Build your repo
Your stack
1Database
ORM
Vercel AI SDK with a streaming chat route, structured output and tool calling.
4 rules · 2 skills · 6 docs
- AI bundle works best with a database.
Users, bans, impersonation and an audit log at /admin. Needs sign in.
2 rules · 2 skills · 8 docs
Analytics
Error tracking
Support chat
Mode
The plan loop without the gate. Best when you work alone.
Agent tools
Next.js 16 on Vercel. The only stack for now.
my-app/, 200 files, Next.js 16 on Vercel
What your agent gets
52 items. 12 written for your 1 battery.
Guard hooks6
- block-destructiveBefore BashBase
Blocks irreversible shell commands: recursive force deletes, DROP and TRUNCATE sent to a database, force pushes, git reset --hard, git clean, dd, and truncating redirects onto tracked files.
- enforce-typecheckBefore BashBase
Rewrites a bare tsc, however it is launched, into the project's typecheck script before it runs.
- env-leak-detectorBefore Bash, Read, GrepBase
Blocks tool calls that would print, transmit or commit a secret: literal credential shapes, reads of local .env files by any command or by the Read and Grep tools, echo of secret variables, environment dumps, and live values from your .env files.
- auto-lintAfter Edit, Write, MultiEditBase
Runs Biome on the file that was just edited, applies safe fixes, and reports anything it could not fix.
- enforce-doc-metaAfter Edit, Write, MultiEditBase
Checks that files written under docs/solutions/ and docs/plans/ carry the frontmatter those directories depend on, and reports exactly what is missing.
2 more hooks run in team mode.
Rules12
- Never interpolate untrusted text into a system promptAI bundle
When editing
src/lib/ai/**+1 more - Model calls stay on the server, and they streamAI bundle
When editing
src/lib/ai/**+4 more - Every structured call carries a Zod schemaAI bundle
When editing
src/lib/ai/**+1 more - Every tool validates its own inputAI bundle
When editing
src/lib/ai/tools/**+2 more - Default: tokens only, and both modes every timeDefault design
When editing
src/components/**+1 more
Skills10
- /add-toolAI bundle
Add a tool the model can call (schema, execute, registry entry, surface and a test) without widening what a stranger's sentence can reach.
- /eval-promptAI bundle
Change a prompt, a model or a schema safely. Build the eval suite first, measure the baseline, change one thing, and compare pass rates.
- /new-componentDefault design
Add a component to the Default kit: prefer pasting from shadcn/ui, fix the two bridge classes, keep it token-only and verify it in both light and dark.
- /deploy-to-vercelBase
Ship my-app to Vercel: local gates, environment variables per scope, preview verification, promotion and rollback.
- /helpBase
Explain the agentic system in this repo (rules, skills, agents, hooks, solution docs and the CE loop) and where to go for help beyond it.
Subagents5
- designerDefault design
Owns the Default design system and its shadcn bridge. The only agent allowed to introduce a new visual pattern or a new token. Refuses to ship a raw colour or a single-mode change.
- documentarianBase
Keeps README, CLAUDE.md, DESIGN.md, docs/onboard.md and docs/solutions/ true to the code. Writes solution docs from work that just landed.
- pr-reviewerBase
Reviews a diff against this repo's rules before it becomes a PR. Convention-aware, blocking on correctness and security, advisory on taste.
- security-auditorBase
Audits the repo or a diff for leaked secrets, broken auth boundaries, injection, unsafe dependencies and unsafe deploy configuration.
- system-managerBase
Maintains the .claude agentic layer itself: rules, skills, agents, hooks, settings. Adds a rule when a correction repeats.
Solution docs19
- Prompt injection through user content: why delimiters are not the fixAI bundle
- Streaming edge cases: aborts, disconnects, backpressure and errors after the first tokenAI bundle
- Tool retries and partial failures: what the AI SDK retries and what it does notAI bundle
- When to add usage metering to an AI feature, and how to do it in an afternoonAI bundle
- When AI work has to move to a background job, and what breaks if you waitAI bundle
MCP servers0
No MCP servers for this stack yet.
- settings.json
- onboard.md
- proxy.ts
- .env.example
- .gitignore
- CLAUDE.md
- DESIGN.md
- README.md
- agentic.config.json
- biome.jsonc
- components.json
- next.config.ts
- package.json
- playwright.config.ts
- postcss.config.mjs
- tsconfig.json
- vercel.json
- vitest.config.ts
CLAUDE.md
Structure preview. Repo-wide rule bodies are written into the real file in full.
