72 agents. 3 stops are yours.
great_cto runs your feature through a team of specialist AI agents. 9 of them work on every feature. The rest join only when your project needs them. 3 decisions always wait for you.
9 agents on the main path. 3 stops are yours.
A feature passes through these 9 in order. Each hands its result to the next; 3 times the work stops and waits for your decision.
-
1Product owner product-ownerTurns a raw idea into a product brief: the problem, the options, a recommendation.So you decide what gets built before anyone designs or codes it.Then you decide: what gets built
-
2Architect architectDesigns how the feature will be built: components, key decisions, a cost estimate.So the hard choices are made once, on paper, instead of being discovered in code.Then you decide: how it is built
-
3Breaks the design into tasks with dependencies, an order and a timeline.So work can run in parallel, and you see the plan before it starts.
-
4Developer senior-devWrites the code for each task, tests first.This is where the feature actually gets built.
-
5Code reviewer code-reviewerReads every change for bugs, security, speed and clarity, and files what it finds.So the code is checked by someone who did not write it.
-
6QA engineer qa-engineerTests the finished feature the way its kind of product demands, and writes a report.So you learn what breaks before your users do.
-
7Security officer security-officerAudits the feature for security holes and writes a report.Nothing ships until the security check is done.Then you decide: whether it ships
-
8DevOps devopsDeploys the release you approved.So shipping is a repeatable step, not a manual ritual.
-
9Production support l3-supportWatches logs, triages incidents and opens tasks; for an outage, investigates and writes the postmortem.So a problem in production gets an owner right away.
-
What gets builtYou approve the product brief. gate:product
-
How it is builtYou approve the design. gate:arch
-
Whether it shipsYou approve the release. gate:ship
All 9 gates, and how to make it stop more or less often
-
gate:productWhat gets built — stops by default
-
gate:archHow it is built — stops by default
-
gate:planIn what order — stops at: expert, step-by-step
-
gate:codeIs the code good — stops at: strict, expert, step-by-step
-
gate:shipWhether it ships — stops by default
-
gate:qaDoes it work — stops at: expert, step-by-step
-
gate:securityIs it secure — always for regulated
-
gate:complianceDoes it meet the rules — always for regulated
-
gate:importMay outside code come in — never switched off
| Level | gate:product | gate:arch | gate:plan | gate:code | gate:ship | gate:qa | gate:security | gate:compliance | gate:import |
|---|---|---|---|---|---|---|---|---|---|
| auto | — | — | — | — | regulated only | — | regulated only | regulated only | stops |
| product-only | stops | — | — | — | stops | — | regulated only | regulated only | stops |
| ship-only | — | — | — | — | stops | — | regulated only | regulated only | stops |
| gates-only (default) | stops | stops | — | — | stops | — | regulated only | regulated only | stops |
| strict | — | stops | — | stops | stops | — | regulated only | regulated only | stops |
| expert | stops | stops | stops | stops | stops | stops | stops | regulated only | stops |
| step-by-step | stops | stops | stops | stops | stops | stops | stops | regulated only | stops |
Pick your project. See who joins.
Most of the 72 agents never touch your project. Choose what you build and where your users are; the list below is the team great_cto would actually assemble — computed by the same function great-cto init runs.
Fintech · EU
7 agents work on it · it waits for you 6 times · 2 reviewer sign-offs
| Agent | What it does | Why it joins |
|---|---|---|
| Architect architect | Designs how the feature will be built: components, key decisions, a cost estimate. | every project of this kind |
| Design advisor design-advisor | Picks the design system, lists the screens and components, writes wireframes in text, sets accessibility rules. | every project of this kind |
| EU privacy reviewer gdpr-reviewer | Checks the plan against GDPR, the EU AI Act and NIS2. | because of: eu |
| Payments reviewer pci-reviewer | Checks how card data flows and how much of the system falls under PCI DSS. | every project of this kind |
| QA engineer qa-engineer | Tests the finished feature the way its kind of product demands, and writes a report. | every project of this kind |
| Regulated-industry reviewer regulated-reviewer | Checks fintech and other regulated systems against rules such as SOX, DORA and NIS2. | every project of this kind |
| Developer senior-dev | Writes the code for each task, tests first. | every project of this kind |
- What gets builtgate:product
- How it is builtgate:arch
- May outside code come ingate:import
- Is it securegate:security
- Does it meet the rulesgate:compliance
- Whether it shipsgate:ship
More: sign-offs, agents that may also join, file rules
gate:eu-ai-act-classification · gate:gdpr-dpia
accounting-reviewer · db-migration-reviewer · dpdpa-reviewer · tax-reviewer · us-ai-reviewer · us-privacy-reviewer
db-migration-reviewer — db/migrations/0007_add_index.sql · prisma/migrations/20260801_init/migration.sql
pci-reviewer — src/billing/stripe-webhook.ts · api/refund.ts
accounting-reviewer — src/journal-entry.ts · lib/general-ledger.ts
tax-reviewer — src/form-8879.ts · lib/tax-prep.py
regulated-reviewer — config/dora-ict-register.yaml · src/nis2-controls.ts
53 other agents are not in this team.
