📖 Full documentation: Wiki — deep-dive guides per step, FAQ, Troubleshooting, and the 8 Habits Reference.
"ทำเสร็จ ≠ ทำดี" — Shipping code is not the same as shipping good code.
AI coding tools are powerful — but "build me X" without requirements, review, or staging creates fast, fragile code. This plugin adds the discipline AI lacks: 24 skills across a 7-step workflow, grounded in Covey's 8 Habits of effective development.
Get Started
- The Problem — Why this exists
- Quick Start — Install in 3 steps, verify in 1
- Not using Claude Code? — Entry point for Codex, Cursor, Windsurf, Aider, etc.
The Framework
- Design Principle — Thin harness, fat skills
- 7-Step Workflow — Visual pipeline from research to monitoring
- Skills Reference — All 24 skills with habit mappings
- Use Cases — Common scenarios and recommended paths
- End-to-End Recipes — Copy-paste tool sequences for real situations
- The 8 Habits — Principles behind the workflow
- Maturity Model — Dependence to Significance
Deep Dives
- Cross-Verification — 17-question checklist + scoring
- Whole Person Assessment — Body/Mind/Heart/Spirit + worked example
- Agents — Read-only reviewers that analyze your work
- Architecture — File tree + design decisions
- Companion Plugins — Working with
claude-governance+devsecops-ai-team
Reference
- What's New — Version history
- Not a Checklist — Principles, not gates
- Origin — Where these habits come from
- Limitations — Runtime boundaries and evidence expectations
- FAQ — Common questions answered
- Glossary — Key terms defined
- Alternative Setup | Security | Contributing | License
AI coding tools (Claude Code, Cursor, Copilot, Codex) are powerful — but they amplify whatever process you bring to them. No process? You get fast, fragile code that works in demo but breaks in production.
The 7 most common mistakes:
- No requirements — jumping straight to "build me X"
- No design — letting AI decide architecture
- No task breakdown — one giant prompt for everything
- No context — AI doesn't know your codebase
- No review — shipping AI output without reading it
- No staging — deploying directly to production
- No monitoring — "it works on my machine" mindset
This plugin provides a skill for each step — not as a gate, but as a habit.
We follow the "Thin Harness, Fat Skills" pattern — the session hook is bounded (≤300 tokens, enforced in hooks/session-start.sh and documented in CLAUDE.md), and the intelligence lives in on-demand markdown skills loaded when you invoke them. The harness gets out of the way; the skills do the work.
The same principle is documented independently by Garry Tan (President & CEO, Y Combinator) in his 2026 essay "Thin Harness, Fat Skills" and shipped in gbrain. We arrived at it from workflow discipline; he arrived at it from building a brain — same conclusion.
The same shift is happening industry-wide under the name Spec-Driven Development (SDD): after "vibe coding" entered the vocabulary in early 2025, tools like GitHub spec-kit, AWS Kiro, and Tessl emerged to generate code from specs. Those are spec-first tooling — this plugin is spec-first discipline: tool-agnostic guidance that helps any of them (or none of them) produce better specs in the first place. It adds no enforcement and spawns no role-agents — that is the companion claude-governance. We arrived here from workflow discipline; they arrived from building codegen tools — same discipline layer, different delivery.
Install for Claude Code:
claude plugin marketplace add pitimon/8-habit-ai-dev
claude plugin install 8-habit-ai-dev@pitimon-8-habit-ai-devInstall for Codex:
codex plugin marketplace add pitimon/8-habit-ai-dev
codex plugin add 8-habit-ai-dev@pitimon-8-habit-ai-devUse in Claude Code (restart Claude Code, then invoke a skill by slash command):
/requirements # Before you build anything
/review-ai # Before you commit anything
/cross-verify # Before you ship anything
/whole-person-check # Assess Body/Mind/Heart/Spirit balance
Use in Codex (restart Codex after installing; plugin skills are not top-level /skill slash commands):
/skills
Pick requirements, review-ai, cross-verify, or another installed skill from the selector. You can also mention the skill explicitly in your prompt:
$cross-verify ตรวจแผนนี้ก่อน commit
or use plain intent:
Use the cross-verify skill to check this release plan.
Verify Claude Code installation: After restarting, you should see ## 8-Habit AI Dev Active in the session banner with the 7-step workflow reminder. For Codex, run codex plugin list and confirm 8-habit-ai-dev@pitimon-8-habit-ai-dev is installed.
New to the plugin? Start with /workflow for a guided walkthrough, or see Use Cases to find the right skill for your situation.
