curdx/curdx-flow

COLLECTIONattested
v7.3.5curdxMITUpdated 3mo agonpmGitHub

Spec-driven development for Claude Code — turns vague feature requests into research, requirements, design, tasks, then executes them autonomously.

Claude Code 的规格驱动交付层 —— 把一句需求变成可审查、可恢复、可验证的交付记录。 会自动判断当前仓库和目标:直接处理 · 轻量规格 · 完整规格 · 恢复未完成任务 · 或者把大需求拆成多个可执行 spec。 Claude Code 能写代码,但真实任务上会暴露三种典型失败: 没有 curdx-flow | 有了 curdx-flow | 上下文腐烂:越聊越长,模型忘掉原始约束 | 目标钉进 ,跨会话都不会丢 | 完成幻觉:模型说"完成了",没有命令 / 浏览器 / CI 证据 | 完成必须有 ,不允许静默通过 | 流程错配:小任务被压垮,大需求又被一口气做完 | 路由:直接处理 / 轻量 / 完整 / 恢复 / triage | 它不是又一层项目管理系统,而是 给 Claude Code 加一层执行纪律。 推荐 npm 安装器 —— 先让你选界面语言(中文 /…

This collection bundles
105 skills26 agents

⚠ The trust score below reflects the installer package @curdx/flow only. The bundled units are not individually verified or scanned — review them before use.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
42Downloads/wk
3GitHub stars
3mo agoLast update
Package
Authorcurdx
LicenseMIT
Version7.3.5
Sourcegithub
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · beb38ea
Dependencies✓ 10 resolved · none vulnerable
Tool surface13 tools · none privileged
Security scan✓ Cleanv7.3.5 · 3mo agoHow well does this scan work?
EvalsNone
IndexedJun 14, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

13 tools · none privileged
Statically extracted from the published packagev7.3.5 · 3mo ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

puaNo description published

This tool published no description. Forge does not invent one.

claude-memNo description published

This tool published no description. Forge does not invent one.

chrome-devtools-mcpNo description published

This tool published no description. Forge does not invent one.

ui-ux-pro-maxNo description published

This tool published no description. Forge does not invent one.

curdx-flowNo description published

This tool published no description. Forge does not invent one.

sequential-thinkingNo description published

This tool published no description. Forge does not invent one.

context7No description published

This tool published no description. Forge does not invent one.

analyzeNo description published

This tool published no description. Forge does not invent one.

installNo description published

This tool published no description. Forge does not invent one.

uninstallNo description published

This tool published no description. Forge does not invent one.

updateNo description published

This tool published no description. Forge does not invent one.

checkNo description published

This tool published no description. Forge does not invent one.

statusNo description published

This tool published no description. Forge does not invent one.

0 of 13 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Claude Code 的规格驱动交付层 —— 把一句需求变成可审查、可恢复、可验证的交付记录。 会自动判断当前仓库和目标:直接处理 · 轻量规格 · 完整规格 · 恢复未完成任务 · 或者把大需求拆成多个可执行 spec。 Claude Code 能写代码,但真实任务上会暴露三种典型失败: 没有 curdx-flow | 有了 curdx-flow | 上下文腐烂:越聊越长,模型忘掉原始约束 | 目标钉进 ,跨会话都不会丢 | 完成幻觉:模型说"完成了",没有命令 / 浏览器 / CI 证据 | 完成必须有 ,不允许静默通过 | 流程错配:小任务被压垮,大需求又被一口气做完 | 路由:直接处理 / 轻量 / 完整 / 恢复 / triage | 它不是又一层项目管理系统,而是 给 Claude Code 加一层执行纪律。 推荐 npm 安装器 —— 先让你选界面语言(中文 / English),然后进入交互式多选,自己勾选主插件、companion plugins、MCP servers;会同步 marketplace 入口和 管理块。 CI / 脚本环境想跳过所有交互一次性全装:…

Keywords
agentic-workflowai-agentsanthropicclaudeclaude-codeclideveloper-toolsmcpmcp-servernpm-packagepluginslash-commandsspec-driven-developmentcollection
Alternatives
Comparing tool surfaces…

No dependency coverage

This package was last scanned before Forge began storing the resolved tree. The next scan will record it.