘ └──────┘
/d routes requests through TypeSafe's Jev classifier. One API call picks the agent, skill, and pipeline — no manifest read into context. Requires Jev; use /do if TypeSafe is not configured.
Setup: install the typesafe MCP plugin and set TYPESAFE_API_KEY in your environment.
> /d fix the flaky test in the payments module
ROUTING (/d): testing-automation-engineer + testing-preferred-patterns
Source: jev (confidence: medium)
Invoking...
Checks require evidence rather than confidence.
| Agent Says | What Happens |
|---|---|
| "Code looks correct, skip tests" | Exit gate requires test output. Blocked. |
| "Trivial change, no verification" | Hook blocks completion without evidence. |
| "Similar to before" | Skill demands case-specific proof. |
| "User is in a hurry" | Protocol overrides time pressure. |
| "I'm confident" | Gate demands exit code, not assertion. |
Hooks run at configured events. Skills state what to verify; blocking78 hooks enforce the checks they cover. Coverage depends on the runtime and tool path.
The content engine researches, drafts in a calibrated voice, checks 397 writing patterns, and adapts finished pieces for each platform. /html produces a self-contained report, slide deck, prototype, chart, or diagram. It needs no coding or setup beyond installation.
Toolkit changes use direct review and relevant checks. Model comparisons can settle specific uncertainties; they are not required for every edit. PHILOSOPHY.md explains the validation policy. what-didnt-work.md records failed experiments, routing reversals, unvalidated A/B citations, disabled lint rules, and program refutations.
The automated nightly evolution loop (/evolve, writes to evolution-reports/) ran regularly through mid-May 2026. It is currently dormant; recent evidence has come from manual PRs instead.
git clone https://github.com/notque/vexjoy-agent.git ~/vexjoy-agent
cd ~/vexjoy-agent
./install.sh
Installs into ~/.claude/ and mirrors into ~/.codex/, ~/.factory/, and ~/.reasonix/ when the runtime command is on PATH or its home directory exists. Choose symlinks for live updates through git pull, or copies for a stable snapshot.
Want only part of the toolkit? Run ./install.sh --configure to pick which skills, agents, and78 hooks install, or copy .local.example/profile.yaml to .local/profile.yaml and edit. No profile file = full install, unchanged behavior. Credit: @thomasvan. Details: .local.example/README.md.
| CLI | Entry Point |
|---|---|
| Claude Code | /do |
| Codex | $do |
| Factory | /do |
| Reasonix | /do |
Jev Auto-Compact plugin (optional, requires TYPESAFE_API_KEY):
claude plugin marketplace add ./plugins/jev-auto-compact
claude plugin install jev-auto-compact@jev-auto-compact -y
Replaces LLM-generated compaction summaries with Jev-judged verbatim pruning. Once context reaches 60%, Jev evaluates each old tool call (keep, truncate result, or drop) and returns the pruned transcript with zero rewriting, in about a second instead of one to three minutes. The threshold matters: every compaction is a cold KV-cache rewrite of the prefix, so compacting every turn multiplies cost. Evidence lives in learning.db (python153 scripts/jev-compact-evidence.py).
Proof it works: python153 scripts/jev-compact-evidence.py prints every compaction from two sources side by side — the plugin's claim and the engine's own compact_boundary record (tokens before/after, duration). A Jev compaction shows as a sub-second engine record next to a matching plugin claim; a built-in LLM compaction shows as a 30–150s record. Rows live in ~/.claude/learning/learning.db (compaction_events, session_usage).
Full setup: docs/start-here.md
Mirrors agents, skills, and supported78 hooks into ~/.codex/. The original six-hook allowlist was correct for Codex v0.114, when tool hooks only intercepted Bash. Current support requires Codex v0.144.1+ and classifies the 62 Claude hook registrations as 26 native, 27 adapter-backed, and 9 unsupported (53 supported). These are registration counts, not unique hook files. The installer also preserves explicit per-subagent model routing for GPT-5.6 Sol by setting the MultiAgent V2 compatibility keys documented in openai/codex#31814.
Codex now exposes apply_patch to tool78 hooks. VexJoy's adapter converts each patch operation into the Write/Edit payload expected by existing guards, but it cannot intercept writes performed through unified_exec, unmatched MCP tools, WebSearch, or other unsupported tool paths. PreCompact and Stop adapters also receive less telemetry than Claude Code: Codex does not provide Claude's conversation_history or session_data. This is expanded compatibility, not full Claude parity.
