Skip to content

About

🎻 11 professional software-engineering skills for Claude Code β€” backend, frontend, security, testing, deployment & a master orchestrator that takes a project to production-ready.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

9 Commits

Folders and files

Repository files navigation

Coding Orchestra β€” Agent Skills for shipping production web apps

🎻 Coding Orchestra

Seven Agent Skills that help a coding agent take a Next.js / serverless web app to production. They work in Claude Code, Codex and any other agent that reads the open Agent Skills format.

Release License: MIT Skills Languages Agent Skills PRs Welcome

πŸ‡ΉπŸ‡· TΓΌrkΓ§e iΓ§in β†’ README.tr.md Β· Coming from v1 (11 skills)? β†’ Upgrading from v1

Current models already know general engineering practice. What they lack on a real project is the knowledge specific to the stack and the job: how Server Actions, Supabase row level security or Vercel cron fail in production, where to stop and ask before touching something irreversible, what a useful audit report looks like. These skills provide that knowledge, and nothing else, and they load only when the task needs them.


Quick start

Claude Code (plugin):

/plugin marketplace add hamzaciftci/coding-orchestra
/plugin install coding-orchestra@coding-orchestra

Claude Code or Codex (installer script):

git clone https://github.com/hamzaciftci/coding-orchestra.git
cd coding-orchestra
./install.sh --agent all        # Windows: ./install.ps1 -Agent all

Then describe the work:

Check this app for security holes before we launch. Report only, don't change code.

The agent picks security-audit from its description. Other install options, including Turkish and project-scoped installs, are under Install.


The skills

Skill Use it when What it adds
production-delivery You want a whole project audited, finished or made production-ready An audit across six lenses (in parallel when the agent supports subagents), a prioritized roadmap, an approval gate, fixes in verified vertical slices and a final go / no-go report
security-audit You want vulnerabilities found or closed in an app you own An inventory script for routes, Server Actions, cron, middleware coverage and row level security; Next.js, Supabase, Prisma and Stripe pitfalls; an 8-field finding format with confidence labels
deployment-readiness You are about to deploy, a production build fails, or a deployment needs verifying An env-variable inventory script (names only, never values), Vercel / serverless / edge pitfalls, a release checklist with evidence, a smoke-check script
backend-engineering You add or change an endpoint, Server Action, webhook, cron job, auth or payment flow A definition of done for server code and the places where serverless differs from a long-running server
database-api-design You change a schema, write a migration or change an API contract Staged expand/contract recipes, lock-safe DDL, Prisma and Supabase traps, compatibility rules
frontend-engineering You build UI, or an interface needs to look and feel professional A definition of done for UI, App Router notes, a polish review method
testing-qa You add tests, plan QA or verify a fix A risk-first test plan, an authorization matrix, how to test webhooks, cron and Server Actions for real

Written for Next.js (App Router) Β· React Β· TypeScript Β· Tailwind Β· Node serverless Β· PostgreSQL / Supabase / Prisma Β· Vercel Β· Stripe. The method in each skill carries over to other stacks; the reference detail does not.

production-delivery works on its own and goes deeper when the other six are installed. There is deliberately no skill for general coding or bug fixing: current models do that well without one, and a skill that claims every coding task costs context on all of them.

Security work is defensive. The skills are for auditing and fixing systems you own or are authorized to assess, and they tell the agent not to write weaponized exploits or probe third-party hosts.


Usage

Describe the work; the agent matches it to a skill's description:

Audit this project end to end and give me a roadmap. Don't change code until I approve the scope.
We deploy on Friday. What blocks the release?
Rename users.fullname to display_name without downtime.
Add tests for the checkout flow, starting with whatever is most likely to break.

Or call a skill by name:

Agent Explicit call
Claude Code (installer or manual install) /security-audit
Claude Code (plugin) /coding-orchestra:security-audit
Codex $security-audit, or pick it from /skills

The helper scripts also run on their own, with Node 18+ and no dependencies:

node skills/security-audit/scripts/attack-surface.mjs path/to/project
node skills/deployment-readiness/scripts/env-inventory.mjs path/to/project
node skills/deployment-readiness/scripts/smoke.mjs https://staging.example.com / /login /api/health

Built to the Anthropic and OpenAI guidance

v2 follows the published guidance for Agent Skills from both vendors, so the same folder works unchanged in both agents:

Guidance How Coding Orchestra applies it
Use only the fields defined by the Agent Skills specification Frontmatter is limited to name, description, license, compatibility and metadata. The non-standard trigger: field from v1 is gone.
The description is written in the third person and says what the skill does and when to use it, since that is all the agent sees before the skill loads Every description names its scope, then a "Use when…" clause. Out-of-scope requests (bug fixes, refactors, CI) are left for the agent to handle without a skill.
Keep SKILL.md concise (well under 500 lines); move detail into files that load only when needed (progressive disclosure), one level deep Each SKILL.md is under 60 lines. Stack-specific detail lives in references/, linked directly from SKILL.md.
Explain the reasoning instead of stacking rigid rules, and leave the method to the model Skills describe the outcome, the boundaries and the judgment calls, with reasons. No all-caps MUST lists.
Use scripts for deterministic, repeatable work Inventory and smoke-check scripts in scripts/, run by the agent and readable on their own.
Codex reads optional display metadata from agents/openai.yaml Each skill ships one with a display name, short description and default prompt.
Put always-on project rules in AGENTS.md (Codex) or CLAUDE.md (Claude Code), not in a skill A six-line working agreement covers scope, approval points, secret handling and honest reporting.
Evaluate skills instead of assuming they help evals/ holds a validator, a context-cost comparison, a selection test and a seeded-flaw audit benchmark.