The Core 5 (≈80% of daily work): /requirements · /review-ai · /cross-verify · /research · /reflect. If you learn only five skills, learn these — the session banner surfaces the same set each session.
Two commands to install per platform. Claude Code also loads a session reminder; both platforms make 24 skills available. For exact runtime boundaries, see the runtime compatibility matrix, Codex integration guide, and wiki Limitations: Codex gets native packaging, the same markdown skills, and a narrow SessionStart JSON adapter if the host invokes the hook; it does not get Claude hook feature parity or runtime enforcement.
This plugin is maintained through regular releases. Check the GitHub Releases, the wiki changelog, or the "What's New" sections below to see recent changes.
Claude Code:
claude plugin update 8-habit-ai-dev@pitimon-8-habit-ai-devRestart Claude Code after updating so hook and skill changes are loaded.
Codex:
Codex currently has no codex plugin update command. Refresh the Git marketplace snapshot, then reinstall the plugin from that refreshed snapshot:
codex plugin marketplace upgrade pitimon-8-habit-ai-dev
codex plugin list
codex plugin remove 8-habit-ai-dev@pitimon-8-habit-ai-dev
codex plugin add 8-habit-ai-dev@pitimon-8-habit-ai-dev
codex plugin listUse codex plugin marketplace list if you need to confirm the configured marketplace name.
Each step maps to one of Covey's 8 Habits — the habit explains why the step matters.
Step 0 Step 1 Step 2 Step 3
/research ───→ /requirements ─→ /design ────→ /breakdown
H5:Understand H2:End in Mind H8:Find Voice H3:First Things
Step 4 Step 5 Step 6 Step 7
/build-brief ─→ /review-ai ───→ /deploy-guide → /monitor-setup
H5:Understand H4:Win-Win H1:Proactive H7:Sharpen Saw
You don't need all steps every time. Start with requirements before building and review-ai before committing — those two alone eliminate most Vibe Coding problems. In Claude Code that usually means /requirements and /review-ai; in Codex, select them through /skills, mention $requirements / $review-ai, or ask in natural language.
Skill names below use Claude Code slash notation because that is the shortest label for the skill corpus. In Codex, these are installed skills, not plugin-provided top-level slash commands. Use /skills, mention the skill such as $cross-verify, or ask Codex to use the named skill.
| Skill | Step | Habit | Purpose |
|---|---|---|---|
/research |
0 | H5: Seek First to Understand | Investigate with depth levels (Quick/Standard/Deep), modes (General/Compare/Audit), and source verification |
/requirements |
1 | H2: Begin with End in Mind | Draft PRD — what, why, who, scope, success criteria |
/design |
2 | H8: Find Your Voice | Surface architecture decisions for human judgment |
/breakdown |
3 | H3: Put First Things First | Decompose into atomic tasks, prioritize by importance |
/build-brief |
4 | H5: Seek First to Understand | Problem statement gate + context brief before implementing |
/review-ai |
5 | H4: Think Win-Win | 4-level verdict (PASS/CONCERNS/REWORK/FAIL) + dimension balance |
/deploy-guide |
6 | H1: Be Proactive | Staging-first deployment with rollback, plus provider reconciliation gates for production canaries |
/monitor-setup |
7 | H7: Sharpen the Saw | Set up health checks, alerting, error tracking |
| Skill | Habit | Purpose |
|---|---|---|
/cross-verify |
H1-H8 | 17-question checklist + dimension summary (Body/Mind/Heart/Spirit) |
/consistency-check |
H5 + H1 | Cross-artifact analyzer over persisted PRD↔design↔tasks, plus incident/config hotfix mode for symptom↔evidence↔root-cause↔fix↔verification drift (v2.20.1) |
/operational-state |
H1 + H5 + H8 | Operational finding classifier — choose Watch, Fix Candidate, Active Incident, Resolved, Handoff, Known Accepted Issue, False Positive, or Self-Resolved before action. Maps evidence, allowed/prohibited actions, approval gates, artifacts, escalation criteria, and closure criteria. Read-only guidance; no runtime state engine or production mutation. |
/whole-person-check |
H8: Find Your Voice | 4-dimension assessment (1-5 scale) with AI Blind Spot detection |
/security-check |
H1: Be Proactive | Focused OWASP security lens — secrets, injection, auth, deps |
/reflect |
H7: Sharpen the Saw | 5-question micro-retrospective (5 min max) with action tracking |
/workflow |
All | Guided 7-step walkthrough — invoke or skip each step |
/calibrate |
H8: Find Your Voice | Self-assessment (5-7 questions) → writes ~/.claude/habit-profile.md so other skills adapt verbosity to your maturity level |
/using-8-habits |
H5 + H8 | Onboarding meta-skill — all 24 skills + decision tree for "which skill next?" |
/eu-ai-act-check |
H1 + H8 (Spirit) | Redirect stub — migrated to pitimon/claude-governance v3.1.0+ on 2026-05-02 (ADR-012). Install that plugin for the canonical 9-obligation checklist. |
/ai-dev-log |
H4 + H1 | Generate AI-assisted dev log from git history for audit trail |
/save-spec |
H8 + H2 | Deployment-mode helper (not a workflow step) — scaffold a project-root SPEC.md digest when the repo fits the project-orientation hub mode. Generator-only Phase 1 (v2.16.0); refuses to overwrite. Skip if you already have a memory-MCP + short CLAUDE.md (v2.16.4 — see /save-spec "When to Skip" for details) |
/diagnose |
H1 + H5 | Active bug investigation — 6-phase methodology (feedback-loop → reproduce → hypothesise → instrument → fix-with-regression-test → cleanup). Closes the gap between research (too broad) and post-mortem (too late). Phase 1 (feedback-loop-first) enforced before hypothesis generation. Hands off to post-mortem once fix lands. Adapt-with-attribution from mattpocock/skills SHA b8be62ff (v2.18.0, ADR-015 — n=1 friction-driven adoption) |
/post-mortem |
H4 + H7 | Engineering RCA writeup — canonical record of a fixed bug (root cause, mechanism, fix, validation, how it slipped through). Refuses to draft without 4 inputs (reliable repro, known cause, identified fix, validated outcome). Inspired by 9arm-skills (v2.17.0) |
/scrutinize |
H5 + H8 | Outsider-perspective review — questions whether the change should exist at all (Step 1) before line-by-line review. Pairs with review-ai (scope-question vs diff-local). 4-step workflow: Intent → Trace → Verify → Report. Inspired by 9arm-skills (v2.17.0) |
/management-talk |
H4 + H6 | Channel-aware audience reshape — engineer-to-engineer content → leadership channel (JIRA / Slack / standup / email / meeting). Strips function/file/SHA but keeps JIRA keys, PR numbers, workload names. Inspired by 9arm-skills (v2.17.0) |
Start from your situation, not the skill name.
| I want to... | Start with | Then | Habit |
|---|---|---|---|
| Build a new feature from scratch | /requirements |
/design → /breakdown |
H2: Define done first |
| Review code before committing | /review-ai |
/security-check if needed |
H4: Never skip review |
| Understand an unfamiliar codebase | /research |
/build-brief |
H5: Read before writing |
| Deploy / provider canary | /deploy-guide |
/monitor-setup |
H1: Stage, rollback, reconcile |
| Assess overall project health | /cross-verify |
/whole-person-check |
All 8 habits |
| Classify an operational finding | /operational-state |
/deploy-guide or /post-mortem |
H1 + H5 + H8 |
| Fix a production bug | /diagnose |
Fix + regression test → /post-mortem |
H5 + H1: Reproduce before fixing |
| Investigate a hard bug (no obvious cause) | /diagnose |
/post-mortem → /reflect |
H1 + H5: Loop before guessing |
| Question whether a change should exist at all | /scrutinize |
/review-ai for diff-local |
H5 + H8: Intent before diff |
| Brief leadership on engineering work | /management-talk |
(channel-aware reshape) | H4 + H6: Right signal per channel |
| Something feels off about a plan | /cross-verify |
Check dimension scores | H1-H8 |
| Learn the full workflow | /workflow |
(guided walkthrough) | All |
Survive /clear and /compact |
See guides/spec-digest-pattern.md (project-orientation hub) or current-state.md (feature-spec mode) |
Adopt one based on repo archetype | H5: Understand first |
Minimum Viable Discipline — /requirements before building + /review-ai before committing. Two skills, biggest impact.
Full Workflow — /research through /monitor-setup via /workflow. For new features or greenfield projects.
Quality Gate — /cross-verify + /whole-person-check. For pre-PR or pre-release assessment.
For the full 15-situation map, see guides/situation-map.md.
The table above answers "which skill?". These recipes answer "how do I actually drive a whole situation?" — copy-paste sequences that chain skills (and, where it pays off, the plugin's read-only 8-habit-reviewer agent — or an independent-model QA pass, if you run one). Names use Claude Code slash notation; in Codex, invoke the same skills via /skills or $skill-name. Mix, skip, and extend them for your own project — the discipline is the chain (define → build → verify), not any single skill.
