feat: Claude Code Monitor — lanes, pipelines and a merged workspace

Internal SmartGift build of a Claude Code monitoring dashboard.

Lanes: a durable unit of parallel agent work, one per working directory,
tracked across session restarts. Managed lanes are git worktrees the
dashboard provisions and can reset or remove behind a three-check destroy
guard and a counted preflight; adopted lanes are directories you already
own and are never destroyable.

Pipelines: a lane moves through pipeline stages. A stage the agent declares
with evidence renders green; a stage inferred from the tool-event stream
renders dashed amber and never counts as done. Detection is forward-only
within a 30-minute window, and never writes the declared stage.

Workspace: one page at /run with a lane grid, the selected lane's pipeline,
and a full Claude console behind a disclosure.
This commit is contained in:
2026-07-29 17:07:45 +07:00
commit 57dc91585d
783 changed files with 221743 additions and 0 deletions
+29
View File
@@ -0,0 +1,29 @@
# Codex Agent Setup
This directory contains all project-scoped Codex extensions:
- instruction baseline via root [`AGENTS.md`](../AGENTS.md)
- execution policy rules in [`rules/default.rules`](./rules/default.rules)
- custom subagent definitions in [`agents/`](./agents)
- reusable skills in [`skills/`](./skills)
- runtime configuration in [`config.toml`](./config.toml)
## What Codex reads
- `AGENTS.md` from repository root
- `.codex/config.toml` for runtime settings
- `.codex/agents/*.toml` for custom agents
- `.codex/skills/*/SKILL.md` for project skills
- `.codex/rules/*.rules` for execution policy
## Included custom agents
- `reviewer`: read-only, high-rigor review agent
- `implementer`: workspace-write implementation agent
- `release_auditor`: read-only release readiness checker
## Included skills
- `repo-onboarding` — architecture discovery and verification selection
- `mcp-maintainer` — MCP server operations and troubleshooting
- `release-guard` — release readiness checks
+12
View File
@@ -0,0 +1,12 @@
name = "implementer"
description = "Execution-focused agent for contained feature and bug-fix implementation."
model = "gpt-5.3-codex-spark"
model_reasoning_effort = "medium"
sandbox_mode = "workspace-write"
developer_instructions = """
Implement requested changes with minimal scope and strong validation.
Preserve existing contracts unless change is explicitly requested.
Run targeted verification for modified areas and report what was run.
Avoid unrelated refactors.
"""
nickname_candidates = ["Nova", "Forge", "Kite"]
+12
View File
@@ -0,0 +1,12 @@
name = "release_auditor"
description = "Read-only release gate checker for docs, scripts, tests, and risk reporting."
model = "gpt-5.4-mini"
model_reasoning_effort = "medium"
sandbox_mode = "read-only"
developer_instructions = """
Audit release readiness for this repository.
Check command consistency between docs and package scripts.
Look for missing verification, stale architecture notes, and risky behavior changes.
Produce a concise pass/fail summary with exact file references.
"""
nickname_candidates = ["Lumen", "Harbor", "Beacon"]
+12
View File
@@ -0,0 +1,12 @@
name = "reviewer"
description = "Read-only reviewer focused on correctness, regressions, security, and missing tests."
model = "gpt-5.4"
model_reasoning_effort = "high"
sandbox_mode = "read-only"
developer_instructions = """
Review like an owner.
Prioritize behavior regressions, correctness, security risks, and missing tests.
Lead with concrete findings and file references.
Avoid style-only suggestions unless they hide a functional risk.
"""
nickname_candidates = ["Atlas", "Delta", "Echo"]
+7
View File
@@ -0,0 +1,7 @@
project_doc_fallback_filenames = ["TEAM_GUIDE.md", ".agents.md"]
project_doc_max_bytes = 65536
[agents]
max_threads = 6
max_depth = 1
job_max_runtime_seconds = 1800
+71
View File
@@ -0,0 +1,71 @@
# Default execution policy rules for this repository.
# Safe, routine read-only git inspection can run with prompt.
prefix_rule(
pattern = ["git", ["status", "diff", "log", "show"]],
decision = "prompt",
justification = "Git inspection is allowed with approval.",
match = [
"git status",
"git diff",
"git log --oneline -20",
"git show HEAD~1",
],
not_match = [
"git checkout -b feature/new-branch",
],
)
# Destructive reset-style operations are blocked.
prefix_rule(
pattern = ["git", "reset", "--hard"],
decision = "forbidden",
justification = "Hard reset is blocked to prevent data loss. Use explicit file edits or safe restore strategies.",
match = [
"git reset --hard",
"git reset --hard HEAD~1",
],
not_match = [
"git reset --soft HEAD~1",
],
)
# Installing dependencies should always require approval.
prefix_rule(
pattern = ["npm", "install"],
decision = "prompt",
justification = "Dependency installation changes lockfiles and runtime behavior; require explicit approval.",
match = [
"npm install",
"npm install some-package",
],
not_match = [
"npm run build",
],
)
# Potentially destructive filesystem deletes are blocked.
prefix_rule(
pattern = ["rm", "-rf"],
decision = "forbidden",
