Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
Manage .flow/ tasks and specs. An agent skill from gmickel/flow-next.
$ npx skills add gmickel/flow-next --skill flow-next -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gmickel/flow-next flow-next --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gmickel/flow-next.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/flow-next/skills/flow-next .claude/skills/flow-next && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "flow-next" agent skill from https://github.com/gmickel/flow-next/tree/main/plugins/flow-next/skills/flow-next into .claude/skills/flow-next/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flow-next", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gmickel/flow-next/tree/main/plugins/flow-next/skills/flow-nextType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gmickel/flow-next --skill flow-next -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gmickel/flow-next flow-next --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gmickel/flow-next.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/flow-next/skills/flow-next .agents/skills/flow-next && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "flow-next" agent skill from https://github.com/gmickel/flow-next/tree/main/plugins/flow-next/skills/flow-next into .agents/skills/flow-next/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flow-next", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gmickel/flow-next --skill flow-next -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gmickel/flow-next flow-next --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gmickel/flow-next.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/flow-next/skills/flow-next .cursor/skills/flow-next && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "flow-next" agent skill from https://github.com/gmickel/flow-next/tree/main/plugins/flow-next/skills/flow-next into .cursor/skills/flow-next/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flow-next", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gmickel/flow-next.git --path plugins/flow-next/skills/flow-next--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gmickel/flow-next --skill flow-next -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gmickel/flow-next flow-next --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gmickel/flow-next.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/flow-next/skills/flow-next .gemini/skills/flow-next && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "flow-next" agent skill from https://github.com/gmickel/flow-next/tree/main/plugins/flow-next/skills/flow-next into .gemini/skills/flow-next/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flow-next", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gmickel/flow-next flow-nextInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gmickel/flow-next --skill flow-next -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gmickel/flow-next.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/flow-next/skills/flow-next .github/skills/flow-next && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "flow-next" agent skill from https://github.com/gmickel/flow-next/tree/main/plugins/flow-next/skills/flow-next into .github/skills/flow-next/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flow-next", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gmickel/flow-next --skill flow-next -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gmickel/flow-next flow-next --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gmickel/flow-next.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/flow-next/skills/flow-next .opencode/skills/flow-next && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "flow-next" agent skill from https://github.com/gmickel/flow-next/tree/main/plugins/flow-next/skills/flow-next into .opencode/skills/flow-next/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flow-next", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
flow-nextManage .flow/ tasks and specs. An agent skill from gmickel/flow-next.
Flow Next is an agent skill from gmickel/flow-next. Manage .flow/ tasks and specs. Triggers: 'show me my tasks', 'list specs', 'what tasks are there', 'add a task', 'create task', 'what's ready', 'task status', 'show fn-1-add-oauth'. NOT for /flow-next:plan or /flow-next:work.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/declined.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect. The repository describes itself as: Faster than your agent alone. And better. A workflow plugin that takes a bug, idea or ticket to a verified pull request: specs, cross-model review by risk, live QA, receipts in… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 09e291e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Flow Next loads about 1.6k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 306 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gmickel/flow-next at commit 09e291e, republished under its MIT licence (© gmickel). 306 words, ~1,571 tokens.
.claude/skills/flow-next/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Quick task operations in .flow/. For planning features use /flow-next:plan, for executing use /flow-next:work.
CRITICAL: flowctl is BUNDLED — NOT installed globally. which flowctl will fail (expected). Define once; subsequent blocks use $FLOWCTL:
FLOWCTL="${DROID_PLUGIN_ROOT:-${CLAUDE_PLUGIN_ROOT}}/scripts/flowctl"
[ -x "$FLOWCTL" ] || FLOWCTL="<plugin-root>/scripts/flowctl" # <plugin-root> = the directory two levels above this skill's SKILL.md file (the harness gave you that file's absolute path when the skill loaded); substitute it literally
[ -x "$FLOWCTL" ] || FLOWCTL=".flow/bin/flowctl"Discover all commands/options:
$FLOWCTL --help
$FLOWCTL <command> --help # e.g., $FLOWCTL task --help# Check if .flow exists
$FLOWCTL detect --json
# Initialize (if needed)
$FLOWCTL init --json
# List everything (specs + tasks grouped)
$FLOWCTL list --json
# List all specs
$FLOWCTL specs --json
# List all tasks (or filter by spec/status)
$FLOWCTL tasks --json
$FLOWCTL tasks --spec fn-1-add-oauth --json
$FLOWCTL tasks --status todo --json
# View spec with all tasks
$FLOWCTL show fn-1-add-oauth --json
$FLOWCTL cat fn-1-add-oauth # Spec markdown
# View single task
$FLOWCTL show fn-1-add-oauth.2 --json
$FLOWCTL cat fn-1-add-oauth.2 # Task spec
# What's ready to work on?
$FLOWCTL ready --spec fn-1-add-oauth --json
# Create task under existing spec
$FLOWCTL task create --spec fn-1-add-oauth --title "Fix bug X" --json
# Set task description and acceptance (combined, fewer writes; unique per-task temp paths)
$FLOWCTL task set-spec fn-1-add-oauth.2 --description "${TMPDIR:-/tmp}/flow-desc-fn-1-add-oauth.2.md" --acceptance "${TMPDIR:-/tmp}/flow-accept-fn-1-add-oauth.2.md" --json
# Or use stdin with heredoc (no temp file):
$FLOWCTL task set-description fn-1-add-oauth.2 --file - --json <<'EOF'
Description here
EOF
# Start working on task
$FLOWCTL start fn-1-add-oauth.2 --json
# Mark task done (unique per-task temp paths)
echo "What was done" > "${TMPDIR:-/tmp}/flow-summary-fn-1-add-oauth.2.md"
echo '{"commits":["abc123"],"tests":["npm test"],"prs":[]}' > "${TMPDIR:-/tmp}/flow-evidence-fn-1-add-oauth.2.json"
$FLOWCTL done fn-1-add-oauth.2 --summary-file "${TMPDIR:-/tmp}/flow-summary-fn-1-add-oauth.2.md" --evidence-json "${TMPDIR:-/tmp}/flow-evidence-fn-1-add-oauth.2.json" --json
# Validate structure (one spec; repo-wide through a counts-and-errors projection)
$FLOWCTL validate --spec fn-1-add-oauth --json
$FLOWCTL validate --all --json | jq '{valid, total_specs, total_tasks, total_errors, total_warnings, root_errors, failing: [.specs[] | select(.errors | length > 0) | {spec, errors}]}'Find relevant spec:
# List all specs
$FLOWCTL specs --json
# Or show a specific spec to check its scope
$FLOWCTL show fn-1 --jsonCreate task:
$FLOWCTL task create --spec fn-N --title "Short title" --jsonAdd description + acceptance (combined):
# Unique per-task temp paths — written + consumed in this one block
cat > "${TMPDIR:-/tmp}/flow-desc-fn-N.M.md" << 'EOF'
**Bug/Feature:** Brief description
**Details:**
- Point 1
- Point 2
EOF
cat > "${TMPDIR:-/tmp}/flow-accept-fn-N.M.md" << 'EOF'
- [ ] Criterion 1
- [ ] Criterion 2
EOF
$FLOWCTL task set-spec fn-N.M --description "${TMPDIR:-/tmp}/flow-desc-fn-N.M.md" --acceptance "${TMPDIR:-/tmp}/flow-accept-fn-N.M.md" --json# All tasks, projected (add --spec fn-1-add-oauth for one spec)
$FLOWCTL tasks --json | jq -c '[.tasks[] | {id, title, status, spec}]'
# Ready tasks for a spec
$FLOWCTL ready --spec fn-1-add-oauth --json$FLOWCTL briefbrief is orientation only: it omits blocked and dependency-waiting tasks, so never answer a task listing from it.
$FLOWCTL show fn-1-add-oauth.2 --json # Metadata
$FLOWCTL cat fn-1-add-oauth.2 # Full spec(Legacy fn-1.2 / fn-1-xxx.2 still works.)