/requirements → PRD: what / why / who + EARS success criteria
/design → architecture decisions surfaced for YOUR judgment
/breakdown → atomic tasks, no scope creep
( build )
/review-ai → PASS / CONCERNS / REWORK / FAIL verdict before commit
/cross-verify → 17-question gate across Body / Mind / Heart / Spirit
You get: done is defined before the first prompt and reviewed before the commit. In a hurry? /requirements + /review-ai alone remove the two most common vibe-coding failure modes — undefined done and unreviewed output. — H2 + H4
/review-ai → builder-side self-review of the diff
/security-check → OWASP lens: secrets, injection, auth, dependencies
8-habit-reviewer → ask Claude to run this read-only agent — separate eyes on the same diff
You get: the model that wrote the code isn't the only one grading it — a separate reviewer catches what self-review rationalizes as "probably fine." For an even stronger gate, add an independent-model pass (e.g. an external Codex QA loop — not shipped with this plugin), and always grep any reviewer's cited file:line before acting on it. — H4 + H1
/diagnose → feedback-loop FIRST → reproduce → hypothesise → fix + regression test
/post-mortem → engineer-audience RCA (refuses to draft without a real repro)
/reflect → capture the lesson so the whole class of bug is caught earlier next time
You get: a fix backed by a durable regression test, not a one-off curl that proves nothing tomorrow. /diagnose refuses to skip the feedback loop — guessing-before-loop is the anti-pattern it exists to prevent. — H1 + H5 + H7
/research deep (Audit mode) → does our code ALREADY do this? where is the real gap?
( friction-first gate ) → adopt only with a cited first-person need, not "looks nice"
/cross-verify → pressure-test the recommendation before committing
→ if rejected: record it in docs/out-of-scope/ with explicit reversal conditions
You get: you avoid bolting on attractive-but-redundant machinery, and every "no" is documented so the next person doesn't re-litigate it. (This repo's own docs/out-of-scope/grill-with-docs-glossary.md was produced by exactly this recipe.) — H5 + H7
/save-spec → scaffold a project-root SPEC.md digest (hub mode)
guides/spec-digest-pattern.md → project-orientation hub, for larger repos
current-state.md → lightweight save point for in-flight feature work
You get: the next session re-orients from a durable file instead of re-deriving everything from scratch. Pick the archetype that fits your repo — don't adopt both. — H5 + H2
/management-talk → eng-to-eng content → JIRA / Slack / standup / email / meeting
You get: function/file/SHA noise stripped, but JIRA keys, PR numbers, and workload names kept — the channel-appropriate signal, not a wall of implementation detail. — H4 + H6
Recipes are starting points, not rails. The value is the verification chain, not ceremony — escalate to
/cross-verifyor an independent reviewer when an action is irreversible, and keep it light when it isn't.
Based on Stephen Covey's The 7 Habits of Highly Effective People + Habit 8 (The 8th Habit: From Effectiveness to Greatness), adapted for AI-assisted development from real experience building a production system over 910 man-day-equivalents.
| Habit | Principle | In Practice |
|---|---|---|
| H1: Be Proactive | Act on what you can control | Trace all callers of a bug fix, handle edge cases, update docs during implementation |
| H2: Begin with End in Mind | Define done before starting | Write success criteria and test plans before the first prompt |
| H3: Put First Things First | Important over interesting | Tests and CI gates prevent future crises — don't skip them for speed |
| Habit | Principle | In Practice |
|---|---|---|
| H4: Think Win-Win | Every interaction is a deposit | Error messages that help, issue closures with rationale, actionable review feedback |
| H5: Seek First to Understand | Read before you write | Understand existing code and patterns before proposing changes |
| H6: Synergize | Together > apart | Human judgment + AI execution. Parallel agents for independent tasks |
| Habit | Principle | In Practice |
|---|---|---|
| H7: Sharpen the Saw | Invest in capability | Monitor production, track tech debt, automate what you learned |
| H8: Find Your Voice | From effective to significant | Understand why before implementing. Share patterns. Empower others |
Dependence → Independence → Interdependence → Significance
| Stage | Mindset | AI Relationship |
|---|---|---|
| Dependence | "AI writes my code" | Blind acceptance, no review |
| Independence | "I use AI as a tool" | Selective adoption, human judgment |
| Interdependence | "We build together" | Complementary strengths, shared process |
| Significance | "We empower others" | Publishing patterns, raising the bar |
The /cross-verify skill runs 17 questions across all 8 habits, with dimension mapping (Body/Mind/Heart/Spirit) and scoring bands.
| Category | Questions | Dimensions | Habits |
|---|---|---|---|
| Private Victory | 8 questions | Body, Mind | H1 (scope), H2 (criteria), H3 (priority) |
| Public Victory | 6 questions | Mind, Heart | H4 (feedback), H5 (understanding), H6 (synergy) |
| Renewal | 3 questions | Body, Spirit | H7 (learning), H8 (meaning) |
Scoring Bands: 15-17 (proceed) → 12-14 (address gaps) → 8-11 (revisit plan) → <8 (stop and rethink)
Confidence Levels (v1.9.0): For high-stakes reviews, mark each Pass as ✓V (Verified), ✓I (Inferred), or ✓U (Unverified) — inspired by Feynman's honest uncertainty principle.
