Build your repo
Your stack
6- Drizzle ORM came with Supabase. Supabase needs an ORM.
Database
ORM
- Supabase works best with Supabase Auth.
- Supabase works best with Supabase Storage.
Vercel AI SDK with a streaming chat route, structured output and tool calling.
4 rules · 2 skills · 6 docs
Users, bans, impersonation and an audit log at /admin. Needs sign in.
2 rules · 2 skills · 8 docs
Analytics
Error tracking
Support chat
- PostHog works best with error tracking.
Mode
The plan loop without the gate. Best when you work alone.
Agent tools
Next.js 16 on Vercel. The only stack for now.
my-app/, 346 files, Next.js 16 on Vercel
What your agent gets
104 items. 60 written for your 6 batteries.
Guard hooks6
- block-destructiveBefore BashBase
Blocks irreversible shell commands: recursive force deletes, DROP and TRUNCATE sent to a database, force pushes, git reset --hard, git clean, dd, and truncating redirects onto tracked files.
- enforce-typecheckBefore BashBase
Rewrites a bare tsc, however it is launched, into the project's typecheck script before it runs.
- env-leak-detectorBefore Bash, Read, GrepBase
Blocks tool calls that would print, transmit or commit a secret: literal credential shapes, reads of local .env files by any command or by the Read and Grep tools, echo of secret variables, environment dumps, and live values from your .env files.
- auto-lintAfter Edit, Write, MultiEditBase
Runs Biome on the file that was just edited, applies safe fixes, and reports anything it could not fix.
- enforce-doc-metaAfter Edit, Write, MultiEditBase
Checks that files written under docs/solutions/ and docs/plans/ carry the frontmatter those directories depend on, and reports exactly what is missing.
2 more hooks run in team mode.
Rules22
- Authorise from the session, never from the client user objectClerk
When editing
src/app/**+2 more - Clerk's components wear the design's tokens and only render inside the providerClerk
When editing
src/components/auth/**+3 more - The Clerk webhook verifies its signature before anything elseClerk
When editing
src/app/api/webhooks/clerk/**+3 more - Row level security is on by default and the service role is a last resortSupabase
When editing
src/db/** - Schema changes go through supabase/migrations, never the dashboardSupabase
When editing
supabase/**
Skills21
- /add-clerk-roleClerk
Add a role to the Clerk-backed role vocabulary, wire it into the session claim, gate a route with it, and assign it safely.
- /sync-clerk-userClerk
Extend, backfill or re-verify the Clerk user mirror: the users table and ClerkSyncStore that this battery already ships.
- /add-rls-policySupabase
Add or fix row level security policies on a Supabase table, with a migration, a policy test and regenerated types.
- /local-supabaseSupabase
Boot, reset, inspect and troubleshoot the local Supabase stack, and pull schema down from a hosted project.
- /add-tableDrizzle ORM
Add a table to the Drizzle schema, generate and apply its migration, and wire the typed queries for it.
Subagents6
- product-analystPostHog
Read-only product analyst. Answers questions about user behaviour from the event catalogue and the PostHog project, and says plainly when the instrumentation cannot answer them.
- designerPaper design
Owns the Paper design system and its shadcn bridge. The only agent allowed to introduce a new visual pattern or a new token. Refuses to ship a raw colour or a single-mode change.
- documentarianBase
Keeps README, CLAUDE.md, DESIGN.md, docs/onboard.md and docs/solutions/ true to the code. Writes solution docs from work that just landed.
- pr-reviewerBase
Reviews a diff against this repo's rules before it becomes a PR. Convention-aware, blocking on correctness and security, advisory on taste.
- security-auditorBase
Audits the repo or a diff for leaked secrets, broken auth boundaries, injection, unsafe dependencies and unsafe deploy configuration.
Solution docs47
- Clerk impersonation, the act claim, and what to lock while it is onClerk
- Protecting route handlers is not the same as protecting pagesClerk
- Clerk roles: publicMetadata or your own table?Clerk
- Make Clerk's sign-in look native, in light and dark, with CSS variablesClerk
- Testing a Clerk webhook locally without a tunnel round tripClerk
MCP servers2
- supabase
- posthog
- settings.json
- onboard.md
- proxy.ts
- .env.example
- .gitignore
- .mcp.json
- CLAUDE.md
- DESIGN.md
- README.md
- agentic.config.json
- biome.jsonc
- components.json
- drizzle.config.ts
- next.config.ts
- package.json
- playwright.config.ts
- postcss.config.mjs
- sanity.cli.ts
- sanity.config.ts
- tsconfig.json
- vitest.config.ts
CLAUDE.md
Structure preview. Repo-wide rule bodies are written into the real file in full.
