orchestkit

内容来源:README.md(说明文档) · 原始地址 · 查看安装指南

原始内容

OrchestKit - Stop explaining your stack. Start shipping.

105 skills · 36 agents · 218 hooks

Claude Code License GitHub Stars Community Ask DeepWiki

MCP Toplist


Explore the Docs → · OrchestKit Community →
Skill browser, demo gallery, setup wizard


Contents

Quick Start

/plugin marketplace add yonatangross/orchestkit
/plugin install ork

Then start your personalized onboarding:

/ork:setup

The setup wizard scans your codebase, detects your tech stack, recommends skills for your needs, configures MCP servers, and creates a readiness score — all in one command.


Why OrchestKit?

Every Claude Code session starts from zero. You explain your stack, patterns, preferences—again and again.

OrchestKit gives Claude persistent knowledge of production patterns that work automatically:

Without With OrchestKit
"Use FastAPI with async SQLAlchemy 2.0..." "Create an API endpoint" → Done right
"Remember cursor pagination, not offset..." Agents know your patterns
"Don't commit to main branch..." Hooks block bad commits
"Run tests before committing..." /ork:commit runs tests for you

What You Get

One unified plugin, everything included.

Component Details
105 Skills RAG patterns, FastAPI, React 19, testing, security, database design, ML integration — loaded on-demand, zero overhead
36 Agents Specialized personas (backend-architect, frontend-dev, security-auditor) — route tasks to the right expert
218 Hooks Pre-commit checks, git protection, quality gates, browser safety — ship with confidence

All available in a single /plugin install ork. Skills load on-demand. Hooks work automatically.

Browse everything in the Docs →


Key Commands

/ork:auto         # Front door: describe a goal, it routes to the right skill
/ork:setup        # Personalized onboarding wizard
/ork:implement    # Full-stack implementation with parallel agents
/ork:expect       # Diff-aware AI browser testing
/ork:review-pr    # PR review with parallel agents
/ork:verify       # Multi-agent validation
/ork:commit       # Conventional commit with pre-checks
/ork:explore      # Analyze unfamiliar codebase
/ork:remember     # Save to persistent memory
/ork:doctor       # Health check

Configuration

/ork:setup detects your stack, recommends MCP servers, and writes the configuration for you.

Recommended MCP Servers

Server Purpose Required?
Context7 Up-to-date library docs Recommended
Memory Knowledge graph persistence Recommended
Sequential Thinking Structured reasoning for subagents Recommended
Tavily Web search and extraction Optional

Set "alwaysLoad": true on the first three in your .mcp.json. It skips the per-skill tool probe and shaves ~150ms off cold starts.

Customizing skills

Skills install as files on your disk, but don't hand-edit the installed copy — it gets overwritten on update and silently diverges from the canonical playbook. The supported ways to extend (user-level skills, project skills, upstream PRs, or disabling a bundled skill) are in docs/extending-skills.md.


What OrchestKit observes

OrchestKit is a quality-gate plugin, so its hooks are the product rather than an add-on. This section states plainly what they see, where it goes, and how to turn each piece off.

Scope: broad and intentional. OrchestKit registers 218 hooks across 29 lifecycle events, including SessionStart, UserPromptSubmit, PreToolUse, PostToolUse, and Stop. They are not gated to a particular framework or project type, because the gates they enforce (secret-write blocking, protected-file guards, git safety, file-size limits, agent status protocol) apply to any codebase. If you only want gates on some projects, enable the plugin per-project rather than globally.

Where data goes: a local file on your own disk.

What Destination Notes
Lifecycle events (session end, PR merged, goal converged, chain phase) ~/.local/state/orchestkit/events.jsonl Written unconditionally, rotated at 10 MB. ORK_EVENTS_LOG redirects the path (used by the test suite)
Hook metrics: event name, tool name, payload size, duration same local file Size-capped metrics only
Prompt text and file contents Never recorded Hooks read them to make an allow/deny decision, then discard
Remote sync Off No endpoint is compiled in; see below

There is deliberately no global kill switch for the local write, because the gates depend on that state (the git-safety and chain-staleness hooks read their own prior events). To stop it entirely, disable the plugin. Individual noisy hooks have their own opt-outs: ORK_DISABLE_DEBT_TRACKER, ORK_DISABLE_WORKTREE_VERIFIER, ORK_DISABLE_COORDINATION_METRICS, ORK_NO_NOTIFY, ORK_NO_STALE_SWEEP, and ORCHESTKIT_SKIP_SLOW_HOOKS among others.

Network access is opt-in and unset by default. There is no hardcoded remote host anywhere in the shipped hook bundles (grep -o 'https\?://' plugins/ork/hooks/dist/*.mjs returns nothing). An outbound call happens only if you configure a destination yourself, via one of:

  • ORCHESTKIT_HOOK_URL + ORCHESTKIT_HOOK_TOKEN, which enable the manual hooks/bin/telemetry-sync.mjs CLI. It POSTs your local JSONL to your own endpoint. No hook ever invokes it; you run it by hand.
  • ORK_HQ_TELEMETRY_URL, which points the telemetry HTTP sink at your own collector.
  • ORK_HQ_TELEMETRY_USE_HQ_API=1 together with HQ_API_URL, the same sink aimed at a self-hosted HQ API.