Domain Packs: Optional question sets for API, Frontend, Infrastructure, AI/ML, and Mobile work.
Full checklist: guides/cross-verification.md
The /whole-person-check skill evaluates work across Covey's 4 dimensions — one of the plugin's differentiators, since few engineering tools assess all four.
| Dimension | What It Measures | AI Strength |
|---|---|---|
| Body (Discipline) | CI, tests, monitoring, quality gates | Strong — AI excels |
| Mind (Vision) | Architecture, ADRs, roadmap, tech debt | Strong — AI excels |
| Heart (Passion) | Craft quality, empathetic errors, UX, DX | Weak — needs humans |
| Spirit (Conscience) | Security-first, ethics, compliance, sharing | Weak — needs humans |
AI-assisted development systematically neglects Heart and Spirit. This assessment makes the gap visible so teams can compensate.
A worked example (a REST-API feature scorecard), the maturity rubrics, and the plugin's own progression chart are in docs/wiki/Whole-Person-Assessment.md.
The plugin includes two specialized agents — read-only reviewers that analyze without modifying your code.
Deep cross-verification reviewer. Evaluates plans, implementations, or PRs against all 8 habits.
- When it runs: Invoked by
/cross-verifyor manually via the Agent tool - What it produces: Score out of 17, dimension summary, failed items with
file:lineevidence - Tools: Read, Glob, Grep (read-only)
Source verification agent (v2.1.0). Validates every citation in a research brief.
- When it runs: Automatically during
/researchDeep mode - What it produces: Verification report — Verified / Dead / Not Found / Redirected per source
- Tools: Read, Glob, Grep, WebFetch (read-only)
- Principle: Feynman standard — "The first principle is that you must not fool yourself"
Both Claude Code agent definitions use the opus model because they run high-stakes review and citation-integrity gates. This model selection is a Claude Code agent surface; Codex still consumes the shared markdown skills and does not gain Claude subagent model parity from this setting.
See an illustrative repository file tree in docs/wiki/Architecture.md — per-skill step/habit mappings are in the Skills Reference table above.
Design decisions:
- Skills are empowering, not restrictive — reminders and tools, not blocking gates
- Habit content loaded on-demand — skills reference
habits/*.mdonly when invoked, keeping session context lean - Session hook under 300 tokens — light reminder with progress indicators, not a wall of text
- Handoff contracts — each skill declares what it expects from its predecessor and produces for its successor
- Definition of Done — every skill has 3-5 verifiable checkbox items
- When to Skip — honest conditions prevent compliance theater (H8: contribution over compliance)
- Output templates — structured formats for PRD, ADR, task list, review report, research brief
- Dimension mapping — all 17 cross-verify questions tagged with Body/Mind/Heart/Spirit
- Zero dependencies — pure markdown + bash. No npm, no pip, no runtime requirements. Windows PowerShell validator smokes use Git Bash as a compatibility layer; run
scripts/windows-preflight.ps1first.
8-habit-ai-dev works standalone — no hard dependency. For higher-assurance projects, it composes with two companion plugins (also by pitimon):
| Plugin | Layer | When to add |
|---|---|---|
claude-governance |
Policy / Enforcement (fitness functions, ADRs, compliance) | When you need durable policy + audit trail |
devsecops-ai-team |
Operational tooling (SAST/DAST/SCA/Container/IaC + SBOM/AIBOM/VEX) | When you need automated scans or regulator evidence |
Single source of truth for integration: see docs/INTEGRATION.md — covers layer map, choosing-your-stack matrix, integration points, Three Loops asymmetry, EU AI Act scope split, and suggested integrated flow.
Tested against claude-governance 3.3.0 and devsecops-ai-team 10.12.0+.
Naming note (v2.16.5): in
devsecops-ai-teamv10.12.0, the/workflowskill was renamed to/security-workflowto resolve a cross-plugin naming collision with this plugin's/workflow(the 7-step Covey practice). If you have both plugins installed, type/workflowfor the 7-step walkthrough or/security-workflowfor devsecops's scan orchestration. Legacy/workflowin devsecops continues as a deprecation stub through v10.x (removed in v11.0.0). See devsecops ADR-014.
