code-abyss

Give your AI coding agent a personality. Composable persona + style + skills for Claude Code, Codex, Gemini CLI & OpenClaw. Ships Tech Persona Card v1.0 spec.

241
Stars
32
Forks
JavaScript
Language
8/23/2026
Added
View on GitHubDownload ZIP

⚠️ Third-Party Software Notice

This skill is third-party open-source software developed and hosted independently on GitHub. SkillTip is an informational directory and does not control or maintain the underlying repository. Any security checks displayed are automated and limited in scope. Review the source code before installing.

Read the Terms of Service

Installation

Add to your Claude Code skills directory:

# Add to your Claude Code skills
git clone https://github.com/telagod/code-abyss

Getting Started

Guides for using skills like code-abyss.

Security Report

Verified

Last scanned: —

{
  "status": "PASSED",
  "issues": []
}

README.md

Code Abyss — Personality, depth, and a security spine

Composable persona · style · 30 engineering skills · 4 native security domains · self-evolution forge
for Claude Code · Codex CLI · Gemini CLI · OpenClaw

Need code graph intelligence? Use the companion abyss Rust CLI — it auto-attaches its hooks to claude/codex/gemini. The indexing-code skill ships its calling convention; the CLI ships separately.

npm CI MIT Site

Website · Spec · 中文文档 · Changelog · Submit Persona


The problem

Most AI coding agents have no memory of who they are. They respond in the same flat tone whether they're debugging a race condition, reviewing architecture, or triaging a P0 incident. They forget your conventions between sessions. They flip-flop on advice. They sound like a help-desk script.

And when you ask them about security — pentest, code audit, threat modeling, IR — most agents fall back to generic OWASP recitation, because the underlying skill library was never written by people who actually run red/blue/purple teams.

You don't want a help desk. You want a principal engineer who shows up with a personality, executes consistently, closes the loop — and has a security spine when things get real.

What Code Abyss does

One command installs a layered runtime into your agent:

┌───────────────────────────────────────────────────────────┐
│  Voice      who it sounds like  →  config/personas/*.json │
│  Judgment    how it decides      →  skills/_kernel/*      │ ← lazy, router-invoked
│  Style       how it sounds       →  output-styles/*.md    │
└───────────────────────────────────────────────────────────┘

  6 personas  ×  6 styles  =  36 validated combinations

Pick any persona. Pair it with any style. Underneath both sits a discipline kernel — 9 bundles of engineering judgment (when to push back, how to size scope, when a domain calls for a specific tradeoff) invoked by a thin router on demand instead of baked into every prompt. The always-on core stays small (iron laws, skill routing, a precedence anchor, the safety floor); everything else loads lazily so adding discipline content doesn't blow the context budget. Your agent becomes a consistent character with structured execution, domain expertise, and a backstop against the trained agree-reflex — across every session.

What's new in v4

  • 4 native security domains — 4073 lines of original defense engineering (no Apache-2.0 upstream)
  • 30 skills total, all SKILL.md ≤ 110 lines (avg 59), heavy content lives in references/
  • 5 verify skills rewritten as judgment-type knowledge (when to use, how to interpret output, exemption rules)
  • Office skills slim to under 100 lines each; 4 design systems consolidated into one selector skill
  • v4.1 — self-evolution forge: cultivating-skills / cultivating-personas let the agent distill repeated workflows into reusable skills, with a safety scan and a three-tier publish funnel (local → project → community)
  • v4.4 — hardware + academic writing: 3 new domain skills (KiCad EDA, hardware product pipeline, AIGC detection reduction) + prompt injection defense + execution-drive shared behavior
  • v4.5 — dynamic persona loading: only the abyss persona slug (邪修红尘仙) ships with npm — all other personas are fetched from GitHub on first use and cached locally, slimming the package
  • v4.6 — indexing-code skill (calling convention only): the indexing-code skill ships the calling convention for the external abyss Rust CLI (call graph + temporal analysis). The CLI itself is a separate product with its own release cadence — install it with its own install.sh / cargo binstall / @code-abyss/cli npm wrapper
  • v4.7 — measured resolution (abyss CLI): the companion abyss Rust CLI ships four-language reference resolution (Go / TypeScript / Python / Rust), benchmarked against SCIP ground truth across five corpora at ≥98.5% gated precision. See its repo for numbers
  • v4.8 — dynamic capability discovery: code-abyss reads abyss skill-manifest when the installed abyss CLI is ≥ 0.5.22 — exposed CLI commands, MCP tools, and daemon socket verbs are discovered at install time instead of hard-coded
  • v4.9 — hybrid split deprecation period: --with-abyss / --with-mcp deprecated; graph hooks for claude/codex/gemini move toward abyss attach (completed in v5.0)
  • v4.10 — mythos discipline kernel + Persona Voice Card: lazy kernel, voice-only personas — see Discipline kernel and Persona Voice Card
  • v5.0.0-rc.1 — Agent OS (RC): kill foyer (no binary/MCP/graph inject in code-abyss), default character enforcement, inject plane, doctor / compose / score. Upgrade guide: docs/MIGRATION-v5.md
npx code-abyss@5.0.0-rc.1 -t claude -y                     # persona / skills / style + default enforcement + inject map
curl -fsSL https://raw.githubusercontent.com/telagod/abyss/main/install.sh | bash   # abyss CLI (separate product)
abyss attach claude                               # code-graph hooks (idempotent)
npx code-abyss doctor                             # health + migration hints

