A guard
Read-only by tool grant, not by instruction: there is no Edit or Write tool in its configuration to reach for. It produces a plan and stops.
Claude Code configuration kit · v1.2.0
Out of the box, Claude Code will rewrite your auth middleware, drop a column, and refactor three unrelated files on the way to fixing a CSS bug. This kit gives it what a senior teammate has and a fresh model does not: your project's own conventions, an idea of what is dangerous, and the discipline to read only what the task needs.
MIT licensed · no dependencies · Node.js 18+
$ claudeadd a column to the users table ◆ tier 3 — database schema · routed to db-guard read-only. nothing has been written. PLAN 1 ALTER TABLE users ADD COLUMN plan text NULL 2 backfill in batches, no table lock 3 rollback: DROP COLUMN plan awaiting your approval
01 — Side by side
One line typed into Claude Code: add a column to the users table. Flip the switch to see what the kit changes about everything that comes after it.
add a column to the users table ● Edit prisma/schema.prisma● Edit src/types/user.ts● Bash npx prisma migrate dev --name add_plan Drop and recreate `users`? … applied 47 rows lost Done! I added the column and updated the types.
add a column to the users table ◆ tier 3 — DB schema · ESCALATE TO: db-guard db-guard holds no Edit or Write tool. PLAN — additive, zero-downtime 1 ADD COLUMN plan text NULL (no lock) 2 backfill in batches of 1000 3 rollback: DROP COLUMN plan awaiting your approval
The guard is read-only by tool grant, not by instruction — there is no Edit or Write tool in its configuration to reach for. It is not being asked nicely to hold back.
02 — Mechanics
You trigger none of them. Describe the work in plain language; the routing is automatic.
Once per session: package manager, config, CI/CD, ORM and migration layout, architecture shape, and the real test command. What it cannot detect it marks UNKNOWN rather than guessing — a wrong assumption is worse than a stated gap.
Every task lands in a tier, decided before a single file is opened. A one-line CSS fix goes straight through. Anything touching auth, payments, database schema, CI/CD, secrets or infrastructure lands higher.
A guarded noun outranks a task verb: "fix the CSS in the login form" is a security question, not a styling one. Rule files load the same way — by path glob, so a Flutter project never pays for the REST-API rules.
Read-only by tool grant, not by instruction: there is no Edit or Write tool in its configuration to reach for. It produces a plan and stops.
Works inside the conventions it just read, changes the smallest thing that fixes the problem, and leaves the refactor you did not ask for alone.
Targeted test for behaviour, lint plus test for a new file, a build for a new route, a type-check for a type change. Never the full suite for a one-file edit, and no "done" without the command output behind it.
Ordinary requests, and where each one lands before a single file is touched.
fix the broken link on the login page
add a settings page
redesign the checkout flow
add SBOM generation to the Docker CI
add a column to the users table
03 — Context economy
A configuration kit is a standing tax on every prompt you ever send. This one is measured, capped, and mostly not loaded.
452lines load on every turn
18% of the rule set2558 lines in total
04 — Install
Recommended
/plugin marketplace add mtvrkan/senior-dev-kit
Registers this repository as a plugin marketplace.
/plugin install senior-dev-kit@senior-dev-kit
Pulls the agents, skills, commands and stack presets.
/kit-setup
Writes the two things a plugin structurally cannot: the path-scoped rules and
the permission rules. It shows you exactly what it will do, waits for a yes, and
backs up anything it touches.
Restart Claude Code, then run /kit-doctor to confirm every piece landed.
Updates arrive through /plugin marketplace update.
Node.js 18 or newer, no dependencies.
git clone https://github.com/mtvrkan/senior-dev-kit.git
cd senior-dev-kit
node scripts/install.mjs --dry-run
node scripts/install.mjs
Nothing you had is destroyed: the protocol goes into your CLAUDE.md inside
markers, deny rules are merged into your settings.json, and anything
overwritten is backed up first. Pick one path, not both.
05 — Inside
agents
Four are read-only by tool grant, not by instruction: there is no Edit or Write tool in their configuration to reach for. They produce a plan and stop. The other three implement.
skills
Fix a bug, add a page, review a migration, gate a release — each a written discipline the model follows instead of improvising. Most trigger on task shape; a few are manual-only by design.
rule files
Three files load every turn, under a combined line cap a script enforces. The rest load on a path-glob match, and the 18 reference docs load only when a skill needs one.
deny rules
Not a prompt asking nicely — permission rules the harness enforces before a tool ever runs, so a secret cannot reach the context window in the first place.
28 stack presets · house conventions per stack
Stack presets included: angular, astro, django, docker, dotnet, drizzle, fallback, fastapi, flutter, go-api, kubernetes, laravel, mongodb, nestjs, nextjs-saas, node-express, nuxt, postgres, prisma, rails, react-native, react-vite, rust-axum, spring-boot, supabase, sveltekit, swiftui, terraform.
06 — Verified
A configuration kit rots quietly. Nothing crashes when a rule file starts recommending a tool another rule retired, or when a README claims a count that stopped being true six commits ago.
So the repository checks what a test suite normally cannot. On every change, the consistency checks:
Findings get closed at the root, and the check that closes one gets written down, so the same class cannot come back unnoticed. That is the whole method. Even the step list on the right is read out of the gate runner rather than transcribed next to it.