Theme: #375 follow-up (ค) — recover Claude's lost convenience, runtime-neutrally
/cross-verifygains a session-context fallback — when no persistedSKILL_OUTPUTblock exists but the producer skills ran earlier in the same session, it now mines their PRD/design/tasks prose in context to pre-populate Q4/Q8/Q14/Q16 (marked✓I). This restores the same-session auto-populate that file-only emission removed — and it works identically in Codex, because it reads prose, not the HTML-comment block (no runtime-conditional producer behavior, so no ADR-024 conflict).- Producer skills regain a visible completion signal —
/requirements,/design,/breakdown,/review-ainow end conversation output with a plain-text[/<skill>] completeline. This is the visible half of the old attribution line, kept after the block moved to file-only; plain text means it renders cleanly in every runtime with zero Codex noise.
Theme: finish #375 — guard the two output templates that still leaked the block
prd-template.mdandtask-list-template.mdnow label theirSKILL_OUTPUTblock as a persisted-artifact fragment — a guarding comment states the block belongs only at the end of thedocs/specs/<slug>/…file under--persistand must never be emitted to the conversation. Fable's review of the v2.21.39 fix found these two templates still embedded the block unconditionally, so a model following a template verbatim could re-introduce the exact Codex noise #375 removed. This closes that residue.
Theme: close the 2026-06-10 Fable review ledger — F12/F15/F16 (#368)
- Core 5 reaches README readers (F12) — the "80% of daily work" skill set (
/requirements·/review-ai·/cross-verify·/research·/reflect) was only in the session banner; Quick Start now surfaces it too, so the two onboarding entry points agree. - ADR status field carries information (F15) —
docs/adr/README.mdgains a status vocabulary (Accepted/Accepted (amended YYYY-MM-DD, #NNN)/Superseded by ADR-NNN), the validator (validate-content.sh) is widened to enforce it, andADR-013— amended for #375 in v2.21.39 but still marked plainAccepted— now readsAccepted (amended 2026-07-12, #375). Convention + fitness function ship together. - Session-hook token budget recorded as a constraint (F16) — worst-case output measures ~281 tokens (chars/4) against the ≤300 ceiling; a header comment now warns that any new line must trim an existing one. Measured, not trimmed (the enforced estimator passes with headroom — trimming would be gold-plating).
Theme: cross-runtime output hygiene — structured handoff blocks no longer leak into Codex (#375)
SKILL_OUTPUTblocks are now file-only — the machine-readable handoff block from/requirements,/design,/breakdown,/review-aiis written into the persisted artifact (docs/specs/<slug>/…under--persist, or a saved*-review.md), never appended to the conversation. Claude hid the HTML comment; Codex rendered it verbatim as noise. Non-persisted runs emit no block — concise output on every runtime./cross-verifyreads the right place — its auto-detect now globs the canonicaldocs/specs/*/{prd,design,tasks}.mdpaths (the previous*-prd.md-in-cwd glob never matched a persisted file); non-persisted runs fall through to manual assessment as before./diagnoseblock removed — it had no consumer (/post-mortemreads prose,/cross-verifynever globbed it) and itsMETHODOLOGY-COMPLETEmarker was outside the protocol vocabulary.- Contract recorded — ADR-013 amended (conversation-emission superseded; filesystem back-compat invariant preserved); canonical spec in
guides/structured-output-protocol.md§"Emission gate".
Theme: post-review batch — the reviewer reviewing the reviewers (#369)
- Script-count drift fixed at the class level — #360's
ci-local.shmade the shipped "all 12 repo script files" claim false (13th script); the guide gains its classification row and current-doc surfaces drop hardcoded totals entirely — the count can't drift again because it's no longer stated. - Check 32 hardened — the
plugin/CLAUDE.mditeration now counts its siblingplugin/skills/(was accidentally correct via Check 28's mirror guarantee); the row-count awk is scoped to the Skills→Habits Mapping section. - New Check 33 —
ci-local.sh'sSCRIPTSlist is lock-step-guarded againstvalidate.yml(a "MUST stay in lock-step" comment is not a fitness function). - Tracking hygiene — D3 + SLSA gaps re-homed from closed #343 to #367; Fable residue F12/F15/F16 tracked in #368;
SPEC.mdCurrent State refreshed (was 2 releases stale).
