Agent skill

Vibe Coding Production

by Junliu1066 in Junliu1066/vibe-coding-kit

把验证过的 Vibe Coding demo,做成能长期运行、给别人用的正式系统. An agent skill from Junliu1066/vibe-coding-kit.

MITAuto-check passedBackend & APIs

Install Vibe Coding Production

skills CLI
$ npx skills add Junliu1066/vibe-coding-kit --skill vibe-coding-production -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Junliu1066/vibe-coding-kit vibe-coding-production --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Junliu1066/vibe-coding-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vibe-coding-production .claude/skills/vibe-coding-production && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vibe-coding-production
GitHub stars
109
Token cost
~993 tokens
SKILL.md length
277 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

把验证过的 Vibe Coding demo,做成能长期运行、给别人用的正式系统. An agent skill from Junliu1066/vibe-coding-kit.

  • Works in 3 steps: 读 docs/进度账本.md。 确认 S2… → 任一条不满足就别开始:需求/选型没定完,先回… → 本阶段步骤对应账本:S3.1 开发规范 → S3.2 安全基线 → S3.3…
  • Tasks that involve File uploads and storage
  • SKILL.md covers 准入检查(开始本阶段前必做), 一、开发规范(对应 S3.1), 二、安全基线(对应 S3.2) and 三、部署策略(对应 S3.3), plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vibe Coding Production is an agent skill from Junliu1066/vibe-coding-kit. 把验证过的 Vibe Coding demo,做成能长期运行、给别人用的正式系统。 当用户说"想上线"、"怎么部署"、"这个 demo 想做成正式的"、"要注意安全吗"、"怎么测试我的项目", 或者准备把代码开源/公开发布时,使用此 Skill。涵盖开发规范、安全基线、部署、手动验收、文档要求。 这是 vibe-coding-kit 套件里负责"从 demo 到上线"的 Skill。 即使用户没明说"上线"二字,只要 ta 准备把一个能跑的东西交给别人用、或放到服务器/公网上,就应主动用本 Skill。

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering File uploads and storage. It works with Git. The repository describes itself as: 不教你写代码,教你把"用 AI 写代码"彻底想明白 — 给非技术产品人的 vibe coding 规划工具包. The licence is MIT.

When your agent uses it

  • Tasks that involve File uploads and storage

Example prompts

  • “这个 demo 想做成正式的”
  • “要注意安全吗”
  • “怎么测试我的项目”
  • “/vibe-coding-production”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 读 docs/进度账本.md。 确认 S2 架构选型出口门已过(技术栈已选定),且用户明确确认"要做成正式系统、给别人用"。只想跑 demo 的人不进 S3。
  2. 任一条不满足就别开始:需求/选型没定完,先回 S1/S2;用户只想验证想法,就停在 demo,别硬上线。
  3. 本阶段步骤对应账本:S3.1 开发规范 → S3.2 安全基线 → S3.3 部署 → S3.4 测试验收 →(可选)S3.5 文档。每过一步回写账本。

What it can do on your machine

Read from SKILL.md and the folder at commit cb387af. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vibe Coding Production loads about 993 tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 277 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~993

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Junliu1066/vibe-coding-kit at commit cb387af, republished under its MIT licence (© Junliu1066). 277 words, ~993 tokens.

Download SKILL.mdSave it as .claude/skills/vibe-coding-production/SKILL.md (or your agent's skills folder).
name
vibe-coding-production
description
把验证过的 Vibe Coding demo,做成能长期运行、给别人用的正式系统。 当用户说"想上线"、"怎么部署"、"这个 demo 想做成正式的"、"要注意安全吗"、"怎么测试我的项目", 或者准备把代码开源/公开发布时,使用此 Skill。涵盖开发规范、安全基线、部署、手动验收、文档要求。 这是 vibe-coding-kit 套件里负责"从 demo 到上线"的 Skill。 即使用户没明说"上线"二字,只要 ta 准备把一个能跑的东西交给别人用、或放到服务器/公网上,就应主动用本 Skill。

上线准备:从 demo 到正式系统

这是 vibe-coding-kit 里负责"上线"的 Skill。只想验证想法的人用不到它——决定把项目做成能长期运行、给别人用的正式系统时,再来。

前置:先用 vibe-coding-requirements 说清需求、vibe-coding-architecture 选好技术。开发全程配合 vibe-coding-survival 避坑。

