{
  "markdown": "<!-- markdownlint-disable MD033 MD041 -->\n<div align=\"center\">\n\n<img src=\"docs/banner.png\" alt=\"OrchestKit - Stop explaining your stack. Start shipping.\" width=\"100%\" />\n\n**<!--ork:skills-->107<!--/ork--> skills · <!--ork:agents-->36<!--/ork--> agents · <!--ork:hooks-->171<!--/ork--> hooks**\n\n[![Claude Code](https://img.shields.io/badge/Claude_Code-≥2.1.277-7C3AED?style=for-the-badge&logo=anthropic)](https://claude.ai/claude-code)\n[![License](https://img.shields.io/badge/License-MIT-yellow?style=for-the-badge)](./LICENSE)\n[![GitHub Stars](https://img.shields.io/github/stars/yonatangross/orchestkit?style=for-the-badge&logo=github)](https://github.com/yonatangross/orchestkit)\n[![Community](https://img.shields.io/badge/Community-WhatsApp-25D366?style=for-the-badge&logo=whatsapp)](https://platform.yonyon.ai/circle?ref=readme)\n[![Ask DeepWiki](https://img.shields.io/badge/Ask-DeepWiki-1A1A2E?style=for-the-badge&logo=bookstack&logoColor=4F9CF9)](https://deepwiki.com/yonatangross/orchestkit)\n\n[![MCP Toplist](https://mcptoplist.com/badge/io.github.yonatangross%2Forchestkit.svg)](https://mcptoplist.com/server/io.github.yonatangross%2Forchestkit)\n\n</div>\n\n---\n\n<p align=\"center\">\n  <a href=\"https://orchestkit.yonyon.ai/\"><strong>Explore the Docs →</strong></a> ·\n  <a href=\"https://yonyon.ai/go/orchestkit?utm_campaign=readme\"><strong>OrchestKit Community →</strong></a><br>\n  <sub>Skill browser, demo gallery, setup wizard</sub>\n</p>\n\n---\n\n## Contents\n\n- [Quick Start](#quick-start)\n- [Why OrchestKit?](#why-orchestkit)\n- [What You Get](#what-you-get)\n- [Key Commands](#key-commands)\n- [Configuration](#configuration)\n- [What OrchestKit observes](#what-orchestkit-observes)\n- [Install](#install)\n- [FAQ](#faq)\n- [Development](#development)\n- [What's New](#whats-new)\n- [Community](#community)\n\n\n## Quick Start\n\nPick the host you actually use. Claude Code is the full plugin (skills + agents + hooks). Cursor gets the same `ork` plugin minus Claude hook scripts. skills.sh is skills only — start with the 12 below, not the whole catalog.\n\n#### Host support matrix\n\nMeasured 2026-09-08 on pi 0.85, Codex CLI and cursor-agent. Details, commands and the lane model: [OrchestKit on pi, Codex and Cursor](https://orchestkit.yonyon.ai/docs/guides/orchestkit-on-pi-codex-cursor). Antigravity measured 2026-09-18 on agy 1.2.6; full evidence in `docs/audits/agy-host-support-2026-09-18.md`.\n\n| Surface | Claude Code | Cursor | Codex | pi | Devin | Antigravity |\n|---|---|---|---|---|---|---|\n| Skills (SKILL.md) | all | all, via the `ork` plugin | 6 (`ork-codex` pack) | all via `pi install`, 78 auto-listed | 76 of 107, GH-4146 | all via workspace `.agents/skills` (skills.sh); `ork:<name>` via `agy plugin install` |\n| Agents | all | all | 4 role templates | none | not reported by `info` | 36 via `agy plugin install` (validated); none via `.agents/skills` |\n| Hooks | all | none | none | none | none | none of ork's; agy `hooks.json` is a different schema |\n| Rules | repo convention | 14, plugin `rules` key | `AGENTS.md` | none | `AGENTS.md`, always on | `AGENTS.md`, per-directory |\n| Commands | `/ork:<skill>` | 36 wrappers | `$ork-<skill>` | `/skill:<name>` | `/ork:<skill>` | `/<skill-name>`; `ork:<skill>` via plugin install |\n| MCP config | `.mcp.json` | `.cursor/mcp.json` | plugin `mcp.json` | `.pi/mcp.json` | `mcp.json` / `.mcp.json` | `~/.gemini/config/mcp_config.json` or plugin `mcp_config.json`; repo `.mcp.json` not read |\n| Status | shipped | shipped | shipped | shipped | skills only, GH-4146 | skills only, measured agy 1.2.6 |\n\n### Claude Code\n\n```bash\n/plugin marketplace add yonatangross/orchestkit\n/plugin install ork\n```\n\nThen `/ork:setup`. The wizard scans the repo, recommends skills, and writes MCP config.\n\nCLI equivalent: `claude plugin marketplace add yonatangross/orchestkit && claude plugin install ork@orchestkit`.\n\n### Cursor\n\nSettings → Plugins / marketplaces → add `yonatangross/orchestkit` → enable **ork** → **open a new chat**. Same plugin Claude Code installs, not a five-skill fork. See [Install → Cursor](#cursor).\n\n### skills.sh (Cursor, Codex, OpenCode, …)\n\nStarter 12 — doctor, setup, explore, implement, verify, review-pr, commit, expect, assess, brainstorm, create-pr, remember:\n\n```bash\nnpx skills add yonatangross/orchestkit -s doctor -s setup -s explore -s implement -s verify -s review-pr -s commit -s expect -s assess -s brainstorm -s create-pr -s remember\n```\n\nThe skill named `implement` is the implement workflow (`/ork:implement` in Claude Code). There is no `ork-implement` on the Claude plugin; Codex uses `$ork-implement` after the Codex pack is installed. Full catalog: `npx skills add yonatangross/orchestkit` (hundreds of SKILL.md files — do not treat that as unique users).