feat: Claude Code Monitor — lanes, pipelines and a merged workspace
Internal SmartGift build of a Claude Code monitoring dashboard. Lanes: a durable unit of parallel agent work, one per working directory, tracked across session restarts. Managed lanes are git worktrees the dashboard provisions and can reset or remove behind a three-check destroy guard and a counted preflight; adopted lanes are directories you already own and are never destroyable. Pipelines: a lane moves through pipeline stages. A stage the agent declares with evidence renders green; a stage inferred from the tool-event stream renders dashed amber and never counts as done. Detection is forward-only within a 30-minute window, and never writes the declared stage. Workspace: one page at /run with a lane grid, the selected lane's pipeline, and a full Claude console behind a disclosure.
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
# Codex Agent Setup
|
||||
|
||||
This directory contains all project-scoped Codex extensions:
|
||||
|
||||
- instruction baseline via root [`AGENTS.md`](../AGENTS.md)
|
||||
- execution policy rules in [`rules/default.rules`](./rules/default.rules)
|
||||
- custom subagent definitions in [`agents/`](./agents)
|
||||
- reusable skills in [`skills/`](./skills)
|
||||
- runtime configuration in [`config.toml`](./config.toml)
|
||||
|
||||
## What Codex reads
|
||||
|
||||
- `AGENTS.md` from repository root
|
||||
- `.codex/config.toml` for runtime settings
|
||||
- `.codex/agents/*.toml` for custom agents
|
||||
- `.codex/skills/*/SKILL.md` for project skills
|
||||
- `.codex/rules/*.rules` for execution policy
|
||||
|
||||
## Included custom agents
|
||||
|
||||
- `reviewer`: read-only, high-rigor review agent
|
||||
- `implementer`: workspace-write implementation agent
|
||||
- `release_auditor`: read-only release readiness checker
|
||||
|
||||
## Included skills
|
||||
|
||||
- `repo-onboarding` — architecture discovery and verification selection
|
||||
- `mcp-maintainer` — MCP server operations and troubleshooting
|
||||
- `release-guard` — release readiness checks
|
||||
@@ -0,0 +1,12 @@
|
||||
name = "implementer"
|
||||
description = "Execution-focused agent for contained feature and bug-fix implementation."
|
||||
model = "gpt-5.3-codex-spark"
|
||||
model_reasoning_effort = "medium"
|
||||
sandbox_mode = "workspace-write"
|
||||
developer_instructions = """
|
||||
Implement requested changes with minimal scope and strong validation.
|
||||
Preserve existing contracts unless change is explicitly requested.
|
||||
Run targeted verification for modified areas and report what was run.
|
||||
Avoid unrelated refactors.
|
||||
"""
|
||||
nickname_candidates = ["Nova", "Forge", "Kite"]
|
||||
@@ -0,0 +1,12 @@
|
||||
name = "release_auditor"
|
||||
description = "Read-only release gate checker for docs, scripts, tests, and risk reporting."
|
||||
model = "gpt-5.4-mini"
|
||||
model_reasoning_effort = "medium"
|
||||
sandbox_mode = "read-only"
|
||||
developer_instructions = """
|
||||
Audit release readiness for this repository.
|
||||
Check command consistency between docs and package scripts.
|
||||
Look for missing verification, stale architecture notes, and risky behavior changes.
|
||||
Produce a concise pass/fail summary with exact file references.
|
||||
"""
|
||||
nickname_candidates = ["Lumen", "Harbor", "Beacon"]
|
||||
@@ -0,0 +1,12 @@
|
||||
name = "reviewer"
|
||||
description = "Read-only reviewer focused on correctness, regressions, security, and missing tests."
|
||||
model = "gpt-5.4"
|
||||
model_reasoning_effort = "high"
|
||||
sandbox_mode = "read-only"
|
||||
developer_instructions = """
|
||||
Review like an owner.
|
||||
Prioritize behavior regressions, correctness, security risks, and missing tests.
|
||||
Lead with concrete findings and file references.
|
||||
Avoid style-only suggestions unless they hide a functional risk.
