Install
$ agentstack add skill-butterbase-ai-butterbase-skills-journey-plan ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Journey: Plan
Stage 2 of the guided journey. Turn the idea brief into an actionable Butterbase plan.
When to use
- Dispatched by
journeywhencurrent_stage: plan. - Directly via
/butterbase-skills:plan.
Inputs
docs/butterbase/01-idea.md(must exist — if absent, bounce back tojourney-idea).docs/butterbase/00-state.md(forhackathon_mode,hackathon_deadline).
External services — check built-ins first
When the plan needs email, messaging, calendar, CRM, docs, or project-management integration:
- Invoke
butterbase-skills:integrationsand callmanage_integrationsaction: "list_available"to see what Composio covers for this app. - If a toolkit fits, the plan should record "via manage_integrations (toolkit: )" instead of naming an external SDK.
When the plan needs payments:
- Invoke
butterbase-skills:payments. - Default to Stripe Connect via
manage_billingunless the user's region forces a fallback (see the payments skill). - Record the choice ("Stripe Connect" or " via function proxy") in the plan's Payments section.
Procedure
Work through these sections in order. After each section, write the result to 02-plan.md before moving on. One question at a time per the spec's questioning discipline.
- Tables. Read the capability map. Propose a starter table list with columns and types — recommend, don't ask blank. Example:
"Tables I'm seeing: users, orders, items. Missing any?"Then for each table:".: should this be a uuid / text / int / timestamp / enum?". Confirm primary keys, foreign keys, indexes that are obvious (foreign-key columns).
- RLS model. For each table:
"Can user A see user B's rows? ① no, strict isolation ② yes, public-read ③ only shared via explicit grant."Decide policy shape. In hackathon mode, prefer option ① and recommendmanage_rls action: create_user_isolation.
- Auth.
"OAuth providers: ① Google only ② Google + GitHub ③ email/password too ④ none (anonymous app)."Also ask:"Need a demo / judge account seeded? (hackathon mode only)".
- Functions. For each function from the capability map:
": trigger = HTTP / cron / WebSocket? If cron: schedule? If HTTP: idempotency needed?".
- Storage. If used:
"Which objects (avatars, attachments, …)? Public-read or per-user?".
- AI / RAG / realtime / durable. Only if used. Capture model choice (AI), collections (RAG), tables to subscribe to (realtime), object kinds (durable).
6b. Agents. Only if create_agent is tagged in the idea. For each agent, capture:
name(slug), one-line purpose.- Tool surface: which builtins (
query_table,insert_row, …), which functions (must exist in the Functions section), which MCP servers (URL + transport). - Visibility: private | authenticated | public. If public AND any write tool is reachable, mark
safety_acknowledged_needed: trueand set per-IP / per-user / per-app rate limits +daily_budget_usd. - Default model.
- Note that the agent record will not be carried by clone replay — the spec JSON (under
agents/.json) rides along in the repo snapshot, so this matters for the publish stage too.
- Frontend stack.
"Frontend: ① Vite + React ② Next.js ③ static HTML ④ none (API-only)."Write to00-state.mdfrontend_stack.
7b. Publish-as-template. Read publish_as_template from 00-state.md front-matter (set by journey-idea). If yes or unlisted, plan for it now:
- README outline (one-liner, env-var-per-function list, OAuth setup, agent re-import, MCP server registration, seed data, first-run smoke).
- Which env vars use the auto-mint convention (
butterbase_api_key) vs. require manual user input on clone. - Whether
agents/*.jsonfiles need to be exported and committed (yes if Agents section is non-empty). - Note that publishing requires
butterbase repo pushto upload the source tree as a snapshot — without it, cloners get an empty file tree.
Toolchain question
Ask: "Will your app's code use @butterbase/sdk only in the frontend, only server-side (functions, scripts), or both?" Record under Toolchain → SDK surfaces.
Ask: "Want to install @butterbase/cli for the local dev loop (logs, scaffolding, key rotation)? (yes/no — default yes)" Record under Toolchain → CLI usage.
- Scope cut (hackathon mode). Re-read the must-haves list. For each, ask:
"Ship now or post-hackathon?"Write the cut list into02-plan.md's "Post-hackathon" section.
- Annotate skipped stages. For every build stage NOT used in this plan (check the capability map and feature list), update
00-state.md's checklist to read- [ ] (n/a)for that row. Also do this forrlsifhackathon_mode: true(mark as(folded into schema)).
- Final approval. Show the user the assembled plan and ask:
"Plan looks good? (yes / revise )". Loop until yes.
02-plan.md format
# Plan
## Tables
- `users` (id uuid pk, email text unique, created_at timestamp)
- `orders` (id uuid pk, user_id uuid fk→users.id, status enum[pending,paid,shipped], total int, created_at timestamp; index on user_id)
- ...
## RLS
- `orders`: user-isolation (create_user_isolation, owner column = user_id)
- ...
## Auth
- Providers: Google
- Demo user: yes (email demo@example.com, password set via seed)
## Functions
- `stripe-webhook` — HTTP, idempotency table `_processed_events`
- `daily-digest` — cron 0 9 * * * UTC
## Storage
- bucket: `avatars` (per-user, private; download via presigned URL)
## AI / RAG / realtime / durable
- (none)
## Agents
- `order-summariser` — purpose: summarise a user's recent orders on demand.
- Tools: builtin `query_table`, function `format-currency`.
- Visibility: authenticated. Rate: 60/hr per user. Daily budget: $5.
- Default model: claude-haiku-4-5-20251001.
- Spec file: `agents/order-summariser.json` (committed to repo).
- (omit section entirely if no agents)
## Publish-as-template
- Intent: yes / unlisted / no
- README outline:
- Env vars cloners must supply:
- Auto-mint eligible keys: `butterbase_api_key` (etc.)
- Agent specs to bundle: `agents/*.json`
- Snapshot push: `butterbase repo push` at end of journey-templates.
- (omit section entirely if publish_as_template = no)
## Frontend
- Vite + React
## Toolchain
- **SDK surfaces**:
- Client-side: install `@butterbase/sdk` in the frontend; use `auth`, `db`, `storage`, `realtime`.
- Server-side: install `@butterbase/sdk` in functions / scripts; use the service-key flow for elevated access.
- **CLI usage**:
- Yes (default): use `butterbase` CLI for local scaffolding, log tailing (`butterbase logs `), function invocation, and key rotation.
- **Why both**: MCP tools provision and orchestrate; SDK + CLI are the runtime + dev loop.
## Build order
1. schema
2. rls (folded into schema in hackathon mode)
3. auth
4. storage
5. functions
6. ai (if used)
7. rag (if used)
8. realtime (if used)
9. durable (if used)
10. agents (if used — must come after functions, ai, and any MCP-server setup)
11. frontend
12. deploy
13. templates (optional — only if publish_as_template != no)
## Post-hackathon
- email notifications (deferred)
- admin dashboard (deferred)
Outputs
- Writes
docs/butterbase/02-plan.md. - Updates
00-state.md: tick- [x] plan, setfrontend_stack, setcurrent_stage: preflight, annotate skipped build stages with(n/a).
Anti-patterns
- ❌ Asking the user to design every table column without recommending defaults first.
- ❌ Skipping the scope-cut section in hackathon mode.
- ❌ Writing the plan only at the end — write as you go so progress survives a crash.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: butterbase-ai
- Source: butterbase-ai/butterbase-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.