Healthcare · US-CA
7 agents work on it · it waits for you 6 times · 2 reviewer sign-offs
| Agent | What it does | Why it joins |
|---|---|---|
| Architect architect | Designs how the feature will be built: components, key decisions, a cost estimate. | every project of this kind |
| Design advisor design-advisor | Picks the design system, lists the screens and components, writes wireframes in text, sets accessibility rules. | every project of this kind |
| Healthcare reviewer healthcare-reviewer | Checks how patient data is stored, accessed and logged against HIPAA. | every project of this kind |
| QA engineer qa-engineer | Tests the finished feature the way its kind of product demands, and writes a report. | every project of this kind |
| Security officer security-officer | Audits the feature for security holes and writes a report. | every project of this kind |
| Developer senior-dev | Writes the code for each task, tests first. | every project of this kind |
| US privacy reviewer us-privacy-reviewer | Checks the plan against CCPA and other US state privacy laws, COPPA and FTC rules. | because of: us-ca |
- What gets builtgate:product
- How it is builtgate:arch
- May outside code come ingate:import
- Is it securegate:security
- Does it meet the rulesgate:compliance
- Whether it shipsgate:ship
More: sign-offs, agents that may also join, file rules
gate:ccpa-dsrp · gate:us-state-privacy-matrix
gdpr-reviewer · rcm-reviewer · us-ai-reviewer
security-officer — src/auth/session.ts · api/oauth-callback.ts
healthcare-reviewer — src/hipaa-audit.ts · integrations/fhir/client.ts
rcm-reviewer — src/cms-1500.ts · lib/prior-auth.ts
57 other agents are not in this team.
Booking · routing + mobile
13 agents work on it · it waits for you 4 times · 0 reviewer sign-offs
| Agent | What it does | Why it joins |
|---|---|---|
| App scaffolder app-scaffolder | Sets up a working, deployable base app: framework, database, sign-in, CI. | every project of this kind |
| Architect architect | Designs how the feature will be built: components, key decisions, a cost estimate. | every project of this kind |
| Auth engineer auth-engineer | Designs sign-in, sessions, roles and the separation between customers’ data. | every project of this kind |
| Design advisor design-advisor | Picks the design system, lists the screens and components, writes wireframes in text, sets accessibility rules. | every project of this kind |
| Routing engineer geo-routing-engineer | Designs geocoding, route optimization and ETAs, and keeps the cost of map API calls in check. | because of: routing |
| Integrations engineer integrations-engineer | Designs connections to third-party services: authorization, webhooks, retries, rate limits. | every project of this kind |
| Data import engineer migration-import-engineer | Designs how a customer’s data moves in from their old tool: mapping, validation, dry run, rollback. | every project of this kind |
| Mobile app builder mobile-app-builder | Builds the React Native app: offline sync, camera, location, push notifications. | because of: mobile |
| Payments reviewer pci-reviewer | Checks how card data flows and how much of the system falls under PCI DSS. | every project of this kind |
| QA engineer qa-engineer | Tests the finished feature the way its kind of product demands, and writes a report. | every project of this kind |
| Security officer security-officer | Audits the feature for security holes and writes a report. | every project of this kind |
| Developer senior-dev | Writes the code for each task, tests first. | every project of this kind |
| Billing engineer subscription-billing-engineer | Designs plans, usage metering, proration, failed-payment handling and tax. | every project of this kind |
- What gets builtgate:product
- How it is builtgate:arch
- May outside code come ingate:import
- Whether it shipsgate:ship
More: sign-offs, agents that may also join, file rules
none declared for this selection
pci-reviewer — src/billing/stripe-webhook.ts · api/refund.ts
security-officer — src/auth/session.ts · api/oauth-callback.ts
53 other agents are not in this team.