\n\n---\n\n## Why OrchestKit?\n\nEvery Claude Code session starts from zero. You explain your stack, patterns, preferences—again and again.\n\nOrchestKit gives Claude **persistent knowledge** of production patterns that work automatically:\n\n| Without | With OrchestKit |\n|---------|-----------------|\n| \"Use FastAPI with async SQLAlchemy 2.0...\" | \"Create an API endpoint\" → Done right |\n| \"Remember cursor pagination, not offset...\" | Agents know your patterns |\n| \"Don't commit to main branch...\" | Hooks block bad commits |\n| \"Run tests before committing...\" | `/ork:commit` runs tests for you |\n\n---\n\n## What You Get\n\n**One unified plugin, everything included.**\n\n| Component | Details |\n|-----------|---------|\n| **<!--ork:skills-->107<!--/ork--> Skills** | RAG patterns, FastAPI, React 19, testing, security, database design, ML integration — loaded on-demand, zero overhead |\n| **<!--ork:agents-->36<!--/ork--> Agents** | Specialized personas (backend-architect, frontend-dev, security-auditor) — route tasks to the right expert |\n| **<!--ork:hooks-->171<!--/ork--> Hooks** | Pre-commit checks, git protection, quality gates, browser safety — ship with confidence |\n\nAll available in a single `/plugin install ork`. Skills load on-demand. Hooks work automatically.\n\n**[Browse everything in the Docs →](https://orchestkit.yonyon.ai/docs/skills/overview)**\n\n---\n\n## Key Commands\n\n```bash\n/ork:auto         # Front door: describe a goal, it routes to the right skill\n/ork:setup        # Personalized onboarding wizard\n/ork:implement    # Full-stack implementation with parallel agents\n/ork:expect       # Diff-aware AI browser testing\n/ork:review-pr    # PR review with parallel agents\n/ork:verify       # Multi-agent validation\n/ork:commit       # Conventional commit with pre-checks\n/ork:explore      # Analyze unfamiliar codebase\n/ork:remember     # Save to persistent memory\n/ork:doctor       # Health check\n```\n\n---\n\n## Configuration\n\n`/ork:setup` detects your stack, recommends MCP servers, and writes the configuration for you.\n\n### Recommended MCP Servers\n\n| Server | Purpose | Required? |\n|--------|---------|-----------|\n| Context7 | Up-to-date library docs | **Prerequisite** (22 of 36 agents grant its tools) |\n| Memory | Knowledge graph persistence | Recommended |\n| Sequential Thinking | Structured reasoning for subagents | Recommended |\n| Tavily | Web search and extraction | Optional |\n\nSet `\"alwaysLoad\": true` on the first three in your `.mcp.json`. It skips the per-skill tool probe and shaves ~150ms off cold starts.\n\n**Context7 is a prerequisite, and ork does not ship it.** 22 agents grant\n`mcp__context7__*` in their frontmatter, but `.mcp.json` is user-owned and project-scoped,\nso the grant refers to a server you add. Skip it and those agents answer from training\ndata with no error raised. The recommended entry is the hosted HTTP server, which costs\nno local process:\n\n```json\n\"context7\": {\n  \"type\": \"http\",\n  \"url\": \"https://mcp.context7.com/mcp\"\n}\n```\n\nFree tier: 1,000 requests, public repos, no account. Context7 Pro ($10 per seat per\nmonth) raises that to 5,000 per seat and parses private repos; add\n`\"headers\": { \"Authorization\": \"Bearer ${CONTEXT7_API_KEY}\" }` and export the `ctx7sk-`\nkey. Add the header only once the variable is exported: with it unset the unexpanded\nliteral is sent as the token and every query fails, and it does **not** fall back to the\nanonymous free tier, so the keyless entry above is strictly better than a header with no\nkey behind it. The legacy stdio transport (`npx -y @upstash/context7-mcp@4.0.2`) is the fallback\nwhen the hosted endpoint is unreachable, but it spawns one child process per Claude Code\nsession, so the fan-out scales with how many sessions you keep open.\n\n### Customizing skills\n\nSkills install as files on your disk, but **don't hand-edit the installed copy** — it gets overwritten on update and silently diverges from the canonical playbook. The supported ways to extend (user-level skills, project skills, upstream PRs, or disabling a bundled skill) are in [docs/extending-skills.md](docs/extending-skills.md).\n\n---\n\n## What OrchestKit observes\n\nOrchestKit is a quality-gate plugin, so its hooks are the product rather than an\nadd-on. This section states plainly what they see, where it goes, and how to turn\neach piece off.