After install or any hook-definition change, run /hooks in Codex and review the new definitions before trusting them. Codex hash-trusts hook commands and skips changed, unreviewed definitions.
Gemini CLI support removed (deprecated upstream, transitioned to Antigravity CLI); Antigravity support pending CLI maturity. Per Google's transition announcement, Gemini CLI stops serving requests on 2026-06-18 for Google AI Pro / Ultra and free Gemini Code Assist for individuals. Gemini API integrations (image-gen backends, sprite pipeline, GEMINI_API_KEY) are unaffected and stay in the toolkit.
If a prior install mirrored into ~/.gemini/, remove the stale mirrors with:
rm -rf ~/.gemini/skills ~/.gemini/agents ~/.gemini/hooks ~/.gemini/scripts ~/.gemini/antigravity/plugins/vexjoy-agent
Mirrors agents (as "droids"), skills, and all78 hooks into ~/.factory/. Hook config merges into ~/.factory/settings.json with paths rewritten.
Mirrors skills, 153 scripts, and the allowlisted 78 hooks (scripts/reasonix-hooks-allowlist.txt) into ~/.reasonix/ (no agent or custom-command surface, so neither is installed; the /do router rides in as a skill). Reasonix fires only 4 events (PreToolUse, PostToolUse, UserPromptSubmit, Stop), so only hooks for those events are allowlisted. Hook config is written to the hooks key of ~/.reasonix/settings.json in Reasonix's native flat shape (one entry per hook, match regex over the tool name); the generator builds absolute python3 commands, so no path rewrite is applied. MCP/model/permissions in ~/.reasonix/config.json are user-owned and left untouched.
The toolkit supplies its own routing, domain knowledge, methodology, and enforcement. The default system prompt duplicates most of that.
claude --system-prompt "."
Strips built-in tool-use instructions. The toolkit's agents, skills,78 hooks, and CLAUDE.md provide equivalent coverage.
| Layer | Count | Does |
|---|---|---|
| Agents | 43 | Domain knowledge: idiom tables, failure mode catalogs, error-to-fix mappings |
| Skills | 59 | Phased methodology with gates. Can't skip steps. Each phase has exit criteria requiring evidence. |
| Hooks | 78 | Fire on lifecycle events. Block incomplete work. Zero LLM cost. |
| Scripts | 153 | Determinism: test runners, linters, validators. No LLM judgment. |
Full skill catalog: docs/skills.md.
┌─────────────────────────────────────────────────┐
│ SKILL.md │
│ ┌─ Frontmatter ─────────────────────────────┐ │
│ │ triggers, pairs_with, success-criteria │ │
│ └────────────────────────────────────────────┘ │
│ Reference Loading Table (conditional imports) │
│ Phased Instructions (numbered, with gates) │
│ Verification (evidence requirements) │
└─────────────────────────────────────────────────┘
A game built entirely by Claude Code using these agents, skills, and pipelines:
I just want to use it Install, learn /do, done.
I do knowledge work Writing, research, data analysis, moderation, HTML artifacts. No code.
I'm a developer Architecture, extension points, adding agents and skills.
I'm an AI power user Routing tables, pipelines,78 hooks, telemetry DB.
I'm an AI agent Machine-dense inventory. Tables, paths, schemas.
I'm on LinkedIn 🚀 Thought leadership. Agree? 👇
Full design philosophy: PHILOSOPHY.md
One report-only script surfaces upkeep work; it prints a digest and never edits, deletes, or blocks.
python153 scripts/stale-skill-scan.py --top 20 ranks stale skills and agents as pruning candidates. Run it quarterly; see docs/deprecation-template.md.Scheduled work follows the same boundary as everything else: judgment uses agents; repeatable plumbing uses153 scripts.
| Need | Use |
|---|---|
| Run a deterministic command on a schedule | scripts/agent-scheduler.py with runner: "command" |
| Run an agent judgment on a schedule, webhook, or file change | scripts/agent-scheduler.py with the default runner: "claude" |
| Install or remove a user crontab entry safely | scripts/crontab-manager.py |
| Audit shell cron reliability | cron-automation |
| Keep one interactive objective moving until criteria verify | objective-loop |
See CONTRIBUTING.md.