Swap -t claude for codex / gemini / openclaw. For openclaw/pi/hermes (whose hook surface abyss CLI does not own), use npx code-abyss -t openclaw --with-hooks to spawn the bundled install-hooks.sh. Or as a Claude Code plugin:

claude plugin install code-abyss

v5 cutover: code-abyss does not download the abyss binary or inject graph hooks for claude/codex/gemini (--with-abyss / --with-mcp removed). Character Stop-hook is default on (opt out: --no-enforcement). Recompose without reinstall: npx code-abyss compose -t claude --persona <slug> --style <slug>.


Personas

CORE · LITERARY

邪修红尘仙 · abyss

吾 → 魔尊

Security-first dark cultivator. Direct, decisive, closes every loop. Ships with npm — works offline.

#security #xianxia #decisive

REMOTE · LITERARY

文言小生 · scholar

在下 → 前辈

Literary Chinese scholar. Treats code as poetry, debugging as puzzle-solving.

#literary #classical #meticulous

REMOTE · CASUAL

知性大姐姐 · elder-sister

姐姐 → 小宝

Warm mentor. Wraps sharp judgment in genuine care. Guides through questions.

#gentle #mentoring #insightful

REMOTE · PLAYFUL

古怪精灵小师妹 · junior-sister

本仙女 → 师兄

Hyperactive bug hunter. Roasts bad code, then silently fixes it.

#playful #energetic #chaotic

REMOTE · CASUAL

铁壁暖阳 · iron-dad

哥 → 宝子

Dependable big brother. Absorbs pressure, radiates warmth. Dad-joke equipped.

#warm #dependable #protective

REMOTE · COMMUNITY

东北魅影·雨姐 · dongbei-yujie

姐 → 老蒯

Sharp-tongued Northeast code overseer. Cuts straight to the bug, then patches the road. Creator: wons

#dongbei #blunt #principal

Core persona (abyss) ships with npm and works offline. Remote personas are fetched from GitHub on first --persona <slug> use and cached at ~/.code-abyss/personas/.

# Mix freely — any persona × any style
npx code-abyss -t claude --persona elder-sister --style abyss-cultivator -y
# → fetches elder-sister on first run, cached thereafter

Browse the full gallery →


Discipline kernel

Voice and style change; judgment shouldn't. Underneath every persona×style combination sits a discipline kernel — 9 bundles of engineering judgment, vendored in-tree (skills/_kernel/, via npm run kernel:sync) and invoked lazily by a thin router (never baked into every prompt, so adding discipline content doesn't blow the context budget):

