by CloudAI-X
Universal Claude Code workflow plugin with agents, skills, hooks, and commands
# Add to your Claude Code skills
git clone https://github.com/CloudAI-X/claude-workflow-v2Guides for using ai agents skills like claude-workflow-v2.
Last scanned: 4/28/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-04-28T06:30:22.865Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how claude-workflow-v2 compares with popular alternatives.
claude-workflow-v2 is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by CloudAI-X. Universal Claude Code workflow plugin with agents, skills, hooks, and commands. It has 1,418 GitHub stars.
Yes. claude-workflow-v2 passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/CloudAI-X/claude-workflow-v2" and add it to your Claude Code skills directory (see the Installation section above).
claude-workflow-v2 is primarily written in Python. It is open-source under CloudAI-X on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh claude-workflow-v2 against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A universal Claude Code workflow plugin with specialized agents, skills, hooks, and mode commands for any software project. Compatible with skills.sh — works with Claude Code, Cursor, Codex, and 35+ AI agents.
npx skills add CloudAI-X/claude-workflow-v2
Installs skills to Claude Code, Cursor, Codex, Windsurf, Cline, and 35+ other AI agents automatically.
npx install-claude-workflow-v2@latest
Copies agents, commands, skills and hook scripts into .claude/ and registers the hooks in .claude/settings.json (existing files and settings are kept). Two differences from a plugin install: commands are not namespaced (/commit instead of /project-starter:commit), and permissionMode: acceptEdits on the debugger, docs-writer, refactorer and test-architect agents takes effect (Claude Code ignores that field for plugin agents).
# Clone the plugin
git clone https://github.com/CloudAI-X/claude-workflow-v2.git
# Run Claude Code with the plugin
claude --plugin-dir ./claude-workflow-v2
import { query } from "@anthropic-ai/claude-agent-sdk";
for await (const message of query({
prompt: "Hello",
options: {
plugins: [{ type: "local", path: "./claude-workflow-v2" }],
},
})) {
// Plugin commands, agents, and skills are now available
}
# Add this repository as a marketplace, then install the plugin from it
claude plugin marketplace add CloudAI-X/claude-workflow-v2
claude plugin install project-starter@claude-workflow
After loading the plugin, verify it's working:
> /plugin
Tab to Installed - you should see project-starter listed.
Tab to Errors - should be empty (no errors).
These commands become available:
/project-starter:architect # Architecture-first mode
/project-starter:rapid # Ship fast mode
/project-starter:commit # Auto-generate commit message
/project-starter:verify-changes # Multi-agent verification
| Component | Count | Description |
|---|---|---|
| Agents | 7 | Specialized subagents for code review, debugging, security, etc. |
| Commands | 26 | Slash commands for workflows, output styles, planning, and onboarding |
| Skills | 14 | Knowledge domains with on-demand context loading |
| Hooks | 14 | Automation scripts for formatting, security, metrics, and notifications |
Auto-commit your changes:
> /project-starter:commit
Looking at staged changes...
✓ Created commit: feat(auth): add JWT refresh token endpoint
Full git workflow:
> /project-starter:commit-push-pr
✓ Committed: feat: add user dashboard
✓ Pushed to origin/feature/dashboard
✓ Created PR #42: https://github.com/you/repo/pull/42
Verify before shipping:
> /project-starter:verify-changes
Spawning verification agents...
├─ build-validator: ✓ Build passes
├─ test-runner: ✓ 42 tests pass
├─ lint-checker: ⚠ 2 warnings (non-blocking)
└─ security-scanner: ✓ No vulnerabilities
Ready to ship!
Agents spawn automatically based on your request:
You say: "The login is broken, users get 401 errors"
[debugger agent activated]
→ Checking auth middleware... found issue
→ Token validation uses wrong secret in production
→ Fix: Update AUTH_SECRET in .env.production
You say: "Review my changes"
[code-reviewer agent activated]
→ Analyzing 3 files changed...
✓ Logic is correct
⚠ Missing null check on line 42
⚠ Consider adding rate limiting to this endpoint
You say: "Add authentication to the API"
[orchestrator agent activated]
→ Breaking down into subtasks:
1. Design auth schema (applying the designing-architecture skill)
2. Implement JWT middleware
3. Add login/register endpoints
4. Write tests (spawning test-architect)
5. Update API docs (spawning docs-writer)
Skills provide domain knowledge automatically:
You ask: "How should I structure the payment service?"
[designing-architecture skill applied]
→ Recommending hexagonal architecture
→ Payment providers as adapters
→ Core domain isolated from infrastructure
You ask: "Make this endpoint faster"
[optimizing-performance skill applied]
→ Adding database indexes
→ Implementing response caching
→ Using pagination for large results
Hooks run automatically on events:
Security block (pre-edit):
🚫 BLOCKED - Security issue detected in src/config.ts:
- Potential API key detected → Move to .env file and use environment variables (e.g., process.env.API_KEY)
Auto-format (post-edit):
The edited file is formatted silently with the project's own formatter; the hook prints nothing.
Desktop notifications:
🔔 "Claude needs input" - when waiting for your response
🔔 "Task complete" - when finished
All commands use the format /project-starter:<command>.
| Command | Mode |
|---|---|
/project-starter:architect |
System design mode - architecture before code |
/project-starter:rapid |
Fast development - ship quickly, iterate |
/project-starter:mentor |
Teaching mode - explain the "why" |
/project-starter:review |
Code review mode - strict quality |
| Command | Purpose |
|---|---|
/project-starter:commit |
Auto-generate conventional commit message |
/project-starter:commit-push-pr |
Commit → Push → Create PR (full workflow) |
/project-starter:quick-fix |
Fast fix for lint/type errors |
/project-starter:add-tests |
Generate tests for recent changes |
/project-starter:lint-fix |
Auto-fix all linting issues |
/project-starter:sync-branch |
Sync with main (rebase or merge) |
/project-starter:summarize-changes |
Generate standup/PR summaries |
| Command | Purpose |
|---|---|
/project-starter:verify-changes |
Multi-subagent adversarial verification |
/project-starter:validate-build |
Build process validation |
/project-starter:run-tests |
Tiered test execution |
/project-starter:lint-check |
Code quality checks |
/project-starter:security-scan |
Security vulnerability detection |
/project-starter:code-simplifier |
Post-implementation cleanup |
| Command | Purpose |
|---|---|
/project-starter:parallel-review |
Review multiple files/dirs via subagents |
/project-starter:parallel-analyze |
Multi-perspective analysis via subagents |
| Command | Purpose |
|---|---|
/project-starter:plan |
Persistent PLAN.md with phase tracking |
/project-starter:refactor-guided |
4-phase systematic refactoring with safety |
/project-starter:dependency-upgrade |
Safe dependency upgrades with rollback |
| Command | Purpose |
|---|---|
/project-starter:tutorial |
Interactive guided tutorial for new users |
/project-starter:bootstrap-repo |
10-agent parallel repo exploration |
/project-starter:save-session-learnings |
Persist session discoveries to docs |
/project-starter:metrics |
Summarise the per-turn records in .claude/agent-metrics.jsonl |
Agents are specialized subagents that Claude spawns automatically based on your task.
| Agent | Purpose | Auto-Triggers |
|---|---|---|
orchestrator |
Coordinate multi-step tasks | "improve", "enhance", "build", "architecture", complex tasks |
code-reviewer |
Review code quality | "review", "PR review", "lint", code changes |
debugger |
Systematic bug investigation | Errors, crashes, memory leaks, timeouts, race condit |