Agent skill

Phase 2 Convention

by ww-w-ai in ww-w-ai/bkit-claude-code

Define coding rules, conventions, and standards for AI collaboration.

Apache-2.0Auto-check: notesBackend & APIs

Install Phase 2 Convention

skills CLI
$ npx skills add ww-w-ai/bkit-claude-code --skill phase-2-convention -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ww-w-ai/bkit-claude-code phase-2-convention --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/phase-2-convention .claude/skills/phase-2-convention && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phase-2-convention
GitHub stars
601
Token cost
~3.8k tokens
SKILL.md length
529 words
Files
1
Skills in repo
44
Repo updated
First seen
Licence
Apache-2.0

At a glance

Define coding rules, conventions, and standards for AI collaboration.

  • Backend & APIs work in your project
  • SKILL.md covers Purpose, What to Do in This Phase, Deliverables and PDCA Application, plus 7 more sections
  • Needs AUTH_SECRET and DB_PASSWORD

What it does

Phase 2 Convention is an agent skill from ww-w-ai/bkit-claude-code. Define coding rules, conventions, and standards for AI collaboration. Triggers: convention, coding style, lint, rules

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: bkit Vibecoding Kit - PDCA methodology + Claude Code mastery for AI-native development. The licence is Apache-2.0.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/phase-2-convention”

Requirements

  • A credential in API_STRIPE_SECRET
  • A credential in AUTH_SECRET
  • Pre-approved tools (allowed-tools): Read, Write, Glob, Grep

What it can do on your machine

Read from SKILL.md and the folder at commit 85b4913. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AUTH_SECRET
    • DB_PASSWORD
    • API_STRIPE_SECRET
    • SMTP_PASSWORD
    • AUTH_GOOGLE_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phase 2 Convention loads about 3.8k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 529 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:115
    - Never commit sensitive info in .env files
  • NoteMentions a .env fileSKILL.md:118
    ### .env File Structure
  • NoteMentions a .env fileSKILL.md:123
    ├── .env.local          # Local development (Git ignored)
  • NoteMentions a .env fileSKILL.md:124
    ├── .env.development    # Development env defaults
  • NoteMentions a .env fileSKILL.md:125
    ├── .env.staging        # Staging env defaults
  • NoteMentions a .env fileSKILL.md:126
    ├── .env.production     # Production defaults (no sensitive info)
  • NoteMentions a .env fileSKILL.md:127
    └── .env.test           # Test environment
  • NoteMentions a .env fileSKILL.md:134
    # Set actual values in .env.local
  • NoteMentions a .env fileSKILL.md:162
    | Variable Type | .env.example | .env.local | CI/CD Secrets |
  • NoteMentions a .env fileSKILL.md:203
    - [ ] Register .env.local in .gitignore

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ww-w-ai/bkit-claude-code at commit 85b4913, republished under its Apache-2.0 licence (© ww-w-ai). 529 words, ~3,764 tokens.

Download SKILL.mdSave it as .claude/skills/phase-2-convention/SKILL.md (or your agent's skills folder).
name
phase-2-convention
description
Define coding rules, conventions, and standards for AI collaboration. Triggers: convention, coding style, lint, rules
allowed-tools
Read, Write, Glob, Grep
context
fork
background
false
classification
workflow
classification-reason
Process automation persists regardless of model advancement
deprecation-risk
none
effort
medium
agent
bkit:pipeline-guide
user-invocable
false
imports
${PLUGIN_ROOT}/templates/pipeline/phase-2-convention.template.md, ${PLUGIN_ROOT}/templates/shared/naming-conventions.md
next-skill
phase-3-mockup

Phase 2: Coding Convention

Define code writing rules

Purpose

Maintain consistent code style. Especially important when collaborating with AI - clarify what style AI should use when writing code.

What to Do in This Phase

  1. Naming Rules: Variables, functions, files, folder names
  2. Code Style: Indentation, quotes, semicolons, etc.
  3. Structure Rules: Folder structure, file separation criteria
  4. Pattern Definition: Frequently used code patterns

Deliverables

Project Root/
├── CONVENTIONS.md          # Full conventions
└── docs/01-plan/
    ├── naming.md           # Naming rules
    └── structure.md        # Structure rules

PDCA Application

  • Plan: Identify necessary convention items
  • Design: Design detailed rules
  • Do: Write convention documents
  • Check: Review consistency/practicality
  • Act: Finalize and proceed to Phase 3