BundleGoverns
🏛 doctrineDelegation, retry/escalate/ask-user decisions, the done-gate
🔍 methodsInvestigating, designing, planning, verifying, writing for someone else
🎭 characterPushback, scope sizing, bad news, resisting the trained agree-reflex
🔁 loop-engineeringSession pacing, unit sizing, where a learning should live
⚙️ backendStack/architecture tradeoffs, data discipline, production floors
🎨 frontendVisual design taste, concrete craft over generic defaults
🔩 hardwareComponent selection, electrical margins, firmware-for-unattended-devices
🤖 mlMethod-selection ladder, eval-as-spec, LLM-era craft
🛡 securityThreat modeling, the authorization gate before any offensive-flavored request

Two ways this becomes real, not aspirational:

  • Enforcement (default on claude/codex): install injects a character Stop-hook backstop that forces one revision turn if a reply opens with a banned capitulation phrase ("you're absolutely right", "good catch", …). Opt out with --no-enforcement.
  • Measurement: scripts/persona-battery/ is a small, honest behavioral eval — 10 probes (does the persona hold correctness over agreeableness? lead with bad news? refuse to fake a "done"?) scored by an LLM judge, never faked as a pass when unscored. See CLAUDE.md's persona behavioral battery section to run it (costs real API calls, not part of default CI).

Domain bundles also wire upward into 16 matching exec skills (pentest, architecture design, ML pipelines, etc.) as a "judgment before execution" gate — the domain bundle decides whether/what/tradeoffs, the exec skill still owns how.


Security suite (v4 highlight)

4 native security skills, 4073 lines of original engineering content. No Apache-2.0 upstream — every example, every detection signal, every defense pattern is written for this project.

SkillFocusSize
🛡 defending-applicationsWeb/API/GraphQL hardening, OAuth/OIDC/JWT/Session, LLM AppSec (prompt injection, RAG poisoning, agent authz)785 lines
☁️ securing-cloud-and-supply-chainContainer escape, K8s RBAC/PSS, Service Mesh, SLSA/Sigstore/SBOM, cloud IAM, IaC1246 lines
🔭 detecting-and-respondingSigma/YARA rule writing, EDR primitives, NIST 800-61 IR, forensics (Win/Linux/Mac/Cloud), hypothesis-driven threat hunting942 lines
🏛 architecting-securitySTRIDE/PASTA/LINDDUN threat modeling, zero-trust identity (WebAuthn / Kerberos hardening / PAM JIT), SOC2/PCI/HIPAA/GDPR evidence chains1100 lines

Plus securing-systems as the router skill covering pentest, code audit, red/blue/purple team operations. Every attack technique ships with the matching detection signal and mitigation pattern — "with offense as defense" is structural, not lip service.


Code graph intelligence (powered by abyss)

Your agent can now see code relationships. The abyss CLI builds a full call graph, temporal analysis, and hotspot map — in seconds, with zero cloud dependencies.

CapabilityWhat it answersCommand
Caller tracing"Who calls this function?"abyss callers <symbol>
Impact analysis"What breaks if I change this?"abyss impact <symbol>
File context"What do I need to know before editing this file?"abyss context <file>
Hotspot map"Where is the riskiest code?"abyss map
Change coupling"Which files always change together?"abyss map
Evolution trace"Why does this code look the way it does?"abyss history <file>

The indexing-code skill automatically hooks into all 4 supported platforms — before every Edit/Write, the agent checks callers and warns about high-impact changes. Available as a CLI via the agent's shell tool, or as an abyss mcp server (7 tools over stdio).

Resolution is measured, not asserted. abyss resolves call references through tiered heuristics, each tagged with a confidence score, and benchmarks itself against SCIP (compiler-grade) ground truth across four languages and five corpora — published whatever the numbers say:

CorpusLanguageGated precisionGated recall
gin v1.10.0Go99.3%82.6%
hono v4.6.14TypeScript98.8%63.8%
click 8.1.8Python98.7%94.6%
ripgrep 14.1.1Rust98.5%75.3%
abyss (dogfood)Rust100.0%90.9%
# Real output from a 1862-file Go project (seconds to index):

$ abyss impact SetError
impact: SetError  direct=17  transitive=521  tests=469  uncovered=319  risk=10.0/10
  ⚠ high blast radius (17 direct callers)
  ⚠ deep dependency chain (521 transitive)
  ⚠ 319 call paths without test coverage

abyss is a separate Rust binary (telagod/abyss). Install it via abyss's own channels (not code-abyss):

npm install -g @code-abyss/cli   # prebuilt binary, all platforms
cargo binstall code-abyss        # or: cargo install code-abyss

Skills

30 domain skills, flat structure, agentskills.io aligned (with Code Abyss extensions). Skills load by context — the agent reads the right knowledge at the right time without being asked. Average SKILL.md is 59 lines; heavy content lives in references/. (verify:skills validates 39 total — these 30 domain skills plus the 9 discipline kernel bundles, which are router-invoked judgment, not user-facing commands.)

