idea-to-deploy
v1.106.0Vendor-neutral harness engineering methodology from idea to deployed and hardened product, packaged for Codex.
By HiH-DimaNLicense: MIT25 GitHub starsUpdated 2 hours ago
Directory evidence
- Runtimes
- Codex and Claude Code
- Parsed components
- 40 skill or MCP entries
- Source updated
- Sep 30, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install idea-to-deploy for Codex and Claude Code
codex plugin marketplace add IchenDEV/agent-plugin-mkt
codex plugin marketplace upgrade agent-plugin-marketplace
codex plugin add idea-to-deploy@agent-plugin-marketplacePaste and run these commands in a terminal with Codex. They add and refresh the PluginsMP catalog, then install this plugin.
Compatibility: the page URL and API slug “idea-to-deploy-2” remain stable.
- Codex:
idea-to-deploy-2@agent-plugin-marketplace→idea-to-deploy@agent-plugin-marketplace
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/hihol-labs/idea-to-deployClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The repository root is the plugin root.
Plugin files
├── .codex-plugin/plugin.json├── .claude-plugin/plugin.json├── skills/adopt/SKILL.md├── skills/advisor/SKILL.md├── skills/autopilot/SKILL.md├── skills/blueprint/SKILL.md├── skills/browser-check/SKILL.md├── skills/bugfix/SKILL.md├── skills/caveman/SKILL.md├── skills/context-mode-setup/SKILL.md├── skills/cross-review/SKILL.md├── skills/deploy/SKILL.md├── skills/deps-audit/SKILL.md├── skills/discover/SKILL.md├── skills/doc/SKILL.md├── skills/explain/SKILL.md├── skills/github-workflow/SKILL.md├── skills/goal/SKILL.md├── skills/grill-me/SKILL.md├── skills/guide/SKILL.md├── skills/handoff/SKILL.md├── skills/harden/SKILL.md├── skills/infra/SKILL.md├── skills/kickstart/SKILL.md├── skills/market-scan/SKILL.md├── skills/mcp-docs/SKILL.md├── skills/migrate/SKILL.md├── skills/migrate-prod/SKILL.md├── skills/obsidian-export/SKILL.md├── skills/perf/SKILL.md├── skills/project/SKILL.md├── skills/refactor/SKILL.md├── skills/retro/SKILL.md├── skills/review/SKILL.md├── skills/security-audit/SKILL.md├── skills/security-guidance-setup/SKILL.md├── skills/seo-setup/SKILL.md├── skills/session-save/SKILL.md├── skills/strategy/SKILL.md├── skills/task/SKILL.md├── skills/test/SKILL.md└── skills/tool-sync/SKILL.md
Included Skills40
Adopt a legacy project into the model-neutral idea-to-deploy methodology. Uses AGENTS.md + bundled hooks on Codex or CLAUDE.md + project settings on Claude Code, then bootstraps canonical .itd contracts and state. Idempotent; does not reverse-engineer plan docs.
Advisory/consulting mode — analysis and recommendations only, no code changes. Uses business-analyst and devils-advocate subagents for multi-perspective evaluation.
Auto-pipeline: runs the full methodology chain (discover → blueprint → kickstart → review → test) autonomously under the methodology mechanical gates (review-before-commit, DoD, careful, the native permissions.ask matrix) — it never performs an outward/irreversible action itself (no deploy, no push, no PR; stops at a local commit). Inspired by GSD auto mode.
Generate project documentation set (strategic plan, architecture, implementation plan, PRD, README, guide). Planning only, no code.
Local browser smoke testing for frontend, full-stack, and visual workflows using the bundled Playwright harness (or Browser Use / in-app browser as fallback). Use when a UI, route, form, dashboard, landing page, generated app, or frontend regression needs interactive verification.
Systematically debug an issue — find root cause and fix it. Traces errors through stack traces, logs, git history.
Token-efficiency mode — terse caveman-style replies that cut output tokens ~75% while keeping full technical accuracy. Modes: lite, full, ultra, wenyan-*. Use for less-tokens / be-brief / compressed status updates without losing idea-to-deploy gate status, blockers, or verification evidence.
Context-window optimization companion — sets up and integrates the upstream Context Mode plugin (mksglu/context-mode) into idea-to-deploy. Context Mode sandboxes large tool output into a local FTS5 store so the agent searches it instead of dumping it into context (vendor claim ~98% per-call reduction). Use for long /kickstart builds, long /task or /bugfix debugging sessions, or any step where Bash/Read/Grep/WebFetch produce huge output. Detects install, prints the verified CLI commands, and maps the plugin onto the lifecycle; does NOT vendor upstream code.
Run one mandatory fresh opposite-GPT pre-PR review over the exact evidence-bound candidate.
Deploy to production — sync files, build containers, apply migrations, verify health. Reads per-project deploy config. Refuses without explicit confirmation.
Audit third-party dependencies for known CVEs, license issues, and abandoned packages. Read-only report with severity tiers.
