アプリ・Webサービス・業務ツールの制作を、証拠分析→確定的な初稿→要件定義→体験設計→機能分解→実装→品質ゲート→リリース判定の手順ゲート制で進めるスキル。質問で要件を埋めるのではなく、依頼文・既存コード・資料・ログから最有力案を選び、動く成果物を先に出して差分で改善する。ユーザーが「アプリを作りたい」「ツールを作って」「〜を自動化したい」「システム化したい」「要件定義」「仕様を決めたい」「UI/UXを設計して」「体験を良くしたい」「機能を洗い出して」「MVPを決めたい」「品質チェック」「リリースしていいか判断して」などと言ったら必ず使用する。外部データの取込・マスタ・締め処理を伴う業務システムでは references/data-lifecycle.md も併用する。新規・既存を問わずアプリの制作・改善・リニューアルで使用する。
run-codex-plugin-install
Claude Code/Codexへlocal repositoryの全pluginをcwd非依存でuser installしたいとき、またはCodexへmerge済みGit refから単独installしたいときに、marketplace登録・install・receipt検証へ使う。
インストール方法を見る含まれるファイル(3)
- SKILL.md11.4 KB
- prompts/R1-install.md4.1 KB
- workflow-manifest.json4.8 KB
SKILL.md(原文)
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Pre-choice usable artifact execution
Purpose & Output Contractの最小の実成果物またはremote mutation previewをmain contextで作成する。effect別のparse/open・secret・irreversible・corrupt guardだけを実行し、現物path・digest・開き方またはpreview receiptを提示してからaccept-as-is/light/standard/detailedを記録する。accept-as-isはmutationを実行せずhandoff完了とし、後続sectionを実行しない。
Post-choice selected improvement execution
以下の既存workflow・goal-seek・評価・修正sectionおよびexternal mutation safety wrapperはlight/standard/detailedが記録されてsemantic_evaluator_startedへ遷移した場合だけ実行する。actual mutationはcanonical preview→hook-confirm→authorize→execute wrapperだけを通し、release/exhaustiveは別の明示eventを必要とする。
Canonical external mutation receipt flow (mandatory)
Never execute the external mutation argv directly. Replace every angle-bracket placeholder with the reviewed value from this run; the central CLI fails closed on missing/invalid values.
Resolve the guard plugin root once, before preview. An installed plugin cannot reach a sibling
plugin as <plugin root>/.., so never guess that path:
python3 "${PLUGIN_ROOT:-${CLAUDE_PLUGIN_ROOT}}/scripts/extract-plugin-root.py" skill-governance-adapters
Use the printed absolute path as <GUARD_PLUGIN_ROOT> in preview, authorize and execute
(other Bash is blocked while the confirmation is pending, so do not resolve it again).
If the resolver exits non-zero, stop without any external mutation and tell the user to install
the skill-governance-adapters plugin.
python3 "<GUARD_PLUGIN_ROOT>/scripts/build-external-mutation-guard.py" preview --project-root "$PWD" --entrypoint-ref "plugin:<PLUGIN_NAME>/skills/<SKILL_NAME>/SKILL.md" --target-scope "<TARGET_SCOPE>" --diff-summary "<DIFF_SUMMARY>" --side-effect-summary "<SIDE_EFFECT_SUMMARY>" --command-json '<MUTATION_ARGV_JSON>'
Present that official preview output to the user. Only the exact user reply printed by preview
may trigger the registered hook-confirm producer. Then use the two returned receipt paths:
python3 "<GUARD_PLUGIN_ROOT>/scripts/build-external-mutation-guard.py" authorize --project-root "$PWD" --preview-receipt "<PREVIEW_RECEIPT_PATH>" --confirmation-receipt "<CONFIRMATION_RECEIPT_PATH>"
python3 "<GUARD_PLUGIN_ROOT>/scripts/build-external-mutation-guard.py" execute --project-root "$PWD" --authorization-receipt "<AUTHORIZATION_RECEIPT_PATH>" --command-json '<MUTATION_ARGV_JSON>'
Do not use an auto-approval flag or invoke the mutation command outside this receipt flow.
