BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

sd0x-dev-flow

Skill Development Usable
Works inClaude Code
Usable Reviewed

Prevents AI-generated code from bypassing safety gates during review cycles; enforces dual approval and state persistence across context windows, reducing de…

The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and fail-closed safety where it counts. Quality gates that AI can't skip.

188 starsMIT (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Prevents AI-generated code from bypassing safety gates during review cycles; enforces dual approval and state persistence across context windows, reducing deployment risk from incomplete or unvetted changes.

Engineering teams integrating Claude Code into CI/CD pipelines requiring enforced peer review and audit trails.

Claude Code Claude Cowork Claude Chat

https://github.com/sd0xdev/sd0x-dev-flow

By sd0xdev

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
/plugin marketplace add sd0xdev/sd0x-dev-flow  then  /plugin install sd0x-dev-flow@sd0xdev-marketplace  (inside Claude Code); then /project-setup

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me require dual code review before AI-generated changes merge
PrerequisitesClaude Code 2.1+. Optional: Codex MCP — the /codex-* dual-review skills require it; without it review falls back to single-reviewer mode. Run /project-setup after install to auto-detect framework, package manager, and scripts.CostFree

Trust Signals Reviewed

Stars188Contributors1Last updated2026-08-10LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-12 · scanner vattempted-no-data

Community Pulse New

No community discussions found yet. This doesn't mean the tool isn't good — it may be new or serve a niche use case.

Reviewer notes

Reviewed review. These are observations, not a security certification.

Auto-assessment from April sweep — baseline scores pending hands-on review.

2026-04-18: Approved in April sweep: Solid community adoption with a clear description and active maintenance.

Things to check

  • Requires integration into existing CI/CD and code review workflows; effectiveness depends on humans actually enforcing gates rather than rubber-stamping approvals. Not a substitute for code review discipline.
  • Single maintainer. Consider the risk if this person stops maintaining the project.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
3/5
Overall score3.00 / 5.00 UsableEvaluatedApr 2026

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →