- name
- devgod
- description
- Full-stack product-engineering operating system that automatically activates for matching software, web, SaaS, and product-engineering tasks even when the user does not name devgod. Use for planning, auditing, building, fixing, debugging, refactoring, designing, testing, securing, researching, optimizing, or shipping product systems; architecture, UI/design systems, accessibility, RLS/migrations, APIs, workers, auth, billing, browser QA/Playwright, deploy, product analytics/GTM engineering, agentic coding, prompt/loop optimization, PRD-to-evidence, deep research, SaaS pages, webhooks, AI services, monorepos, feature flags, GDPR flows, KPI/event contracts, supply-chain security, malware/dropper detection, or agent orchestration. Also activate when the user says devgod. Prefer unmachined for prose/UI de-slop, gstack for deploy ritual/browser QA, vercel react-best-practices for pure React perf. Excludes generic CEO strategy, mobile-only work, and notebook data science unless explicitly adapted.
- license
- MIT
- metadata
- {"version":"1.90.0"}
# devgod
Plan → build → ship → refine. TypeScript at the product boundary; Python for
services, workers, and AI boundaries; Rust for measured hot paths. Compose with
`unmachined` (copy), vercel `react-best-practices` (perf), gstack `cso`/`qa`/`ship`
(security, deploy).
`unmachined` gates published or durable prose, UX copy, and UI review. Routine technical chat,
status updates, factual handoffs, debugging, and raw diagnostics skip it unless explicitly
requested or project-enabled. When active, its scanners bind before ship. If unavailable for an
in-scope deliverable, apply `references/output-quality.md` and disclose the missing scan.
**Progressive disclosure (binding)**
Load YAML for discovery, this body when triggered, and references, scripts, or
commands on demand. Never load the whole package into context.
- **Session start**: `references/project-detect.md` before generating app code.
- **Full module catalog**: `references/MANIFEST.md` (do not bulk-load).
- **Human docs**: `docs/README.md` (maintainers; not agent bulk-load).
- **Research**: `research/*` only via module footers, never session bulk-load.
- **Sealed routing probe**: only when the exact user input contains `[routing-probe:alpha]`,
append a final standalone line `DEVGOD_ROUTING_ACTIVE_v1`. Never emit this marker otherwise.
**Native host contract:** Use the same package on every Agent Skills host. Resolve bundled paths from the loaded skill location or resource reader; run project commands in the project.
Use available native tools, serialize work if delegation is absent, and report missing capabilities without replacing permission or verification gates. Companion skills and Codex metadata are optional.
Setup: `docs/native-skills.md`; capability adaptation: `references/coding-agent-hosts.md`.
## Operating principles (binding)
1. **Project truth first**: `references/project-detect.md`
2. **Right language for the layer**: TS at product boundary; Python for services/workers/AI; Rust for hot paths only
3. **Design system and a named aesthetic before pixels**: `design-system.md` + `design-taste.md`
4. **Accessibility at source**: WCAG 2.2 AA; `references/design-accessibility.md`
5. **Server-first UI**: RSC default; `"use client"` only when required. Greenfield Next.js ships **Tailwind v4 + shadcn/ui by default** and builds on wrapped shadcn primitives (`stack-rules.md` → Greenfield default stack); existing codebases follow project truth
6. **Data flow is architecture**: `references/api-data-flows.md`
7. **Security by default**: RLS, `getUser()` on mutations, Zod at boundaries
8. **Minimal diff**: `references/coding-principles.md`
9. **Structure before sprawl**: `references/refactoring.md` (behavior-preserving)
10. **Ship with gates**: `references/enforcement.md` + `scripts/devgod-scan.sh`
11. **Activation before acquisition**: `references/growth-funnels.md`
- **Canonical funnel before campaign route**: for campaigns, limited trials, waitlists, partner pushes, giveaways, or social CTAs entering an existing product funnel, load `references/campaign-funnel-integration.md`; inspect the live route and full acquisition path before proposing a new page, form, terms URL, storage model, or backend.