\n\n**Scope: broad and intentional.** OrchestKit registers <!--ork:hooks-->171<!--/ork--> hooks across <!--ork:events-->32<!--/ork-->\nlifecycle events, including `SessionStart`, `UserPromptSubmit`, `PreToolUse`,\n`PostToolUse`, and `Stop`. They are **not** gated to a particular framework or\nproject type, because the gates they enforce (secret-write blocking, protected-file\nguards, git safety, file-size limits, agent status protocol) apply to any codebase.\nIf you only want gates on some projects, enable the plugin per-project rather than\nglobally.\n\n**Where data goes: a local file on your own disk.**\n\n| What | Destination | Notes |\n|---|---|---|\n| Lifecycle events (session end, PR merged, goal converged, chain phase) | `~/.local/state/orchestkit/events.jsonl` | Written unconditionally, rotated at 10 MB. `ORK_EVENTS_LOG` redirects the path (used by the test suite) |\n| Hook metrics: event name, tool name, payload size, duration | same local file | Size-capped metrics only |\n| Prompt text and file contents | **Never recorded** | Hooks read them to make an allow/deny decision, then discard |\n| Remote sync | **Off** | No endpoint is compiled in; see below |\n\nThere is deliberately **no global kill switch** for the local write, because the\ngates depend on that state (the git-safety and chain-staleness hooks read their\nown prior events). To stop it entirely, disable the plugin. Individual noisy hooks\nhave their own opt-outs: `ORK_DISABLE_DEBT_TRACKER`, `ORK_DISABLE_WORKTREE_VERIFIER`,\n`ORK_DISABLE_COORDINATION_METRICS`, `ORK_NO_NOTIFY`, `ORK_NO_STALE_SWEEP`, and\n`ORCHESTKIT_SKIP_SLOW_HOOKS` among others.\n\n**Network access is opt-in and unset by default.** There is no hardcoded remote\nhost anywhere in the shipped hook bundles (`grep -o 'https\\?://' plugins/ork/hooks/dist/*.mjs`\nreturns nothing). An outbound call happens only if you configure a destination\nyourself, via one of:\n\n- `ORCHESTKIT_HOOK_URL` + `ORCHESTKIT_HOOK_TOKEN`, which enable the manual\n  `hooks/bin/telemetry-sync.mjs` CLI. It POSTs your local JSONL to *your own*\n  endpoint. No hook ever invokes it; you run it by hand.\n- `ORK_HQ_TELEMETRY_URL`, which points the telemetry HTTP sink at *your own* collector.\n- `ORK_HQ_TELEMETRY_USE_HQ_API=1` together with `HQ_API_URL`, the same sink aimed\n  at a self-hosted HQ API.\n- `ORK_SESSION_CATEGORY_PROVIDER=jev` (or `shadow`) together with the TypeSafe\n  key variable `ORK_TYPESAFE_API_KEY`, a second classifier for the session work\n  category. The session-identity hook already asks a local `claude -p --model haiku`\n  process for a title and a category; with both variables set it also asks\n  TypeSafe's Jev model (`api.typesafe.ai`, model pinned to `jev-1.13.0`) one typed\n  Choice over the same eight categories and the same criteria text. This is the\n  one exception to the \"no hardcoded host\" note above, and it is dormant unless\n  both variables are set. What leaves your machine: the git branch name and the\n  first 600 characters of the session's first prompt, sent to a third-party\n  processor under its own data policy. What changes in `jev` mode: when Jev\n  answers at confidence 0.8 or above, its category decides the session color\n  (held out on 150 sessions, that band is 93.5% correct);\n  below 0.8, or on any error, haiku's category decides as before. The title and\n  emoji always come from haiku. In `shadow` mode nothing you see changes; Jev is\n  only logged beside haiku. To turn it on locally, in the shell that launches\n  `claude`: `export ORK_TYPESAFE_API_KEY=\"$(<your secret manager> ...)\"` and\n  `export ORK_SESSION_CATEGORY_PROVIDER=jev`. Both outcomes are logged once per\n  session in the hook log, as\n  `category jev: haiku=<cat> jev=<cat> agree=<bool> confidence=<n> decided_by=jev|haiku threshold=0.8 latency_ms=<n>`,\n  and as `session-identity.shadow.json` with the same fields (labels, decision,\n  timing; never prompt text) next to the raw answer `session-identity.jev.json`\n  in the session data directory. Cost of opting in: the first prompt of a session\n  waits for the call to settle, 1.1 to 1.7 s measured from a fresh hook process\n  (the eval's 320 ms was a warm connection), 3 s at most before it gives up.