Product discovery phase — market analysis, user personas, competitor research, feature prioritization (MoSCoW + RICE). Outputs DISCOVERY.md ready for /blueprint.
Generate documentation — README, API docs, inline comments. Detects project style and follows existing conventions.
Explain how code works — architecture, data flow, key decisions. Uses ASCII diagrams and step-by-step walkthroughs.
GitHub Issues, Pull Request, CI, release, and code-review workflow for idea-to-deploy projects. Inspects PR/CI/review state, debugs failing GitHub Actions before code changes, prepares branches/changelogs/release notes, and keeps project artifacts aligned with PR/CI status. Explicit-invocation, external-write.
Long-goal mode — decompose a goal that spans multiple sessions into ordered verifiable units in .itd-memory/GOAL.json (user approval required), then drive them ONE at a time through the standard /task pipeline (WIP=1, evidence-gated verified). Resumable: a fresh session continues from the first non-verified unit instead of re-deriving the plan. Brownfield-first; NOT a gate — never bypasses /review, /test, or the DoD.
Interactive read-only stress-test for plans, designs, architecture, strategy, migrations, and risky decisions. Asks one question at a time (with a recommended answer) to surface assumptions, risks, and dependencies BEFORE a decision is locked. Runs before /review, does not replace it.
Generate CLAUDE_CODE_GUIDE.md — step-by-step copy-paste prompts for building the project via Claude Code.
Write a compact HANDOFF.md context packet to transfer work from one session/agent to the next when there is no return path — compaction, delegation, AFK run, or recovery. Distinct from /session-save (milestone save).
Production-readiness hardening — health checks, graceful shutdown, rate limiting, logging, monitoring, backups, secrets, SRE runbook.
Generate infrastructure-as-code — Terraform, Kubernetes, Helm, secrets management. Supports DigitalOcean, AWS, Hetzner.
Generate a complete project from idea — architecture, plans, docs, code, tests, deploy. Full lifecycle in one shot.
Fresh public market and community signal scan for product discovery, validation, ICP, competitor, launch, and roadmap decisions. Pulls recent (~30-day) social/community signals via the last30days engine and normalizes them into artifacts. Distinct from /discover (full discovery phase).
Fresh library and framework documentation lookup through MCP documentation providers such as Context7. Read-only — resolves a library ID, asks a narrow implementation question, records source + decision. Use when implementation depends on current APIs, SDK behavior, framework conventions, setup, or migration details.
Safely apply a database migration — backup, apply, verify, rollback path. Refuses on prod without explicit confirmation.
Migrate running production services between hosts — inventory, setup, data migration, dual-run, DNS cut-over, rollback plan. For DB-only migrations use /migrate instead.
Export idea-to-deploy planning docs, handoff, memory, state, decisions, and gates into an Obsidian-compatible local knowledge graph. Derived, regenerable output under .itd-integrations/obsidian/ — canonical docs stay the source of truth. Use when the user mentions Obsidian, vault, wikilinks, knowledge graph, or linked notes.
Performance analysis — find bottlenecks and optimize. Covers algorithms, DB queries, memory, I/O, caching. Measure first, optimize second.
Smart project CREATION router — routes to /kickstart, /blueprint, or /guide based on user scenario. For work on EXISTING code, use /task instead.
Refactor code for readability and maintainability while preserving behavior. Fowler-style catalog. No feature changes.
Self-proposing improvement cycle for the methodology itself — FACTS from the harness (itd_retro_scan.py aggregates VCR, regressions, active goals, SKILL_BYPASS ledger, cost), PROPOSALS from the model (ranked, every one cites evidence from the scan; anti-Goodhart: external signals only), MERGE stays with the human via the ordinary release pipeline. Never edits the methodology itself; not a gate.
Validate project documentation and code via binary rubric. Checks consistency between PRD, architecture, plan, and code.
Audit code for security vulnerabilities — auth, secrets, injection, CORS/CSP, CVEs, file uploads, error leaks. Read-only report.
Security companion — sets up and integrates the official Anthropic security-guidance plugin (anthropics/claude-code, free, ships in the claude-plugins-official marketplace) into idea-to-deploy. security-guidance is a shift-left, always-on reviewer of Claude-generated code: instant regex pattern warnings on every Edit/Write, an LLM diff review on Stop that feeds high-severity findings back before you see the response, and an agentic commit/push reviewer that traces cross-file data flow (IDOR, auth bypass, SSRF). Use when the user asks about the security-guidance plugin, realtime/shift-left security review as code is written, automatic vulnerability catching on edit or commit, or wiring continuous security review into the lifecycle. Distinct from /security-audit (on-demand deep audit report) — security-guidance is the continuous layer that complements it. Detects install, prints the verified CLI commands, and maps the plugin onto the lifecycle; does NOT vendor upstream code.
