by shinpr
Development workflows for Claude Code that keep broad exploration focused on the outcome you approved.
# Add to your Claude Code skills
git clone https://github.com/shinpr/claude-code-workflowsGuides for using ai agents skills like claude-code-workflows.
Last scanned: 5/24/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-24T07:23:57.359Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how claude-code-workflows compares with popular alternatives.
claude-code-workflows is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by shinpr. Development workflows for Claude Code that keep broad exploration focused on the outcome you approved. It has 693 GitHub stars.
Yes. claude-code-workflows passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/shinpr/claude-code-workflows" and add it to your Claude Code skills directory (see the Installation section above).
claude-code-workflows is primarily written in JavaScript. It is open-source under shinpr on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh claude-code-workflows against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
See comparison
English | 简体中文 | 日本語 | Español | 한국어 | Português (Brasil)
Claude Code can explore a codebase deeply. On non-trivial work, the harder problem is convergence. While designing an account-recovery flow, Claude may find a real inconsistency in token handling and spend most of the design on it, leaving the requested recovery behavior vague.
claude-code-workflows keeps that exploration pointed at an agreed result. It agrees on the outcome and exclusions before design, checks designs against the repository, verifies each task before commit, and, on larger changes, independently reviews the finished implementation to make sure it delivers the agreed result, does not include unnecessary changes, and has no serious functional, reliability, or security problems. Within that scope, Claude chooses the implementation details from the codebase.
Use Claude Code directly when the outcome and safe implementation boundary are already clear. Use these workflows when a change needs scope agreement, durable design decisions, a reliable handoff between contexts, or independent verification.
The workflow adds agent calls and artifacts, so it should earn that cost. Use it when a real side finding could pull a larger change away from its intended result, a design could be internally consistent but miss the requested behavior, or a passing test could fail to observe what it claims to prove. When a change does not need every check, lite mode runs fewer of them.
Once the implementation scope is approved, Claude carries the tasks through focused verification, repository quality checks, commits, and final review without asking for routine implementation decisions. It asks the user only when the agreed product outcome or exclusions must change, or when an irreversible external action needs approval; Claude handles technical design and implementation choices. Because the process is packaged as a Claude Code plugin, a team can apply the same controls across repositories without prescribing Claude's steps.
Requires a Claude Code release with plugin marketplace support.
| What do you need? | Start with | Plugin |
|---|---|---|
| Deliver a backend, API, CLI, or general change end to end | /recipe-implement |
dev-workflows |
| Design a backend or general change before implementation | /recipe-design |
dev-workflows |
| Design and build a React / TypeScript frontend | /recipe-front-design → /recipe-front-plan → /recipe-front-build |
dev-workflows-frontend |
| Deliver a backend and React frontend change together | /recipe-fullstack-implement |
dev-workflows-fullstack |
| Review a completed implementation against the agreed outcome | /recipe-review or /recipe-front-review |
dev-workflows or dev-workflows-frontend |
| Set repository-specific quality rules | /recipe-quality-profile |
Any workflow plugin |
| Investigate a problem before choosing a fix | /recipe-diagnose |
Any workflow plugin |
| Document an existing system from its code | /recipe-reverse-engineer |
dev-workflows or dev-workflows-fullstack |
| A throwaway experiment or prototype | Use Claude Code directly | None |
# 1. Start Claude Code
claude
# 2. Add the marketplace
/plugin marketplace add shinpr/claude-code-workflows
Install the plugin that matches your project. If the install tells you to run /reload-plugins, do that before invoking the recipe.
# Backend or general
/plugin install dev-workflows@claude-code-workflows
/recipe-implement "Add rate limiting to the public API"
# Frontend
/plugin install dev-workflows-frontend@claude-code-workflows
/recipe-front-design "Add account recovery screens"
# Full-stack
/plugin install dev-workflows-fullstack@claude-code-workflows
/recipe-fullstack-implement "Add user authentication with JWT + login form"
Install only one workflow plugin. dev-workflows-fullstack already contains the backend and frontend workflows. If you previously used full-stack recipes from dev-workflows, migrate to dev-workflows-fullstack.
