A Simple and Universal Product Rehearsal Engine, Speccing Anything. 简洁通用的产品推演引擎,推演万物。
# Add to your Claude Code skills
git clone https://github.com/xiaojilele-glitch/WhyBuddyLast scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@chevrotain/cst-dts-gen: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@chevrotain/gast: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@mermaid-js/parser: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@protobufjs/utf8: protobufjs has overlong UTF-8 decoding",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "axios: Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF",
"severity": "high"
},
{
"type": "npm-audit",
"message": "body-parser: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "chevrotain: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "dockerode: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "engine.io: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "engine.io-client: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "express: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "follow-redirects: follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "langium: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash: lodash vulnerable to Code Injection via `_.template` imports key names",
"severity": "high"
},
{
"type": "npm-audit",
"message": "lodash-es: Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "protobufjs: Arbitrary code execution in protobufjs",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "qs: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "socket.io-adapter: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite-node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "xlsx: Prototype Pollution in sheetJS",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-05-30T15:15:18.985Z",
"npmAuditRan": true,
"pipAuditRan": true
}WhyBuddy is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by xiaojilele-glitch. A Simple and Universal Product Rehearsal Engine, Speccing Anything. 简洁通用的产品推演引擎,推演万物。. It has 364 GitHub stars.
WhyBuddy failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/xiaojilele-glitch/WhyBuddy" and add it to your Claude Code skills directory (see the Installation section above).
WhyBuddy is primarily written in TypeScript. It is open-source under xiaojilele-glitch on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh WhyBuddy against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A slide rule is an engineer’s analog calculator: scales, a cursor, and alignment before you trust a number.
SlideRule is the same idea for product decisions — not a magic “one-click app factory,” but a rehearsal instrument:
If AI says “done,” that still does not count. The gate has to pass.
You enter one sentence. SlideRule rehearses a complete product plan — then lets you run it.
Five-system model · Evidence-gated artifacts · Publish closure · Browser live runtime
Fully visible · Fully exportable · Fully backed by an evidence trail
You spend days writing a PRD, weeks aligning the team, and months before you know whether the direction is even right.
Enter an idea → one coffee’s worth of real multi-loop deliberation, every step visible → full rehearsal → decide whether it is worth building → if not, move on without months of sunk cost.
| SlideRule is | SlideRule is not |
|---|---|
| A product rehearsal engine (intent → gated plan → previewable app) | A pure code agent (Devin / Cursor-style repo labor) |
| A business-structure generator (data · RBAC · workflow · pages · AIGC) | A chatbot / workflow builder alone (Dify / n8n) |
| A trust-first system: gates, evidence, fail-closed tools | An unconstrained “vibe UI” generator with no publish bar |
Closest mental models people use: “v0/Lovable for the generation surface, Power Platform–like business structure, Manus-like long deliberation — ending in a gated app model, not a git repo.”
The static demo runs entirely in your browser — no backend, no key, nothing to install:
What you can do there:
A consolidated 16-screen photo wall from SlideRule example rehearsals.
Watch the Full Rehearsal Demo
TRAE SOLO-based product rehearsal automation: from a one-sentence idea to executable specs.
Click the video cover above to open the Bilibili demo.
One sentence in → multi-loop reasoning over a capability pool (evidence search, risk analysis, counter-arguments, synthesis, reporting…) → a five-system model (data model · RBAC · workflow · pages · AIGC) → ships only when publish closure holds 6/6 evidence.
An AI claiming something is done does not count. Only artifacts that pass deterministic gates count.
flowchart LR
U["一句话意图<br/>One-sentence intent"] --> ORCH["Orchestrator<br/>rules + Agentic Pick"]
ORCH --> PAR["轮内并行批<br/>parallel caps per loop<br/>(synthesis/report barriered)"]
PAR --> GATE{"证据信任门<br/>structure gates · G-GROUND"}
GATE -->|gated_pass| STATE[("产物库 STATE<br/>trustLevel · stale tracking")]
GATE -->|fail| FEED["错误回喂重试<br/>error-fed retry"]
FEED --> PAR
STATE --> ECTX["证据上下文管道<br/>evidence context pipeline<br/>(only gated artifacts injected)"]
ECTX --> PAR
STATE --> CLOSE{"发布闭环<br/>publish closure 6/6"}
CLOSE -->|closed| APP["可运行应用<br/>Browser Live Runtime"]
CLOSE -->|blocked| AWAIT["AWAIT 停泊<br/>clarify → re-enter"]
AWAIT --> ORCH
What makes it different from “an LLM with a long prompt”:
| Mechanism | What it does |
|---|---|
| Evidence trust gate | Every artifact passes structural + grounding gates before it earns gated_pass; failures re-ask with validator errors |
| Evidence context pipeline | Downstream reasoning is fed only gated upstream artifacts, priority-packed under budget with honest omission notes |
| Publish closure | Ships only when all six skills (dataModel · RBAC · workflow · page · AIGC · appBundle) hold evidence — otherwise parks at AWAIT |
| Real tools | web.search and code.run (E2B sandbox, fail-closed without a key) via an MCP-style registry |
| Blind-judged upgrades | Engine changes ship with paired blind evals (A/B, position-swapped) — e.g. agentic pick 4:0, evidence pipeline 2:0 |
Deep dives: V5.7 architecture (Chinese) · five-system generation eval · live-runtime blueprint
The rehearsed model is not just diagrams — the browser renders it into an operable system. The five-system JSON is the schema: zero backend, zero database for the runtime preview.
| Studio home — brand sidebar, session gallery, guided examples | X-ray cursor (游标) — hover any element and read five-system declarations: fields, roles, workflow nodes |
| Live workflow — role-colored nodes; running instances light up their current node | Run the app — Pro shell from the model: charts, tables, forms, approvals |
After a topic closes (all state in the browser, per-session):