SEO companion — sets up and integrates the upstream Claude SEO plugin (AgriciDaniel/claude-seo, MIT) into idea-to-deploy. Claude SEO ships 25 sub-skills + 18 sub-agents for technical SEO, content quality (E-E-A-T), Schema.org, sitemaps, Core Web Vitals, local SEO, backlinks, AI/GEO, ecommerce, hreflang, and Google APIs. Use when a project needs SEO — audits, schema, Core Web Vitals, AI Overviews/GEO visibility, keyword/competitor research, on-page or technical SEO — and you want it wired into the discover/blueprint/kickstart/harden/deploy lifecycle. Detects install, prints the verified CLI commands, and maps the plugin onto the lifecycle; does NOT vendor upstream code.
Save session context to project memory — what was done, decisions, blockers, next steps. Ensures continuity between sessions and flags parallel sessions via an active-session lockfile.
Strategic replanning for existing projects — analyze current state, update LAUNCH_PLAN.md, create ADRs for pivot decisions. For NEW projects use /blueprint instead.
Smart daily-work router — routes to the right implementation skill (/bugfix, /refactor, /doc, /test, /perf, /security-audit, /deps-audit, /migrate, /harden, /infra) based on what the user needs to do in an EXISTING project.
Generate comprehensive tests — unit, integration, edge cases. Detects project test framework and follows existing conventions.
Synchronize idea-to-deploy state with external planning and documentation tools — GitHub, Linear, Notion, Google Drive (Docs/Sheets/Slides), and local Obsidian vaults. Connector-native reads before writes, export-only fallback to .itd-integrations/. Explicit-invocation, external-write.
Plugin manifests2
{
"name": "idea-to-deploy",
"version": "1.106.0",
"description": "Vendor-neutral harness engineering methodology from idea to deployed and hardened product, packaged for Codex.",
"author": {
"name": "HiH-DimaN",
"email": "[email protected]",
"url": "https://github.com/HiH-DimaN"
},
"homepage": "https://github.com/hihol-labs/idea-to-deploy",
"repository": "https://github.com/hihol-labs/idea-to-deploy",
"license": "MIT",
"keywords": [
"codex",
"harness-engineering",
"methodology",
"project-lifecycle",
"ai-coding"
],
"skills": "./skills/",
"interface": {
"displayName": "Idea to Deploy",
"shortDescription": "Model-neutral engineering harness for Codex.",
"longDescription": "Use the Idea to Deploy contracts, skills, lifecycle gates, persistent state, and verification discipline from Codex without forking the methodology core.",
"developerName": "HiH-DimaN",
"category": "Developer Tools",
"capabilities": [
"project lifecycle",
"verification gates",
"persistent task state",
"security and deployment"
],
"defaultPrompt": "Use Idea to Deploy: read AGENTS.md and .itd contracts, preserve WIP=1, and verify completion with evidence."
}
}{
"name": "idea-to-deploy",
"version": "1.106.0",
"description": "Complete project lifecycle methodology — 40 skills + 10 specialized subagents + 30 enforcement hooks from idea to deployed and hardened product. Product discovery (MoSCoW/RICE), market & community research, planning, scaffolding, coding, testing, debugging, optimization, security audit (with Red/Blue Team mode), dependency audit, safe DB migrations, production migration between hosts, deployment, production hardening, infrastructure-as-code, browser smoke-testing, library docs lookup (MCP/Context7), session context persistence, context handoff, daily-work routing, long-goal mode with a persistent unit ledger (GOAL.json, resumable across sessions), a telemetry-driven self-improvement retro (facts from the harness, proposals evidence-gated, merge stays human), strategic replanning, advisory/consulting mode, decision stress-testing, self-review mode, legacy project adoption, external-tool sync (GitHub/Linear/Notion), Obsidian export, safety guardrails, live execution tracing, skill enforcement with escalation, a Definition-of-Done pre-commit gate, an opt-in cross-vendor pre-commit second-opinion review (codex/gemini, fail-open), session-open diagnostics, context-switch detection, memory staleness warnings, session-end handoff-readiness detection, WIP=1 scope gating with a Verified Completion Rate metric, a mechanical subagent narration-final stop-gate and a vendor-neutral verdict-contract stop-gate (SubagentStop), and a Completion-Gate subsystem (v1.51.0) that judges task completion from a runtime-signal ledger — a PreToolUse commit veto on unproven completion layers (L1 static → L2 tests → L3 e2e), auto-collected runtime signals, and teacher-style WHY+FIX failure marks, degrading to advisory when no signals exist.",
"author": {
"name": "HiH-DimaN",
"email": "[email protected]",
"url": "https://github.com/HiH-DimaN"
},
"homepage": "https://github.com/hihol-labs/idea-to-deploy",
"repository": "https://github.com/hihol-labs/idea-to-deploy",
"license": "MIT",
"keywords": [
"claude-code",
"methodology",
"project-lifecycle",
"developer-tools",
"ai-coding",
"plugin",
"testing",
"deployment",
"code-review",
"security-audit",
"product-discovery"
],
"skills": [
"./skills/"
],
"agents": [
"./agents/"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[idea-to-deploy on Agent Plugins Marketplace](https://pluginsmp.com/plugins/idea-to-deploy-2)