New:Socket for Asana Is Now Available.Learn more
Get Started

@drafthq/draft

Package Overview
Dependencies
Maintainers
1
Versions
18
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@drafthq/draft

Context-Driven Development for AI coding agents — install Draft into Claude Code, Cursor, Codex, or opencode.

Source
npmnpm
Version
3.7.1
Version published
Maintainers
1
Created
Source

Draft

Stop shipping AI-generated bugs.
One command runs a three-stage review on your branch — validation, spec compliance, code quality — and writes the missing tests. Free. Open-source. MIT.

GitHub release MIT License Stars Graph engine: codebase-memory-mcp

Powered by codebase-memory-mcp by DeusData — a 159-language, 100% local knowledge-graph engine.

Website · Docs · Methodology · Watch (8 min) · All Videos

The 60-second pitch

Your AI assistant just wrote 200 lines. Some of them are bugs. Some don't match your patterns. Some skip tests.

/draft:review

Three stages, one command:

  • Validation — runs your tests, lints, type-checks, and surfaces real failures
  • Spec compliance — checks the diff against the agreed spec, not vibes
  • Code quality — flags hotspots, blast radius, and missing test coverage using a tree-sitter knowledge graph of your repo

No setup required for the first run: on an un-indexed repo it reviews the diff and names the structural checks it skipped, so you see findings before you spend anything.

Free. No API keys. No paid tier. No vendor lock-in. Catches the 3 bugs you missed before they hit your reviewer.

Demo coming soon — for now, watch the 8-minute walkthrough.

Install (30 seconds)

One command installs Draft into your agent. No clone, no config.

npx @drafthq/draft install <host>      # claude-code | cursor | codex | opencode

…or install the CLI once and reuse it:

npm install -g @drafthq/draft
draft install <host>
draft list                             # show every host + where it installs

Each host installs the way that host actually loads extensions — no manual steps after the command:

Hostdraft install …What it does
Claude Codeclaude-codeRegisters the plugin via claude plugin marketplace add + claude plugin install (user scope). Restart Claude Code.
CursorcursorCopies the plugin into ~/.cursor/plugins/local/draft/, writes .cursor-plugin/plugin.json, registers draft@draft-plugins in Cursor's plugin registry, and enables it. Restart Cursor (or Developer: Reload Window). Existing installs upgrade with draft install cursor --force.
CodexcodexWrites ./AGENTS.md, which Codex reads automatically.
opencodeopencodeWrites ./AGENTS.md + ~/.agents/skills/draft/, both auto-discovered.

Flags: --global / --project to pick scope, --dry-run to preview, --force to overwrite, --no-graph to skip the graph-engine fetch.

Then, in Claude Code (after restarting):

/draft:review     # ← start here. No setup, no indexing. Reviews your current diff.
/draft:init       # once you've seen what it catches: index the repo (one-time)
/draft:review     # same command, now with blast radius + hotspots + cycle detection

/draft:review runs on an un-indexed repo and tells you exactly which structural checks it had to skip. Indexing is the upgrade, not the entry fee.

Run /draft for the full command map.

Other ways to install →

Claude Code — native marketplace

/plugin marketplace add drafthq/draft
/plugin install draft

Cursor — from GitHub

Cursor requires .cursor-plugin/plugin.json; the draft install cursor command also registers the plugin via the shared Claude plugin registry that Cursor reads on many builds. To add from source instead, use Settings > Rules, Skills, Subagents > Rules > New > Add from Github:

https://github.com/drafthq/draft.git

GitHub Copilot

Copilot reads a committed instructions file — copy it directly (not a draft install host):

mkdir -p .github && curl -o .github/copilot-instructions.md \
  https://raw.githubusercontent.com/drafthq/draft/main/integrations/copilot/.github/copilot-instructions.md

Gemini

curl -o .gemini.md https://raw.githubusercontent.com/drafthq/draft/main/integrations/gemini/.gemini.md

The five commands

CommandWhat it does
/draft:review3-stage review of your diff. Works with zero setup — run it first.
/draft:initIndex the repo once. Adds blast radius, caller lookup, hotspot ranking, and cycle detection to every later review.
/draft:new-trackTurn an idea into a spec + plan before any code is written.
/draft:implementExecute the plan task-by-task under TDD with verification gates.
/draft:graphBuild or refresh the knowledge-graph snapshot on its own.

That is the whole loop. 28 more specialist commands — bug hunting, ACID audits, ADRs, tech debt, incident response, Jira, coverage, standups — sit behind five intent routers (/draft:plan, /draft:discover, /draft:ops, /draft:docs, /draft:jira).

Full command reference → · run /draft for the interactive intent map

Built-in Code Intelligence

Draft is powered by a local knowledge graph engine (codebase-memory-mcp) that gives every command precise structural context — module boundaries, call graphs, dependencies, hotspots. It's 100% local (no API key, no SaaS), fetched during draft install (best-effort; --no-graph to skip), with first-use fetch as a fallback.