# my-app Generated by [Agentic Boilerplate](https://github.com/agentic-studio/agentic-boilerplate) from [Agentic Studio](https://theagentic.studio). Same `agentic.config.json`, same repo: regenerate and diff any time. - **Stack:** Next.js on Vercel (`nextjs-vercel`)- **Batteries:** AI bundle (`ai-bundle`)- **Design:** Default (`default`). See [DESIGN.md](DESIGN.md).- **Package manager:** bun- **Mode:** solo- **Agent targets:** claude ## Read this first On a fresh clone, read [docs/onboard.md](docs/onboard.md) before running orediting anything. It lists every environment variable, where to get it, andthe order to set the services up. ```shbun installcp .env.example .env.localbun run verifybun run dev``` ## How this repo is set up for agents - `.claude/rules/`: 12 rules. 3 load every session, 9 load when you read a file they cover.- `.claude/agents/`: 5 subagents, listed below.- `.claude/skills/`: 10 skills, listed below.- `.claude/hooks/`: 6 guard hooks, wired in `.claude/settings.json` for Claude Code.- `docs/solutions/`: 19 solved problems. Read the relevant one before re-solving anything.- `docs/plans/`: one plan per unit of work. Run `bun run verify:hooks` to prove the guards still block what they claim to block.Do not edit `.claude/settings.json` by hand: the `system-manager` agent owns it. ## Workflow The Compound Engineering plugin adds the loop: `/ce-brainstorm`, `/ce-plan`, `/ce-work`, `/ce-code-review`, `/ce-compound`.`.claude/settings.json` enables it once you trust this folder. If the commands are missing, run `/plugin install compound-engineering@compound-engineering-plugin`. ## Rules Loaded every session: - [Code style and file conventions](.claude/rules/code-style.md)- [Git and change hygiene](.claude/rules/git.md)- [Security rules](.claude/rules/security.md) Loaded when you read a file they cover: | Rule | Applies to ||---|---|| [Never interpolate untrusted text into a system prompt](.claude/rules/ai-prompt-safety.md) | `src/lib/ai/**`, `src/app/api/**` || [Model calls stay on the server, and they stream](.claude/rules/ai-server-boundary.md) | `src/lib/ai/**`, `src/app/api/chat/**`, `src/app/api/agent/**`, `src/components/ai/**`, `vercel.json` || [Every structured call carries a Zod schema](.claude/rules/ai-structured-output.md) | `src/lib/ai/**`, `src/app/api/**` || [Every tool validates its own input](.claude/rules/ai-tools.md) | `src/lib/ai/tools/**`, `src/lib/ai/agent.ts`, `src/app/api/agent/**` || [Deployment rules](.claude/rules/deployment.md) | `next.config.ts`, `vercel.json`, `package.json`, `src/proxy.ts`, `src/app/**/route.ts`, `.env.example` || [Landing page, legal pages and llms.txt](.claude/rules/landing-and-legal.md) | `src/lib/site.ts`, `src/lib/llms.ts`, `src/app/page.tsx`, `src/app/(legal)/**`, `src/app/llms.txt/**`, `src/components/marketing/**`, `src/components/site/**` || [Testing rules](.claude/rules/testing.md) | `tests/**`, `src/**/*.test.ts`, `src/**/*.test.tsx` || [Default: tokens only, and both modes every time](.claude/rules/tokens-only.md) | `src/components/**`, `src/app/**` || [Build UI from the component kit](.claude/rules/ui-kit.md) | `src/components/**`, `src/app/**` | ## Skills | Skill | Use it for ||---|---|| `/add-tool` | Add a tool the model can call (schema, execute, registry entry, surface and a test) without widening what a stranger's sentence can reach. || `/deploy-to-vercel` | Ship my-app to Vercel: local gates, environment variables per scope, preview verification, promotion and rollback. || `/eval-prompt` | Change a prompt, a model or a schema safely. Build the eval suite first, measure the baseline, change one thing, and compare pass rates. || `/help` | Explain the agentic system in this repo (rules, skills, agents, hooks, solution docs and the CE loop) and where to go for help beyond it. || `/landing-copy` | Rewrite the landing page, the metadata and the legal details for the real product from a short brief, by editing src/lib/site.ts only. || `/new-component` | Add a component to the Default kit: prefer pasting from shadcn/ui, fix the two bridge classes, keep it token-only and verify it in both light and dark. || `/qa-feature` | Exercise a feature end to end (happy path, unhappy paths, auth boundaries, refresh and mobile) before anyone calls it done. || `/security-audit` | Run the standing security pass through the security-auditor agent (secrets, auth boundaries, injection, dependencies and deploy config) and turn findings into fixes. || `/verify` | Prove the repo is actually configured: every required env var present, every configured service reachable, and the guard hooks still blocking what they claim to block. || `/write-spec` | Turn a loose request into a written spec (problem, scope, behaviour, acceptance criteria) that /ce-plan can consume without guessing. | ## Subagents | Agent | Use it for ||---|---|| `designer` | Owns the Default design system and its shadcn bridge. The only agent allowed to introduce a new visual pattern or a new token. Refuses to ship a raw colour or a single-mode change. || `documentarian` | Keeps README, CLAUDE.md, DESIGN.md, docs/onboard.md and docs/solutions/ true to the code. Writes solution docs from work that just landed. || `pr-reviewer` | Reviews a diff against this repo's rules before it becomes a PR. Convention-aware, blocking on correctness and security, advisory on taste. || `security-auditor` | Audits the repo or a diff for leaked secrets, broken auth boundaries, injection, unsafe dependencies and unsafe deploy configuration. || `system-manager` | Maintains the .claude agentic layer itself: rules, skills, agents, hooks, settings. Adds a rule when a correction repeats. | ## Credit Generated by [Agentic Boilerplate](https://github.com/agentic-studio/agentic-boilerplate) from [Agentic Studio](https://theagentic.studio). - [AI Mechanic](https://theagentic.studio/ai-mechanic): Fix a vibe-coded repo, then install this system into it.- [Claude Engineering System](https://theagentic.studio/claude-engineering-system): The same agentic layer, installed into your existing codebase.- [AI Product Sprint](https://theagentic.studio/ai-product-sprint): We build the MVP on top of a repo like this one.
Default. shadcn done carefully. Neutral greys, near-black actions, one blue for links, Geist throughout.
Your agents read this design’s DESIGN.md before they touch a colour.