Level-wise Application

LevelApplication Level
StarterBasic (essential rules only)
DynamicExtended (including API, state management)
EnterpriseExtended (per-service rules)

Core Convention Items

Naming
  • Components: PascalCase
  • Functions: camelCase
  • Constants: UPPER_SNAKE_CASE
  • Files: kebab-case or PascalCase
Folder Structure
src/
├── components/     # Reusable components
├── features/       # Feature modules
├── hooks/          # Custom hooks
├── utils/          # Utilities
└── types/          # Type definitions

Environment Variable Convention

Why Define at Design Stage?
❌ Organizing env vars just before deployment
   → Missing variables, naming inconsistency, deployment delays

✅ Establish convention at design stage
   → Consistent naming, clear categorization, fast deployment
Environment Variable Naming Rules
PrefixPurposeExposure ScopeExample
NEXT_PUBLIC_Client-exposedBrowserNEXT_PUBLIC_API_URL
DB_DatabaseServer onlyDB_HOST, DB_PASSWORD
API_External API keysServer onlyAPI_STRIPE_SECRET
AUTH_AuthenticationServer onlyAUTH_SECRET, AUTH_GOOGLE_ID
SMTP_Email serviceServer onlySMTP_HOST, SMTP_PASSWORD
STORAGE_File storageServer onlySTORAGE_S3_BUCKET
⚠️ Security Principles
- Never expose anything except NEXT_PUBLIC_* to client
- API keys and passwords must be server-only variables
- Never commit sensitive info in .env files
.env File Structure
Project Root/
├── .env.example        # Template (in Git, values empty)
├── .env.local          # Local development (Git ignored)
├── .env.development    # Development env defaults
├── .env.staging        # Staging env defaults
├── .env.production     # Production defaults (no sensitive info)
└── .env.test           # Test environment
.env.example Template
bash
# .env.example - This file is included in Git
# Set actual values in .env.local

# ===== App Settings =====
NODE_ENV=development
NEXT_PUBLIC_APP_URL=http://localhost:3000

# ===== Database =====
DB_HOST=
DB_PORT=5432
DB_NAME=
DB_USER=
DB_PASSWORD=

# ===== Authentication =====
AUTH_SECRET=                    # openssl rand -base64 32
AUTH_GOOGLE_ID=
AUTH_GOOGLE_SECRET=

# ===== External Services =====
NEXT_PUBLIC_API_URL=
API_STRIPE_SECRET=
SMTP_HOST=
SMTP_USER=
SMTP_PASSWORD=
Environment-wise Value Classification
Variable Type.env.example.env.localCI/CD Secrets
App URLTemplateLocal valuePer-env value
API endpointsTemplateLocal/devPer-env value
DB passwordEmptyLocal value✅ Secrets
API keysEmptyTest key✅ Secrets
JWT SecretEmptyLocal value✅ Secrets
Environment Variable Validation
typescript
// lib/env.ts - Validate env vars at app startup
import { z } from 'zod';

const envSchema = z.object({
  // Required
  DATABASE_URL: z.string().url(),
  AUTH_SECRET: z.string().min(32),

  // Optional (with defaults)
  NODE_ENV: z.enum(['development', 'staging', 'production']).default('development'),

  // Client-exposed
  NEXT_PUBLIC_APP_URL: z.string().url(),
});

// Validation and type inference
export const env = envSchema.parse(process.env);

// Type-safe usage
// env.DATABASE_URL  ← autocomplete supported
Environment Variable Checklist
  • Naming Consistency

    • Follow prefix rules (NEXT_PUBLIC_, DB_, API_, etc.)
    • Use UPPER_SNAKE_CASE
  • File Structure

    • Create .env.example (template)
    • Register .env.local in .gitignore
    • Separate .env files per environment
  • Security

    • Classify sensitive info
    • Verify client-exposed variables
    • Organize Secrets list (for Phase 9 deployment)

Clean Architecture Principles

Why Define at Design Stage?
Clean Architecture = Code resilient to change

❌ Developing without architecture
   → Spaghetti code, multiple file changes for each modification

