by kaanozhan
ADE( Agentic Development Environment) The spec-driven environment for AI coding agents, where your planning becomes lasting, shared project context.
# Add to your Claude Code skills
git clone https://github.com/kaanozhan/FrameLast scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@electron/node-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@electron/rebuild: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@isaacs/brace-expansion: @isaacs/brace-expansion has Uncontrolled Resource Consumption",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@tootallnate/once: @tootallnate/once vulnerable to Incorrect Control Flow Scoping",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "cacache: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "electron: Electron has ASAR Integrity Bypass via resource modification",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash: lodash vulnerable to Code Injection via `_.template` imports key names",
"severity": "high"
},
{
"type": "npm-audit",
"message": "make-fetch-happen: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tmp: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape",
"severity": "high"
}
],
"status": "WARNING",
"scannedAt": "2026-05-30T15:03:23.939Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how Frame compares with popular alternatives.
Frame is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by kaanozhan. ADE( Agentic Development Environment) The spec-driven environment for AI coding agents, where your planning becomes lasting, shared project context. It has 409 GitHub stars.
Frame returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/kaanozhan/Frame" and add it to your Claude Code skills directory (see the Installation section above).
Frame is primarily written in JavaScript. It is open-source under kaanozhan on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh Frame against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The shape of software development changed, agents write the code now, but the foundation didn't: good results still come from good planning. Frame puts planning back at the center. You write a spec once, and that single spec becomes two things at once: the plan your agents follow, and the durable, shared context your project keeps across every session. Every future agent arrives knowing what was done and why no more re-explaining your architecture every time you open a terminal.
Built on Claude Code. Codex CLI work too, and because your context lives in plain, git-versioned files, it stays yours and stays readable by any tool.
As projects grow with AI agents, things fall apart fast:
These problems are manageable on small projects. On larger ones, they become blockers.
Frame solves all of this.
Frame brings a consistent structure to every project you work on. When you initialize Frame in a project, it creates:
| File | Purpose |
|---|---|
.frame/AGENTS.md |
Project rules and instructions — AI reads this automatically |
.frame/STRUCTURE.json |
Module map with intentIndex for fast file lookup |
.frame/PROJECT_NOTES.md |
Architectural decisions and context that persist across sessions |
.frame/tasks.json |
Task tracking with status, context, and acceptance criteria |
.claude/rules/frame.md |
Two lines pointing Claude Code at .frame/AGENTS.md |
Everything Frame writes lives under .frame/, plus that one pointer file. Your
project root stays yours: an existing CLAUDE.md, AGENTS.md or .cursorrules
is never read, moved or replaced, and "Remove Frame" leaves no Frame-authored
bytes behind. Needs Claude Code new enough to load .claude/rules/ — verified
with Claude Code 2.1.x; run /context in a session to confirm
.claude/rules/frame.md loaded.
Upgrading: update Frame before pulling a repository that has been migrated to
.frame/. An older Frame looks for the meta files at the project root, finds none, and reports the project as empty — and its spec phases as unstarted.
Every project gets its own isolated session — its own context, its own task list, its own notes. Switching projects in Frame means switching to a completely fresh, project-specific AI context. No bleed-over, no confusion.
This standard works with any AI tool. Claude Code loads .claude/rules/frame.md
natively at session start, which imports .frame/AGENTS.md — no launch flags, no
wrapper. For Codex CLI, Frame injects the same file via a wrapper script.
The result: any developer (or AI agent) who opens a Frame project immediately knows where everything is and what's been decided. Onboarding a new AI session to a large project takes seconds, not minutes.
One of the hardest problems in agentic development is knowing when to capture context. Session boundaries are fuzzy — you might stay in the same session for hours. Task completion is ambiguous — agents don't always signal clearly when something is done. Trying to detect "important moments" mid-session is unreliable.
Frame's approach: use git commits as the single reliable boundary.
When you commit, something real happened. It's intentional, it's deterministic, and it's a natural checkpoint you're already making. Frame builds its entire context system around this moment:
.frame/STRUCTURE.json — auto-updated via pre-commit hook, always reflects the current architecture.frame/tasks.json — task state syncs at commit time.frame/PROJECT_NOTES.md — the right moment to capture what changed and whyWhen the next session starts, these files are read automatically. The agent picks up exactly where things left off — not from a vague session transcript, but from structured, up-to-date context written at the one moment you can be certain something real was completed.
The practical implication: commit often. Small, intentional commits aren't just good git hygiene — in Frame, they're how context stays accurate and agents stay oriented.
For features that won't fit in one session, Frame ships a built-in spec workflow. Each spec is four markdown files on disk:
.frame/specs/<slug>/
spec.md what we're building
plan.md how we'll build it
tasks.md broken-down work
outcome.md what actually shipped
Describe what you want and the AI drafts the spec. /spec.plan produces an implementation plan. /spec.tasks breaks the plan into discrete tasks that import into tasks.json (tagged with source: "spec:<slug>:T<n>"). /spec.implement walks them one by one — and after each task, the agent appends 2-3 sentences to outcome.md: what shipped, what diverged from the plan, what to follow up on.
That last file is the move that makes the rest worth doing. Plans tell you intent. Code tells you reality. outcome.md tells you the story between them, written while the agent's memory was fresh — the kind of context that's normally lost the moment a session ends.
Two principles shaped this:
tasks.json workflows are untouched either way.Instead of scanning the entire codebase, Frame's intentIndex maps concepts to files:
node scripts/find-module.js github # → githubManager.js + githubPanel.js
node scripts/find-module.js terminal # → all terminal-related files
node scripts/find-module.js --list # → all features and their files
This means AI agents spend zero time searching — they go directly to the right file.
Switch between AI tools without leaving Frame:
.claude/rules/frame.md natively, which imports .frame/AGENTS.md.frame/bin/codex injects .frame/AGENTS.md as initial prompt.frame/AGENTS.md when pointed at it; the files are plain markdown and JSONMulti-AI is a principle here, not a race: Frame goes deep on Claude Code, and keeps your specs, plans, outcomes, and notes in plain markdown and JSON — so the context your work produces outlives any single tool, including Frame.
.frame/STRUCTURE.json — auto-updated on every commit via pre-commit hooks