Anatomy of one skill:

skills/security-audit/
β”œβ”€β”€ SKILL.md              # ~50 lines: outcome, approach, boundaries, judgment calls
β”œβ”€β”€ references/           # loaded only when the task needs them
β”‚   β”œβ”€β”€ stack-pitfalls.md
β”‚   └── report-template.md
β”œβ”€β”€ scripts/
β”‚   └── attack-surface.mjs
└── agents/openai.yaml    # display metadata for Codex

Results

Measured on 2026-10-05 against v1; full numbers and their limits are in evals/RESULTS.md.

  • Less context. When a skill triggers, its body is 57–86% smaller than the v1 file it replaces, and general coding or bug-fix requests now load nothing. The always-on skill listing grew by 23%, because descriptions now say when to use each skill.
  • Better selection. The right skill was picked for 31–32 of 32 in-scope requests, and no skill loaded on any of 14 out-of-scope requests (v1 loaded one on 4–6 of them).
  • Audit recall depends on the model. On Sonnet every condition, with or without a skill, found all 30 seeded flaws; what improved was the report. On Haiku, v2 found 25.7 of 30 on average against 21.5 for v1 and 19.5 with no skill, mostly on stack-specific flaws.
  • Not cheaper to run. Tokens per audit were about the same as v1.

Samples are small (two or three runs per cell), the benchmark fixture was written by the skills' author, and nothing has been run inside Codex yet.


Install

English is the default. Each route has a Turkish variant.

Claude Code plugin

/plugin marketplace add hamzaciftci/coding-orchestra
/plugin install coding-orchestra@coding-orchestra       # English
/plugin install coding-orchestra-tr@coding-orchestra    # Turkish

Claude Code asks for an install scope (user, project or local). Plugin skills are namespaced: /coding-orchestra:security-audit, /coding-orchestra-tr:security-audit.

Installer script (Claude Code, Codex or both)

./install.sh                     # Claude Code, English -> ~/.claude/skills
./install.sh --agent codex       # Codex                -> ~/.agents/skills
./install.sh --agent all --tr    # both, Turkish

Windows PowerShell: ./install.ps1, ./install.ps1 -Agent codex, ./install.ps1 -Agent all -Tr.

Flag (sh / ps1) Effect
--agent claude|codex|all / -Agent Which agent's skills directory to install into (default claude)
--lang en|tr, --en, --tr / -Lang, -En, -Tr Language (default en)
--project / -Project Install into the current project (.claude/skills, .agents/skills) so teammates get the skills from the repo
--dir PATH / -Dir PATH Install into the project at PATH
--skill NAME / -Skill a,b Install only the named skills
--prune-legacy / -PruneLegacy Remove v1 skills that no longer exist
--force / -Force Replace a same-named skill that did not come from Coding Orchestra
--dry-run / -DryRun Show what would happen without changing anything

The installer only replaces Coding Orchestra skills. A different skill with the same name is left alone unless you pass --force.

Manual

Copy any skill folder into the directory your agent scans. Each folder is self-contained.

cp -r skills/security-audit ~/.claude/skills/     # Claude Code
cp -r skills/security-audit ~/.agents/skills/     # Codex

Turkish skills are in locales/tr/skills/. Both languages use the same skill names, so install one language per location.

Optional: the working agreement

Skills load on demand. For the few rules you want in every session, copy the section in templates/AGENTS.md into your project's AGENTS.md (Codex and others) or CLAUDE.md (Claude Code). Turkish: locales/tr/templates/AGENTS.md.

Claude Code and Codex both pick up newly installed skills on their own. If a skill does not show up, run /reload-plugins after a plugin install in Claude Code, or start a new session.


Upgrading from v1

v1 was eleven long rulebooks written for models that needed step-by-step management. v2 keeps what still changes behaviour and drops the rest.

v1 skill v2
production-delivery production-delivery (rewritten)
fullstack-delivery merged into production-delivery
ui-ux-polish merged into frontend-engineering (polish review)
security-audit, backend-engineering, database-api-design, deployment-readiness, frontend-engineering, testing-qa same names, rewritten
general-coding retired; replaced by the working agreement
bug-fix-refactor retired; current models do this without a skill

Other breaking changes:

  • English moved to skills/ and is now the installer default. Turkish moved to locales/tr/skills/; pass --tr to install it.
  • The trigger: frontmatter field was removed.

To upgrade an existing install and remove the retired skills:

git pull
./install.sh --prune-legacy          # add --tr to keep Turkish; Windows: ./install.ps1 -PruneLegacy

Repository layout

coding-orchestra/
β”œβ”€β”€ skills/                  # English skills (also the Claude Code plugin's skills)
β”œβ”€β”€ locales/tr/              # Turkish skills, plugin manifest and working agreement
β”œβ”€β”€ templates/AGENTS.md      # optional always-on working agreement
β”œβ”€β”€ .claude-plugin/          # plugin and marketplace manifests
β”œβ”€β”€ evals/                   # validator, context cost, selection test, audit benchmark
β”œβ”€β”€ install.sh, install.ps1
└── README.md, README.tr.md, CONTRIBUTING.md, CHANGELOG.md, LICENSE

Contributing

See CONTRIBUTING.md. In short: add knowledge the model does not already have, keep SKILL.md lean, change English and Turkish together, and run node evals/validate.mjs before every commit.

License

MIT Β© Hamza Γ‡iftΓ§i.


Not affiliated with Anthropic or OpenAI. "Claude" and "Claude Code" are trademarks of Anthropic; "Codex" is a trademark of OpenAI.

About

🎻 11 professional software-engineering skills for Claude Code β€” backend, frontend, security, testing, deployment & a master orchestrator that takes a project to production-ready.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages