
Research
/Security News
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
Claude Code works best with structure — without it, conversations drift, context gets lost, and results get inconsistent. kyos-cli installs a set of workflow commands into your project so you can move from idea to working code in a repeatable way. One command sets it up; the rest is up to you and Claude.
npx kyos-cli --init
--apply to add only what's missing, or --init --force to start fresh.Getting consistent results from Claude on complex tasks takes more than a single prompt — you need structure, clear steps, and a way to keep context across the session. kyos-cli gives you a starting point for that structure.
kyos-cli installs a structured workflow that breaks the process into clear steps:
| Command | What it does |
|---|---|
/spec | Nail down what you're building before touching any code |
/tech | Turn the idea into a concrete plan Claude can follow |
/tasks | Break the plan into small, checkable steps |
/implement | Execute the steps one by one, with verification at each |
/verify | Confirm the result actually matches what was planned |
Run them in order for any feature or fix:
/spec → /tech → /tasks → /implement → /verify
Each step saves its output to a file, so you can pause, resume in a new session, or hand off to someone else without losing context.
Three commands sit outside the main chain. Reach for them when the repo needs a safety check, a technical direction, or better tooling support:
| Command | What it does |
|---|---|
/prevalidate | Quick safety check before making changes |
/architecture | Set or revise your project's technical direction |
/hire | Create skills, agents, or wire up MCPs to fill gaps in your repo's support layer |
/spec or /tech, run /compact before continuing. Everything is saved to disk, so nothing is lost and the next command starts with a clean budget./clear just before /implement to give the implementation run the full context window. Then reference the saved tasks file directly: /implement @docs/execution/your-feature/tasks.md.spec.md, tech.md, or tasks.md already exist when you open a new session, pass them in directly: /tech @docs/execution/your-feature/spec.md. Claude will read the file and continue from there./tech or /tasks (scope shifts, new constraints, a better approach), reflect those changes back in the earlier files too. Keeping spec, tech, and tasks aligned means they can later be assembled into accurate feature documentation with minimal effort./spec, /tech, or /tasks, set your model with /model: use sonnet for straightforward issues, opus for large or architecturally complex ones. Don't forget to revert when the planning phase is done./hire before anything else. It's the fastest way to give Claude the right capabilities for your stack before you start building.| Command | Description |
|---|---|
kyos-cli --init | Set up or inspect an existing setup (default) |
kyos-cli --init --force | Reset everything to a clean baseline |
kyos-cli --apply | Add only missing files, never overwrites anything |
kyos-cli --update | Pull in the latest managed files without touching your customizations |
kyos-cli --add <type> <name> | Add a skill, agent, or MCP from the catalog |
kyos-cli --doctor | Check that everything is in order |
Extend your setup with optional capabilities:
kyos-cli --add skill critic # Adds a sparring-partner skill that challenges plans before you commit to them
kyos-cli --add skill silent-execution # Cuts Claude's narration dramatically — act first, explain only when needed. Saves a significant amount of tokens on large tasks.
kyos-cli --add mcp context7 # Gives Claude up-to-date docs for libraries and frameworks you use
kyos-cli --add mcp filesystem # Lets Claude read and write files outside the project directory
MCP entries are wired up automatically.
The CLI runs in whatever directory you're in, so you can roll it out across projects with a simple loop:
for repo in ./repo-a ./repo-b ./repo-c; do
(cd "$repo" && npx kyos-cli --init)
done
kyos-cli.To report a vulnerability, see SECURITY.md.
FAQs
Bootstrap and safely evolve a shared Claude Code repo structure.
We found that kyos-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.

Research
/Security News
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.

Security News
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.