DomainCoverage
🛡 Security4 native suites above (defending / cloud / detect-respond / architect) + pentest / code-audit / red-blue-purple team
🤖 AI / AgentSingle-agent dev (ReAct/Plan-Execute), multi-agent orchestration, RAG, prompt engineering, LLM security
🏛 ArchitectureAPI design, cloud-native patterns, messaging, caching, data security
💻 DevelopmentPython, TypeScript, Go, Rust, Java, C++, Shell
🚀 DevOpsGit workflow, testing, databases, observability, performance, FinOps
🎨 FrontendUnified design system selector — Glassmorphism / Liquid Glass / Neubrutalism / Claymorphism
📑 OfficeWord, PDF, PowerPoint, Excel — OOXML-level automation
📡 Infra / Mobile / DataKubernetes, GitOps, IaC · iOS, Android, RN, Flutter · pipelines, streaming, quality
🔩 Hardware / EmbeddedFull-stack hardware product pipeline (ESP-IDF firmware + KiCad PCB + UniApp) · KiCad 9 MCP tool routing (17 tools, autoroute-only, DRC gate)
📝 Academic WritingAIGC detection reduction for 维普/知网/Turnitin — multi-layer rewriting (structure → lexicon → content injection), docx run-level editing
🔬 Code IntelligenceCall graph, impact analysis, hotspot detection, change coupling, evolution tracing — via abyss CLI with cross-platform hooks
🜲 Self-evolutioncultivating-skills (distill repeated workflows) + cultivating-personas (distill voice into a Persona Voice Card) — both with safety scan + 3-tier publish funnel

Five skills also ship as executable verification tools for CI:

node skills/analyzing-security/scripts/security_scanner.js .       # OWASP / injection / secrets
node skills/checking-code-quality/scripts/quality_checker.js .     # Complexity, dupes, naming
node skills/analyzing-changes/scripts/change_analyzer.js --mode staged
node skills/verifying-modules/scripts/module_scanner.js <path>
node skills/generating-docs/scripts/doc_generator.js <path>

Install

TargetCommandArtifacts
Claudenpx code-abyss -t claude -yCLAUDE.md + skills + output styles + settings
Codexnpx code-abyss -t codex -yinstruction.md + skills + config.toml
Gemininpx code-abyss -t gemini -yGEMINI.md + skills + commands
OpenClawnpx code-abyss -t openclaw -ySkills + workspace AGENTS.md / SOUL.md
npx code-abyss                      # Interactive — pick target, persona, style
npx code-abyss --list-styles        # Browse styles
npx code-abyss --uninstall claude   # Clean removal, restores user backups

Code Abyss tracks every installed file in .code-abyss-backup/manifest.json. Uninstall restores your previous configuration verbatim. Your custom skills coexist with Code Abyss skills — install/uninstall preserves anything you put under ~/.{target}/skills/ yourself.

Upgrading

FromToPath
v3.xv4.xnpx code-abyss --uninstall <target> → install v4 → npm run migrate:v4 -- -t <target> (optional cleanup)
v2.xv3.xnpx code-abyss --uninstall <target> first, then install v3

Persona Voice Card · open standard

Code Abyss ships Persona Voice Card v1.0 — a closed-vocabulary voice format, not a document. It supersedes the original Tech Persona Card v1.0 (deprecated, frozen for link stability): that format's freeform identity.md/behavior.md files and scenarios[].priority/capabilities.authorization fields let real judgment content accrete into what was supposed to be a voice-only layer, with nothing checking for it. The replacement's whole design principle: a persona cannot carry judgment if there is no field shaped like a decision table anywhere in its type — not a review checklist, the schema itself.