/recipe-front-design stops after the applicable UI Spec and Design Doc are reviewed and approved. Run /recipe-front-plan and /recipe-front-build when you are ready to continue. For a backend or general change, /recipe-design, /recipe-plan, and /recipe-build provide the same staged path.
Claude Code supports project-scoped marketplaces and plugins. Commit the resulting .claude/settings.json so contributors are prompted to use the same workflow plugin.
claude plugin marketplace add shinpr/claude-code-workflows --scope project
claude plugin install dev-workflows-fullstack@claude-code-workflows --scope project
Replace dev-workflows-fullstack with the plugin that matches the repository. See the Claude Code plugin documentation for project and managed installation options.
flowchart LR
A[Request] --> B[Agree on outcome and exclusions]
B --> C{One evident implementation path?}
C -->|Yes| S[Direct task cycle]
S --> J[Complete]
C -->|No| D[Inspect, design, and review]
D --> E[Approve implementation scope]
E --> F[Per task: implement, verify, quality-check, commit]
F --> I[Independent implementation and security review]
I -->|Correction| F
I -->|Boundary changed| B
I -->|Passed| J[Complete]
The route depends on how many product and design decisions the change involves, not on file count. A change with one outcome that follows an existing pattern within one responsibility goes straight to a task cycle. A change that crosses responsibilities or needs a lasting design decision first gets a reviewed Design Doc and Work Plan, plus a PRD, UI Spec, or ADR when one of its decisions calls for it.
Review suggestions do not become work automatically. The main session decides which findings belong to the agreed outcome and declines the rest with a reason.
/recipe-implement "Lite mode. Add rate limiting to the public API"
Ask for lite mode in the request to any recipe. It keeps the same phases and approval stops but runs fewer checks: Design Docs are not checked against the repository or against each other, and the separate security review is skipped. Repository quality checks run once after the last task instead of before every commit, and the final code review still runs. Lite mode stays on for the rest of the session until you ask Claude to drop it.
The incremental sync feature in mcp-local-rag was a 42-file change across filesystem scanning, storage, and both the CLI and MCP surfaces. An independent security review sent the implementation back twice. It caught file reads happening before validation and a path-containment escape through a symlinked parent.
The run began with an existing Work Plan that referred to an ADR and Design Doc that were not present, leaving the approved source for its technical decisions unclear. The user chose to treat the Work Plan as the source of truth, and the recipe divided it into 13 planned tasks. The final implementation included the changes needed to verify the approved behavior, while the PR records why watch mode and persistent jobs were left out.
/recipe-implement "Add rate limiting to the public API"
The recipe scopes the change, inspects the current implementation, creates only the documents required by its decisions, pauses when a decision is needed, and carries the plan through implementation and final review.
# Backend or general
/recipe-design "Design rate limiting for the public API"
/recipe-plan
/recipe-build
# React frontend
/recipe-front-design "Build a user profile dashboard"
/recipe-front-plan
/recipe-front-build
The design recipes inspect the existing code, confirm the scope, create the required documents, run an independent consistency review, and stop for approval. Planning and implementation can continue later, in a new context or by another contributor, from those approved artifacts. Each task in the Work Plan cites the design decisions and acceptance criteria it must satisfy, and the final reviewers check the completed code against those same sources instead of the earlier conversation.
The frontend path adds UI analysis and a UI Spec when UI structure or behavior remains to be designed, plus component architecture, React Testing Library, and TypeScript checks.
For example, two dashboard components may each handle loading correctly while the combined screen has no defined behavior when one is loading and the other has failed. The UI Spec records that state combination and traces it into design and test work before integration.
/recipe-fullstack-implement "Add user authentication with JWT + React login form"
When the change has multiple independent product outcomes, one PRD covers the whole feature. Backend and frontend design stay se