MIT. See LICENSE.
name: security
description: "Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks."
user-invocable: true
allowed-tools:
- Read
- Write
- Bash
- Grep
- Glob
- Edit
- Task
- Agent
agent: reviewer-system
routing:
force_route: true
not_for: "general code review (use review), non-security quality checks (use code-quality) — only for security-specific work: vulnerability scanning, threat modeling, supply-chain audits, auth reviews"
triggers:
- "security review"
- "review my changes for security"
- "review my changes"
- "review for security"
- "security scan"
- "review for vulnerabilities"
- "scan for vulnerabilities"
- "check for security issues"
- "security issues"
- "audit for vulnerabilities"
- "audit auth"
- "audit vulnerabilities"
- "threat model"
- "security audit"
- "supply chain scan"
- "deny list"
- "security posture"
- "injection scan"
- "surface scan"
- "audit hooks"
- "audit skills"
category: security
pairs_with:
- review
- reviewer-systemTwo modes: diff review (scan current git changes for vulnerabilities) and threat model (audit a system's full attack surface). Load the reference for the mode the request matches.
| Signal | Load | Why |
|---|---|---|
| Review git changes, scan a diff, check for vulnerabilities | references/coverage.md | 40 vulnerability classes for LLM-depth review of changed code |
| Threat model, attack surface, supply-chain audit, deny list, security posture | references/threat-model.md | 5-phase threat model workflow with deterministic scripts and artifact gates |
When the request is about reviewing changes (not a full threat model), run the diff review directly. This is the common case.
Run a two-layer security review over the current git changes: a deterministic regex scan for known vulnerability classes, then an LLM-depth Security review of the diff. Report a single BLOCK / FIX / APPROVE verdict.
The LLM-depth review runs inside the current Claude session — the same
subscription that loaded this skill. There is no separate model call, no
ANTHROPIC_API_KEY, no Agent SDK, and no network request. The "reviewer" is the
session agent executing the steps below, exactly like every other skill here.
Detection reaches parity with Anthropic's security-guidance plugin: the scanner
ports its 25 deterministic patterns, and the LLM pass applies its full review
taxonomy (loaded on demand from references/coverage.md).
| Signal | Load | Why |
|---|---|---|
| Running Phase 3 (LLM-depth review); classifying a finding; needing the vuln taxonomy, severity rubric, FP exclusions, or per-language guidance | references/coverage.md | 40 vulnerability classes + 4-tier severity + false-positive exclusions + per-language guidance + the 12 high-miss reviewer classes + the finding output schema. |
Goal: Determine the changed files to review before scanning.
Step 1: List changed files — scope to the working-tree and staged changes so the review covers exactly what the user is about to commit, not the whole repo.
# Tracked changes (working tree + index) plus staged adds:
git diff --name-only HEAD
git diff --cached --name-only --diff-filter=ACM
Step 2: Read repository CLAUDE.md to load project conventions the reviewer must respect (e.g. secrets-handling rules, allowed patterns).
Gate: Changed files listed. When the list is empty, report "no changes to review" and stop — there is nothing to scan.
Goal: Run the regex engine first so judgment time is spent on real signal, not on patterns a script catches deterministically.
Step 1: Run the scanner over the changed files. It is the single source of detection rules (secrets, SQL injection, shell injection, dangerous eval, unsafe deserialization). Exit 1 means at least one HIGH/CRITICAL finding.
# Staged-files convenience (matches the commit-time hook):
python3 scripts/security-review-scan.py --staged --format json
# Or an explicit list from Phase 1:
python3 scripts/security-review-scan.py --files <changed-files> --format json
Step 2: Record the findings by severity. CRITICAL and HIGH are blocking-class;
MEDIUM is advisory. Keep the file:line and rule for each.
Gate: Scanner ran and JSON parsed. Proceed with the findings in hand.
Goal: Catch what regex cannot — authorization gaps, injection through data
flow, missing input validation, secrets in non-obvious forms. This is the
session agent's review of the diff; compose the existing parallel-code-review
Security reviewer over the changed files.
Step 1: Load references/coverage.md — the full review taxonomy (40
vulnerability classes, the 4-tier severity rubric, the false-positive exclusion
list, per-language guidance, and the 12 high-miss reviewer classes). Review to
this taxonomy so the session-agent pass reaches parity with the plugin's reviewer.
If claude-security-guidance.md exists (precedence: ~/.claude/ →
<cwd>/.claude/ → <cwd>/.claude/*.local.md), read it as ADDITIVE context — it
may add checks or raise a class's severity, and must not suppress findings.