Theme: Mind-cluster doc-drift close — Fable F3/F7/F8 (#358); bundled with tooling + security-CI batches before release
- F3 — CLAUDE.md skill table complete (19 → 24 rows) —
/diagnose,/post-mortem,/scrutinize,/save-spec,/management-talkwere missing from the Skills→Habits table. New validator Check 32 pins table-row count toskills/dir count so this class can't recur. - F7 — routing knows the newer skills — README "Fix a production bug" now routes to
/diagnose(reproduce-first is diagnose Phase 1-2), and the/using-8-habitsdecision tree gains leaves for bug investigation (/diagnose→/operational-state→/post-mortem), proposal review (/scrutinize), leadership briefs (/management-talk), and repo save points (/save-spec). - F8 —
Last citationcolumn shipped — the SKILL-EFFECTIVENESS tally column promised in the 2026-06-06 tally now exists; values are traceable to each row's existing trend notes (no invented dates;—= never cited).
Theme: least-privilege residue + Fable doc-drift close (#353) · script-vs-AI-workflow portability (#354)
- Stub Bash dropped — the
eu-ai-act-checkredirect stub'sallowed-toolsis now["Read"]; closes the least-privilege carry named in the v2.21.35 notes (CLAUDE.md Bash-skill count reconciled 10 → 9). - Fable F17/F19/F20 doc drift closed —
link-check.ymlno longer callsplugin/a symlink; the README EU AI Act badge now points to the canonicalclaude-governancetoolkit (the ADR-012 deferred badge fix); the verbosity guide's "17 skills" is dated to v2.7.0 design time and its snippet matches the hook's realDIRECTIVE_LEVELvariable. /ai-dev-logNo-Script Fallback — whengenerate-ai-dev-log.shcan't run (Windows without Git Bash, restricted host), the skill now documents performing the 6 process steps via individual git commands; a host with no shell reports "not generatable" instead of inventing statistics (#354).- New guide:
guides/script-vs-ai-workflow.md— the execution/verification boundary: AI workflows may replace script execution when a deterministic verifier gates the result; they must never replace verification (validators stay scripts — LLM re-checks are the grade-saturation trap F4 closed). Classifies every repo script file (see the guide's table — count guarded against drift after the "10 vs 12" QA catch).
Theme: #343 adversarial-Spirit-pass workstream — fail-closed hook + security docs + self-check honesty
- F6 + F6b + F6c — fully fail-closed pre-commit example —
hooks/pre-commit.sh.exampleno longer ships the banned|| truefalse-success shape. A CLI crash, REWORK/FAIL verdict, missing verdict, or missingclaudeeach block the commit; only an explicit PASS/CONCERNS proceeds (HABIT_REVIEW_SKIP=1escape hatch). Verdict regex tightened soNOT PASScan't false-proceed.tests/test-pre-commit-hook.sh(20 assertions, both mirrors) guards it. - S1 — SECURITY.md + threat model — added a disclosure policy +
docs/security/threat-model.md(the plugin's own/security-checkapplied to the repo). - F4 — retired the frozen "16/17 = 100%" SELF-CHECK headline (grade-saturation fossil) → points to the living per-release list.
- B1 — Check 5b: documented 1500-line bash-tooling exemption (the plugin's validators exceeded the 800-line rule they enforce).
- F5 — CLAUDE.md Bash-skill drift reconciled (3 → 10).
Driven by a 2026-06-29 adversarial Spirit pass (
governance-reviewer) corroborating the Fable model review: honest score Body 4 / Mind 3.5 / Heart 4 / Spirit 3 = 3.6/5, not the self-assessed 4.5. Closes #343. Each item passed independent Codex QA.
Theme: Karpathy simplicity + surgical-edit gaps recorded as deferred doctrine (ADR-026 Deliverable B, #339)
- Two Karpathy rules logged as deferred candidates — the
multica-ai/andrej-karpathy-skillsrules #2 (simplicity / YAGNI) and #3 (surgical / minimal-diff edits) are recorded as N8 + N9 (T2, drop-date 2026-12-27) inguides/anthropic-engineering-doctrine-audit.mdTable 2 — the greppable defensive-citation surface a contributor checks before re-proposing a blog-post pattern. They are deferred, not adopted: no first-person friction citation exists, and repo popularity is not friction (ADR-014). Rule #3 also carries a recorded tension with H1 (defense-in-depth) that must be reframed before any future ship.
Follow-up to ADR-026 (the prior-art audit of the 5 viral-post repos). This is the "Deliverable B" discoverability step: the audit verdict lives in the ADR; this lands the rows where the
How to use this guidegrep-protocol will actually find them. Docs/doctrine only — no skill, rule, or enforcement behavior changed.