每个环节都配了直接发给 AI 的话术和你用来验收的标准——你不需要会写代码,只需会问、会检查。


准入检查(开始本阶段前必做)

本 skill 是流程第三阶段 S3·上线准备。开始前:

  1. 读 docs/进度账本.md。 确认 S2 架构选型出口门已过(技术栈已选定),且用户明确确认"要做成正式系统、给别人用"。只想跑 demo 的人不进 S3。
  2. 任一条不满足就别开始:需求/选型没定完,先回 S1/S2;用户只想验证想法,就停在 demo,别硬上线。
  3. 本阶段步骤对应账本:S3.1 开发规范 → S3.2 安全基线 → S3.3 部署 → S3.4 测试验收 →(可选)S3.5 文档。每过一步回写账本。

一、开发规范(对应 S3.1)

把下面四段整理成一份"规范说明",每次让 AI 写代码时贴上,确保风格一致、日后好维护。

1.1 Git 分支策略(最简版)
main 分支          ← 永远是能稳定部署的版本
  └── dev 分支     ← 日常开发,AI 写的代码先合到这
        └── feat/xxx 分支  ← 每个新功能开一个,做完合回 dev

"每次写新功能时,顺便告诉我:① 该建什么分支名 ② commit message 写什么。"

(完全不用 git 也没关系,但至少要做 vibe-coding-survival 里的"保住能用的版本"——那是 git 的朴素替代。)

1.2 日志规范

"所有关键操作必须打日志,格式统一为 [时间] [级别] [模块] 内容。级别分三级:INFO(正常流程)、WARN(异常但能自动恢复)、ERROR(需我人工处理)。至少记录:请求进入、鉴权结果、数据库操作、外部调用、返回结果。卡密、密码等敏感信息脱敏,只显示前 4 位和后 4 位,中间用 *** 代替。"

1.3 错误处理规范

"所有可能出错的地方都要显式处理。错误信息必须含三要素:① 哪里出错(模块/函数名)② 为什么出错(具体原因)③ 建议怎么解决。绝不要把错误悄悄吞掉(catch 了却什么都不做)。"

1.4 代码风格

"代码注释用中文。每个函数上方注释说明:这函数做什么、输入什么、输出什么。变量名和函数名用英文,但要见名知意。"


二、安全基线(对应 S3.2)

▸ 过门:8 条逐条确认(标"已做"或"不适用")→ 账本 S3.2 标 ✅。涉及钱/别人隐私的,触发 survival 红线、提示找真人。

逐条把要求提给 AI,再逐条确认它做没做到。

#安全要求对 AI 说的话
1鉴权"所有接口都要验证身份,没通过的直接拒绝,返回 401。"
2防暴力破解"同一 IP 连续失败 N 次后,锁定 M 分钟。"
3输入校验"所有用户输入都要校验和清理,防止注入攻击。"
4HTTPS"生产环境必须用 HTTPS。"
5敏感信息保护"密钥、密码用环境变量或配置文件读取,绝不写死在代码里。"
6日志脱敏"敏感数据在日志里脱敏。"
7最小权限"数据库连接用最小必要权限,不要用 root。"
8错误信息"对外返回的错误信息不要暴露内部实现细节。"

开源专属提醒: 把代码公开(push 到 GitHub 等)之前,务必再确认一遍:代码里、配置里、提交历史里,没有任何密钥、密码、token。一旦推到公开仓库,就当全世界都看到了——即使事后删除也来不及,必须立刻作废并更换那个密钥。最稳妥的做法是把密钥放进一个单独的配置文件,并让 AI 帮你把它加进 .gitignore(让 git 永远忽略它)。

注意红线: 涉及真实收付款、存别人的个人信息等,别独自硬上——见 vibe-coding-survival 的「红线」。


三、部署策略(对应 S3.3)

▸ 过门:部署步骤可执行、亲手走通一遍 → 账本 S3.3 标 ✅。

"告诉我完整的部署步骤,每步用一句话说明为什么需要它。包括:① 服务器要装哪些依赖(运行环境、数据库等)② 文件放哪个目录 ③ 配置文件放哪 ④ 怎么启动服务 ⑤ 怎么设置开机自启 ⑥ 怎么看日志 ⑦ 怎么更新版本(停旧启新的流程)。"