|
||||
"""
|
||||
nickname_candidates = ["Atlas", "Delta", "Echo"]
|
||||
@@ -0,0 +1,7 @@
|
||||
project_doc_fallback_filenames = ["TEAM_GUIDE.md", ".agents.md"]
|
||||
project_doc_max_bytes = 65536
|
||||
|
||||
[agents]
|
||||
max_threads = 6
|
||||
max_depth = 1
|
||||
job_max_runtime_seconds = 1800
|
||||
@@ -0,0 +1,71 @@
|
||||
# Default execution policy rules for this repository.
|
||||
|
||||
# Safe, routine read-only git inspection can run with prompt.
|
||||
prefix_rule(
|
||||
pattern = ["git", ["status", "diff", "log", "show"]],
|
||||
decision = "prompt",
|
||||
justification = "Git inspection is allowed with approval.",
|
||||
match = [
|
||||
"git status",
|
||||
"git diff",
|
||||
"git log --oneline -20",
|
||||
"git show HEAD~1",
|
||||
],
|
||||
not_match = [
|
||||
"git checkout -b feature/new-branch",
|
||||
],
|
||||
)
|
||||
|
||||
# Destructive reset-style operations are blocked.
|
||||
prefix_rule(
|
||||
pattern = ["git", "reset", "--hard"],
|
||||
decision = "forbidden",
|
||||
justification = "Hard reset is blocked to prevent data loss. Use explicit file edits or safe restore strategies.",
|
||||
match = [
|
||||
"git reset --hard",
|
||||
"git reset --hard HEAD~1",
|
||||
],
|
||||
not_match = [
|
||||
"git reset --soft HEAD~1",
|
||||
],
|
||||
)
|
||||
|
||||
# Installing dependencies should always require approval.
|
||||
prefix_rule(
|
||||
pattern = ["npm", "install"],
|
||||
decision = "prompt",
|
||||
justification = "Dependency installation changes lockfiles and runtime behavior; require explicit approval.",
|
||||
match = [
|
||||
"npm install",
|
||||
"npm install some-package",
|
||||
],
|
||||
not_match = [
|
||||
"npm run build",
|
||||
],
|
||||
)
|
||||
|
||||
# Potentially destructive filesystem deletes are blocked.
|
||||
prefix_rule(
|
||||
pattern = ["rm", "-rf"],
|
||||
decision = "forbidden",
|
||||
justification = "Recursive force deletion is blocked. Use targeted edits or safer deletion commands.",
|
||||
match = [
|
||||
"rm -rf /tmp/test-folder",
|
||||
],
|
||||
not_match = [
|
||||
"rm -r ./tmp",
|
||||
],
|
||||
)
|
||||
|
||||
# Network fetch commands should be reviewed each time.
|
||||
prefix_rule(
|
||||
pattern = ["curl"],
|
||||
decision = "prompt",
|
||||
justification = "Network access should be explicitly reviewed per command.",
|
||||
match = [
|
||||
"curl https://example.com",
|
||||
],
|
||||
not_match = [
|
||||
"cat README.md",
|
||||
],
|
||||
)
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
name: mcp-maintainer
|
||||
description: Operate and maintain the local MCP server for this repository. Use for MCP tool updates, policy-guard changes, host configuration, and MCP runtime troubleshooting.
|
||||
---
|
||||
|
||||
# MCP Maintainer Skill
|
||||
|
||||
## Workflow
|
||||
- Confirm dashboard API availability (`/api/health`).
|
||||
- Inspect affected MCP domain modules under `mcp/src/tools/domains/`.
|
||||
- Preserve safety gates in `mcp/src/policy/tool-guards.ts`.
|
||||
- Validate with `npm run mcp:typecheck` and `npm run mcp:build`.
|
||||
|
||||
## Safety rules
|
||||
- Keep loopback-only target checks enabled.
|
||||
- Keep mutating and destructive tools behind explicit flags.
|
||||
- Do not log protocol data to stdout.
|
||||
|
||||
## References
|
||||
- `references/tool-domain-map.md`
|
||||
- `references/operations-runbook.md`
|
||||
@@ -0,0 +1,4 @@
|
||||
interface:
|
||||
display_name: "MCP Maintainer"
|
||||
short_description: "Maintain MCP tools, policy gates, and host integration."
|
||||
default_prompt: "Use mcp-maintainer to update MCP tooling safely and verify runtime integrity."
|
||||
@@ -0,0 +1,14 @@
|
||||
# MCP Operations Runbook
|
||||
|
||||
## Modes
|
||||
- Read-only:
|
||||
- `MCP_DASHBOARD_ALLOW_MUTATIONS=false`
|
||||
- `MCP_DASHBOARD_ALLOW_DESTRUCTIVE=false`
|
||||
- Admin:
|
||||
- Set mutations true for controlled maintenance operations.
|
||||
- Destructive:
|
||||
- Set both true and require `confirmation_token = CLEAR_ALL_DATA`.