\n- `ORK_ROUTE_JEV=shadow` (or `steer`) together with `ORK_TYPESAFE_API_KEY`, the\n  Jev routing seam for `/ork:auto` (#4233). Off by default. When set, every\n  build-shaped prompt (the same test the once-per-session executor reminder\n  uses: an imperative build or fix verb, 40 characters or more, no explicit\n  `/plugin:skill`) is sent to the same TypeSafe endpoint and model as one typed\n  Choice over nineteen route classes plus four side judgments (needs a worktree,\n  needs a browser, mutation risk, needs the operator). What leaves your machine:\n  the first 1,500 characters of the prompt after a redactor has replaced\n  secrets, emails, Israeli phone numbers, nine digit ids, `op://` references and\n  the names of directories under `clients/` with `[SECRET]`, `[EMAIL]`,\n  `[PHONE]` and `[CLIENT]`, plus the repository basename. The serialized request\n  is scanned again before it leaves; anything that survives redaction refuses\n  the call. In `shadow` mode nothing you see changes; the verdict is logged. In\n  `steer` mode, at confidence `ORK_ROUTE_JEV_FLOOR` (default 0.5) or above, the\n  one-line executor reminder names the executor the class maps to\n  (`route: dev_fix -> /ork:fix-issue (conf 0.83)`); the model still reads the\n  `/ork:auto` table and says whether it agrees. Fallbacks are fail open: no key,\n  timeout, non-2xx, malformed answer, below the floor, or the daily token budget\n  (`ORK_ROUTE_JEV_DAILY_TOKENS`, default 2,000,000) spent all mean the existing\n  path runs untouched; a 402 or 429 switches the seam off for 24 hours. One log\n  line per prompt,\n  `route jev: intent=<class> conf=<n> top3=<a:p,b:p,c:p> worktree=<n> browser=<n> mutation=<n> operator=<n> floor=<n> decided_by=jev|table|off|budget|egress latency_ms=<n> input_tokens=<n> redacted=<n>`,\n  and one record per prompt in `jev-route.jsonl` next to\n  `session-identity.jev.json` (labels, timings and a sha256 of the redacted\n  text; never prompt text). Offline replay: `node scripts/eval/route-check.mjs --jev`\n  and `node scripts/eval/jev-route-score.mjs`. The vendor's agent skill is a\n  peer plugin installed from its own marketplace, never a copied directory:\n  `claude plugin marketplace add typesafe-ai/skills` then\n  `claude plugin install typesafe@typesafe-ai`; `/ork:doctor` reports the\n  installed version against the marketplace and prints the update commands.\n\nThe sink returns early when the URL or the token is missing, and\n`telemetry-sync.mjs` prints `No ORCHESTKIT_HOOK_URL or TOKEN configured. Nothing\nto sync.` then exits 0. There is no analytics ping, no crash reporter, and no\nfeature-flag fetch.\n\n**What OrchestKit never reads.** No OS keychain lookups, no `~/.aws/credentials`,\nno SSH private keys, no browser cookie or login stores, no clipboard. The one\nplace secret-shaped paths appear in the source is\n`plugins/ork/hooks/dist/pretool.mjs`, where `id_rsa`, `.pem`, `.env`, and\n`credentials.json` form a **blocklist** that stops Claude writing to them. That\ncode denies access; it does not read those files.\n\n**Third-party MCP servers are recommendations, not bundled dependencies.** The\nplugin ships no `.mcp.json` and declares no `mcpServers`. The table under\n[Configuration](#configuration) is advisory, and `/ork:setup` asks before writing\nanything.\n\n---\n\n## Install\n\n```bash\n/plugin install ork\n```\n\nNo tiering. No version confusion. Just one powerful plugin.\n\nNot on Claude Code? Pull a **starter 12** into any agent (Cursor, Codex, OpenCode, …) via [skills.sh](https://www.skills.sh/yonatangross/orchestkit) — do not install the whole firehose on day one:\n\n```bash\nnpx skills add yonatangross/orchestkit -s doctor -s setup -s explore -s implement -s verify -s review-pr -s commit -s expect -s assess -s brainstorm -s create-pr -s remember\n```\n\nAll skills: `npx skills add yonatangross/orchestkit`. The implement skill is [`implement`](https://www.skills.sh/yonatangross/orchestkit/implement), not `ork-implement`.\n\n### Cursor\n\nCursor loads [Agent Plugins](https://agent-plugins.org) and Cursor plugins.\nThis repo already ships the Agent Plugins manifest at `plugins/ork/plugin.json`.\nAdd the GitHub repo as a Cursor marketplace (Settings → `yonatangross/orchestkit`),\nenable **`ork`**, then **open a new chat**. That is the same plugin Claude Code\ninstalls, not a five-skill fork.\n\nIt also ships 14 rules under the plugin's `rules` key, generated from\n`src/rules/` and `src/shared/rules/`. They are agent-fetched, so a rule costs\ncontext only when its description matches the task.\n\nClaude hook scripts are not registered for Cursor: they depend on\n`${CLAUDE_PLUGIN_ROOT}` (orchestkit#293, closed). Cursor enforcement for HQ\nrepos stays in the consuming project's `.cursor/hooks.json`.\n\n\"Include third-party Plugins\" can leak SKILL.md from `~/.claude/plugins`. That\nis not an install. Proof is the `ork` plugin id plus the full skill catalog.