✅ Define layers at design stage
   → Separation of concerns, easy testing, easy maintenance
src/
├── presentation/        # or app/, pages/
│   ├── components/      # UI components
│   ├── hooks/           # State management hooks
│   └── pages/           # Page components
│
├── application/         # or services/, features/
│   ├── use-cases/       # Business use cases
│   └── services/        # API service wrappers
│
├── domain/              # or types/, entities/
│   ├── entities/        # Domain entities
│   ├── types/           # Type definitions
│   └── constants/       # Domain constants
│
└── infrastructure/      # or lib/, api/
    ├── api/             # API clients
    ├── db/              # Database connections
    └── external/        # External services
Layer Responsibilities and Rules
LayerResponsibilityCan Depend OnCannot Depend On
PresentationUI rendering, user eventsApplication, DomainInfrastructure directly
ApplicationBusiness logic orchestrationDomain, InfrastructurePresentation
DomainCore business rules, typesNothing (independent)All external layers
InfrastructureExternal system connectionsDomainApplication, Presentation
Show full SKILL.md (204 more words)Show less
Dependency Rule
typescript
// ❌ Bad: Presentation directly calls Infrastructure
// components/UserList.tsx
import { apiClient } from '@/lib/api/client';  // Direct import forbidden!

export function UserList() {
  const users = apiClient.get('/users');  // ❌
}

// ✅ Good: Presentation → Application → Infrastructure
// hooks/useUsers.ts
import { userService } from '@/services/user.service';

export function useUsers() {
  return useQuery({
    queryKey: ['users'],
    queryFn: userService.getList,  // ✅ Call through Service
  });
}

// components/UserList.tsx
import { useUsers } from '@/hooks/useUsers';

export function UserList() {
  const { data: users } = useUsers();  // ✅ Call through Hook
}
File Import Rules
typescript
// ===== Allowed import directions =====

// In presentation/:
import { User } from '@/domain/types';           // ✅ Domain OK
import { useUsers } from '@/hooks/useUsers';     // ✅ Same layer OK
import { userService } from '@/services/user';   // ✅ Application OK

// In application/:
import { User } from '@/domain/types';           // ✅ Domain OK
import { apiClient } from '@/lib/api/client';    // ✅ Infrastructure OK

// In domain/:
// Minimize external imports (pure types/logic only)

// In infrastructure/:
import { User } from '@/domain/types';           // ✅ Domain OK

// ===== Forbidden imports =====

// In domain/:
import { apiClient } from '@/lib/api/client';    // ❌ Infrastructure forbidden
import { Button } from '@/components/ui/button'; // ❌ Presentation forbidden

// In infrastructure/:
import { useUsers } from '@/hooks/useUsers';     // ❌ Presentation forbidden
Level-wise Application
LevelArchitecture Application
StarterSimple structure (components, lib)
Dynamic3-4 layer separation (recommended structure)
EnterpriseStrict layer separation + DI container
Starter Level Folder Structure
src/
├── components/     # UI components
├── lib/            # Utilities, API
└── types/          # Type definitions
Dynamic Level Folder Structure
src/
├── components/     # Presentation
│   └── ui/
├── features/       # Feature modules (Application + Presentation)
│   ├── auth/
│   └── product/
├── hooks/          # Presentation (state management)
├── services/       # Application
├── types/          # Domain
└── lib/            # Infrastructure
    └── api/
Enterprise Level Folder Structure
src/
├── presentation/
│   ├── components/
│   ├── hooks/
│   └── pages/
├── application/
│   ├── use-cases/
│   └── services/
├── domain/
│   ├── entities/
│   └── types/
└── infrastructure/
    ├── api/
    └── db/

Phase Connection

Conventions defined in this Phase are verified in later Phases:

Definition (Phase 2)Verification (Phase 8)
Naming rulesNaming consistency check
Folder structureStructure consistency check
Environment variable conventionEnv var naming check
Clean architecture principlesDependency direction check

Template

See templates/pipeline/phase-2-convention.template.md

Next Phase

Phase 3: Mockup Development → Rules are set, now rapid prototyping


6. Reusability Principles

6.1 Function Design
Creating Generic Functions
typescript
// ❌ Handles only specific case
function formatUserName(user: User) {
  return `${user.firstName} ${user.lastName}`
}

// ✅ Generic
function formatFullName(firstName: string, lastName: string) {
  return `${firstName} ${lastName}`
}

// Usage
formatFullName(user.firstName, user.lastName)
formatFullName(author.first, author.last)
Parameter Generalization
typescript
// ❌ Tied to specific type
function calculateOrderTotal(order: Order) {
  return order.items.reduce((sum, item) => sum + item.price, 0)
}

// ✅ Generalized with interface
interface HasPrice { price: number }
function calculateTotal<T extends HasPrice>(items: T[]) {
  return items.reduce((sum, item) => sum + item.price, 0)
}