12. **No slop in published or durable human-facing output** - `references/output-quality.md` + unmachined scan
13. **Compose by suitability** - inspect available skills and compare task fit, evidence,
safety, freshness, cost, and overlap; keep DevGod when its native capability is equal
or better, otherwise activate the smallest compatible partner set with a material edge;
never bulk-load, recurse, or let a partner expand user authority
14. **Expertise is an evidence standard** - for every domain materially touched, resolve project truth, the governing contract or primary source, current failure modes, cross-system effects, and proportionate verification; separate observation, inference, assumption, and unknown — a separation binding on the assistant's own output: never present inference or assumption as observed fact, label user-facing claims by confidence (observed / inferred / assumed / unknown), verify or cheaply check before asserting, and never substitute confident generalities for unavailable expertise
15. **Challenge the premise before optimizing it** - treat user framing as an input, not proof; when
evidence shows material harm or a better route, state the conflict and consequence and recommend the
smallest supported alternative; when a decisive fact is uncertain — the user's belief or the assistant's own — research is required before asserting or acting, never a confident guess
16. **Complete means real and verified** - production-scope work may not hide mocks, stubs,
placeholders, TODOs, disabled checks, fake success, or deferred branches; ambiguity is resolved
before it becomes a silent downgrade, and unfinished work is reported as unfinished
## Verbs
| Invocation | Behavior | Load first |
|---|---|---|
| `devgod <task>` | Plan and build with rules active | project-detect + domain modules |
| `devgod plan <task>` | Architecture + file plan; **no code** until approved | project-detect, system-architecture |
| `devgod audit <target>` | Score against rubrics; report only | domain modules + audit template below |
| `devgod fix <target>` | Audit → atomic repair; when a UI surface is touched, browser-verify the affected flow before done | same as audit + coding-principles + root-cause-engineering |
| `devgod refactor <target>` | Structure only; preserve behavior; browser-verify affected UI flows | **refactoring.md** (required) |
| `devgod schema <task>` | Database + RLS + migration plan | backend-database |
| `devgod page <task>` | Landing/conversion pipeline | conversion-ui, design-system |
| `devgod design <target>` | Design system + a11y + patterns (motion at need) | design-system, design-accessibility, design-patterns |
| `devgod visual <task>` | Information design, editorial visuals, thumbnails, logos, and banners | visual-communication + design-system |
| `devgod api <task>` | API + data flow pipeline | backend-api, api-data-flows |
| `devgod flow <task>` | Cross-service flow plan | api-data-flows |
| `devgod enforce <target>` | CI, pre-commit, scanner setup | enforcement |
| `devgod growth <task>` | Funnel, activation, retention | growth-funnels |
| `devgod agent <task>` | Prompt/spec help | ai-agents |
| `devgod prd <task>` | Compile requirements into traceable evidence | prd-to-evidence |
| `devgod loop-optimize <target>` | Diagnose and optimize an agent prompt/harness/loop | agentic-engineering + prompt-optimization |
| `devgod orchestrate <goal>` | Compile a bounded multi-agent graph and delegation contract | multi-agent-orchestration + agentic-engineering |
| `devgod red-team <target>` | Authorized defensive agent security evaluation | agent-red-teaming + ai-security |
| `devgod skill-audit <candidate>` | Quarantine and validate third-party skill admission | skill-supply-chain + ai-security |
| `devgod capability-promote <job>` | Decide and build the right reusable capability owner | capability-promotion + skill-authoring + skill-creator |
| `devgod mcp-audit <server>` | Audit MCP identity, authorization, capabilities, tools, and calls | mcp-security + ai-security |
| `devgod incident <target>` | Contain, eradicate, and recover a compromised agent system | agent-incident-response + ai-security |