\n\n### Codex\n\nCodex uses its own plugin format, skill picker, and standalone role\nconfiguration. Add OrchestKit's Codex marketplace, then install the small\nportable workflow pack:\n\n```bash\ncodex plugin marketplace add yonatangross/orchestkit --ref main --sparse .agents/plugins --sparse plugins/ork-codex\ncodex plugin add ork-codex@orchestkit-codex\n```\n\nRestart Codex after installation. Invoke a workflow explicitly with\n`$ork-brainstorm`, `$ork-explore`, `$ork-implement`, `$ork-assess`, `$ork-verify`,\nor `$ork-review-pr`; their narrow descriptions also let Codex select the relevant\nworkflow automatically.\n\nThe plugin intentionally ships roles as templates because Codex loads custom\nroles from `~/.codex/agents/`, not from a plugin manifest. From an OrchestKit\ncheckout, run this one-time, non-overwriting install:\n\n```bash\nplugins/ork-codex/scripts/install-codex-roles.sh ~/.codex/agents\n```\n\nIt installs `ork_explorer`, `ork_implementer`, `ork_reviewer`, and\n`ork_verifier`; restart Codex before spawning them.\n\n#### Unattended runs: the `ork-mech` profile\n\nFor mechanical work (renames, bumps, codemods, sweeps that end in a diff),\ninstall the shipped profile and run `codex exec` against it:\n\n```bash\nplugins/ork-codex/scripts/install-codex-profile.sh ~/.codex\ncodex exec --profile ork-mech \"<task>\" </dev/null\n```\n\nThe profile is a FILE, not a snippet you paste into `config.toml`. Measured on\ncodex-cli 0.153.4: `--profile <name>` layers `$CODEX_HOME/<name>.config.toml`\nover the base config, and a legacy `[profiles.<name>]` table left inside\n`config.toml` makes the same flag a hard config-load error. The installer\nrefuses to run next to that table, and refuses to overwrite a profile you\nalready have.\n\nWhat it sets, as `codex exec` prints it in its own header:\n\n```\napproval: never\nsandbox: workspace-write [workdir, /tmp, $TMPDIR] (network access enabled)\nreasoning effort: high\n```\n\nIt deliberately does not pin a model (pass `-m`) and does not use\n`--dangerously-bypass-approvals-and-sandbox`, which drops the sandbox entirely.\nTwo contracts a TOML file cannot express, so they stay on the command line:\n\n- **`</dev/null`.** `codex exec` reads stdin even when a prompt argument is\n  given. An inherited open pipe blocks the run with `Reading additional input\n  from stdin...` and no timeout.\n- **`--add-dir` inside a git worktree.** The writable roots are\n  `[workdir, /tmp, $TMPDIR]`. A linked worktree's git common dir sits outside\n  the workdir, so the first commit dies on `index.lock`. Add it:\n\n  ```bash\n  codex exec --profile ork-mech \\\n    --add-dir \"$(git rev-parse --path-format=absolute --git-common-dir)\" \\\n    \"<task>\" </dev/null\n  ```\n\n#### Keeping the install current\n\n`ref main` in the marketplace source is a cached snapshot, not a tracker. On the\n2026-09-08 audit machine `codex plugin list` showed `10.0.0-beta.5` while main\nwas three releases ahead. After an OrchestKit release, update and check:\n\n```bash\ncodex plugin update\ncodex plugin list | grep ork-codex          # installed version\njq -r .version plugins/ork-codex/.codex-plugin/plugin.json   # what main ships\n```\n\n#### Documentation lookup (context7)\n\nThe plugin ships a [context7](https://context7.com) MCP server in its own\nmanifest (`mcpServers` in `.codex-plugin/plugin.json`, defined in `mcp.json`),\nso installing the plugin registers it. Confirm with `codex mcp get context7`.\nIt is scoped to the only two tools context7 exposes, `resolve-library-id` and\n`query-docs`, and it uses the hosted HTTP transport rather than an `npx` stdio\nchild, so it costs no extra process per Codex session.\n\nExport a key before starting Codex. The plugin references the variable name\nand never stores the value, so no token is written to `~/.codex/config.toml`:\n\n```bash\nexport CONTEXT7_API_KEY_CODEX=\"<your-context7-api-key>\"\n```\n\nPut that in your shell profile so every Codex session inherits it. Get the\nkey from your own context7 account and keep the value out of the repository.\nIf you store it in a secret manager, substitute your own vault and item names\n(with the 1Password CLI the reference is `op://<vault>/<item>/credential`), and\ncache the resolved value instead of re-reading the vault in every shell: each\nraw read is a separate unlock prompt.\n\nTwo behaviors worth knowing:\n\n- A server you already define yourself under `[mcp_servers.context7]` in\n  `~/.codex/config.toml` **wins**, and the plugin's definition is ignored\n  entirely (including its tool scoping). That is intentional: your own\n  configuration is never overridden. Remove your entry if you want the\n  plugin's.