$FLOWCTL spec create --title "Spec title" --json
# Returns: {"success": true, "id": "fn-N-spec-title", ...}$FLOWCTL spec close fn-1-add-oauth --retire superseded --by fn-2-sso --jsonPick the reason that is true: superseded (another spec replaced it), delivered-elsewhere (it shipped
under another spec or pull request) or moot (it is no longer needed, including a decision not to build
it). Name each successor with --by. Its never-run tasks read retired, not done.
Before closing any spec: read references/declined.md; it decides whether the
close earns a .flow/memory/declined/ file.
fn-N-slug where slug is derived from title (e.g., fn-1-add-oauth, fn-2-fix-login-bug)fn-N-slug.M (e.g., fn-1-add-oauth.1, fn-2-fix-login-bug.2)Legacy formats fn-N and fn-N-xxx (random 3-char suffix) are still supported.
$FLOWCTL --help to discover all commands and options.flow/memory/declined/*.md file above, which has no flowctl verb. A session that edits .flow/ JSON or task markdown by hand has broken this..flow/ state, via --json (detect, list, specs, tasks, show, ready) or cat for markdown. An answer assembled from files skimmed by hand has broken this.flowctl done carrying both --summary-file and --evidence-json. A bare status flip has broken this.flow-next:flow-next-plan and flow-next:flow-next-work. Improvising them here has broken this.© gmickel, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/flow-next/skills/flow-next of gmickel/flow-next.
Open the folder on GitHubat commit 09e291e
Flow Next next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Flow Next this skillgmickel/flow-next | 707 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Antipattern Preventiondoorkeeper-gem/doorkeeper | 5.5k | — | ~1.1k | Automated safety check: Pass | MIT | |
| OmniRoute Provider Managementdiegosouzapw/OmniRoute | 74k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Stripe Best Practiceskanchengw/cnllm | 175 | 3 repos | ~925 | Automated safety check: Pass | Apache-2.0 | |
| Notion Worker Third-Party Auth Guidemakenotion/workers-template | 439 | 1 repos | ~3.5k | Automated safety check: Notes | MIT |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
doorkeeper-gem/doorkeeper
Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.
diegosouzapw/OmniRoute
Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.
kanchengw/cnllm
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…
makenotion/workers-template
Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.
doorkeeper-gem/doorkeeper
Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper.
gmickel/flow-next
Resolve PR review feedback. An agent skill from gmickel/flow-next.
gmickel/flow-next
Resolve PR review feedback — fetch unresolved threads, triage, dispatch per-thread resolver agents, validate, commit, reply + resolve via GraphQL.
gmickel/flow-next
Audit .flow/memory/ entries against the current codebase and decide Keep / Update / Consolidate / Replace / Delete / Harden per entry.
gmickel/flow-next
Save the current conversation as a source-tagged flow-next spec, then offer review or editing.
gmickel/flow-next
Decision-map discovery for one oversized unclear idea before capture.
gmickel/flow-next
Decision-map discovery for one oversized/unclear idea before capture.
Categories
Manage .flow/ tasks and specs. An agent skill from gmickel/flow-next. Flow Next is an agent skill from gmickel/flow-next.flow/ tasks and specs.
Flow Next fits situations like: tasks that involve OAuth and OpenID Connect.
Run `npx skills add gmickel/flow-next --skill flow-next -a claude-code`. Or copy the skill folder (plugins/flow-next/skills/flow-next in gmickel/flow-next) into .claude/skills/flow-next in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gmickel/flow-next --skill flow-next -a codex`. Or copy the skill folder (plugins/flow-next/skills/flow-next in gmickel/flow-next) into .agents/skills/flow-next in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gmickel/flow-next --skill flow-next -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flow-next, .gemini/skills/flow-next, .github/skills/flow-next and .opencode/skills/flow-next in your project.
Going by SKILL.md and its folder, Flow Next needs the command-line tools its instructions call (jq).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Flow Next is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 266 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Flow Next: Fortify Development (coollabsio/coolify, 63k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 74k stars) and Stripe Best Practices (kanchengw/cnllm, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gmickel (a GitHub user) maintains it in gmickel/flow-next, which has 707 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on October 7, 2026.
Source: gmickel/flow-next on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.