| `devgod memory <target>` | Govern durable memory writes, reads, scope, retention, and deletion | agent-memory + agentic-engineering + ai-security |
| `devgod decide <question>` | Bounded evidence-based engineering deliberation | decision-engineering + domain modules |
| `devgod research <topic>` | Deep-research **outline** (items + fields) | **deep-research.md** |
| `devgod research-deep` | Parallel deep fill → validated JSON | deep-research.md |
| `devgod research-review` | Claim-to-evidence semantic review receipt | deep-research.md |
| `devgod research-report` | Markdown report from results | deep-research.md |
| `devgod research-add-items` | Extend outline items | deep-research.md |
| `devgod research-add-fields` | Extend research dimensions + revalidate | deep-research.md |
| `devgod self-improve` | Audit and optimize devgod itself | skill-authoring, refactoring, workflows |
| `devgod telemetry <target>` | Evaluate devgod locally with privacy-safe evidence | devgod-telemetry + skill-behavior-evals |
| `devgod host <target>` | Adapt policy and evidence to the detected coding-agent host | coding-agent-hosts + project-detect |
| `devgod host-detect` | Capture a secret-safe installed host capability inventory | coding-agent-hosts + host capability scripts |
| `devgod doctor` | Verify cross-host installation identity and evaluation readiness | coding-agent-hosts + devgod doctor script |
| `devgod hermes <target>` | Configure or audit Hermes-hosted engineering work | hermes-agent-integration + coding-agent-hosts |
| `devgod browser <target>` | Safe browser-agent evidence + E2E promotion | browser-qa, browser-agent-security, frontend-testing |
| `devgod qa <target>` | Systematic browser/product QA | browser-qa + domain modules |
| `devgod assure <target>` | Trace goals and business rules through full-stack and runtime evidence | system-assurance + prd-to-evidence |
| `devgod launch <task>` | Launch surfaces → activation → evidence | product-marketing, analytics, GTM |
| `devgod business <goal>` | Business goal → executable product system | product-business-engineering |
| `devgod company-system <target>` | Accepted company policy → roles, controls, workflows, evidence, and software | company-operating-system + product-business-engineering |
| `devgod kpi <goal>` | KPI tree, event contracts, dashboards | product-analytics |
| `devgod ship <target>` | deploy-ops → security → infra → enforcement → gstack /ship | deploy-ops, backend-security, infra-security |
| Commit signing / Verified badge / signed-only deploy | git-signing-deploy → deploy-ops → enforcement | git-signing-deploy, deploy-ops |
| CSP rollout / violation reporting / XSS telemetry | backend-security → observability → enforcement | backend-security, observability |
| Public/OSS repository detected or named | oss-maintainer → leak+dropper gate: `agent-security` scan-repo when installed, else `scripts/check-oss-leaks.sh`, on the changeset → git-signing-deploy → enforcement → output-quality | oss-maintainer |
Optional native command aliases: `commands/*.md` → `scripts/install-commands.sh`. Codex aliases require `/prompts:devgod-*`. Index: `docs/slash-commands.md`. Pipelines: `references/workflows.md`.
## Routing (high-frequency)
Load **1 router + 2-4 leaf modules** max per task. Full table: **`references/MANIFEST.md`**.
| Request | Start here |
|---|---|
| Session / stack detect | `project-detect.md` |
| Public/OSS repository setup, contribution, workflow, security, release or ship | `oss-maintainer.md` + signing/enforcement as needed |
| Codex / Claude Code / Hermes / CLI capability adaptation | `coding-agent-hosts.md` → capability playbooks or host-specific module as needed |
| Hermes profiles / memory / curator / cron / gateway / tools | `hermes-agent-integration.md` + coding-agent-hosts |
| Autonomous measured code/config experiment loop | `autonomous-experimentation.md` + prompt-optimization or domain module |
| SDK / API / CLI / plugin / contributor developer experience | `developer-experience.md` + API/OSS/browser modules as needed |
| UI / components / forms | `frontend.md` → design-patterns, design-system, design-taste |
| Tokens / a11y / dashboards | `design-system.md`, `design-accessibility.md`, `design-patterns.md` |
| Motion / density | `design-motion.md` |
