원클릭으로
candid-init
Generate Technical.md and config.json by deeply analyzing your codebase structure, architecture, and patterns
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Generate Technical.md and config.json by deeply analyzing your codebase structure, architecture, and patterns
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | candid-init |
| description | Generate Technical.md and config.json by deeply analyzing your codebase structure, architecture, and patterns |
You are a senior technical architect conducting a thorough codebase audit. Your job is to generate a Technical.md that:
The output should feel like it was written by someone who spent days understanding THIS specific codebase - not a generic template.
| Level | Time | Analysis | Output |
|---|---|---|---|
quick | ~30 sec | Grep/find pattern detection | ~50 lines |
medium | ~1-2 min | + Read 5-8 key files | ~150 lines |
thorough | ~5-10 min | + Sub-agents read ALL files | ~500 lines |
Default: thorough
Thorough mode runs 5 parallel analysis sub-agents (Step 6), then 5 parallel generation sub-agents (Step 9), then synthesis.
ls .candid/Technical.md .candid/config.json 2>/dev/null
If Technical.md exists, ask user: "Overwrite", "Create as .new", or "Cancel" If config.json exists, ask user: "Overwrite", "Keep existing", or "Cancel"
Check for --effort flag. Default is thorough.
cat package.json 2>/dev/null | head -50
ls requirements.txt pyproject.toml go.mod Cargo.toml 2>/dev/null
| Detection | Framework |
|---|---|
| package.json with react/next/vue | React |
| package.json without frontend | Node.js |
| requirements.txt or pyproject.toml | Python |
| go.mod | Go |
| Cargo.toml | Rust |
| None | Minimal |
ls .eslintrc* eslint.config.* .prettierrc* biome.json tsconfig.json .flake8 ruff.toml 2>/dev/null
Critical: If linters exist, SKIP all rules they enforce. Focus Technical.md on what linters CANNOT check: architecture, domain rules, patterns.
This is the core of generating project-specific rules. Execute based on effort level.
# Get full directory tree (3 levels)
find . -type d -maxdepth 3 | grep -v node_modules | grep -v .git | grep -v __pycache__ | grep -v venv | grep -v dist | grep -v build | sort
# Identify key directories
ls -d src/*/ lib/*/ app/*/ packages/*/ 2>/dev/null | head -20
Extract:
controllers/, services/, repositories/, models/?features/, modules/, domain directories?shared/, common/, utils/, lib/?# File suffixes
find . -type f \( -name "*.ts" -o -name "*.tsx" -o -name "*.js" \) 2>/dev/null | grep -v node_modules | sed 's/.*\///' | grep -oE '\.[a-z]+\.(ts|tsx|js)$' | sort | uniq -c | sort -rn | head -15
# Class/component naming
grep -rhoE "^export (default )?(class|function|const) [A-Z][a-zA-Z]+" --include="*.ts" --include="*.tsx" 2>/dev/null | grep -v node_modules | head -30
This is critical for architecture rules.
# What imports what - build mental model of dependencies
grep -rh "^import.*from" --include="*.ts" --include="*.tsx" 2>/dev/null | grep -v node_modules | grep -oE "from ['\"][^'\"]+['\"]" | sort | uniq -c | sort -rn | head -30
# For each layer dir (controllers, services, ...), check what it imports — flags layer violations:
grep -rh "^import.*from" src/controllers/ --include="*.ts" 2>/dev/null | grep -v node_modules | head -20
# Check for cross-module imports (feature A importing from feature B)
grep -rh "^import.*from.*features/" --include="*.ts" 2>/dev/null | grep -v node_modules | head -20
# Path aliases in use
grep -rh "from '@/\|from '~/\|from 'src/\|from '#" --include="*.ts" --include="*.tsx" 2>/dev/null | grep -v node_modules | head -10
Detect barrel exports (index.ts count + samples), dependency injection, middleware/decorator patterns, and domain-specific directories — commands in reference/analysis-commands.md.