<!-- /external-mutation-guard-cli:v1 -->run-codex-plugin-install
Runtime root contract
runtime_root_policy: host-skill-path の製品別root解決、cwd推測禁止、prompt継承は
ref-cross-platform-runtime の共有正本
をそのまま適用する。installerに渡すrepository rootはplugin runtime rootと混同せず明示入力にする。
Purpose & Output Contract
明示されたlocal/Git sourceとplugin scopeを入力に、marketplace登録・install・CLI実測を一連で実行し、検証済みreceiptを出力する。成功出力は status=installed、verified=true、installed/enabledの実測、runtime identity、hook_trust=user-review-required を含む。user-global install状態を変更する副作用はユーザーがinstallを依頼した場合に限り、hook trustは変更しない。
ユーザーが install を明示依頼した場合だけ、Claude Codeのuser scopeまたはCodexの user-global marketplace/cache/configを変更する。package生成とは別の副作用境界とし、 hook trustは自動承認しない。
入力
plugin-name: marketplaceに掲載済みのplugin identitysource: repository rootの絶対/相対path、またはGit source (owner/repo等)ref: Git sourceだけで指定可能。PR merge後のbranch/tag/SHA
ゴールシーク実行
ゴール (Goal)
ユーザーが明示したplugin scopeだけが指定sourceからinstalledと検証され、runtime identityとhook trust境界を含むreceiptが後続へ渡せる状態になっている。
目的・背景 (Why)
CLIのexit 0だけではinstall実体、enabled状態、version/source/runtimeの一致は証明できない。操作と実測を分け、ユーザー指定scopeとtrust決定権を保ったまま収束させる。
完了チェックリスト (Checklist)
- local/Gitのsource種別、plugin名、refが明示入力と一致する
- receiptに
status/plugin_id/verified/enabled/runtime_pathが存在する -
status=installedかつverified=trueをCLI listのinstalled/enabled実測が支持する - plugin名・version・source・runtime identityが一致する
- runtime pathがabsoluteかつ実在し、repository外cwdの
--checkがexit 0になる - hook trustが
user-review-requiredとして残り、自動承認されていない
ゴールシークループ
workflow-manifest.json の依存とR1 promptを読み、未充足のチェックを1つ選ぶ。preflight・install・receipt検証の候補から現状に必要な最小操作を都度立案・実行し、検証結果でチェックを更新する。全項目充足まで反復し、3周で未達なら残項目を open_issues に記録して成功扱いせず停止する。
ゴールシーク配線
反復はfrontmatter goal_seek.fork=subagent で親contextから分離する。周回状態は eval-log/run-codex-plugin-install-progress.json、アンカーは eval-log/run-codex-plugin-install-intermediate.jsonl に追記し、original_goal を不変として次周の merged_directive_for_next に必ず合流させる。
ゴールシーク検証
アンカーの機械検査は goal-seek正本 を適用する。各行の required_keys、progressの original_goal_hash、hashlib.sha256 による不変アンカー照合が通らなければ完了にしない。
検証
- local全件routeは
install-local-plugins.py --all --checkをrepository外cwdから実行する - 単一local/Git routeはreceiptの
status=installed/verified=true/ identityとcodex plugin list --jsonの実測を照合する - 非0・非JSON・同名多重activation・依存cache version不一致はPASSに変換しない
Claude Code / Codexへlocal全件install
絶対script pathを使えば、harness外のどのcwdからでも実行できる。helperはClaude側では
<repo>/marketplaces/local、Codex側では<repo>を別々の絶対marketplace rootとして登録する。
python3 /absolute/path/to/harness/plugins/harness-creator/scripts/install-local-plugins.py --all
別cwdからread-only verification:
cd /tmp
python3 /absolute/path/to/harness/plugins/harness-creator/scripts/install-local-plugins.py --all --check
1件だけなら--plugin <name>、片方だけなら--platform claude|codexを付ける。
Codex単独のlocal / Git実行
local repository:
python3 "$PLUGIN_ROOT/scripts/install-codex-plugin.py" \
--source /absolute/path/to/repository \
--plugin <plugin-name>
merge済みGit ref:
python3 "$PLUGIN_ROOT/scripts/install-codex-plugin.py" \
--source owner/repo \
--ref main \
--plugin <plugin-name>
helperはmarketplace名をCLI receiptから取得し、Git sourceが既登録ならsnapshotをupgrade、
pluginをinstallし、codex plugin list --jsonでinstalled/enabledを再確認する。
完了条件
- report
status=installed plugin_id=<plugin>@<marketplace>が installed- enabled状態をreportに記録
- local全件installでは両catalogのplugin集合一致、全cache pathの絶対path・実在を確認
- repository外cwdで
--checkがstatus=verified - hook trustは
user-review-requiredのまま保持 - current hook command/eventをユーザーが確認してtrust後、新規threadでskillを確認
失敗時
- local marketplaceに対象entryがなければglobal状態を変更する前に停止
- local sourceへ
--refを指定したら停止 - marketplace add/install/listのいずれかが非0または非JSONならexit 3
- hook trustを代行しない
レビュー
まだレビューはありません。使ってみた感想をお寄せください。
同じリポジトリのスキル
概要と使いどころ
Webアプリの準備→要件定義→設計→実装→公開→品質ゲートを実行する内部オーケストレーター。Claude Codeの /build-app /improve-app、Codexの $build-app / $improve-app から明示的に委譲された場合、custom agent起動時、または利用者が $app-orchestrator を明示した場合だけ使用する。一般のアプリ相談から暗黙起動しない。
run-extract-blueprint が生成した章別ブループリントの忠実性を独立 context で評価したいとき、事実/推測区別と粒度と被覆を検証し draft_hash に束縛した PASS/FAIL verdict をローカル品質ゲート (C01 の周回内の受入判定・差し戻し) へ渡したいときに使う。
確認点で利用者が見る深さを選んだあと打ち合わせ資料を作り手とは別の目で確かめたいとき、正確さ・言葉・見た目・シンプルさの指摘を資料の編集なしで受け取りたいときに使う。
生成した handout 資料が初心者に伝わるか読みやすさレビューを依頼したいとき、独立 context のレビュアーから指摘と根拠つきの verdict を回収したいときに使う。
Notion ページを描画する直前に粒度を検証したいとき、info-collector-agent ページと同等の section 充足度を section_canonical_map 基準で機械検証したいときに使う。