007
無料Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
This skill should be used when the user says "add a billing agent", "add a bookkeeping agent", "set up a support tier-1 agent", "add a recruiting agent", "add a compliance agent", "add a CRM agent", "add a contracts agent", "add an analytics agent", "add a marketing email agent", "add a CMS agent", "scaffold a function-specific agent", or wants to add a single business-function agent backed by a verified-write MCP integration. Each agent ships with explicit scope, "what this will NOT do" constraints, and recommended human-in-the-loop checkpoints.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Scaffold a single business-function agent backed by a verified-write MCP integration. Each function is opt-in. The plugin does NOT pretend that "scaffolding a marketing folder" gives you a marketing agent — it gives you nothing until you explicitly add one via this skill, with the MCP wired up and the scope written down.
For each --function you add:
<project-or-company>/.claude/agents/<function>-agent.md — with tools restricted to the relevant MCP, model selection rationale, and a system prompt that describes scope..mcp.json — with environment variables for credentials (never hardcoded).SCOPE.md file at <project-or-company>/.claude/agents/<function>-scope.md — explicit "what this agent will / will NOT do" + recommended human-in-the-loop checkpoints + escalation rules.Only functions with a verified write-capable MCP are supported. If a function isn't in this list, it's because the integration doesn't exist or is read-only.
--function | MCP | Vendor status | Agent can | Agent will NOT |
|---|---|---|---|---|
billing | Stripe MCP (official) | GA | Look up customers, create/void invoices, issue refunds (within limit), pull payment history, manage subscriptions | Issue refunds > configured limit; modify pricing; touch Connect / Treasury without explicit human approval |
bookkeeping | QuickBooks MCP (official Intuit) OR Xero MCP (official) | GA | Reconcile transactions, categorize expenses, generate reports, post journal entries to draft state | Finalize close; modify chart of accounts; file taxes; alter prior-period entries |
support-tier1 | Intercom MCP (official) | GA | Look up users, search conversations, draft replies, tag/route tickets, escalate to human queue | Send replies autonomously (drafts only by default); refund or compensate without human; close tickets touching billing/legal |
recruiting | Greenhouse MCP (community, mature) OR Lever MCP (community) | Community | First-pass screening notes, schedule interviews, sync candidate status, generate offer-letter drafts | Make hiring decisions; send rejection emails autonomously; modify job requisitions |
compliance | Vanta MCP (official open-source) OR Drata MCP (official, hosted) | GA | Pull evidence, check control status, generate audit reports, flag missing evidence | Mark controls as compliant; modify policies; respond to auditors |
crm-ops | HubSpot MCP (official) OR Salesforce MCP (official, hosted) | GA / Beta | Update contact/deal records, log activities, run reports, segment lists | Send autonomous outbound; modify pipeline definitions; bulk-delete records |
contracts | DocuSign MCP (official, beta) | Beta | Send pre-approved templates, check signing status, query Navigator agreements, trigger Maestro workflows | Send custom contracts without human review; modify signed documents; legally bind without explicit human send |
analytics-reporting | PostHog OR Mixpanel OR Amplitude OR GA4 MCP (all official) | GA | Run queries, build dashboards, export reports, drill into events | Modify tracking implementation; delete data; share PII outside approved destinations |
marketing-email | Mailchimp MCP (community, mature) OR Customer.io MCP (official) | GA / Community | Build segments, draft campaigns, schedule sends to test segments, pull metrics | Send to full list without human approval; modify suppression list autonomously; touch GDPR / unsubscribe records |
web-cms | Webflow MCP (official) | GA | Read/write CMS items, manage Sites API, publish (with confirmation) | Publish without human approval; modify Designer canvas without MCP Bridge App |
social-drafts | (no MCP for Buffer/Hootsuite — drafts only, written to filesystem) | N/A | Draft posts to a social-drafts/ folder for human review and manual posting | Post anything autonomously (no integration exists in 2026 for write-capable scheduling) |
These functions don't get an agent because the integration isn't there:
| Function | Status | Why no agent |
|---|---|---|
payroll | No MCP for Gusto/Rippling write; Deel is read-only | Cannot reliably execute payroll without write APIs |
banking-ops | No MCP for Mercury/Brex/Ramp | Cannot move money out of operating accounts |
support-tier2-zendesk | Zendesk is MCP client, not server | Cannot let Claude act in Zendesk |
support-helpscout | No MCP | No write integration |
clm | No Ironclad MCP (only DocuSign signing) | Contract lifecycle management is human-only |
social-scheduling | No Buffer/Hootsuite MCP | Drafts only — see social-drafts |
apollo-outbound | No first-party Apollo MCP | Use crm-ops if you sync Apollo data into HubSpot/Salesforce first |
Find the right .claude/agents/ directory. If --project <path> is given, use that. Otherwise:
.claude/agents/CLAUDE.md + .claude/)Confirm --function is in the supported list above. If not, surface the "not supported" table above and explain why — never silently fall back to a generic template.
Ask the user for:
STRIPE_SECRET_KEY, INTERCOM_ACCESS_TOKEN)billing: what's the autonomous refund limit? for marketing-email: which segment is the agent allowed to send to without human approval?escalations/ folder where the agent dumps anything outside its scopeIn --dry-run mode, skip prompts and emit the proposed file contents to stdout instead of writing.
Load references/function-agent-templates.md and pick the matching template. Customize:
Read, Grep, Glob, Bash plus the specific MCP tool prefix (e.g., mcp__stripe__*)Write to .claude/agents/<function>-agent.md.
Critical step. Write .claude/agents/<function>-scope.md containing:
The scope file is the honesty contract. The agent's system prompt references it.
Read existing .mcp.json (or create fresh). Merge in the new server entry from references/function-agent-templates.md. Use ${ENV_VAR} references — never hardcode credentials.
If .mcp.json already has a server with the same name, ask before overwriting.
Add a one-line entry in the appropriate CLAUDE.md (engineering/<project>/CLAUDE.md or company root, depending on scope) under an "Agents" section:
## Function-Specific Agents
- `billing-agent` — Stripe operations within scope. See `.claude/agents/billing-scope.md` for limits.
This tells other agents and humans that the specialist exists.
Run the validators:
python3 ${plugin_root}/scripts/check-mcp-config.py <project>/.mcp.json
python3 ${plugin_root}/scripts/audit-structure.py <project> --skip-projects --skip-hooks
Report:
/mcp in Claude CodeTell the user, verbatim:
Added
<function>agent at<path>. Before this is useful:
- Set the env var(s) listed above
- Restart Claude Code so the MCP server picks up the new config
- Run
/mcpto verify the server is connected- Read
<scope-file>— what this agent will and will NOT doThe agent does not run autonomously. You invoke it like any other Claude Code subagent. Recommended human-in-the-loop checkpoints are listed in the scope file.
claude mcp list and /mcp are the verification tools.references/function-agent-templates.md — Full agent + MCP + scope templates for each supported functionscripts/check-mcp-config.py — Run after MCP changesscripts/audit-structure.py — Run after agent file changesまだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).
日本語の概要は準備中です。原文の説明を表示しています。
You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.
日本語の概要は準備中です。原文の説明を表示しています。
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。