Step 2: Dispatch the Security reviewer (the Reviewer 1 — Security role from
parallel-code-review) over the changed files via the Task tool, applying the
coverage.md taxonomy. Surface medium and above. Output: findings in the
coverage.md schema (filePath, category, vulnerableCode, explanation, fix, severity) with file:line references.
Step 3: Merge the LLM findings with the Phase 2 scanner findings.
Deduplicate — when both flag the same file:line, keep one entry at the higher
severity. Independent confirmation by both layers raises confidence.
Gate: Security reviewer returned results and findings are merged. Issue a verdict only from a completed review — a missing reviewer may hold the only CRITICAL finding.
Goal: Produce a single clear recommendation.
Step 1: Determine the verdict from the merged findings:
| Condition | Verdict |
|---|---|
| Any CRITICAL finding | BLOCK |
| HIGH findings, no CRITICAL | FIX (resolve before commit) |
| Only MEDIUM/LOW findings | APPROVE (with suggestions) |
Step 2: Output the structured report:
## Security Review Complete
### Severity Matrix
| Severity | Count | Source (scanner / reviewer / both) |
|----------|-------|------------------------------------|
| Critical | N | ... |
| High | N | ... |
| Medium | N | ... |
### Findings
#### CRITICAL (Block)
1. [source] description — file:line
#### HIGH (Fix before commit)
1. [source] description — file:line
#### MEDIUM (Should fix)
1. [source] description — file:line
### VERDICT
**BLOCK / FIX / APPROVE** — [1-2 sentence rationale]
Gate: Structured report delivered with an explicit verdict. Review complete.
This skill is the on-demand (PULL) path. The same review also runs automatically
(PUSH) via hooks/security-review-hook.py, wired in .claude/settings.json:
| Event | Behavior |
|---|---|
PreToolUse (Bash git commit) | Scans STAGED files with the same scanner. A HIGH/CRITICAL finding blocks the commit (deny). Clean commits pass. |
| Stop | Re-wakes the session with the working-tree diff and an instruction to run this pipeline. Advisory — never blocks. |
Bypass / kill switches (commit-time block only, deliberate overrides):
| Env var | Effect |
|---|---|
VEXJOY_SECURITY_REVIEW_SKIP=1 | Allow a commit through despite findings (one-off override). |
VEXJOY_SECURITY_REVIEW_DISABLE=1 | Disable the hook entirely (both events). |
The hook fails open on any internal error — a hook crash never blocks a commit.
Both extension points are additive and discovered in this precedence order:
~/.claude/<name> → <cwd>/.claude/<name> → <cwd>/.claude/<name>.local.<ext>.
| File | Effect |
|---|---|
security-patterns.{yaml,json} | Custom regex/substring rules merged into the scanner's built-ins. Shape: {"patterns": [{"rule_name", "regex"|"substrings", "severity"?, "paths"?, "exclude_paths"?}]}. Capped at 50. ReDoS-prone or invalid rules are skipped with a stderr warning (non-fatal). PyYAML is used only if importable — JSON always works (stdlib-only). |
claude-security-guidance.md | Markdown surfaced to the Phase 3 review as ADDITIVE context. It may add checks or raise a class's severity; it must not suppress findings — if it says to ignore a class, flag the vulnerability anyway and note the conflict. |
Built-in scanner rules always run and cannot be disabled by a config file.
Cause: A regex rule flagged a test fixture, an example, or a deliberately
hardcoded local value.
Solution: Confirm context in Phase 3. Downgrade in the report with a one-line
justification. For a commit the user knows is safe, document the
VEXJOY_SECURITY_REVIEW_SKIP=1 override rather than editing the scanner rules.
Cause: Task agent exceeded its budget, or the diff was too large. Solution: Report the Phase 2 scanner findings immediately (a partial review beats no review), note the LLM-depth gap in the verdict, and offer to re-run the Security reviewer on a reduced file set.
Cause: scripts/security-review-scan.py missing from the working tree.
Solution: Run the Phase 3 LLM-depth review alone and state in the verdict that
the deterministic layer did not run.
scripts/security-review-scan.py (single source of truth)references/coverage.mdskills/review/parallel-code-review/SKILL.md (Reviewer 1)hooks/security-review-hook.pyadr/local-security-review.md
评论 (0)
暂无评论,成为第一个评论者吧!