# my-app Generated by [Agentic Boilerplate](https://github.com/agentic-studio/agentic-boilerplate) from [Agentic Studio](https://theagentic.studio). Same `agentic.config.json`, same repo: regenerate and diff any time. - **Stack:** Next.js on Vercel (`nextjs-vercel`)- **Batteries:** Drizzle ORM (`drizzle`), Supabase (`supabase`), Clerk (`clerk`), Resend (`resend`), PostHog (`posthog`), Sanity blog (`blog-sanity`)- **Design:** Paper (`paper`). See [DESIGN.md](DESIGN.md).- **Package manager:** bun- **Mode:** solo- **Agent targets:** claude ## Read this first On a fresh clone, read [docs/onboard.md](docs/onboard.md) before running orediting anything. It lists every environment variable, where to get it, andthe order to set the services up. ```shbun installcp .env.example .env.localbun run verifybun run dev``` ## How this repo is set up for agents - `.claude/rules/`: 22 rules. 3 load every session, 19 load when you read a file they cover.- `.claude/agents/`: 6 subagents, listed below.- `.claude/skills/`: 21 skills, listed below.- `.claude/hooks/`: 6 guard hooks, wired in `.claude/settings.json` for Claude Code.- `.mcp.json`: 2 MCP servers (`posthog`, `supabase`). Setup is in [docs/onboard.md](docs/onboard.md).- `docs/solutions/`: 47 solved problems. Read the relevant one before re-solving anything.- `docs/plans/`: one plan per unit of work. Run `bun run verify:hooks` to prove the guards still block what they claim to block.Do not edit `.claude/settings.json` by hand: the `system-manager` agent owns it. ## Workflow The Compound Engineering plugin adds the loop: `/ce-brainstorm`, `/ce-plan`, `/ce-work`, `/ce-code-review`, `/ce-compound`.`.claude/settings.json` enables it once you trust this folder. If the commands are missing, run `/plugin install compound-engineering@compound-engineering-plugin`. ## Rules Loaded every session: - [Code style and file conventions](.claude/rules/code-style.md)- [Git and change hygiene](.claude/rules/git.md)- [Security rules](.claude/rules/security.md) Loaded when you read a file they cover: | Rule | Applies to ||---|---|| [Pages in the signed-in app](.claude/rules/app-shell.md) | `src/app/(app)/**`, `src/components/app/**`, `src/components/ui/sidebar.tsx`, `src/lib/app-shell.ts`, `src/lib/nav.ts` || [Authorise from the session, never from the client user object](.claude/rules/authorise-on-the-server.md) | `src/app/**`, `src/components/**`, `src/lib/auth/**` || [Clerk's components wear the design's tokens and only render inside the provider](.claude/rules/clerk-ui-follows-the-design.md) | `src/components/auth/**`, `src/lib/auth/appearance.ts`, `src/app/(auth)/**`, `src/components/site/header.tsx` || [Deployment rules](.claude/rules/deployment.md) | `next.config.ts`, `vercel.json`, `package.json`, `src/proxy.ts`, `src/app/**/route.ts`, `.env.example` || [Every schema change ships with its generated migration](.claude/rules/drizzle-migrations.md) | `src/db/**`, `drizzle/**`, `drizzle.config.ts` || [Schema and query conventions for Drizzle](.claude/rules/drizzle-schema.md) | `src/db/**` || [Every email goes through sendEmail, from a verified domain, with a reply-to](.claude/rules/email-sending-discipline.md) | `src/lib/email/**`, `src/app/api/webhooks/resend/**`, `src/lib/auth/**`, `src/lib/billing/**` || [Events are declared in the catalogue, named object_verb, past tense](.claude/rules/event-naming.md) | `src/lib/analytics/**`, `src/app/**`, `src/components/**` || [Identify before the first event that matters, reset on sign-out](.claude/rules/identify-timing.md) | `src/lib/analytics/**`, `src/app/**`, `src/components/**` || [Landing page, legal pages and llms.txt](.claude/rules/landing-and-legal.md) | `src/lib/site.ts`, `src/lib/llms.ts`, `src/app/page.tsx`, `src/app/(legal)/**`, `src/app/llms.txt/**`, `src/components/marketing/**`, `src/components/site/**` || [Read tokens stay on the server, Portable Text uses design tokens](.claude/rules/sanity-runtime.md) | `src/app/(sanity)/**`, `src/app/studio/**`, `src/app/api/draft-mode/**`, `src/app/api/sanity/**`, `src/components/sanity/**`, `sanity/lib/**` || [The schema is code, and every GROQ query lives in one file](.claude/rules/sanity-schema.md) | `sanity/**`, `sanity.config.ts` || [Server events for anything a client can lie about, and never PII in properties](.claude/rules/server-truth-and-pii.md) | `src/lib/analytics/**`, `src/app/**`, `src/components/**` || [Row level security is on by default and the service role is a last resort](.claude/rules/supabase-db-access.md) | `src/db/**` || [Schema changes go through supabase/migrations, never the dashboard](.claude/rules/supabase-migrations.md) | `supabase/**` || [Testing rules](.claude/rules/testing.md) | `tests/**`, `src/**/*.test.ts`, `src/**/*.test.tsx` || [Paper: tokens only, and both modes every time](.claude/rules/tokens-only.md) | `src/components/**`, `src/app/**` || [Build UI from the component kit](.claude/rules/ui-kit.md) | `src/components/**`, `src/app/**` || [The Clerk webhook verifies its signature before anything