By kyzodb
A GitHub Projects work board as typed MCP tools: pure reads (read_board_status, read_column, ...), gated epic/story lifecycle (start_epic, start_story, finish_epic), free column moves, and authoring verbs — plus the kyzo-plan-manage-board skill that carries the operating model.
RUN FIRST after start_story — delete Condemned paths only. Red tree OK; preservation fails. Parent arms condemned allowlist and path-monitors. No Bash, git, or build. Not development or judge.
Execute ONE story T# under allowlist — Edit/Write only, then kyzo-plan-task-completion-request to the judge. After demolition. Spawn via task_spawn XML. No Bash, git, or board mutate. Not demolition or judge.
Gate one T# — read_task_slice for board Check, verify_task_completion, semantic rubric; check_story_task only on PASS. No repo browse, no help, no check_final_qa.
ONLY board read/write — plan MCP tools, never raw gh. Tool descriptions are role×verb. Not write-story or run-story.
Parent after start_story — arm paths, spawn demolition then each T#, run board Check, spawn judge, allowlist-commit on PASS / path-restore on FAIL, Final QA verdict then check_final_qa. Not write-story or manage-board.
Minimal completion_request the development-task sends to the judge after allowlist edits. Not board writes, not git, not tree meters.
Author or revise board epics — name + outcome as the value state the story group creates. Not story contracts (write-story), not T# runs (run-story), not column moves (manage-board).
Author or revise board story contracts (name, sources, condemned, ceiling, choice, allowlisted T#s, Final QA DoD). Not epic authorship (write-epic), not T# execution (run-story), not raw board moves (manage-board).
Admin access level
Server config contains admin-level keywords
Executes bash commands
Hook triggers when Bash tool is used
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
This plugin requires configuration values that are prompted when the plugin is enabled. Sensitive values are stored in your system keychain.
board_repoOverride — defaults to the checkout's origin repo
${user_config.board_repo}board_ownerOverride — defaults to the checkout's origin owner
${user_config.board_owner}board_projectOverride — defaults to the repo's sole open linked GitHub Project
${user_config.board_project}Modifies files
Hook triggers on file write and edit operations
Modifies files
Hook triggers on file write and edit operations
Uses power tools
Uses Bash, Write, or Edit tools
Uses power tools
Uses Bash, Write, or Edit tools
You decide what's worth building and write it once — agents execute against that
judgment, gated on git, with a judge before every checkbox and a token meter kept lean by design.
Kyzo Plan is a control plane for people who still own the product judgment — and for agents that must not re-derive it. Intent is written once, upstream, as an execution contract. The board is shared state, not a handoff chain. 35 typed MCP tools operate it; git and a completion judge keep motion honest. A checkbox is a fact, not a self-attestation.
Requirements: uv on PATH, gh authenticated against
the board's GitHub org, Python 3.12+.
Claude Code
/plugin marketplace add https://github.com/kyzodb/plan
/plugin install kyzo-plan@kyzo
Zero config in the common case: board owner and repo come from origin, project
number from the repo's sole open linked GitHub Project. create_board provisions
a fresh board with this schema if you're starting from nothing.
Overrides on enable (/plugin configure kyzo-plan@kyzo) or at install:
claude plugin marketplace add https://github.com/kyzodb/plan
claude plugin install kyzo-plan@kyzo \
--config board_owner=OWNER --config board_repo=REPO --config board_project=N
Cursor — same skills, agents, and MCP server. Claude Code is the supported install from this repository today.
Uninstall with /plugin uninstall kyzo-plan@kyzo. Board state lives on GitHub;
uninstalling leaves nothing behind.
What you see is what agents operate. Stock GitHub Projects; one screen is the working truth — not a status chain between roles:

Epics carry roll-up progress (1 / 3 — 33%). Classification is the GitHub label.
One card in In Progress answers what is being built right now. Filter Backlog
and Done away:

Agentic cost is mostly input: context re-read on every step. Five drains, five mechanisms — thinking stays upstream; agents don't burn the meter rediscovering it:
The kyzo-plan-manage-board skill carries what lives between the tools: orient
with read_board_status, never work around a refusal, never touch the board
through raw gh.
npx claudepluginhub kyzodb/plan --plugin kyzo-planType-Contract-Architecture skills for Python: five layers (values, adapters, verbs, state, wiring), each with success constructs and failure patterns.
Harness-native ECC plugin for engineering teams - 67 agents, 279 skills, 94 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses
Evidence-gated AI coding workflow: scan → analyze → plan → TDD → execute → fix → verify → review, powered by Codebase Memory MCP >= 0.9.0 with optional Serena LSP intelligence. Includes blast-radius planning, test/cycle gates, independent review, and Windows Git Bash hook auto-resolution.
v9.54.1 — Reliability wave: tangle contextual review correction loop with hard round ceiling, progress-supervised review rounds (per-agent stall watch, descendant-tree kills), council diversity and agy pin fixes, marketplace generator source-of-truth fix, provider troubleshooting runbook and cost-expectations docs. Run /octo:setup.
Core skills library for Claude Code: TDD, debugging, collaboration patterns, and proven techniques
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
Reliable automation, in-depth debugging, and performance analysis in Chrome using Chrome DevTools and Puppeteer