By tartinerlabs
Automates git workflows, GitHub operations, security audits, and code quality enforcement for JavaScript/TypeScript projects, including conventional commits, branch management, PR creation, npm supply chain hardening, GitHub Actions audits, file naming and project structure audits, Tailwind CSS checks, and testing with Vitest.
Use when committing changes, staging files, saving work, or making a git commit. Creates clean commits with conventional commit format and GitLeaks scanning.
Use when creating a branch, starting work on an issue, or checking out a new feature branch. Validates branch naming and links to GitHub issues automatically.
Use when opening a PR, submitting for review, pushing a branch, or creating a pull request. Pushes and creates GitHub PRs with auto-assignment and description.
Use when hardening npm supply chain, pinning dependency versions, adding .npmrc security flags, or setting up Renovate. Locks down install-time scripts, registries, version ranges, and CI checks.
Use when adding CI/CD, creating workflows, auditing GitHub Actions, or fixing action pinning. Creates and audits workflows for SHA pinning and permissions.
Uses power tools
Uses Bash, Write, or Edit tools
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Powertools for coding agents: git workflows, GitHub automation, code quality, and project tooling. Each skill ships with modular, independently editable rules for deep, opinionated guidance.
rules/ directories. Rules can be added, removed, or edited independently without touching the main skill logic.security, github-actions, tailwind, and refactor produce structured severity-graded reports, then auto-fix issues.commit, security, and setup skills all enforce GitLeaks secret detection as a first-class concern.Install the plugin for your agent, then invoke skills through that agent's native skill or command interface.
| Skill | Description |
|---|---|
| commit | Clean git commits with conventional commit detection and GitLeaks secret scanning |
| create-branch | Create and checkout a branch with naming validation and GitHub issue linking |
| Skill | Description |
|---|---|
| create-pr | Push branch and create a pull request with structured description and auto-assignment |
| github-issues | Create, update, query, and comment on GitHub issues with MCP |
| github-actions | Create and audit GitHub Actions workflows with SHA pinning, permissions, and caching checks |
| Skill | Description |
|---|---|
| deps | Harden npm supply chain with .npmrc flags, version pinning, and Renovate config |
| refactor | Audit and refactor TypeScript/JavaScript code for dead code, deep nesting, type assertions, and design patterns |
| security | OWASP Top 10 security audit with GitLeaks secret detection and dependency vulnerability scanning |
| tailwind | Audit and fix Tailwind CSS v4 anti-patterns for spacing, 8px grid, mobile-first, and GPU animations |
| testing | Write and run tests with Vitest and React Testing Library for JS/TS projects |
| Skill | Description |
|---|---|
| setup | Add Biome, Husky, commitlint, lint-staged, GitLeaks, and TypeScript to JS/TS projects |
| project-structure | Audit project directory structure for colocation, grouping, and anti-pattern detection |
| naming-format | Audit and fix filename and export naming conventions for consistency |
| update-project | Update and maintain CLAUDE.md, README.md, agents, skills, and rules to match current project state |
Agents invoke skills autonomously with an isolated worktree. Invoke with claude agent run <name>.
| Agent | Description |
|---|---|
| deps | Autonomous supply chain hardening — runs the deps skill in an isolated worktree and outputs a structured summary |
claude plugin install tartinerlabs/skills
This repository includes repo-scoped Codex plugin metadata in .codex-plugin/plugin.json and .agents/plugins/marketplace.json.
To use it in Codex:
tartinerlabs from the repo marketplaceThis repository includes Cursor plugin metadata in .cursor-plugin/plugin.json and .cursor-plugin/marketplace.json.
For local development, install the plugin with Cursor's plugin flow or copy the repository into Cursor's local plugin directory:
mkdir -p ~/.cursor/plugins/local
ln -s "$(pwd)" ~/.cursor/plugins/local/tartinerlabs
npx claudepluginhub tartinerlabs/skills --plugin tartinerlabsHarness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.
Tools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.
Comprehensive feature development workflow with specialized agents for codebase exploration, architecture design, and quality review
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.