For the full version history, see CHANGELOG.md (v2.3.0+), docs/wiki/Changelog.md (v2.2.0 and earlier), or GitHub Releases.
Checklists create compliance theater — people tick boxes without understanding why.
These are principles that change how you think:
- You don't "apply H5" — you develop the instinct to read before writing
- You don't "check H3" — you naturally prioritize tests over gold-plating
- You don't "follow H8" — you genuinely ask "does this help someone?"
The cross-verification exists for planning reviews, not as a gate for every commit.
This framework was developed while building MemForge — a production AI memory system with 15 services, 154K+ observations, and a 3-node Docker Swarm cluster. Over 910 man-day-equivalents of AI-assisted development, these habits emerged from real mistakes:
- H1: A deploy bypassed staging and went straight to production (now there's a mandatory staging-first rule)
- H4: Code reviews were skipped "just this once" — 2 CRITICAL and 3 HIGH issues shipped (now review-before-commit is enforced)
- H7: Monitoring was the weakest step across 3 projects — a systematic blind spot we only caught through cross-project analysis
- H5: A database password mismatch crashed production because nobody validated the .env file before deploying
Every habit in this plugin exists because skipping it caused real damage.
Q: Do I need to use all 24 skills for every task?
No. Start with /requirements before building and /review-ai before committing. Those two alone eliminate most Vibe Coding problems. Add more skills as they feel natural. See Use Cases.
Q: What is "Vibe Coding"? Building software by feel — jumping straight to "build me X" without requirements, design, or review. AI tools amplify this tendency because they make coding feel effortless. This plugin provides structure without removing speed.
Q: How is this different from a linter or CI tool? Linters check syntax. CI checks tests. This plugin checks process — did you define success criteria? Did you review before committing? Did you consider security? It operates at the planning and judgment layer, not the code layer.
Q: What does "ทำเสร็จ ≠ ทำดี" mean? Thai: "Done is not done well." Completing a task (ทำเสร็จ) is not the same as completing it with quality (ทำดี). This principle is the plugin's core identity — speed without discipline creates debt.
Q: Can I use this without Claude Code?
Yes. v2.19.0 adds native Codex packaging via .codex-plugin/plugin.json and .agents/plugins/marketplace.json. Other agent platforms can still load skills/<name>/SKILL.md manually; start at AGENTS.md.
Q: What are the "Whole Person dimensions"? Covey's model: Body (discipline/quality), Mind (vision/architecture), Heart (passion/craft/empathy), Spirit (conscience/ethics/security). AI excels at Body and Mind but systematically neglects Heart and Spirit. See Whole Person Assessment.
Q: How do the agents work? Agents are read-only reviewers that run inside Claude Code. They analyze your code and produce reports but never modify files. See Agents.
Q: Is this plugin opinionated? Yes, deliberately. The opinions come from 910 man-day-equivalents of production AI-assisted development. Every rule exists because skipping it caused real damage. See Origin.
Key terms — Vibe Coding, Handoff Contract, AI Blind Spot, Whole Person Model, Domain Pack, Fitness Function, and more — are defined in docs/wiki/Glossary.md.
If you prefer not to install the plugin in Claude Code or Codex, you can use the rules file directly:
# Install rules only (no skills, no hooks)
mkdir -p ~/.claude/rules
curl -sL https://raw.githubusercontent.com/pitimon/8-habit-ai-dev/main/rules/effective-development.md \
-o ~/.claude/rules/effective-development.mdThis auto-loads the 8-Habit principles into every Claude Code session without the skills or hooks. For other agents, load AGENTS.md, then use skills/RESOLVER.md to pick the right SKILL.md.
This plugin ships markdown guidance only — no runtime service, endpoints, database, or network client — so the conventional application-layer attack surface does not apply. The real surface is supply-chain (integrity of skill / hook / rule content) and the opt-in hooks/pre-commit.sh.example.
- 📄 Security Policy — how to report a vulnerability (private disclosure; please do not open a public issue).
- 🛡️ Threat Model — STRIDE for a markdown-only plugin, trust boundaries, and an honest list of controls not yet present.
Found a habit that worked (or broke) in your AI-assisted development? PRs welcome.
See CONTRIBUTING.md for the full guide — skill authoring conventions, blank templates, and quality checklist.
Quick options:
- Add a new skill — follow the template in CONTRIBUTING.md
- Add real examples to
habits/*.mdfiles - Add domain question packs in
guides/cross-verify-packs/ - Report issues at GitHub Issues
MIT
Version: 2.21.42 | Last updated: 2026-07-13