\n- Without a valid key the server still connects and still lists its tools.\n  Only a real call fails, with `Invalid API key`. A successful connection is\n  therefore not proof of authentication.\n\n### pi\n\npi (0.85) reads the same SKILL.md format, and the repo now carries a `pi`\nmanifest, so the package installs directly:\n\n```bash\npi install git:github.com/yonatangross/orchestkit\n```\n\nThat registers every skill. Add `-l` to write `.pi/settings.json` in the\nproject instead of your user settings. Pointing pi at a checkout still works\nand needs no install (`pi --skill ./plugins/ork/skills`).\n\nThe 29 skills marked `disable-model-invocation` stay reachable only as\n`/skill:<name>`. Two measured caveats: `--no-builtin-tools` hides every skill\n(pi lists skills only when a file-reading tool is enabled), and `pi -p` blocks\non an open stdin, so headless runs need `</dev/null`.\n\nMCP servers for pi come from `.pi/mcp.json`, then `.mcp.json`, then\n`~/.config/mcp/mcp.json`. Copy the shipped template to get the recommended\nservers with a read-only `includeTools` allowlist per server:\n\n```bash\ncp .pi/mcp.json.example .pi/mcp.json\n```\n\nFull detail and the tracking epic:\n[OrchestKit on pi, Codex and Cursor](https://orchestkit.yonyon.ai/docs/guides/orchestkit-on-pi-codex-cursor).\n\n### Devin\n\n```bash\ndevin plugins install yonatangross/orchestkit\n```\n\nDevin checks a plugin root for a manifest in this order: `.devin-plugin/plugin.json`,\nthen `.claude-plugin/plugin.json`, then root `plugin.json`\n([plugins reference](https://docs.devin.ai/cli/extensibility/plugins/overview)).\nThe repo root only had the last one, the [Agent Plugins](https://agent-plugins.org)\nmanifest, which fixes skills at a root `skills/` directory this repo does not have,\nso a bare install used to list 0 of 107 skills, 0 hooks, and only the `AGENTS.md`\nrule (GH-4146). A root level `.devin-plugin/plugin.json` now maps `skills` to\n`./plugins/ork/skills`, the same built tree Claude Code and Cursor already read.\n\n`devin plugins info ork` lists 76 of 107 skills after that change (measured on\nDevin CLI 3000.10.27). The other 31, `auto`, `verify`, `help`, `brainstorm`, and\nsimilar router or workflow skills, declare a `triggers:` frontmatter key shaped\nas an object (`keywords`, `examples`, `anti-triggers`). Devin's own `triggers`\nfield expects a flat `[user, model]` list, and the shape mismatch drops the\nwhole skill instead of warning. Renaming that key touches three other readers\n(`scripts/eval/eval-coverage.sh`, `tests/skills/triggering/test-trigger-keywords.sh`,\nand the `SKILL_ONLY` allowlist in `tests/plugins/test-command-frontmatter-passthrough.sh`),\nso it stays tracked on GH-4146 instead of folded into this fix. Installing the\nsubpath directly, `devin plugins install yonatangross/orchestkit#plugins/ork`,\nreaches the same 76 skills plus the plugin's 36 custom subagents, which neither\npath surfaces through `devin plugins info`. That subpath is what this repo's own\n`.claude-plugin/marketplace.json` already points Claude Code at.\n\nOrchestKit's plugin hooks work under Claude Code only today; none of the 171\nfire under Devin. Two reasons. Location: OrchestKit ships hooks at\n`plugins/ork/hooks/hooks.json`, while Devin's own plugin format reads a bare\n`hooks.json` at the plugin root instead. Shape and tool names: OrchestKit's\nfile matches Claude Code tool names such as `Bash` and `Write|Edit` and\nexpands `${CLAUDE_PLUGIN_ROOT}` in command args, both Claude Code specific.\nDevin's own\n[hooks.v1.json](https://docs.devin.ai/cli/extensibility/hooks/overview) format\nmatches its own tool names instead, `exec`, `write`, `edit` and friends (see\n[lifecycle hooks](https://docs.devin.ai/cli/extensibility/hooks/lifecycle-hooks)),\ninside the same `{matcher, hooks:[{type, command}]}` event map shape.\n`devin plugins info` confirms `Hooks (none)` even once skills resolve.\n`PreToolUse` and `PostToolUse` read the closest to what OrchestKit's own\npretool and posttool hooks already do, and are the first candidates for a\nfuture Devin hook manifest once the tool name mapping is written deliberately\ninstead of guessed.