The sink returns early when the URL or the token is missing, and telemetry-sync.mjs prints No ORCHESTKIT_HOOK_URL or TOKEN configured. Nothing to sync. then exits 0. There is no analytics ping, no crash reporter, and no feature-flag fetch.

What OrchestKit never reads. No OS keychain lookups, no ~/.aws/credentials, no SSH private keys, no browser cookie or login stores, no clipboard. The one place secret-shaped paths appear in the source is plugins/ork/hooks/dist/pretool.mjs, where id_rsa, .pem, .env, and credentials.json form a blocklist that stops Claude writing to them. That code denies access; it does not read those files.

Third-party MCP servers are recommendations, not bundled dependencies. The plugin ships no .mcp.json and declares no mcpServers. The table under Configuration is advisory, and /ork:setup asks before writing anything.


Install

/plugin install ork

No tiering. No version confusion. Just one powerful plugin.

Not on Claude Code? Pull the skills into any agent (Cursor, Codex, OpenCode, …) via skills.sh:

npx skills add yonatangross/orchestkit

FAQ

Plugin not found?
/plugin list
/plugin uninstall ork && /plugin install ork
Hooks not firing?

Run /ork:doctor to diagnose.

Claude Code version?

Requires ≥2.1.220 (supported floor; Opus 5 as the default Opus, xhigh effort, dynamic workflows, sandbox.network.strictAllowlist, native binary, hardened Bash(rm:*)/Bash(find:*) rules). Check with claude --version.

Raising this floor is a breaking change and ships as a major release. See STABILITY.md for the full contract, and shared/cc-support.json for the authoritative window.


Development

npm run build      # Build plugins from src/
npm test           # Run all tests

Edit src/ and manifests/, never plugins/ (generated).

See CONTRIBUTING.md for details.


What's New

v9.2.1 · 2026-07-28

  • evals: propagate INCONCLUSIVE through the --changed fan-out (#3188)
  • quickviz: ship visual-style.md inside the skill bundle (#3185)
  • bump the github-actions group across 1 directory with 2 updates (#3174)

v9.2.0 · 2026-07-28

  • docs: derive a flow graph for every skill reference page (#3184)
  • hooks: skip ASK tiers in bypassPermissions mode (#3177)
  • visual-style: stop the emoji vocabulary rejecting the ASCII palette (#3169)
  • deps: bump the npm-minor-patch group across 1 directory with 4 updates (#3179)
  • deps: bump the remotion group across 1 directory with 21 updates (#3175)
  • …and 2 more (see CHANGELOG.md)

v9.1.1 · 2026-07-26

  • sync README and changelog data to v9.1.0 (#3167)

v9.1.0 · 2026-07-26

  • retro-hardening mechanisms 5+6 (invocability check, byte-budget guard) (#3161)
  • viz: re-anchor visual-style rule + quickviz on-ramp (#3164)
  • viz: stop throttling explicit visual asks (#3166)

v9.0.2 · 2026-07-26

  • ci: remove the Claude PR Review workflow and its labeler (#3159)

v9.0.1 · 2026-07-26

  • bound rotated analytics archives, unstale the CC floor (#3156)
  • build: default-deny frontmatter gate, pass all 10 fields (#3158)
  • readme: refresh What's New for 9.0.0 and isolate the RTL table cell (#3153)
  • cc-watch: snapshot upstream CHANGELOG (2.1.220) (#3155)

v9.0.0 · 2026-07-25

  • cc: the Claude Code support floor is now 2.1.220. Claude Code 2.1.206 through 2.1.219 are no longer supported; hooks and skills may no-op or error on them, and that is not treated as a bug. Upgrade Claude Code before updating OrchestKit.
  • cc: adopt Opus 5, strict-renew the support floor to 2.1.220 (#3141)
  • verify: add the Reachability Proof axis (REACHED vs UNREACHED) (#3149)
  • docs: pin playground links to the commit SHA, not the branch (#3148)
  • hooks: bound hook-timing.jsonl, the one analytics file with no cap (#3151)
  • …and 1 more (see CHANGELOG.md)

v8.85.0 · 2026-07-25

  • agent activation routing (M170) (#3133)
  • 3 defects found by /ork:assess on the M170 diff (#3136)
  • build: stop dropping argument-hint from generated commands (#3146)
  • hooks: make network-egress-guard DENY tier quote-aware (#3124)
  • hooks: redirect pipe-to-interpreter deny instead of dead-ending (#3121)
  • …and 8 more (see CHANGELOG.md)

See CHANGELOG.md for the full release history.


Community

Join the Building with AI community for AI dev tips, OrchestKit support, and connecting with other builders:

Room Who it's for Link
Building with AI The umbrella community. One join, every room below. Join
Builders For people already building Join
OrchestKit For OrchestKit users Join
AI for Business For people leading AI adoption Join

Names and audiences match what yonyon.ai renders, so the two surfaces cannot drift. Every link resolves through yonyon.ai/go/*, so a rotated invite never needs a README change and no raw invite is published here.


Docs · Issues · Discussions · Community

MIT License · @yonatangross