输出物: 部署步骤清单。


四、测试验收(对应 S3.4)

▸ 过门:验收清单是 checkbox 格式、每条可验证 → 账本 S3.4 标 ✅。

你不用写测试代码,但要有一份能逐条手动验证的清单。

"给我一份功能验收清单,列出所有场景,我逐条手动验证。包括:① 正常流程的每个步骤 ② 异常情况(无效输入、超时、资源不足)③ 边界情况(空值、极限值)。"

每一条都要你亲手跑通才算过,不是 AI 说过就过(参见 vibe-coding-survival 的"让 AI 证明给你看")。

输出物: 功能验收清单(可逐条打勾的 Checklist)。


五、文档要求(对应 S3.5 ·可选)

▸ 过门:交付文档齐全 → 账本 S3.5 标 ✅;个人小项目可精简,跳过须留痕。

让 AI 每次写完代码都配套产出说明,免得过几天就忘了哪是哪。

"每次代码修改完成后,给我一份简短说明:① 新增/修改了哪些文件 ② 每个文件做了什么(一句话)③ 怎么验证功能正常 ④ 有什么要注意的(配置改动、新增依赖等)。"

把这些汇总进你的「项目说明书」(模板见仓库 examples/项目说明书-模板.md)。


上线前最终检查清单

  • 需求基准描述、技术栈、目录结构都记在项目说明书里
  • 安全基线 8 条逐条确认
  • 代码/历史里没有任何密钥、密码(尤其要开源时)
  • 部署步骤亲手走通一遍
  • 功能验收清单逐条打勾
  • 留了一个"能用版"备份
  • 涉及钱/别人隐私的部分,已找人把关或已确认不涉及

出口门(声称 S3 完成前必过)

以下约束来自项目治理配置 harness.json(workflow.stages[S3].exit_gate)和 CLAUDE.md。 在声称"上线准备完成"之前,你必须逐条确认。 全过之后,最后一步:在 docs/进度账本.md 把 S3 标记为「已完成、出口门 ✓」。这是流水线最后一阶段,到此全流程走完。

必须产出的内容
  • docs/项目说明书.md 中「安全清单」已填写
  • docs/项目说明书.md 中「验收清单」已填写
  • docs/进度账本.md 中 S3 各必经步骤为 ✅(S3.5 文档可跳并留痕)
  • docs/项目说明书.md 中「部署步骤」建议填写(如准备部署)
  • docs/项目说明书.md 中「开发规范要点」建议填写
硬性检查
  • 「安全清单」中 8 条安全基线至少逐条确认(标注"已做"或"不适用")
  • 「验收清单」是可以逐条打勾的 checkbox 格式(- [ ] 或 - [x])
  • 每条验收项写成"我做 X,应该看到 Y"的可验证格式
  • 代码和提交历史中无密钥、密码、token(尤其准备开源时)
  • .gitignore 中已加入敏感配置文件(如有)
自检完成声明

全部通过后声明: "✅ S3 出口门通过:安全清单已逐条确认,验收清单可逐条打勾验证,账本 S3 已标完成。全流程走完,可用 vibe-coding-harness 做最终质检。"

© Junliu1066, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/vibe-coding-production of Junliu1066/vibe-coding-kit.

Open the folder on GitHubat commit cb387af

Compare with similar skills

Vibe Coding Production next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vibe Coding Production compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vibe Coding Production this skillJunliu1066/vibe-coding-kit109—~993Automated safety check: PassMIT
Atmos Vendoringcloudposse/atmos1.4k—~4.8kAutomated safety check: WarnApache-2.0
Stripe Projectsfossasia/eventyay1.7k5 repos~2kAutomated safety check: NotesApache-2.0
Arcgis To Portaljsdatopian/portaljs2.4k1 repos~2kAutomated safety check: PassMIT
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
Spatialduckdb/duckdb-skills6031 repos~1kAutomated safety check: NotesMIT

Similar skills

  • Atmos Vendoring

    cloudposse/atmos

    Component vendoring: vendor.yaml and component.yaml manifests, immutable vendor.lock.yaml receipts, pulling from Git/S3/HTTP/OCI/Terraform Registry, --stack/--labels/--tags selector composition…

    1.4k GitHub stars~4.8k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check: notes
  • Arcgis To Portaljs

    datopian/portaljs

    Migrate a whole ArcGIS Hub site into a PortalJS Arc portal end-to-end.