justification = "Recursive force deletion is blocked. Use targeted edits or safer deletion commands.",
match = [
"rm -rf /tmp/test-folder",
],
not_match = [
"rm -r ./tmp",
],
)
# Network fetch commands should be reviewed each time.
prefix_rule(
pattern = ["curl"],
decision = "prompt",
justification = "Network access should be explicitly reviewed per command.",
match = [
"curl https://example.com",
],
not_match = [
"cat README.md",
],
)
+21
View File
@@ -0,0 +1,21 @@
---
name: mcp-maintainer
description: Operate and maintain the local MCP server for this repository. Use for MCP tool updates, policy-guard changes, host configuration, and MCP runtime troubleshooting.
---
# MCP Maintainer Skill
## Workflow
- Confirm dashboard API availability (`/api/health`).
- Inspect affected MCP domain modules under `mcp/src/tools/domains/`.
- Preserve safety gates in `mcp/src/policy/tool-guards.ts`.
- Validate with `npm run mcp:typecheck` and `npm run mcp:build`.
## Safety rules
- Keep loopback-only target checks enabled.
- Keep mutating and destructive tools behind explicit flags.
- Do not log protocol data to stdout.
## References
- `references/tool-domain-map.md`
- `references/operations-runbook.md`
@@ -0,0 +1,4 @@
interface:
display_name: "MCP Maintainer"
short_description: "Maintain MCP tools, policy gates, and host integration."
default_prompt: "Use mcp-maintainer to update MCP tooling safely and verify runtime integrity."
@@ -0,0 +1,14 @@
# MCP Operations Runbook
## Modes
- Read-only:
- `MCP_DASHBOARD_ALLOW_MUTATIONS=false`
- `MCP_DASHBOARD_ALLOW_DESTRUCTIVE=false`
- Admin:
- Set mutations true for controlled maintenance operations.
- Destructive:
- Set both true and require `confirmation_token = CLEAR_ALL_DATA`.
## Verification
- `npm run mcp:typecheck`
- `npm run mcp:build`
@@ -0,0 +1,8 @@
# MCP Tool Domain Map
- `observability-tools.ts`: health, stats, analytics, snapshots, export.
- `session-tools.ts`: list/get/create/update sessions.
- `agent-tools.ts`: list/get/create/update agents.
- `event-tools.ts`: event listing and hook ingestion.
- `pricing-tools.ts`: pricing CRUD and cost calculations.
- `maintenance-tools.ts`: cleanup, reimport, reinstall hooks, destructive clear.
+21
View File
@@ -0,0 +1,21 @@
---
name: release-guard
description: Run release-readiness checks for this repository. Use when validating docs, scripts, verification coverage, and operational safety before merge or release.
---
# Release Guard Skill
## Workflow
- Check command consistency across docs and `package.json`.
- Verify architecture docs align with current code paths.
- Validate that safety controls are still documented and enforced.
- Report pass/fail with concrete file references.
## Focus areas
- Hook flow and failure behavior.
- Session/agent lifecycle semantics.
- MCP safety gates and host setup instructions.
- Troubleshooting accuracy.
## References
- `references/release-checklist.md`
@@ -0,0 +1,4 @@
interface:
display_name: "Release Guard"
short_description: "Audit release readiness across code, docs, and safety controls."
default_prompt: "Use release-guard to audit this branch for release readiness and report concrete findings."
@@ -0,0 +1,7 @@
# Release Checklist
- Commands in docs exist in root `package.json`.
- Validation steps are documented for backend, frontend, and MCP.
- Behavior-changing diffs mention migration/compatibility impacts.
- Safety-sensitive operations remain guarded by explicit flags.
- Troubleshooting sections reflect the current architecture.
+21
View File
@@ -0,0 +1,21 @@
---
name: repo-onboarding
description: Understand this repository quickly before making changes. Use for architecture discovery, ownership mapping, command selection, and initial implementation planning.
---
# Repo Onboarding Skill
## Workflow
- Read `AGENTS.md`, `README.md`, and `ARCHITECTURE.md`.
- Determine target layer: `server/`, `client/`, `mcp/`, or docs.
- Identify the minimal file set needed for the task.
- Select verification commands before editing.
## Verification defaults
- Backend: `npm run test:server`
- Frontend: `npm run test:client`
- MCP: `npm run mcp:typecheck` and `npm run mcp:build`
## References
- `references/module-map.md`
- `references/verification-map.md`
@@ -0,0 +1,4 @@
interface:
display_name: "Repo Onboarding"
short_description: "Map architecture, ownership, and verification strategy before coding."
default_prompt: "Use repo-onboarding to analyze scope, affected modules, and validation commands for this task."
@@ -0,0 +1,9 @@
# Module Map
- `server/index.js`: app startup and route mounting.
- `server/routes/*.js`: API contracts and route behavior.
- `server/db.js`: schema and statement layer.
- `server/websocket.js`: live update broadcast path.
- `client/src/pages/`: route-level UI.
- `client/src/components/`: reusable UI primitives.
- `mcp/src/tools/domains/`: MCP tool families.
@@ -0,0 +1,11 @@
# Verification Map
- Backend changes:
- `npm run test:server`
- Frontend changes:
- `npm run test:client`
- MCP changes:
- `npm run mcp:typecheck`
- `npm run mcp:build`
- Docs-only changes:
- validate command consistency against root `package.json`