|
||||
|
||||
## Verification
|
||||
- `npm run mcp:typecheck`
|
||||
- `npm run mcp:build`
|
||||
@@ -0,0 +1,8 @@
|
||||
# MCP Tool Domain Map
|
||||
|
||||
- `observability-tools.ts`: health, stats, analytics, snapshots, export.
|
||||
- `session-tools.ts`: list/get/create/update sessions.
|
||||
- `agent-tools.ts`: list/get/create/update agents.
|
||||
- `event-tools.ts`: event listing and hook ingestion.
|
||||
- `pricing-tools.ts`: pricing CRUD and cost calculations.
|
||||
- `maintenance-tools.ts`: cleanup, reimport, reinstall hooks, destructive clear.
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
name: release-guard
|
||||
description: Run release-readiness checks for this repository. Use when validating docs, scripts, verification coverage, and operational safety before merge or release.
|
||||
---
|
||||
|
||||
# Release Guard Skill
|
||||
|
||||
## Workflow
|
||||
- Check command consistency across docs and `package.json`.
|
||||
- Verify architecture docs align with current code paths.
|
||||
- Validate that safety controls are still documented and enforced.
|
||||
- Report pass/fail with concrete file references.
|
||||
|
||||
## Focus areas
|
||||
- Hook flow and failure behavior.
|
||||
- Session/agent lifecycle semantics.
|
||||
- MCP safety gates and host setup instructions.
|
||||
- Troubleshooting accuracy.
|
||||
|
||||
## References
|
||||
- `references/release-checklist.md`
|
||||
@@ -0,0 +1,4 @@
|
||||
interface:
|
||||
display_name: "Release Guard"
|
||||
short_description: "Audit release readiness across code, docs, and safety controls."
|
||||
default_prompt: "Use release-guard to audit this branch for release readiness and report concrete findings."
|
||||
@@ -0,0 +1,7 @@
|
||||
# Release Checklist
|
||||
|
||||
- Commands in docs exist in root `package.json`.
|
||||
- Validation steps are documented for backend, frontend, and MCP.
|
||||
- Behavior-changing diffs mention migration/compatibility impacts.
|
||||
- Safety-sensitive operations remain guarded by explicit flags.
|
||||
- Troubleshooting sections reflect the current architecture.
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
name: repo-onboarding
|
||||
description: Understand this repository quickly before making changes. Use for architecture discovery, ownership mapping, command selection, and initial implementation planning.
|
||||
---
|
||||
|
||||
# Repo Onboarding Skill
|
||||
|
||||
## Workflow
|
||||
- Read `AGENTS.md`, `README.md`, and `ARCHITECTURE.md`.
|
||||
- Determine target layer: `server/`, `client/`, `mcp/`, or docs.
|
||||
- Identify the minimal file set needed for the task.
|
||||
- Select verification commands before editing.
|
||||
|
||||
## Verification defaults
|
||||
- Backend: `npm run test:server`
|
||||
- Frontend: `npm run test:client`
|
||||
- MCP: `npm run mcp:typecheck` and `npm run mcp:build`
|
||||
|
||||
## References
|
||||
- `references/module-map.md`
|
||||
- `references/verification-map.md`
|
||||
@@ -0,0 +1,4 @@
|
||||
interface:
|
||||
display_name: "Repo Onboarding"
|
||||
short_description: "Map architecture, ownership, and verification strategy before coding."
|
||||
default_prompt: "Use repo-onboarding to analyze scope, affected modules, and validation commands for this task."
|
||||
@@ -0,0 +1,9 @@
|
||||
# Module Map
|
||||
|
||||
- `server/index.js`: app startup and route mounting.
|
||||
- `server/routes/*.js`: API contracts and route behavior.
|
||||
- `server/db.js`: schema and statement layer.
|
||||
- `server/websocket.js`: live update broadcast path.
|
||||
- `client/src/pages/`: route-level UI.
|
||||
- `client/src/components/`: reusable UI primitives.
|
||||
- `mcp/src/tools/domains/`: MCP tool families.
|
||||
@@ -0,0 +1,11 @@
|
||||
# Verification Map
|
||||
|
||||
- Backend changes:
|
||||
- `npm run test:server`
|
||||
- Frontend changes:
|
||||
- `npm run test:client`
|
||||
- MCP changes:
|
||||
- `npm run mcp:typecheck`
|
||||
- `npm run mcp:build`
|
||||
- Docs-only changes:
|
||||
- validate command consistency against root `package.json`
|
||||
Reference in New Issue
Block a user