by FullAgent
Fulling is an AI-powered Full-stack Engineer Agent. Built with Next.js, Claude, shadcn/ui, and PostgreSQL. Use kubernetes as infra.
# Add to your Claude Code skills
git clone https://github.com/FullAgent/fullingLast scanned: 4/24/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-04-24T06:08:13.014Z",
"semgrepRan": false,
"npmAuditRan": false,
"pipAuditRan": true
}fulling is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by FullAgent. Fulling is an AI-powered Full-stack Engineer Agent. Built with Next.js, Claude, shadcn/ui, and PostgreSQL. Use kubernetes as infra. It has 2,439 GitHub stars.
Yes. fulling passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/FullAgent/fulling" and add it to your Claude Code skills directory (see the Installation section above).
fulling is primarily written in TypeScript. It is open-source under FullAgent on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh fulling against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Fulling is building dedicated AI workspaces: persistent environments that combine skills, files, memory, scripts, and runtime. The current v3 foundation provides the identity and Kubernetes credential boundary required for that product model.
SelfSubjectReviewThe repository intentionally contains no compatibility layer for the previous product model or authentication system.
Read docs/architecture.md for the target Workspace model. The user-level kubeconfig in this foundation is not the final Workspace Runtime ownership model.
The public application does not require PostgreSQL or an OAuth provider. The legacy authenticated workspace additionally requires PostgreSQL and a GitHub OAuth App.
Configure the GitHub OAuth callback as:
${BETTER_AUTH_URL}/api/auth/callback/github
npm ci
npm run dev
This starts the public application with sign-in disabled. To exercise the legacy authenticated workspace instead:
cp .env.template .env.local
# Fill in the database, Better Auth, and GitHub values.
npm run prisma:migrate
npm run dev
Open http://localhost:3000.
This release uses a new baseline schema. Run it against a new database or an explicitly reset database; it does not migrate v2 data.
npm run dev # Start the development server
npm run build # Generate Prisma client and build
npm run lint # Run ESLint
npm test # Run Vitest
npm run test:e2e # Run Playwright
npm run prisma:format # Format the Prisma schema
npm run prisma:validate # Validate the Prisma schema
npm run prisma:migrate # Deploy the baseline migration
Kubeconfigs are stored as plaintext in PostgreSQL. Database read access grants access to users' Kubernetes credentials. Browser-facing APIs never return saved content, and logs must not contain tokens, keys, certificates, or kubeconfig content.
Validation rejects executable credential plugins, auth-provider plugins, local file credential fields, proxy configuration, non-HTTPS API servers, redirects, and anonymous identities. Authenticated users may still configure an HTTPS API server on any network address. This authenticated outbound-request/SSRF boundary is an explicit deployment decision.
Before replacing a v2 deployment, follow docs/v2-resource-inventory.md. Resetting the Fulling database does not delete Kubernetes resources created by v2.
Use docs/github-oauth-verification.md to verify a real OAuth application before release.
Fulling can use Vercel's native Next.js deployment without a vercel.json file.
The public application builds and starts without environment variables. The
current GitHub sign-in, database-backed workspace, and kubeconfig flows remain
disabled until their complete legacy configuration is present.
Follow docs/vercel-deployment.md for the complete project setup, zero-configuration behavior, verification steps, and rollback procedure.