gstack
garrytan/gstack
A set of 55 slash-command skills that gives Claude Code a sprint process from planning to review, QA and shipping.
gstack is a free, MIT-licensed set of slash-command skills by Garry Tan, President and CEO of Y Combinator. It turns Claude Code into a team of specialist roles for planning, design, code review, QA in a real browser, security audits and release. The README says the skills run in sprint order: think, plan, build, review, test, ship and reflect, and that each skill feeds the next.
Facts checked on against the sources listed at the end of this page.
- GitHub stars
- 134,819
- Skills in the pack
- 60
- Agents supported
- 9plus a 2 KB instruction-only digest for any agent that reads rules files
- Instruction size
- 349k wordsacross all SKILL.md files
How to install gstack
| Agent | Command | Copy |
|---|---|---|
| Claude Code | Needs Git and Bun 1.0 or later. The README then asks you to add a gstack section to CLAUDE.md that lists the skills. Team mode: (cd ~/.claude/skills/gstack && ./setup --team) && ~/.claude/skills/gstack/bin/gstack-team-init required | |
| Codex | Without --host, setup detects the agents you have installed. | |
| Cursor | | |
| OpenCode | | |
| Factory Droid | |
Commands for 2 more agents
| Kiro | | |
|---|---|---|
| OpenClaw | Installs four methodology skills that run in OpenClaw without a Claude Code session. |
Commands as given in the README on 2 October 2026.
What is inside gstack
| Skill | What it makes the agent do |
|---|---|
| office-hours | Asks six forcing questions that reframe the product before any code and writes a design doc that later skills read. |
| plan-ceo-review | Challenges the scope of a plan in one of four modes: expansion, selective expansion, hold scope or reduction. |
| plan-eng-review | Locks architecture, data flow, edge cases and a test plan, with diagrams. |
| autoplan | Runs the CEO, design, developer experience and engineering reviews in order and surfaces only taste decisions for approval. |
| review | Reviews a branch for bugs that pass CI, auto-fixes obvious ones and flags completeness gaps. |
| qa | Explores a browser, API, CLI, job or webhook, writes a failing regression test for each bug, fixes it and re-verifies. |
| cso | Runs a security audit with an application model, findings that are challenged, and stated coverage. |
| ship | Syncs main, runs tests, audits coverage and docs, pushes and opens a pull request. |
| land-and-deploy | Merges the pull request, waits for CI and deploy, and checks production health. |
| careful, freeze and guard | Warn before destructive commands, lock edits to one directory, or both at once. |
The pack also has design skills (design-consultation, design-shotgun, design-html, design-review), browser skills (browse, scrape, pair-agent), docs and PDF skills, iOS testing skills, a second-opinion skill for Codex, and standalone command-line tools such as gstack-egress and gstack-model-benchmark. The count includes the root router skill.
What gstack runs on your machine
| Hooks | Yes. Setup registers a default-on Stop hook (gstack-timeline-stop) in ~/.claude/settings.json that closes dangling timeline entries and can be turned off with ./setup --no-timeline-stop-hook. The README also names a session-start auto-update hook and AskUserQuestion hooks that the uninstaller removes. The verify-gate Stop hook is opt-in. |
|---|---|
| Bundled scripts | Yes. ./setup builds a bundled Chromium through Playwright, and the repo ships standalone command-line binaries such as gstack-egress, gstack-evidence and gstack-model-benchmark. |
| Network calls | Yes. An update check runs at session start, throttled to once an hour. Usage telemetry to Supabase is opt-in and off by default. Every off-machine send writes a hash-chained receipt to ~/.gstack/security/egress.jsonl before it goes out. /design-shotgun generates mockups with GPT Image. |
| API keys needed | The README names GSTACK_ANTHROPIC_API_KEY and GSTACK_OPENAI_API_KEY for paid evals and gbrain embeddings when running in Conductor. Outside reviews need the Codex or Claude Code CLI installed and signed in. |
| Tool permissions | The root router skill allows Bash, Read and AskUserQuestion. |
These are facts read from the repo, not a security rating. Read the files before you install any skill.
How much context gstack uses
| All 60 skills | 349,077 words across every SKILL.md file |
|---|---|
| Largest skill | design-review, 18,706 words |
| Loaded at start | Only each skill's name and description. The full text loads when a task needs that skill. |
Word counts are measured from the repo every day. Reference files a skill loads on demand are not counted.
How gstack works
gstack gives each stage of building software to a named role. /office-hours acts as a product interrogator, /plan-eng-review as an engineering manager, /review as a staff engineer, /qa as a QA lead who opens a real browser, /cso as a security officer and /ship as a release engineer. Each skill reads what the earlier one wrote, so a design doc from /office-hours feeds /plan-ceo-review, and a test plan from /plan-eng-review is picked up by /qa.
Browser skills drive the Aside browser on macOS when it is open and fall back to a Chromium that setup builds. The README describes defenses against prompt injection in pages the agent reads, including a local classifier that runs on your machine. The author says he runs 10 to 15 parallel sprints with Conductor.
A good fit for
- Solo founders and small teams that want review, QA and release steps run by the agent on every change
- People who want the agent to test in a real browser and write a regression test for each bug it finds
- Teams that want the same skills on every machine, using team mode to keep installs in step
- Developers who want a second opinion from another model, with Claude Code and Codex reviewing each other
Skip it if
- Anyone who wants a few light skills, because the pack is large, installs its own binaries and expects Bun
- Setups that block session hooks or outbound requests, since it adds hooks and checks for updates at session start
- Quick one-file edits, where a planning and review pipeline adds more steps than the change needs
Is gstack still maintained?
| Last commit | , 11 hours ago |
|---|---|
| Stars gained in 7 days | Shown after 7 days of tracking |
| Stars gained in 30 days | Shown after 30 days of tracking |
| Open issues and pull requests | 830 |
| Forks | 20,064 |
Tools gstack works with
Questions about gstack
Does gstack work outside Claude Code?
Yes. The README says setup supports 10 agents and gives a --host flag for Codex, OpenCode, Cursor, Factory Droid, Kiro, Slate, OpenClaw and Hermes. Any agent that reads a rules file can use the 2 KB digest in agents-digest/gstack-AGENTS.md instead.
Is gstack free?
Yes. It is MIT licensed and the README says there is no premium tier. NOTICE.md lists some files derived from Apache-2.0 works.
Does gstack send my data anywhere?
Telemetry is off unless you opt in, and the README says it sends only the skill name, duration, success or failure, gstack version and OS. Every off-machine send, telemetry included, is logged to a local receipt file first. Run gstack-config set telemetry off to turn it off.
How do I remove it?
Run ~/.claude/skills/gstack/bin/gstack-uninstall. It removes skills, symlinks, state, browse daemons and its hook entries. It does not edit CLAUDE.md, so delete the gstack sections yourself.
Can it test things that are not web pages?
Yes. The README says /qa and /qa-only work on CLIs, APIs, jobs and webhooks using a documented local fixture, and name the tools and write permissions first.