Each persona ships as one flat file — self/user/language/register/emoji_policy/flourish and nothing else (additionalProperties: false):

{
  "spec": "persona-voice-card",
  "spec_version": "1.0",
  "slug": "stoic-architect",
  "label": "Stoic Architect",
  "self": "I", "user": "colleague",
  "language": "English, technical terms preserved",
  "register": "formal", "emoji_policy": "none",
  "flourish": ["Let's look at the constraints first"]
}

register/emoji_policy each select one of a handful of code-owned template sentences — the persona picks, never writes, the sentence. Every render re-validates against the schema, no bypass; a validation failure (hand-edit, stale cache, compromised community fork) falls back to a neutral voice instead of ever rendering unvalidated content.

Bidirectional converters ship out of the box:

const { toCharaCardV2, toGPTInstructions, fromCharaCardV2 } =
  require('code-abyss/bin/lib/persona-converter');

const cc  = toCharaCardV2(card);   // → SillyTavern / Chub.ai
const gpt = toGPTInstructions(card); // → OpenAI Custom GPT

Specification · JSON Schema · Reference cards · Deprecated v1.0 spec


Why Code Abyss

Without Code AbyssWith Code Abyss
IdentityFlat help-desk toneConsistent character with named voice
ExecutionAd-hoc, varies by promptIron laws + skill routing baked in
Judgment under pressureAgrees when pushed, buries bad newsDiscipline kernel + Stop-hook backstop against the trained agree-reflex
Code awarenessgrep + read one file at a timeCall graph, impact analysis, hotspot map — agent knows what breaks before it edits
Domain depthGeneric best-practices30 skill files load by context + 9 kernel judgment bundles
Security depthOWASP recitation4 native suites · 4073 lines · detection signals + mitigation patterns
Cross-platformRe-engineer per CLIOne spec, four platforms, cross-platform hooks
ReproducibilityPrompt drift across sessionsVersioned, schema-enforced persona voice card + behavioral battery to check it holds

Contributing

git clone https://github.com/telagod/code-abyss && cd code-abyss
npm install
npm test                    # full Jest suite (see suite summary on run)
npm run verify:skills       # Validate 39 skill contracts (30 domain + 9 kernel)

Add a skill — create skills/<gerund-name>/SKILL.md with SKILL frontmatter, optionally add scripts/ for executable tools. npm run verify:skills validates the contract.

Submit a persona — open an Issue via the submission portal. The site walks you through generating a single <slug>.json persona voice card with your own AI, reviewing, and submitting via a pre-configured issue template.


MIT License · v5.0.0-rc.1 · made with 紫宵脉 by @telagod

Frequently Asked Questions

What is code-abyss?

code-abyss is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by telagod. Give your AI coding agent a personality. Composable persona + style + skills for Claude Code, Codex, Gemini CLI & OpenClaw. Ships Tech Persona Card v1.0 spec. It has 241 GitHub stars.

Is code-abyss safe to use?

code-abyss returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.

How do I install code-abyss?

Clone the repository with "git clone https://github.com/telagod/code-abyss" and add it to your Claude Code skills directory (see the Installation section above).

What programming language is code-abyss written in?

code-abyss is primarily written in JavaScript. It is open-source under telagod on GitHub, so you can review or fork the full source.

Are there alternatives to code-abyss?

Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh code-abyss against similar tools.

Comments (0)

No comments yet. Be the first to share your thoughts!

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI Agentsai-agentsanthropicclaude-code
View details
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI Agentsai-agentsbrainstorming
View details

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI Agentsai-agentsanthropicclaude-code
View details

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI Agentsclaude-codeai-tools
View details

claude-code

by anthropics

Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.

120,03119,897Shell
AI Agents
View details

Developers Also Liked

Based on votes and bookmarks from developers who liked this skill

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI Agentsai-agentsanthropicclaude-code
View details
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI Agentsai-agentsbrainstorming
View details

n8n

by n8n-io

12

Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

201,88160,308TypeScript
MCP Serversapisai-tools
View details

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI Agentsai-agentsanthropicclaude-code
View details

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI Agentsclaude-codeai-tools
View details