Endika/eskills

Lean personal Claude Code skills pack — my conventions, task flow, and quality lenses. Requires the superpowers plugin.

★ 0Forks 0PythonGitHub ↗Compare
agent-skillsaiclaude-codeclaude-code-pluginclaude-skillsdeveloper-toolsproductivity

README

eskills

A lean, trustworthy personal Claude Code skills pack. It encodes my own conventions for detecting bugs, building features, testing, and shipping — and rides superpowers rather than duplicating it.

The goal is trust: when I follow one of these skills, the result is what I expect, with evidence — not a hopeful claim. This is the deliberate opposite of a maximalist catalog; every skill has to justify its place.

Requires

  • superpowers — these skills invoke it by name (brainstorming, writing-plans, subagent-driven-development, systematic-debugging, verification-before-completion, finishing-a-development-branch). It is the only required runtime dependency. Nothing else is installed.

Optional: ux-bar layers on the frontend-design skill and security-bar on the built-in security-review. task-flow can dispatch the code-explorer and code-architect agents from the feature-dev plugin — that plugin ships agents and a command, no skills — and falls back to the built-in Explore agent without it. None of these are required.

Install

Stable (any environment):

claude plugin marketplace add Endika/eskills
claude plugin install eskills@endika

You only ever receive stable releases: work-in-progress commits on main share the same version until release-please bumps it.

Dev (load HEAD directly):

claude --plugin-dir path/to/eskills   # or, from the clone: make dev

Skills

Invoked as eskills:<name>.

Core

Skill Use when
standards About to commit, write/design tests, name identifiers, write user-facing copy, choose an ID type, or push — enforces my conventions floor (commits, tests, repo hygiene, inclusive language, IDs).
task-flow Implementing a feature end-to-end — orchestrates spec → plan → per-task implement/verify/review over superpowers, with a single human gate plus a human-pulled respec gate to correct the spec mid-build.
spec-intake Turning a task (Jira/Linear/URL/free text) into a normalized spec before planning.
gen-uml Generating a Mermaid diagram (architecture/flow/sequence) from existing code.
postmortem After an important bug/failure — capture, root cause, fix, lesson as an archivable doc.
stack-gotchas Hitting a known failure in my stack — release-please, Pages, gh/Dependabot, Supabase, Flipper, WSL, a remote box — a symptom index over per-family recipes in references/.
context-budget Context feels heavy / added skills, MCP, or memory — audits whole-setup token consumption with a prioritized trim list.
exploit-hunt Hunting actually-exploitable vulnerabilities (SSRF, SQLi, command injection, RCE, path traversal, XSS) — offensive counterpart to security-bar, on-demand, not a per-task lens.
stacks Working in a non-default stack (Flipper FAP/C, Docker/Compose and PyTorch training now; Django/Flask/FastAPI coming) — per-stack architecture/build/test/release conventions under references/<stack>/. One skill, many stacks.
gdpr Building/shipping/auditing a B2C app for GDPR/privacy — data-posture classifier, decision gates, lawful basis/minimization/retention/DSR, processors & transfers, privacy notice, cookieless analytics.
comms Writing text that leaves the machine with a person on the other end — email, an issue/comment on a repo I don't own, a maintainer follow-up, release notes, a review-bot reply. Drafts only; sending is mine.

Quality lenses

Short rubrics in my voice — usable standalone on a diff, and invoked by task-flow's review stage. Hard cap of 4.

Lens Use when
ux-bar Building/reviewing UI — my design-system, semantic-color and inclusive-copy rules on top of frontend-design.
security-bar Reviewing for security — my checklist on top of security-review.
arch-bar Judging whether an architecture fits its scale — catches over- and under-engineering.
perf-bar Assessing performance/algorithmic soundness — Big-O, N+1, egress, benchmarks; React and Vite-build rule sheets in references/.

The task-flow, end to end

How task-flow sequences everything — Phase 1 → the single human gate → the Phase 2 per-task loop (where the quality lenses fan out) → Phase 3. The quality lenses live in step 4 of the loop.

flowchart TD
  classDef gate fill:#FFF1EF,stroke:#FF5A47,stroke-width:2px,color:#9A3412
  classDef plan fill:#EEF2FF,stroke:#6366F1,color:#3730A3
  classDef lens fill:#F8FAFC,stroke:#94A3B8,color:#0F172A
  classDef offensive fill:#FFF5F4,stroke:#DC2626,color:#991B1B

  subgraph P1["Phase 1 — Understand and plan (auto, adaptive)"]
    direction TB
    SI["eskills:spec-intake<br/>objective · acceptance criteria · constraints · DoD<br/>classify greenfield/brownfield · flag hard-tech"]
    CE["feature-dev:code-explorer<br/>understand the existing code"]
    SP["SPIKE — 2-3 approaches<br/>benchmark with perf-bar · pick before planning"]
    BR["superpowers:brainstorming<br/>refine intent and trade-offs"]
    WP["superpowers:writing-plans<br/>files · concrete change · acceptance criteria · validation commands"]
    PLAN(["PLAN + acceptance criteria + subagent design + rationale"])
    SI -. if brownfield .-> CE
    SI -. if hard-tech .-> SP
    SI --> BR
    CE --> BR
    SP --> BR
    BR --> WP --> PLAN
  end