    2.4k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Spatial

    duckdb/duckdb-skills

    Official

    Answer questions about spatial data using DuckDB. An agent skill from duckdb/duckdb-skills.

    603 GitHub starsUsed in 1 repo~1k tokens
    Backend & APIsAuto-check: notes
  • R Oop

    ab604/claude-code-r-skills

    R object-oriented programming guide for S7, S3, S4, and vctrs.

    207 GitHub starsUsed in 2 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from Junliu1066/vibe-coding-kit

  • Vibe Coding Harness

    Junliu1066/vibe-coding-kit

    质检 Agent:检查 vibe-coding-kit 其他 Skill 的产出物是否符合治理规范. An agent skill from Junliu1066/vibe-coding-kit.

    109 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Vibe Coding Prd

    Junliu1066/vibe-coding-kit

    一个"访谈式"的需求 Agent:通过一问一答 + 在岔路口给建议,把一个说不清需求的人,带到一份 AI 能直接照着开工的 PRD。

    109 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Vibe Coding Requirements

    Junliu1066/vibe-coding-kit

    Vibe Coding(用 AI 写代码)项目的第一步:把模糊的想法,变成 AI 能精准落地、不会跑偏的需求. An agent skill from Junliu1066/vibe-coding-kit.

    109 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Vibe Coding Survival

    Junliu1066/vibe-coding-kit

    Vibe Coding(用 AI 写代码)开发过程中的避坑与自救——真正翻车大多发生在"开工后". An agent skill from Junliu1066/vibe-coding-kit.

    109 GitHub stars~857 tokensUpdated 3 mo ago
    Auto-check passed
  • Vibe Coding Architecture

    Junliu1066/vibe-coding-kit

    教非技术背景的人看懂技术架构、做好技术选型——把"只会照搬话术的小白"练成"能看穿方案好坏的人". An agent skill from Junliu1066/vibe-coding-kit.

    109 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Vibe Coding Production

What does Vibe Coding Production do?

把验证过的 Vibe Coding demo,做成能长期运行、给别人用的正式系统. An agent skill from Junliu1066/vibe-coding-kit. Vibe Coding Production is an agent skill from Junliu1066/vibe-coding-kit.

When should I use Vibe Coding Production?

Vibe Coding Production fits situations like: tasks that involve File uploads and storage.

How do I install Vibe Coding Production in Claude Code?

Run `npx skills add Junliu1066/vibe-coding-kit --skill vibe-coding-production -a claude-code`. Or copy the skill folder (skills/vibe-coding-production in Junliu1066/vibe-coding-kit) into .claude/skills/vibe-coding-production in your project. Claude Code loads it when a task matches its description.

How do I install Vibe Coding Production in Codex?

Run `npx skills add Junliu1066/vibe-coding-kit --skill vibe-coding-production -a codex`. Or copy the skill folder (skills/vibe-coding-production in Junliu1066/vibe-coding-kit) into .agents/skills/vibe-coding-production in your project. Codex loads it when a task matches its description.

Can I use Vibe Coding Production in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Junliu1066/vibe-coding-kit --skill vibe-coding-production -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vibe-coding-production, .gemini/skills/vibe-coding-production, .github/skills/vibe-coding-production and .opencode/skills/vibe-coding-production in your project.

What does Vibe Coding Production need to run?

SKILL.md names no scripts, command-line tools or credentials: Vibe Coding Production is instructions for the agent only.

Does Vibe Coding Production access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vibe Coding Production safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vibe Coding Production use?

Vibe Coding Production is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vibe Coding Production use?

About 993 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vibe Coding Production?

Skills that share tags, products or a category with Vibe Coding Production: Atmos Vendoring (cloudposse/atmos, 1.4k stars), Stripe Projects (fossasia/eventyay, 1.7k stars), Arcgis To Portaljs (datopian/portaljs, 2.4k stars) and Foundatio (FoundatioFx/Foundatio, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vibe Coding Production?

Junliu1066 (a GitHub user) maintains it in Junliu1066/vibe-coding-kit, which has 109 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on June 30, 2026.

Source: Junliu1066/vibe-coding-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.