~ / rigs / skullninja / coco-workflow

skullninja/coco-workflow

Autonomous spec-driven development plugin for Claude Code. Describe a feature, get merged, tested, reviewed code. Full pipeline from PRD to PR with dependency-aware task tracking, AI code review, and zero dependencies beyond bash + jq.

↗ GitHub ★ 7 MIT updated 1mo ago project Claude Code Claude plugin
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~8.5k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
1/5
No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit skullninja/coco-workflow/.claude ./rig-coco-workflow  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit skullninja/coco-workflow/skills/design .claude/skills/design
$ npx degit skullninja/coco-workflow/skills/execute .claude/skills/execute
$ npx degit skullninja/coco-workflow/skills/hotfix .claude/skills/hotfix
$ npx degit skullninja/coco-workflow/skills/import .claude/skills/import
$ npx degit skullninja/coco-workflow/skills/interview .claude/skills/interview
$ npx degit skullninja/coco-workflow/skills/tasks .claude/skills/tasks
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/skullninja/coco-workflow/main/agents/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/pre-commit-tester.md https://raw.githubusercontent.com/skullninja/coco-workflow/main/agents/pre-commit-tester.md
$ curl -fsSL --create-dirs -o .claude/agents/task-executor.md https://raw.githubusercontent.com/skullninja/coco-workflow/main/agents/task-executor.md
$ curl -fsSL --create-dirs -o .claude/agents/test-auditor.md https://raw.githubusercontent.com/skullninja/coco-workflow/main/agents/test-auditor.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (6)

Subagents (4)

code-reviewer
model: opus
Use this agent to review pull request diffs for code quality, correctness, security, and best practices. Invoke when a PR is created and needs review before merge.\n\n<example>\nContext: An issue PR h
pre-commit-tester
model: opus
Use this agent to validate UI/UX changes before committing. Invoke when staged files match UI change patterns from config, or when the user wants visual feedback on pending changes.\n\n<example>\nCont
task-executor
model: sonnet
Use this agent to execute a single tracked task with TDD, commit, and PR creation in an isolated git worktree. Dispatched by /coco:loop for parallel execution.\n\n<example>\nContext: Multiple tasks ar
test-auditor
model: opus
Use this agent to score a scoped set of test files against the test value rubric, identifying tests that defend no failure mode. Dispatched by /coco:test-audit for large suites.\n\n<example>\nContext:

Slash commands (14)

/constitution/dashboard/execute/loop/phase/planning-session/planning-triage/prd/roadmap/setup/standup/status/sync/test-audit

Permissions

deny (0)
—
ask (0)
—
allow (22)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git branch:*)
Bash(git checkout:*)
Bash(git add:*)
Bash(git commit:*)
Bash(git mv:*)
Bash(git rm:*)
Bash(git push:*)
Bash(git pull:*)
Bash(git merge:*)
Bash(git worktree:*)
Bash(git remote:*)
Bash(git stash:*)
Bash(gh pr:*)
Bash(gh issue:*)
Bash(gh project:*)
Bash(bash tests/test-tracker.sh:*)
Bash(bash -n:*)
Bash(bash:*)
Read(~/.claude/plugins/cache/**)

Similar rigs

copied ✓