
Security News
NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets
NIST will stop enriching most CVEs under a new risk-based model, narrowing the NVD's scope as vulnerability submissions continue to surge.
codingbuddy-claude-plugin
Advanced tools
Claude Code Plugin for CodingBuddy - PLAN/ACT/EVAL workflow, specialist agents, and reusable skills
Version 5.5.0
Multi-AI Rules for consistent coding practices - PLAN/ACT/EVAL workflow, specialist agents, and reusable skills for systematic development.
# Via npm
npm install codingbuddy-claude-plugin
# Or via Claude Code
claude plugin add codingbuddy
All commands use the codingbuddy: namespace to avoid collisions with Claude Code built-ins.
/codingbuddy:plan - Enter PLAN mode/codingbuddy:act - Enter ACT mode/codingbuddy:eval - Enter EVAL mode/codingbuddy:auto - Enter AUTO mode/codingbuddy:checklist - Generate contextual checklists/codingbuddy:buddy - Show project status and next actionsTip: Type
PLAN,ACT,EVAL, orAUTOas keywords for the fastest workflow entry.
Legacy bare commands (/plan, /act, /eval, /auto, /buddy, /checklist) are deprecated.
They continue to work during the transition period, but all new commands use the codingbuddy:* namespace.
See Migration Guide for details.
35 AI agents for different domains:
Reusable workflows for consistent development:
The plugin works standalone with core features. MCP integration unlocks the full experience:
| Feature | Standalone | With MCP |
|---|---|---|
| PLAN/ACT/EVAL/AUTO keyword triggers | ✅ | ✅ |
| Staged planning (Discover→Design→Plan) | ✅ | ✅ |
| Clarification gate (ambiguous prompts) | ✅ | ✅ |
| Permission forecast (prompt-aware) | ✅ | ✅ |
| Council scene (agent eye glyphs) | ✅ ¹ | ✅ |
| Specialist agent prompts | ⚠️ ¹ | ✅ |
| Slash commands (codingbuddy:*) | ✅ | ✅ |
| Dynamic checklists | — | ✅ |
| Context persistence across modes | — | ✅ |
| Rule search & impact reports | — | ✅ |
| Session briefings & recovery | — | ✅ |
¹ Standalone features that read agent definitions require a local
.ai-rules/directory. Runnpx codingbuddy-rules initto scaffold it. See #1216 for the standalone enhancement roadmap.
Install the CodingBuddy MCP server to unlock the full feature set:
npm install -g codingbuddy
The MCP server provides:
packages/rules/.ai-rules/ ← Single source of truth (agents, skills, rules)
↓ (MCP protocol)
packages/claude-code-plugin/ ← Thin plugin (manifest + MCP configuration)
This architecture ensures:
packages/rules/.ai-rules/ is the canonical sourceMIT
FAQs
Claude Code Plugin for CodingBuddy - PLAN/ACT/EVAL workflow, specialist agents, and reusable skills
The npm package codingbuddy-claude-plugin receives a total of 9,549 weekly downloads. As such, codingbuddy-claude-plugin popularity was classified as popular.
We found that codingbuddy-claude-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
NIST will stop enriching most CVEs under a new risk-based model, narrowing the NVD's scope as vulnerability submissions continue to surge.

Company News
/Security News
Socket is an initial recipient of OpenAI's Cybersecurity Grant Program, which commits $10M in API credits to defenders securing open source software.

Security News
Socket CEO Feross Aboukhadijeh joins 10 Minutes or Less, a podcast by Ali Rohde, to discuss the recent surge in open source supply chain attacks.