Crewforth — Security skill for Claude Code
Enterprise engineering workflow for Claude Code — not just prompts.
How to install Crewforth
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open crewforth/crewforth and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Crewforth does
Enterprise engineering workflow for Claude Code — not just prompts. AI agents that plan, build, audit, and ship with security gates, privacy checks, and approval-controlled commits. Safely adopt it into new or existing repositories.
Alternatives in Security
- Goal Prompt Builder — Build audit-friendly /goal prompts for OpenAI Codex 225 ★
- Commit Hook Checklist — Audit commit-hook automation as gates against AI slop and broken commits (Node.js, Go, polyglot) 168 ★
- Release Audit — Use right before cutting a release — it spawns ONE fresh sibling session via CCC that audits only the JUDGMENT 130 ★
README
 
🇬🇧 English · [🇹🇷 Türkçe](README.tr.md)
**Crewforth is your engineering crew for Claude Code.**
It adds subagents, skills, commands and hooks to Claude Code: 12 specialist agents that each own a domain,
39 skills that hold the method, 10 commands you start with `/crew-…`, and hooks that enforce the rules that matter.
Why Crewforth
- Work goes to a specialist. An unclear request is planned before any code is written, server work goes to
crew-backend-expert, and a risky change is reviewed bycrew-security-expertbefore it closes. A routing hook names the owner beside your request. - The rules that matter are enforced by gates, not remembered. A destructive command is refused before it runs, a commit waits for your approval, and a leaked key never reaches history.
- Every result is measured and published, including the ones that did not hold. The same prompt is run with Crewforth and without it, and graded on what each left on disk. See How we measure.
Quick start
npx crewforth init # set up a new project
npx crewforth add # add one agent or skill only
npx crewforth studio # open the Studio panel
You approve a summary before anything is written, and `add` copies into `./.claude` without the full install. For an existing repository, `npx crewforth adopt` lands everything on a separate branch, staged and u
Related Skills
ContAIned
A governed coding agent CLI built on Claude Code. Runs inside an isolated Docker container with operator-contr
Enterprise Readiness Skill
Supply chain security, SLSA, OpenSSF, SBOMs, quality gates
6F
Macro + micro engineering-content audit for git-healthy repositories — Claude Code Agent Plugin (Hub-of-Facts
Agentic Sdlc Orchestrator
A governed, gated orchestration engine that drives a real Claude agent through a full SDLC: requirements, desi
Mastra System Check
Claude Code skill that validates Mastra AI agent projects with 66 checks across configuration, agents, workflo
Ship PR
Run all pre-merge checks (tests, evals, security, spec compliance) and open the PR via gh. Does NOT merge — hu
Related Agents
Privacy Auditor
Audit code for privacy and data protection issues. Checks personal data flows, missing consent gates, retentio
Release Readiness Reviewer
Verifies a release is ready to ship — checks skill and command validity, findings store, version sync, convent
Vbw Dev
Execution agent with full tool access (denylist-controlled) for implementing plan tasks with atomic commits pe