  PLAN --> GATE{{"HUMAN GATE — the only human stop<br/>review and approve the plan · then /compact"}}
  GATE --> IMP

  subgraph P2["Phase 2 — Build (auto, per task)"]
    direction TB
    IMP["1 · Implementer<br/>implement · test · commit · self-review<br/>pulls eskills:stacks · stack-gotchas · gdpr as needed"]
    SR["2 · Spec reviewer<br/>independent · does it match the spec?"]
    AV["3 · Adversarial verifier<br/>fresh context · re-runs lint + types + tests<br/>defaults to NOT done"]
    QR["4 · Quality reviewer<br/>applies only the lenses that fit · cap 4"]
    UX["ux-bar<br/>semantic color · tokens · a11y · responsive"]
    SEC["security-bar<br/>client guards are not security · RLS · server-side authz"]
    ARCH["arch-bar<br/>over- and under-engineering"]
    PERF["perf-bar<br/>Big-O · N+1 · egress"]
    DONE(["all green → next task"])
    RESPEC["RESPEC GATE — human-pulled<br/>pause · correct the spec · re-plan · relaunch"]
    EH["exploit-hunt — offensive, on-demand<br/>NOT in the per-task loop"]
    IMP --> SR --> AV --> QR
    QR --> UX
    QR --> SEC
    QR --> ARCH
    QR --> PERF
    UX --> DONE
    SEC --> DONE
    ARCH --> DONE
    PERF --> DONE
    DONE -. next task .-> IMP
    IMP -. spec is wrong .-> RESPEC
    RESPEC -. re-spec → re-plan → relaunch .-> IMP
    SEC -. offensive counterpart .-> EH
  end

  DONE --> VBC

  subgraph P3["Phase 3 — Finish (auto)"]
    direction TB
    VBC["superpowers:verification-before-completion<br/>+ a final review pass"]
    FIN["superpowers:finishing-a-development-branch"]
    REL["PR / release<br/>Conventional Commits (eskills:standards) · release-please"]
    VBC --> FIN --> REL
  end

  class GATE,RESPEC gate
  class PLAN plan
  class UX,SEC,ARCH,PERF lens
  class EH offensive
Loading

How it relates to upstream

One rule shapes the whole repo:

Copy/adapt small, stable ideas where I want my version. Reference large, living engines where I want to ride their updates.

So superpowers is referenced (invoked by name); a few small patterns are adapted and rewritten. ECC is never installed — it was mined for ideas only.

Adapted material carries its provenance where it landed: an origin: line in a skill's frontmatter, or an Origin section at the foot of a reference file, saying what the source was and what had to be rewritten for this stack. If it isn't marked, it's mine.

Hooks

Three, all shipped with the plugin:

  • SessionStart — injects the precedence rule (this pack overrides superpowers) and the notes-directory convention.
  • PreToolUse on git * and gh * — matches commit, PR, issue and release text against the high-precision half of comms/references/ai-tells.md and warns without blocking. Single padding words are deliberately not matched: measured against this repo's own history it fires on 0 of 89 real commits, which is the point — a hook that cries wolf is a hook you turn off.
  • PreToolUse on git commit — scans the lines the commit adds (Markdown and plain text excluded) against the mechanical half of standards/references/code-tells.md: comments addressed to the reader, leftover placeholders, step banners, emoji in log calls, bare except: pass. Also warns without blocking. Measured before shipping: 0 of 1,301 commits across my repos, 3 of 1,800 across five third-party ones.

Development

make            # list targets
make list       # skills + their trigger descriptions
make check      # validate frontmatter, JSON, and design caps (run before pushing)
make new name=<kebab>   # scaffold a new skill
make details    # component inventory + token cost (anti-bloat watch)
make tag        # create the release tag (validates plugin.json vs marketplace)

Feature work on short-lived branches (feat/…, fix/…, chore/…) → PR → rebase-merge, so main stays linear (never a merge commit). Releases via release-please (Conventional Commits → version bump + CHANGELOG + tag).

License

MIT © Endika

Contributors

Endikagithub-actions[bot]dependabot[bot]

Issues