else](.claude/rules/verify-the-webhook-first.md) | `src/app/api/webhooks/clerk/**`, `src/lib/auth/user-sync.ts`, `src/lib/auth/user-store.ts`, `src/lib/auth/webhook-idempotency.ts` | ## Skills | Skill | Use it for ||---|---|| `/add-app-page` | Add a page to the signed-in app (sidebar entry, session check, loading state), or a new tab under /settings. || `/add-clerk-role` | Add a role to the Clerk-backed role vocabulary, wire it into the session claim, gate a route with it, and assign it safely. || `/add-email-template` | Add a React Email template, preview it, wire it into a send, and check it renders and lands in a real inbox. || `/add-event` | Add a product event end to end: catalogue entry, the question it answers, the capture call on the correct side of the network, and a check that it arrives. || `/add-rls-policy` | Add or fix row level security policies on a Supabase table, with a migration, a policy test and regenerated types. || `/add-sanity-type` | Add or extend a Sanity document type end to end (schema, GROQ projection, result type, renderer and cache tags) so nothing renders blank. || `/add-table` | Add a table to the Drizzle schema, generate and apply its migration, and wire the typed queries for it. || `/ask-product` | Answer a question about user behaviour from this repo's event catalogue and the PostHog project, with the caveats that make the number usable. || `/deploy-to-vercel` | Ship my-app to Vercel: local gates, environment variables per scope, preview verification, promotion and rollback. || `/help` | Explain the agentic system in this repo (rules, skills, agents, hooks, solution docs and the CE loop) and where to go for help beyond it. || `/landing-copy` | Rewrite the landing page, the metadata and the legal details for the real product from a short brief, by editing src/lib/site.ts only. || `/local-supabase` | Boot, reset, inspect and troubleshoot the local Supabase stack, and pull schema down from a hosted project. || `/migrate` | Generate, review and apply Drizzle migrations safely, including backfills, destructive changes and the deploy step. || `/new-component` | Add a component to the Paper kit. Prefer pasting from shadcn/ui, fix the two bridge classes, keep it token-only and verify it in both light and dark. || `/preview-and-test-email` | Diagnose an email problem (not sending, landing in spam, rendering wrong) in the order that finds the cause fastest. || `/preview-draft` | Set up or debug Sanity draft previews: the enable route, the secret, the banner, and why an editor is still seeing published content. || `/qa-feature` | Exercise a feature end to end (happy path, unhappy paths, auth boundaries, refresh and mobile) before anyone calls it done. || `/security-audit` | Run the standing security pass through the security-auditor agent (secrets, auth boundaries, injection, dependencies and deploy config) and turn findings into fixes. || `/sync-clerk-user` | Extend, backfill or re-verify the Clerk user mirror: the users table and ClerkSyncStore that this battery already ships. || `/verify` | Prove the repo is actually configured: every required env var present, every configured service reachable, and the guard hooks still blocking what they claim to block. || `/write-spec` | Turn a loose request into a written spec (problem, scope, behaviour, acceptance criteria) that /ce-plan can consume without guessing. | ## Subagents | Agent | Use it for ||---|---|| `designer` | Owns the Paper design system and its shadcn bridge. The only agent allowed to introduce a new visual pattern or a new token. Refuses to ship a raw colour or a single-mode change. || `documentarian` | Keeps README, CLAUDE.md, DESIGN.md, docs/onboard.md and docs/solutions/ true to the code. Writes solution docs from work that just landed. || `pr-reviewer` | Reviews a diff against this repo's rules before it becomes a PR. Convention-aware, blocking on correctness and security, advisory on taste. || `product-analyst` | Read-only product analyst. Answers questions about user behaviour from the event catalogue and the PostHog project, and says plainly when the instrumentation cannot answer them. || `security-auditor` | Audits the repo or a diff for leaked secrets, broken auth boundaries, injection, unsafe dependencies and unsafe deploy configuration. || `system-manager` | Maintains the .claude agentic layer itself: rules, skills, agents, hooks, settings. Adds a rule when a correction repeats. | ## Credit Generated by [Agentic Boilerplate](https://github.com/agentic-studio/agentic-boilerplate) from [Agentic Studio](https://theagentic.studio). - [AI Mechanic](https://theagentic.studio/ai-mechanic): Fix a vibe-coded repo, then install this system into it.- [Claude Engineering System](https://theagentic.studio/claude-engineering-system): The same agentic layer, installed into your existing codebase.- [AI Product Sprint](https://theagentic.studio/ai-product-sprint): We build the MVP on top of a repo like this one.
Paper. Serif headlines on white paper, a grainy peach haze, black pill buttons and product sheets that float.
Your agents read this design’s DESIGN.md before they touch a colour.