# Custom error classes
grep -rh "class.*Error\|extends Error\|extends.*Error" --include="*.ts" 2>/dev/null | grep -v node_modules | head -15
# Error response patterns
grep -rh "res.status.*json\|throw new\|catch.*error" --include="*.ts" 2>/dev/null | grep -v node_modules | head -20
# Error handling location (where are errors caught?)
grep -rl "try.*catch\|\.catch(" --include="*.ts" 2>/dev/null | grep -v node_modules | head -20
# Test file locations
find . -name "*.test.*" -o -name "*.spec.*" -o -name "*_test.*" 2>/dev/null | grep -v node_modules | head -20
# Test organization (colocated vs separate)
ls -d **/__tests__/ **/tests/ test/ tests/ 2>/dev/null | head -10
# Test naming patterns
grep -rh "describe(\|it(\|test(" --include="*.test.*" --include="*.spec.*" 2>/dev/null | grep -v node_modules | head -15
# Mock patterns
grep -rh "jest.mock\|vi.mock\|sinon\|@Mock" --include="*.test.*" --include="*.spec.*" 2>/dev/null | grep -v node_modules | head -10
Detect route definitions, validation patterns (zod/yup/joi/decorators), and auth middleware — commands in reference/analysis-commands.md.
Detect custom hooks, state management libraries, component patterns (memo/forwardRef/lazy/Suspense), and event handler naming — commands in reference/analysis-commands.md.
Detect tsconfig strictness, any/as any usage counts, and interface-vs-type preference — commands in reference/analysis-commands.md.
How files are analyzed depends on effort level.
Use the Read tool to examine representative files:
src/index.ts, app/layout.tsxExtract: naming patterns, error handling, import organization, examples to cite.
Launch 5 Explore sub-agents IN PARALLEL (Task tool, subagent_type: "Explore"). Read reference/analysis-prompts.md (relative to this skill) for the exact prompt for each:
Each returns proposed rules with file:line evidence.
After all agents complete, synthesize their findings:
This creates the architecture rules that make Technical.md valuable.
Based on directory structure and import analysis, determine:
Layer Structure Detected:
├── src/controllers/ → HTTP layer (should only import services)
├── src/services/ → Business logic (can import repos, not controllers)
├── src/repositories/ → Data access (can import models, not services)
└── src/models/ → Data models (no internal imports)
Generate rules like:
src/controllers/ must not import from src/repositories/ directly - go through services"src/services/ must not import from src/controllers/"If feature-based structure detected (e.g., src/features/auth/, src/features/billing/, src/shared/), generate cross-module rules the same way, e.g. "Feature modules must not import from each other directly — use src/shared/ for cross-cutting concerns."
Look for actual violations in the codebase:
# Example: Find files in controllers/ that import from repositories/
grep -rl "from.*repository\|from.*repositories" src/controllers/ 2>/dev/null
If violations found, note them:
src/controllers/UserController.ts imports directly from UserRepository. Refactor to use UserService."Compare detected patterns to best practices. For each category, identify gaps.
| Category | Best Practice | Check | If Missing |
|---|---|---|---|
| Security | Input validation at boundary | Look for zod/joi/yup | "Consider adding Zod for input validation at API boundaries" |
| Security | Parameterized queries | Check for raw SQL strings | "Found raw SQL in X. Use parameterized queries." |
| Security | Auth middleware | Check route protection | "Not all routes appear to have auth checks" |
| Security | Secret management | Check for hardcoded values | "Found potential hardcoded secret in X" |
| Error Handling | Custom error classes | Look for extends Error | "No custom error classes found. Consider adding AppError hierarchy." |
| Error Handling | Consistent error format | Check response patterns | "Error responses use inconsistent formats across files" |
| Error Handling | Error logging | Check for logger usage | "Errors caught but not logged in X files" |
| Testing | Tests exist | Find test files | "No tests found for src/services/" |
| Testing | Test organization | Check patterns | "Tests use inconsistent naming (mix of .test.ts and .spec.ts)" |
| TypeScript | Strict mode | Check tsconfig | "strict mode not enabled. Consider enabling for new code." |
| TypeScript | No any | Count any usage | "Found 47 uses of any. Consider typing or using unknown." |
For thorough mode, generate a comprehensive ~500 line Technical.md by launching generation sub-agents in parallel. Each agent writes one major section with full detail.
Each section is generated independently by a focused sub-agent working from specific analysis results, and the final synthesis combines sections without truncation — this lets Claude Code produce long, detailed output. Launch the agents simultaneously.
| Agent | Section | ~Lines |
|---|---|---|
| 1 | Architecture | ~100 |
| 2 | Naming & Style | ~80 |
| 3 | Error Handling & Logging | ~80 |
| 4 | Testing | ~80 |
| 5 | Security & Framework | ~100 |
Read reference/generation-prompts.md (relative to this skill) and launch all 5 agents in parallel via Task, pasting the relevant analysis results into each prompt where indicated.