// Can be used in various places
calculateTotal(order.items)
calculateTotal(cart.products)
calculateTotal(invoice.lineItems)
6.2 Component Design
Composable Components
tsx
// ❌ Hardcoded structure
function UserCard({ user }: { user: User }) {
  return (
    <div className="card">
      <img src={user.avatar} />
      <h3>{user.name}</h3>
      <p>{user.email}</p>
    </div>
  )
}

// ✅ Composable
function Card({ children, className }: CardProps) {
  return <div className={cn("card", className)}>{children}</div>
}

function Avatar({ src, alt }: AvatarProps) {
  return <img src={src} alt={alt} className="avatar" />
}

// Use by combining
<Card>
  <Avatar src={user.avatar} alt={user.name} />
  <h3>{user.name}</h3>
  <p>{user.email}</p>
</Card>
Props Extensibility
tsx
// ❌ Limited props
interface ButtonProps {
  label: string
  onClick: () => void
}

// ✅ Extend HTML attributes
interface ButtonProps extends React.ButtonHTMLAttributes<HTMLButtonElement> {
  variant?: 'default' | 'outline' | 'ghost'
  size?: 'sm' | 'md' | 'lg'
}

// All button attributes available
<Button type="submit" disabled={isLoading}>
  Save
</Button>
6.3 Extraction Criteria
When to Extract as Function
1. Same logic used 2+ times
2. Logic is complex enough to need a name
3. Logic that needs testing
4. Can be used in other files
When to Extract as Component
1. Same UI pattern repeats
2. Has independent state
3. Is a reusable unit
4. JSX over 50 lines

7. Extensibility Principles

7.1 Configuration-Based Design
typescript
// ❌ Listing conditionals
function getStatusColor(status: string) {
  if (status === 'active') return 'green'
  if (status === 'pending') return 'yellow'
  if (status === 'error') return 'red'
  return 'gray'
}

// ✅ Configuration object
const STATUS_CONFIG = {
  active: { color: 'green', label: 'Active' },
  pending: { color: 'yellow', label: 'Pending' },
  error: { color: 'red', label: 'Error' },
} as const

function getStatusConfig(status: keyof typeof STATUS_CONFIG) {
  return STATUS_CONFIG[status] ?? { color: 'gray', label: status }
}

// Adding new status = just add config
7.2 Strategy Pattern
typescript
// ❌ Listing switch statements
function processPayment(method: string, amount: number) {
  switch (method) {
    case 'card':
      // Card payment logic
      break
    case 'bank':
      // Bank transfer logic
      break
  }
}

// ✅ Strategy pattern
interface PaymentStrategy {
  process(amount: number): Promise<Result>
}

const paymentStrategies: Record<string, PaymentStrategy> = {
  card: new CardPayment(),
  bank: new BankTransfer(),
}

function processPayment(method: string, amount: number) {
  const strategy = paymentStrategies[method]
  if (!strategy) throw new Error(`Unknown method: ${method}`)
  return strategy.process(amount)
}

// Adding new payment method = just add strategy
7.3 Plugin Structure
typescript
// Extensible system
interface Plugin {
  name: string
  init(): void
  execute(data: unknown): unknown
}

class PluginManager {
  private plugins: Plugin[] = []

  register(plugin: Plugin) {
    this.plugins.push(plugin)
  }

  executeAll(data: unknown) {
    return this.plugins.reduce(
      (result, plugin) => plugin.execute(result),
      data
    )
  }
}

// New feature = add plugin

8. Duplication Prevention Checklist

Before Writing Code
  • Is there a similar function in utils/?
  • Is there a similar component in components/?
  • Is there a similar hook in hooks/?
  • Did you search the entire project?
After Writing Code
  • Is the same code in 2+ places? → Extract
  • Can this code be used elsewhere? → Move
  • Are there hardcoded values? → Make constants
  • Is it tied to a specific type? → Generalize

© ww-w-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/phase-2-convention of ww-w-ai/bkit-claude-code.

Open the folder on GitHubat commit 85b4913

Compare with similar skills

Phase 2 Convention next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phase 2 Convention compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phase 2 Convention this skillww-w-ai/bkit-claude-code601—~3.8kAutomated safety check: NotesApache-2.0
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
ToolJet Marketplace Plugin BuilderToolJet/ToolJet41k—~2.1kAutomated safety check: PassAGPL-3.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Infer Conventionsanonaddy/anonaddy4.9k5 repos~3.1kAutomated safety check: PassMIT
RuView CLI, API and WASMruvnet/RuView97k—~1.2kAutomated safety check: NotesMIT

Similar skills

  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.