/draft:graph                                  # build / refresh the snapshot
scripts/tools/graph-impact.sh --file src/auth/login.go
# → blast radius: which files, which symbols, which tests/docs/configs
CapabilityWhat it provides
Multi-language extractionTree-sitter + LSP-grade resolution across 159 languages, 100% local
Call graphCallers/callees with confidence signals so review/bughunt can weight findings
Impact analysisBlast-radius with file-class dimension (code/test/doc/config) — answers "what breaks if I change this?"
Cycle detectionFlags circular call dependencies before they bite
Hotspot rankingFan-in score so high-risk symbols get extra scrutiny
Incremental indexinggit-aware, content-based; only changed code re-indexes
Track impact memorymetadata.json.impact snapshots each completed track's blast radius — /draft:new-track flags overlap with recent work

The graph powers /draft:graph and /draft:impact, enriches /draft:bughunt and /draft:review, and is consumed by skills via core/shared/graph-query.md. The engine is installed via scripts/fetch-memory-engine.sh; the deterministic shell helpers live under scripts/tools/.

Deterministic helper tools

Skills also call into shell helpers under scripts/tools/ for mechanical work — git metadata, file classification, test-framework detection, hotspot ranking, freshness checks, ADR indexing, and live graph queries (graph-callers.sh, graph-impact.sh, hotspot-rank.sh, cycle-detect.sh, mermaid-from-graph.sh). All emit JSON or markdown, follow a uniform exit-code contract, and degrade gracefully when their input source is unavailable.

How It Works

┌─────────────────────────────────────────────────────────────┐
│                        /draft:init                          │
│    5-phase codebase analysis + signal detection + state     │
│  architecture.md + .ai-context.md + .state/ (freshness,    │
│                   signals, run memory)                      │
└────────────────────────────┬────────────────────────────────┘
                             │
                             ▼
┌─────────────────────────────────────────────────────────────┐
│                      /draft:new-track                       │
│            AI-guided spec.md + phased plan.md               │
└────────────────────────────┬────────────────────────────────┘
                             │
                             ▼
┌─────────────────────────────────────────────────────────────┐
│                     /draft:implement                        │
│              RED → GREEN → REFACTOR (repeat)                │
└────────────────────────────┬────────────────────────────────┘
                             │
                             ▼
┌─────────────────────────────────────────────────────────────┐
│                      /draft:review                          │
│        Three-stage review (validation + spec + quality)     │
└─────────────────────────────────────────────────────────────┘

         /draft:init refresh  ←── incremental: only re-analyze
                                   files with changed hashes

Context output modes (/draft:init)

/draft:init packages your architecture context in one of two modes, selected automatically by repo size (override with DRAFT_INIT_MODE):

  • monolith (default for small repos, tiers 1–2) — a single graph-primary architecture.md is the source of truth; .ai-context.md is the token-optimized AI view derived from it.
  • okf (default for larger repos, tiers 3+) — an OKF concept taxonomy under draft/wiki/ is the source of truth (one concept per file, cross-links form the graph), .ai-context.md becomes the navigable index root (Synopsis + Concept Map), and architecture.md is demoted to a generated rendered view. An optional self-contained offline HTML viewer ships under draft/wiki/web/.

Both modes produce the same product.md, tech-stack.md, workflow.md, guardrails.md, tracks, and .state/ — only the architecture packaging differs.

Full workflow →

Why Draft?

AI tools are fast but unstructured. Draft applies Context-Driven Development to impose clear boundaries: explicit context, phased execution, and built-in verification, ensuring outputs remain aligned, predictable, and production-ready.

product.md       →  "Build a task manager"
tech-stack.md    →  "React, TypeScript, Tailwind"
architecture.md  →  Comprehensive: 10-section graph-primary engineering reference, Mermaid diagrams (source of truth). Mature brownfield projects with strong existing agent docs (CLAUDE.md, INVARIANTS.md, etc.) receive early Context Quality Audit, graph fidelity dashboard, and explicit Relationship + Gaps sections (no blind duplication).
.ai-context.md   →  200-400 lines: condensed from architecture.md (token-optimized AI context)
.state/          →  freshness hashes, signal classification, run memory (incremental refresh)
spec.md          →  "Add drag-and-drop reordering"
plan.md          →  "Phase 1: sortable, Phase 2: persist"

Each layer narrows the solution space. By the time AI writes code, decisions are made.

Incremental refresh: After initial setup, /draft:init refresh uses stored file hashes and signal classification to only re-analyze what changed — no full re-scan needed.

Read methodology →

Contributing

Source of Truth

  • core/methodology.md — Master methodology
  • skills/<name>/SKILL.md — Command implementations
  • integrations/ — Auto-generated (don't edit)

Update Workflow

# 1. Edit core/methodology.md or skills/*/SKILL.md
# 2. Rebuild integrations
./scripts/build-integrations.sh

Full architecture →

Star History

Star History Chart

MIT License · Graph engine: codebase-memory-mcp by DeusData

Credits: Inspired by gemini-cli-extensions/conductor

Keywords

claude-code

FAQs

Package last updated on 19 Aug 2026

Related posts