After all generation agents complete, collect all sections and combine into one ~500-line file in this order: (1) header — title, "Standards for [project]. Generated [date] from comprehensive codebase analysis." plus Analysis Summary bullets (files analyzed, patterns detected, violations found, gaps identified); (2) the five agent sections separated by ---; (3) Gaps vs Best Practices table (Area | Current State | Recommended | Priority); (4) Appendix: File Reference listing key cited files; (5) footer line: Generated by candid-init. Run /candid-validate-standards to check rule quality.
For medium mode: Generate ~150 lines (condensed version of above) For quick mode: Generate ~50 lines (essential rules only)
Tag each rule [observed N/M] (count via grep) or [recommended], with known exceptions listed.
Every rule MUST:
Reference specific paths from this project
src/services/ must not import from src/controllers/"Include actual examples from the codebase
handle* pattern (e.g., handleUserLogin in src/components/LoginForm.tsx)"Be measurable/verifiable
Note current state if it differs from the rule
Tag provenance and adherence
[observed 12/14] — convention followed by 12 of 14 relevant files. List the 2
violating files as Known exceptions: path1, path2 so reviews flag only NEW violations,
not pre-existing code.[recommended] — best practice not yet present in this codebase. Must also appear in
the Gaps table; reviews should surface these as suggestions, never as hard violations.[observed] — move it to Gaps.Build the project config by auto-detecting what you can from the codebase and prompting the user for preferences. Always set "version": 1.
Note: The focus field is intentionally not set during init — it's a per-review concern (e.g., --focus security before a release), not a project-level default.
Run:
git branch -a 2>/dev/null
Map detected branches to a branching strategy:
| Detection | Strategy | mergeTargetBranches |
|---|---|---|
develop branch exists | Git Flow | ["develop", "main"] |
trunk branch exists | Trunk-based | ["trunk"] |
main and master both exist | Migration | ["main"] |
main exists (no develop/trunk) | GitHub Flow | ["main"] |
master exists (no main) | Legacy | ["master"] |
| None detected | Default | ["main"] |
Check both local and remote branch names (e.g., remotes/origin/develop counts as develop).
Use AskUserQuestion to confirm:
Question: "Detected [strategy] branching strategy. Use [detected branches] as merge target branches?"
Options:
mergeTargetBranches field (candid-review defaults to ["main", "stable", "master"])Scan the project for files and directories that should be excluded from reviews. Check for:
# Generated files
find . -maxdepth 4 \( -name "*.generated.ts" -o -name "*.generated.js" -o -name "*.g.dart" \) 2>/dev/null | head -5
# Vendor directories
ls -d vendor/ third_party/ 2>/dev/null
# Build output
ls -d dist/ build/ .next/ out/ 2>/dev/null
# Minified files
find . -maxdepth 4 \( -name "*.min.js" -o -name "*.min.css" \) 2>/dev/null | head -5
Build a list of detected exclude patterns:
*.generated.ts / *.generated.js — if generated files foundvendor/* — if vendor directory founddist/* / build/* / .next/* — if build output directories found*.min.js / *.min.css — if minified files foundIf patterns detected: Use AskUserQuestion:
Question: "Detected files that should be excluded from reviews:\n[list each pattern with example file]\n\nUse these exclude patterns?"
Options:
exclude fieldIf no patterns detected: Skip this step silently. Omit exclude field.
Use AskUserQuestion:
Question: "What review tone do you prefer?"
Options:
If "Harsh" → set "tone": "harsh". If "Constructive" → set "tone": "constructive". If "Skip" → omit tone field (candid-review will prompt each time or use user config).
Use AskUserQuestion:
Question: "Automatically commit fixes after applying them during reviews?"
Options:
If "Yes" → set "autoCommit": true. If "No" → omit autoCommit field (defaults to false).
Use AskUserQuestion:
Question: "Enable the decision register to track questions and decisions during reviews?"
Options:
"decisionRegister": { "enabled": true } to the generated configdecisionRegister field from the generated config (disabled by default)If the user enables it, the default path (.candid/register) and default mode ("lookup") are used. The user can customize these later in the config file.