\n\nPin a release instead of tracking `main`: release-please tags every release as\n`v10.0.0-beta.N`. The single argument `devin plugins install <source>` command\nhas no ref pinning syntax of its own; pin through a `requiredPlugins` entry\n(in this repo's own `.devin/config.json`, or a personal, org, or enterprise\nmanifest) instead:\n\n```json\n{\n  \"requiredPlugins\": [\n    { \"source\": \"github\", \"repo\": \"yonatangross/orchestkit\", \"ref\": \"v10.0.0-beta.30\" }\n  ]\n}\n```\n\n### Antigravity\n\n```bash\nnpx skills add yonatangross/orchestkit -s doctor -s setup -s explore -s implement -s verify -s review-pr -s commit -s expect -s assess -s brainstorm -s create-pr -s remember\n```\n\nAntigravity (`agy`, Google's agentic CLI) reads Agent Skills from a workspace\n`.agents/skills` directory, so the shared skills.sh line above is the install\npath and Antigravity is already in that installer's universal target list\n(measured on agy 1.2.6; full evidence in\n`docs/audits/agy-host-support-2026-09-18.md`). Verify from the repo root with\n`agy -p \"/skills\" --add-dir \"$PWD\"`: print mode only registers a workspace from\nan absolute `--add-dir`, while the interactive TUI takes the launch directory\nas the workspace and needs no flag.\n\nTwo honest gaps. `npx skills add -g` lands in `~/.agents/skills`, which agy\ndoes not read; user scope lives at `~/.gemini/config/skills` (or\n`~/.gemini/skills`). And none of ork's 171 hooks port: agy's `hooks.json` uses\nits own event names and payload shape, and `agy plugin validate plugins/ork`\nreports hooks skipped because ork keeps them at `hooks/hooks.json`, not the\nplugin-root `hooks.json` agy looks for.\n\nA fuller install exists but needs a local checkout:\n`agy plugin validate <checkout>/plugins/ork` reports `skills: 108 processed`,\n`agents: 36 processed`, and `agy plugin install <checkout>/plugins/ork` copies\nthem into `~/.gemini/config/plugins/ork/` namespaced `ork:<name>`, which matches\nthe `/ork:<skill>` spelling. Plugin-bundled `mcp_config.json` also works\n(marker-verified end to end), but a repo-level `.mcp.json` is never read.\n\n---\n\n## FAQ\n\n<details>\n<summary><strong>Plugin not found?</strong></summary>\n\n```bash\n/plugin list\n/plugin uninstall ork && /plugin install ork\n```\n</details>\n\n<details>\n<summary><strong>Hooks not firing?</strong></summary>\n\nRun `/ork:doctor` to diagnose.\n</details>\n\n<details>\n<summary><strong>Claude Code version?</strong></summary>\n\nRequires **≥2.1.277** (supported floor; Opus 5 as the default Opus, Opus 5.5 from 2.1.280, `xhigh` effort, dynamic workflows, `sandbox.network.strictAllowlist`, native binary, hardened `Bash(rm:*)`/`Bash(find:*)` rules). Check with `claude --version`.\n\nRaising this floor is a breaking change and ships as a major release. See [STABILITY.md](STABILITY.md) for the full contract, and `shared/cc-support.json` for the authoritative window.\n</details>\n\n<details>\n<summary><strong>Superpowers vs OrchestKit?</strong></summary>\n\nComplementary, not a rival listing. Superpowers (official Anthropic marketplace) is process — how the agent works a task. OrchestKit is production patterns plus lifecycle hooks. Honest split: [docs](https://orchestkit.yonyon.ai/docs/getting-started/superpowers) · [yonyon.ai](https://yonyon.ai/compare/orchestkit-superpowers).\n</details>\n\n---\n\n## Development\n\n```bash\nnpm run build      # Build plugins from src/\nnpm test           # Run all tests\n```\n\nEdit `src/` and `manifests/`, never `plugins/` (generated).\n\nSee [CONTRIBUTING.md](./CONTRIBUTING.md) for details.\n\n---\n\n## What's New\n\n<!--ork:whats-new-->\n<!-- AUTO-GENERATED from CHANGELOG.md by scripts/stamp-whats-new.mjs — do not hand-edit between the ork:whats-new markers. -->\n<!-- Regenerated on `npm run build`; CI (`--check`) fails if this is stale. Full history: [CHANGELOG.md](CHANGELOG.md). -->\n\n**[v10.0.0-beta.84](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.83...v10.0.0-beta.84)** · 2026-09-23\n\n- **git-hooks:** opt-in targeted pre-push mode with a 2-slot governor (#4238) (#4389)\n\n**[v10.0.0-beta.83](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.82...v10.0.0-beta.83)** · 2026-09-23\n\n- **hooks:** emit PermissionRequest decision.behavior for auto-approve (#4374)\n- **hooks:** read tool_response and lock attribution state (sweep T1) (#4386)\n- **security:** XS hardening batch from the 2026-09-17 audit (#4220) (#4383)\n- **skills:** grant Stitch tools the skills call, and guard skill MCP refs (#4376)\n- **skills:** keep rc capture and cleanup working under set -e (sweep T2) (#4387)\n\n**[v10.0.0-beta.82](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.81...v10.0.0-beta.82)** · 2026-09-23\n\n- **docs-site:** hero option A conductor bleed (#4345)\n- **hooks:** load telemetry sinks only from user scope over https (#4218) (#4380)\n- **hooks:** secret-handler AUDIT default and redacted security-audit log (#4379)\n- **skills:** Gemini model IDs and provider wording missed by [#4381](https://github.com/yonatangross/orchestkit/issues/4381) (#4382)\n\n**[v10.0.0-beta.81](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.80...v10.0.0-beta.81)** · 2026-09-23\n\n- **docs:** skip __pycache__ and .pyc in generated skill folder lists (#4378)\n- **hooks:** age-cap session events and bound Stop git status (#4367)\n- **skills:** correct provider API parameters in skill examples (#4381)\n- **skills:** drop dead agent: bindings under context inherit (F26) (#4358)\n\n**[v10.0.0-beta.80](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.79...v10.0.0-beta.80)** · 2026-09-23\n\n- **agents:** adopt Anthropic's Opus 5.5 working guidance (#4363)\n- **agents:** grant stitch and storybook-mcp tools (F12) (#4362)\n- **hooks:** ConfigChange --no-verify false positives (SC47 F3) (#4368)\n- **hooks:** fall back to raw --no-verify scan on settings parse failure (#4370)\n- **hooks:** require ORK_TEST_MODE for ORK_HOOKS_DIST_DIR (#4371)\n- …and 6 more (see [CHANGELOG.md](CHANGELOG.md))\n\n**[v10.0.0-beta.79](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.78...v10.0.0-beta.79)** · 2026-09-22\n\n- **cc:** adopt CC 2.1.278 and 2.1.280, Opus 5.5 as the default Opus (#4357)\n- **design:** reserve.py exits 3 on generation-cap exhaustion (#4359)\n- **release:** stop marketplace count stamp from rewriting stable ork (#4355)\n- **site:** close orank OG, llms.txt, and /docs landing gaps (#4354)\n- **testing-e2e:** repoint dead planner-agent reference (F27) (#4356)\n\n**[v10.0.0-beta.78](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.77...v10.0.0-beta.78)** · 2026-09-22\n\n- **site:** scope social meta to the homepage ([#4343](https://github.com/yonatangross/orchestkit/issues/4343) follow-up) (#4347)\n- **playground:** drop the homeos-arieh exemplar (#4348)\n\n**[v10.0.0-beta.77](https://github.com/yonatangross/orchestkit/compare/v10.0.0-beta.76...v10.0.0-beta.77)** · 2026-09-22\n\n- **site:** align title and social meta with the OG card (#4343)\n\n_See [CHANGELOG.md](CHANGELOG.md) for the full release history._\n<!--/ork-->\n\n---\n\n## Community\n\nJoin the **Building with AI** community for AI dev tips, OrchestKit support, and connecting with other builders:\n\n| Room | Who it's for | Link |\n|------|--------------|------|\n| **Building with AI** | The umbrella community. One join, every room below. | [Join](https://platform.yonyon.ai/circle?ref=readme) |\n| **Builders** | For people already building | [Join](https://yonyon.ai/go/builders?utm_campaign=readme) |\n| **OrchestKit** | For OrchestKit users | [Join](https://yonyon.ai/go/orchestkit?utm_campaign=readme) |\n| **AI for Business** | For people leading AI adoption | [Join](https://yonyon.ai/go/business?utm_campaign=readme) |\n\nNames and audiences match what [yonyon.ai](https://yonyon.ai/en) renders, so the two surfaces cannot drift. Every link resolves through `yonyon.ai/go/*`, so a rotated invite never needs a README change and no raw invite is published here.\n\n---\n\n## Who builds this\n\nOrchestKit is built and maintained by **[Yonatan Gross](https://github.com/yonatangross)** — [Yonyon AI](https://yonyon.ai/en), an AI consulting practice. It is the toolkit extracted from real client work, not a side project: the patterns here are the ones that survived shipping.\n\nIt stays MIT and free. Nothing is gated, and none of the below changes that.\n\n**Working out where AI actually fits in your business?** The [**AI readiness audit**](https://platform.yonyon.ai/ai-audit) is a free assessment that maps your workflows and returns a prioritized report — the same diagnostic that opens a consulting engagement.\n\n**Want the toolkit running properly in your team?** Setup, configuration, and a working agent loop tailored to your stack is something I do as a fixed-scope engagement. Start a [discussion](https://github.com/yonatangross/orchestkit/discussions) or reach out through the [community](https://yonyon.ai/go/business?utm_campaign=readme).\n\nSecurity policy and reporting: [SECURITY.md](SECURITY.md).\n\n---\n\n<div align=\"center\">\n\n**[Docs](https://orchestkit.yonyon.ai/)** · **[Issues](https://github.com/yonatangross/orchestkit/issues)** · **[Discussions](https://github.com/yonatangross/orchestkit/discussions)** · **[Community](https://platform.yonyon.ai/circle?ref=readme)**\n\nMIT License · [@yonatangross](https://github.com/yonatangross)\n\n</div>\n",
  "bytes": 36055,
  "sha": "89cf300dd04357b5ed75ebe958a33f2ce53bebbd6c53dd88334f200a37a23471",
  "repo_slug": "yonatangross/orchestkit",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_yonatangross_orchestkit_memory_1ebc0827/readme"
}