# Aicrew Dev

> Run the aicrew /dev pipeline in Codex (intake -> research -> design -> TDD -> tests -> security -> audit -> infra -> conclude).

- **Type:** Skill
- **Install:** `agentstack add skill-aksoftcode-aicrew-aicrew-dev`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [AKSoftCode](https://agentstack.voostack.com/s/aksoftcode)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [AKSoftCode](https://github.com/AKSoftCode)
- **Source:** https://github.com/AKSoftCode/aicrew/tree/master/codex-skills/aicrew-dev
- **Website:** https://github.com/AKSoftCode/aicrew

## Install

```sh
agentstack add skill-aksoftcode-aicrew-aicrew-dev
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# aicrew /dev (Codex)

Codex does not support slash commands. Use this skill when the user asks for "/dev" or a full SDLC pipeline.

## Token foundation (mandatory)

`/dev`, `/fix`, and `/quick` all share the same 11-capability token-saving stack — only pipeline depth differs. Full reference: `~/Agents/docs/token-foundation.md`. Stack: graph-first (`codebase-memory-mcp`), speculative Scout → verify (SCOUT schema, two-model routing), Karpathy guardrails, layered guardrails (`guardrails-taxonomy.md`), context-economy read policy, `security-guard.py` hooks, `.ai/state` checkpoints, `/compact` between phases, `/handoff` on tool switch, optional `context-mode` + `token-optimizer-mcp`, caveman default output. For `/dev`, Scout opens Phase 1 Research before any Glob/Grep/Read; re-scout between phases if context grew.

## Default output

Caveman/lean style by default. See `~/Agents/agents/caveman.md` and `~/Agents/agents/context-economy.md`. `/normal` or `/lean off` restores verbose.

Source of truth:
- `~/Agents/commands/dev.md`
- Project overrides in `.ai/skills/` and repo `AGENTS.md` (if present)

Token foundation (mandatory — all phases):
- Graph-first research: codebase-memory-mcp (search_graph → trace_path → get_code_snippet) before any Grep/Read
- Speculative context: Scout pass (cheap model) at start of Phase 1; emit SCOUT: schema; verify before main trace
- Layered guardrails: security-guard.py (input) → scope lock (Phase 0) → karpathy-guardrails (Phase 4) → security-reviewer (Phase 6)
- Context economy: always on; /compact between phases; /lean amplifies
- Two-model routing: Scout on haiku/mini; Research+Implement on sonnet/opus
- See: ~/Agents/docs/token-foundation.md

Workflow summary:
1. Intake: clarify bug/feature/refactor, acceptance criteria, scope, risks, test plan.
2. Research: Scout pass (graph-first) → verify SCOUT schema → confirm root cause or key code paths.
3. Brainstorm: 3 alternatives with trade-offs (features/refactors).
4. Design: interface spec, contract checks, over/under-engineering flags.
5. Implement: load karpathy-guardrails; TDD first (RED -> GREEN -> REFACTOR per acceptance criterion).
6. Tests: targeted automated tests + smoke path.
7. Security: changed files only, no false positives.
8. Audit: if project defines domain audit checks.
9. Conclude: summary, tests run, risks, commit message.

Checkpoints: pause for user confirmation at intake, design, and before concluding.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [AKSoftCode](https://github.com/AKSoftCode)
- **Source:** [AKSoftCode/aicrew](https://github.com/AKSoftCode/aicrew)
- **License:** MIT
- **Homepage:** https://github.com/AKSoftCode/aicrew

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-aksoftcode-aicrew-aicrew-dev
- Seller: https://agentstack.voostack.com/s/aksoftcode
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