Use AskUserQuestion:
Question: "Configure the candid-ship shipping workflow? (review → build → test → PR → merge)"
Options:
If "No, skip" → omit ship field. Proceed to Step 10.7.
If "Yes, configure ship settings":
Auto-detect from package.json:
jq -r '.scripts.build // null' package.json 2>/dev/null
If build script detected: Use AskUserQuestion:
[detected command]"If no build script detected: Use AskUserQuestion:
If "Custom command" → follow-up: "Enter build command:" with free-text response.
If "Skip build step" → omit buildCommand field.
Auto-detect from package.json:
jq -r '.scripts.test // null' package.json 2>/dev/null
Same pattern as 10.6a but for tests. Detect pytest, go test, etc. from project structure if not in package.json:
ls pytest.ini setup.cfg pyproject.toml 2>/dev/null # Python
ls go.mod 2>/dev/null # Go
If test script detected: Use AskUserQuestion with detected command as first option. If no test script detected: Offer common options (npm test, yarn test, Custom, Skip).
If "Custom command" → follow-up: "Enter test command:" with free-text response.
If "Skip test step" → omit testCommand field.
Use the branch detected in Step 10.1 (mergeTargetBranches).
Question: "Target branch for PRs created by candid-ship?"
Options:
If "Custom branch" → follow-up: "Enter target branch name:"
If "Skip" → omit targetBranch field.
Use AskUserQuestion:
Question: "Auto-merge PRs after creation? (requires GitHub auto-merge enabled on repo)"
Options:
If "Yes" → set "autoMerge": true. If "No" → omit autoMerge field.
Use AskUserQuestion:
Question: "Add an additional review prompt for candid-ship? (extra context passed to code review during ship)"
Options:
If "Yes" → follow-up: "Enter additional review prompt:" with free-text response.
If "No" → omit additionalPrompt field.
Use AskUserQuestion:
Question: "Do you use an issue tracker (Linear, Asana, Jira, etc.) and want candid-ship to auto-update issues when you ship?"
Options:
If "No, skip" → omit issueTracker field. Proceed.
If "Yes — other tracker (request support)":
Display:
Issue tracker integration currently supports Linear only. To request support for your tracker (Asana, Jira, GitHub Issues, Shortcut, etc.):
→ Open an issue: https://github.com/ron-myers/candid/issues
Tell us which tracker you use and how you'd like the workflow to behave (state name, when to trigger, etc.) and we'll prioritize accordingly.
Skipping issue tracker config for now.
Omit the issueTracker field. Proceed.
If "Yes — Linear (supported)":
Display:
Linear integration requires the official Linear MCP server (claude.ai/Linear). If it isn't installed, the issue-tracker step is skipped at ship time — the rest of the ship still runs.
Follow-up 1: "Linear team prefixes (comma-separated, e.g. DIS,ENG,DISC):" — free-text response. Split on comma, trim each entry, uppercase. If the user leaves blank, default to ["DIS", "ENG", "DISC"].
Follow-up 2: "Linear state name to set when PR is created:" — free-text response. If blank, default to "In Review". The user should match the exact state name from their Linear workspace (e.g. "In Review", "Code Review", "In Progress").
Follow-up 3: Use AskUserQuestion: "Use the default Linear MCP prompt, or customize it?"
Show the default below the question so the user can see what they're agreeing to:
Update issue {issueId}: set its state to "{state}". Update only this one issue and only its state — do not modify any other issues, fields, or properties. If the issue is already in "{state}", report success without action. If the issue is missing or inaccessible, report the error and stop.
Options:
If "Use the default": write the default prompt verbatim into the prompt field of the generated config. The user can edit .candid/config.json later. Do not omit the field — having the prompt visible in the config is a feature, not noise.
If "Customize now": Free-text follow-up: "Enter your custom prompt. Use {issueId}, {state}, and {provider} as placeholders. Required: the prompt must restrict the action to a single issue and stop on missing-issue errors (don't search for a fallback)." Show the default below as a reference baseline. Use the user's response as the prompt value.
In either case, write the resulting prompt field into the config:
"issueTracker": {
"provider": "linear",
"enabled": true,
"teamPrefixes": ["..."],
"state": "...",
"prompt": "..."