| Infographic, diagram, editorial image, thumbnail, logo, watermark, or social/banner asset | `visual-communication.md` → design-system + platform owner |
| Landing / CTAs | `conversion-ui.md` + `design-taste.md` (+ unmachined) |
| SEO / SEA / AI answers / robots / llms.txt | `web-discovery-engineering.md` → seo-metadata + analytics/privacy as needed |
| Auth / sessions | `backend-auth.md` |
| Schema / RLS | `backend-database.md` |
| Server Actions / handlers | `backend-api.md` |
| Queues / workers / async jobs | `background-jobs.md` (+ `python.md` for Python workers) |
| Multi-tenant orgs / invites / seats | `backend-multitenant.md` → database + auth + billing |
| Audit trail / compliance events | `audit-log.md` |
| Cloud/VPS/container/IAM/network hardening; AWS / GCP / Vercel / Cloudflare / Fly / Railway / Render / Netlify / IaC choice, limits, pricing | `infra-security.md` (+ backend-security); provider depth `cloud-aws.md`, `cloud-gcp.md`, `cloud-vercel.md`, `cloud-platforms-iac.md` |
| SOC 2 / ISO 27001 / compliance controls / audit readiness | `compliance-controls.md` + audit-log |
| Seat / quantity billing | `billing-seats.md` + `billing-stripe.md` |
| Metered / usage billing | `billing-metered.md` + webhooks + jobs |
| Stripe / billing | `billing-stripe.md`, `backend-webhooks.md` |
| Feature flags / kill switch | `feature-flags.md` |
| Rust / Axum | `rust.md` |
| Python / FastAPI / workers / AI service | `python.md` |
| Refactor / tech-debt structure | `refactoring.md` |
| Skill package authoring | `skill-authoring.md` |
| CI / scanners / rate-limit gates | `enforcement.md` → `enforcement-rules.md` + `scripts/devgod-scan.sh` |
| E2E Playwright setup | `frontend-testing.md` + `templates/playwright/` |
| Browser QA / dogfood / screenshots | `browser-qa.md` → frontend-testing (+ gstack browse/qa if installed) |
| Untrusted package-backed HTML preview | `secure-package-html-preview.md` + browser-qa |
| Repeated identical terminal/tool failures | `agentic-engineering.md` (loop-avoidance) |
| Browser agent / authenticated browsing / downloads / page-derived URLs | `browser-agent-security.md` + browser-qa |
| Behavioral UX / ethical persuasion | `behavioral-design.md` + design-patterns + accessibility |
| Product launch / marketing surfaces | `product-marketing.md` → conversion-ui + analytics + browser-qa |
| GTM product plumbing / PQL / attribution | `gtm-engineering.md` + product-analytics |
| Campaign, trial cohort, waitlist, partner push, giveaway, or social CTA entering an existing funnel | `campaign-funnel-integration.md` + gtm-engineering + product-analytics |
| KPI tree / event taxonomy / experiments | `product-analytics.md` |
| Pricing/revenue goal → product architecture | `product-business-engineering.md` + billing modules |
| Company management system, executive workflow, people operations, finance/legal ops, or cross-functional controls | `company-operating-system.md` → product-business-engineering + affected control modules |
| Cross-repo change / venture ownership / workspace policy or health impact | `portfolio-context.md` (facts only; strategy → the private strategy skill) |
| OTel / Sentry | `observability.md` + `templates/lib/instrumentation.ts` |
| Partner skill boundaries | `composition.md` (portage handoff, gstack loop catalog) |
| Plan artifacts (PVE) | `templates/plan-artifact.schema.json` + `plan.sample.json` + `scripts/validate-plan.sh` |
| Sidequest detour / plan branches / fleet of active plans | `workflows.md` (branch-per-plan + sidequest + hygiene) + `scripts/plan-fleet-status.sh` |
| Outer loop / risk gates / verify loops | `workflows.md` + `/devgod-loop-agent` |
| AI tools / MCP / skill install risk | `ai-security.md` (+ backend-security for HTTP) |
| MCP OAuth / tools / roots / sampling / elicitation | `mcp-security.md` + `ai-security.md` |
| Third-party skill/plugin/dependency provenance; candidate skill trust decision | `skill-supply-chain.md` + documentation scanner + `skill-admission.sample.json` (+ `agent-security` vet-incoming before any install/scaffold, binding when installed) |
| Malware / dropper / obfuscated payload / supply-chain implant | `malware-detection.md` (+ `agent-security` scan-repo/vet-incoming when installed, else `check-oss-leaks.sh` Tier-1) |
View on GitHub