    41k GitHub stars~2.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Infer Conventions

    anonaddy/anonaddy

    A skill your agent uses to analyze how a Laravel application is actually written and record its conventions as shared rules.

    4.9k GitHub starsUsed in 5 repos~3.1k tokens
    Backend & APIsAuto-check passed
  • Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.

    97k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Contributor guide for step three of adding a syncable entity to the Twenty server: write the validator, the migration action builder and the orchestrator wiring.

    58k GitHub stars~3.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from ww-w-ai/bkit-claude-code

All 44 skills in this repo
  • Audit

    ww-w-ai/bkit-claude-code

    View audit logs, decision traces, and session history for AI transparency.

    601 GitHub stars~1.6k tokensUpdated 14 days ago
    Auto-check: notes
  • Bkend Auth

    ww-w-ai/bkit-claude-code

    bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

    601 GitHub stars~937 tokensUpdated 14 days ago
    Auto-check: notes
  • Bkend Cookbook

    ww-w-ai/bkit-claude-code

    bkend.ai project tutorials (todo to SaaS) and common error troubleshooting.

    601 GitHub stars~891 tokensUpdated 14 days ago
    Auto-check: notes
  • Bkend Quickstart

    ww-w-ai/bkit-claude-code

    bkend.ai onboarding — MCP setup, resource hierarchy, tenant/user model, first project.

    601 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Bkend Storage

    ww-w-ai/bkit-claude-code

    bkend.ai file storage — upload (presigned URL), download (CDN), visibility levels, buckets.

    601 GitHub stars~901 tokensUpdated 14 days ago
    Auto-check: notes
  • Bkit

    ww-w-ai/bkit-claude-code

    bkit plugin help - list available functions including /pdca (9-phase feature cycle), /sprint (8-phase feature container, v2.1.13), /control (Trust L0-L4 + SPRINTAUTORUNSCOPE), /bkit-explore, and 40+…

    601 GitHub stars~1.4k tokensUpdated 14 days ago
    Auto-check passed

Questions about Phase 2 Convention

What does Phase 2 Convention do?

Define coding rules, conventions, and standards for AI collaboration. Phase 2 Convention is an agent skill from ww-w-ai/bkit-claude-code. Define coding rules, conventions, and standards for AI collaboration.

When should I use Phase 2 Convention?

Phase 2 Convention fits situations like: backend & APIs work in your project.

How do I install Phase 2 Convention in Claude Code?

Run `npx skills add ww-w-ai/bkit-claude-code --skill phase-2-convention -a claude-code`. Or copy the skill folder (skills/phase-2-convention in ww-w-ai/bkit-claude-code) into .claude/skills/phase-2-convention in your project. Claude Code loads it when a task matches its description.

How do I install Phase 2 Convention in Codex?

Run `npx skills add ww-w-ai/bkit-claude-code --skill phase-2-convention -a codex`. Or copy the skill folder (skills/phase-2-convention in ww-w-ai/bkit-claude-code) into .agents/skills/phase-2-convention in your project. Codex loads it when a task matches its description.

Can I use Phase 2 Convention in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ww-w-ai/bkit-claude-code --skill phase-2-convention -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phase-2-convention, .gemini/skills/phase-2-convention, .github/skills/phase-2-convention and .opencode/skills/phase-2-convention in your project.

What does Phase 2 Convention need to run?

Going by SKILL.md and its folder, Phase 2 Convention needs credentials named AUTH_SECRET, DB_PASSWORD, API_STRIPE_SECRET and SMTP_PASSWORD. Our summary lists: A credential in API_STRIPE_SECRET; A credential in AUTH_SECRET. Its frontmatter pre-approves these tools: Read, Write, Glob, Grep.

Does Phase 2 Convention access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Phase 2 Convention safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Phase 2 Convention use?

Phase 2 Convention is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phase 2 Convention use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Phase 2 Convention?

Skills that share tags, products or a category with Phase 2 Convention: Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), ToolJet Marketplace Plugin Builder (ToolJet/ToolJet, 41k stars), Payload (payloadcms/payload, 45k stars) and Infer Conventions (anonaddy/anonaddy, 4.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phase 2 Convention?

ww-w-ai (a GitHub organization) maintains it in ww-w-ai/bkit-claude-code, which has 601 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on September 27, 2026.

Source: ww-w-ai/bkit-claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.