}
The skill's runtime default is identical to the value written here — the explicit-in-config approach simply makes the prompt visible to the user without changing behavior.
Use AskUserQuestion:
Question: "Configure candid-fast-ship? It's a minimal ship path that runs only the steps you enable — nothing runs by default except PR creation. (Command values are inherited from the ship block you just configured.)"
Options:
If "No, skip" → omit fastShip field. Proceed to Step 10.8.
If "Yes, configure fast ship":
Use AskUserQuestion:
Question: "Which steps should candid-fast-ship enable by default?"
Options:
If "Custom — let me choose": Ask the user to confirm each of the following with Yes/No:
ship.installCommand was configured)ship.buildCommand was configured)ship.testCommand was configured)ship.issueTracker was configured)ship.postMergeCommand was configured)Build the fastShip object from the selections. Set only fields that the user explicitly enabled to true; omit fields that are false (they default to false when absent). Always omit targetBranch from the generated config (it falls back to ship.targetBranch automatically).
For the preset options:
"fastShip": {}"fastShip": { "build": true } (omit if ship.buildCommand not configured; use {} instead with a note)"fastShip": { "build": true, "autoMerge": true } (same caveat for build)Assemble the config object from all detected and prompted values. Only include fields that were explicitly set — omit fields the user skipped (they default correctly when absent).
Show the assembled config as valid JSON. Example with all fields enabled:
⚙️ Generated config.json:
{
"version": 1,
"tone": "harsh",
"mergeTargetBranches": ["main"],
"exclude": ["dist/*", "*.min.js"],
"autoCommit": true,
"decisionRegister": {
"enabled": true
},
"ship": {
"buildCommand": "npm run build",
"testCommand": "npm test",
"targetBranch": "main",
"autoMerge": false
},
"fastShip": {
"build": true,
"autoMerge": true
}
}
Use AskUserQuestion:
Question: "Write this config to .candid/config.json?"
Options:
Ensure the .candid/ directory exists, then write both files:
mkdir -p .candid
Use the Write tool to create:
.candid/Technical.md (or the path passed via --output) — the synthesized content from Step 9.candid/config.json — the assembled config from Step 10.8Skip this substep entirely unless --optimize or --auto-optimize was passed.
If --optimize is set (interactive):
Print:
Running optimization audit on generated context…
Invoke the candid-optimize skill with no extra flags. It will display the token budget (Step 2), analyze Technical.md / excludes / register / config (Steps 3–6), and run its own interactive apply phase (Step 7) including the before/after token report.
When candid-optimize returns, continue to Step 11.3.
If --auto-optimize is set (non-interactive):
Print:
Running optimization audit and applying all recommendations…
Invoke the candid-optimize skill with the --apply-all flag. All recommendations are applied without prompting; the before/after report still prints.
When candid-optimize returns, continue to Step 11.3.
Print a summary with: Technical.md location + effort level; counts of architecture rules (and violations), naming patterns, error handling/testing/security status, gaps identified; config.json location with ship / fastShip configured-or-not; Next Steps 1-4 (review rules, address gaps, run /candid-validate-standards, run /candid-review).
If Step 11.2 ran (either --optimize or --auto-optimize): replace step 3 of "Next Steps" with Run /candid-validate-standards to check rule quality (optimization already applied) so the user knows the audit pass already happened.
If Step 11.2 was skipped: append a final hint line below the Next Steps block:
💡 Tip: run /candid-optimize to audit and tighten the generated context.
Before outputting, verify:
Use when you have an output — copy, a doc, an answer, a plan, a prompt, any text artifact — and want it made better against your goal. Runs a critique→refine loop with configurable stop conditions and auto/review-each/interactive modes. Default is a single pass using the current session context to decide what "better" means.
Fast ship for low-risk changes — runs only the steps you explicitly enable in fastShip config
Use when the code works and you want a focused pass on improving approach, clarity, and quality — distinct from candid-review's defect hunt. Each suggestion includes a concrete before/after, tradeoffs, and confidence level.
Run candid-review in a loop until all issues are resolved, with configurable auto, review-each, or interactive modes and support for ignored issues
Use when reviewing code changes before commit or PR — configurable harsh or constructive review against Technical.md standards, with categorized issues, actionable fixes, todo tracking, and optional auto-commit.
Ship your changes - review, build, test, create PR, and optionally auto-merge