crewforth

Crewforth — Security skill for Claude Code

Security community

Enterprise engineering workflow for Claude Code — not just prompts.

How to install Crewforth

This entry records only its repository, not the path inside it, so there is no exact command to give. Open crewforth/crewforth and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Crewforth does

Enterprise engineering workflow for Claude Code — not just prompts. AI agents that plan, build, audit, and ship with security gates, privacy checks, and approval-controlled commits. Safely adopt it into new or existing repositories.

Alternatives in Security

  • Goal Prompt Builder — Build audit-friendly /goal prompts for OpenAI Codex 225 ★
  • Commit Hook Checklist — Audit commit-hook automation as gates against AI slop and broken commits (Node.js, Go, polyglot) 168 ★
  • Release Audit — Use right before cutting a release — it spawns ONE fresh sibling session via CCC that audits only the JUDGMENT 130 ★

README

Crewforth

![Version](https://img.shields.io/badge/version-3.0.0-6D28D9?style=flat-square) ![License](https://img.shields.io/badge/license-MIT-5c6472?style=flat-square)

🇬🇧 English · [🇹🇷 Türkçe](README.tr.md)

**Crewforth is your engineering crew for Claude Code.**

It adds subagents, skills, commands and hooks to Claude Code: 12 specialist agents that each own a domain,
39 skills that hold the method, 10 commands you start with `/crew-…`, and hooks that enforce the rules that matter.

Watch the one-minute overview on crewforth.com

Why Crewforth

  • Work goes to a specialist. An unclear request is planned before any code is written, server work goes to crew-backend-expert, and a risky change is reviewed by crew-security-expert before it closes. A routing hook names the owner beside your request.
  • The rules that matter are enforced by gates, not remembered. A destructive command is refused before it runs, a commit waits for your approval, and a leaked key never reaches history.
  • Every result is measured and published, including the ones that did not hold. The same prompt is run with Crewforth and without it, and graded on what each left on disk. See How we measure.

Quick start

npx crewforth init              # set up a new project
npx crewforth add  # add one agent or skill only
npx crewforth studio            # open the Studio panel

You approve a summary before anything is written, and `add` copies into `./.claude` without the full install. For an existing repository, `npx crewforth adopt` lands everything on a separate branch, staged and u