The rules behind this — four tables
| Archetype | Adds | Agents |
|---|---|---|
| AI agent | ai-eval-engineer · ai-prompt-architect · ai-security-reviewer | 6 |
| AI system | ai-eval-engineer · ai-prompt-architect · ai-security-reviewer | 6 |
| Booking / scheduling | app-scaffolder · auth-engineer · design-advisor · integrations-engineer · migration-import-engineer · pci-reviewer · subscription-billing-engineer | 11 |
| Browser extension | design-advisor · web-store-reviewer | 5 |
| CLI tool | cli-reviewer | 4 |
| CMS | cms-reviewer · design-advisor | 5 |
| E-commerce | design-advisor · pci-reviewer | 6 |
| Content / media platform | app-scaffolder · auth-engineer · design-advisor · integrations-engineer · media-pipeline-engineer · migration-import-engineer · pci-reviewer · subscription-billing-engineer | 12 |
| CRM | app-scaffolder · auth-engineer · design-advisor · integrations-engineer · migration-import-engineer · subscription-billing-engineer | 10 |
| Dashboard / analytics | app-scaffolder · auth-engineer · connector-builder · design-advisor · integrations-engineer · migration-import-engineer · subscription-billing-engineer | 11 |
| Data platform | data-platform-reviewer | 4 |
| defense-govcon | cmmc-reviewer · gov-reviewer | 6 |
| Developer tool | devtools-reviewer | 4 |
| EdTech | design-advisor · edtech-reviewer | 5 |
| Enterprise SaaS | design-advisor · enterprise-saas-reviewer | 5 |
| Fintech | design-advisor · pci-reviewer · regulated-reviewer | 6 |
| Game | design-advisor · game-reviewer | 5 |
| Government | design-advisor · gov-reviewer | 6 |
| New project | regulated floor only | 3 |
| Healthcare | design-advisor · healthcare-reviewer | 6 |
| Infrastructure | infra-reviewer | 4 |
| Insurance | design-advisor · insurance-reviewer · regulated-reviewer | 6 |
| IoT / embedded | firmware-reviewer | 4 |
| Legal / Law firm | design-advisor · legal-reviewer | 6 |
| Library / SDK | library-reviewer | 4 |
| Marketplace | design-advisor · marketplace-reviewer · pci-reviewer | 6 |
| Marketplace | app-scaffolder · auth-engineer · design-advisor · integrations-engineer · migration-import-engineer · pci-reviewer · subscription-billing-engineer | 11 |
| MLOps pipeline | ai-security-reviewer · mlops-reviewer | 5 |
| Mobile app | design-advisor · mobile-store-reviewer | 6 |
| Regulated system | regulated-reviewer | 4 |
| Streaming system | streaming-reviewer | 4 |
| Vertical SaaS | app-scaffolder · auth-engineer · design-advisor · integrations-engineer · migration-import-engineer · subscription-billing-engineer | 10 |
| Web service | design-advisor | 5 |
| Web3 / DeFi | design-advisor · oracle-reviewer · smart-contract-auditor | 6 |
| Jurisdiction | Adds | Agents |
|---|---|---|
| EU · GDPR | gdpr-reviewer | 1 |
| US · FTC Act § 5 | us-privacy-reviewer | 1 |
| US-CA · CCPA / CPRA | us-privacy-reviewer | 1 |
| UK · UK GDPR | gdpr-reviewer | 1 |
| IN · DPDPA 2023 | dpdpa-reviewer | 1 |
| BR · LGPD | gdpr-reviewer | 1 |
| AU · Privacy Act 1988 | us-privacy-reviewer | 1 |
| SG · PDPA 2012 | us-privacy-reviewer | 1 |
| CA · PIPEDA | us-privacy-reviewer | 1 |
| JP · APPI 2022 | us-privacy-reviewer | 1 |
| CN · PIPL 2021 | gdpr-reviewer | 1 |
| KR · PIPA | us-privacy-reviewer | 1 |
| Signal | Adds | Agents |
|---|---|---|
| Voice / telephony | voice-ai-reviewer | 1 |
| Hiring | hr-ai-reviewer | 1 |
| Public API | api-platform-reviewer | 1 |
| Tracking pixels | adtech-privacy-reviewer · us-privacy-reviewer | 2 |
| AI governance | us-ai-reviewer | 1 |
| Routing / maps (archetype-gated) | geo-routing-engineer | 1 |
| Mobile / field crews (archetype-gated) | mobile-app-builder | 1 |
| Reviewer | Example paths |
|---|---|
| db-migration-reviewer | db/migrations/0007_add_index.sql · prisma/migrations/20260801_init/migration.sql |
| pci-reviewer | src/billing/stripe-webhook.ts · api/refund.ts |
| security-officer | src/auth/session.ts · api/oauth-callback.ts |
| ai-security-reviewer | prompts/system.txt · src/rag/retriever.ts |
| ai-eval-engineer | tests/eval/runner.mjs · data/golden_set.jsonl |
| mobile-store-reviewer | fastlane/Fastfile · ios/iap-manager.swift |
| api-platform-reviewer | api/openapi.yaml · src/webhooks.ts |
| voice-ai-reviewer | integrations/twilio-handler.ts · src/ivr/menu.ts |
| hr-ai-reviewer | src/hiring/rank.ts · lib/resume_screen.py |
| edtech-reviewer | src/coppa-consent.ts · lib/student_data.py |
| gov-reviewer | config/fedramp-boundary.yaml · src/fisma-controls.ts |
| game-reviewer | src/loot_box.ts · config/esrb.json |
| enterprise-saas-reviewer | src/scim/provision.ts · db/row-level-security.sql |
| procurement-reviewer | src/purchase-order.ts · lib/punchout.ts |
| accounting-reviewer | src/journal-entry.ts · lib/general-ledger.ts |
| msp-reviewer | src/rmm-agent.ts · lib/credential-vault.ts |
| tax-reviewer | src/form-8879.ts · lib/tax-prep.py |
| insurance-reviewer | src/naic-filing.ts · lib/actuarial-model.py |
| legal-reviewer | src/iolta-ledger.ts · lib/conflict-check.ts |
| healthcare-reviewer | src/hipaa-audit.ts · integrations/fhir/client.ts |
| rcm-reviewer | src/cms-1500.ts · lib/prior-auth.ts |
| regulated-reviewer | config/dora-ict-register.yaml · src/nis2-controls.ts |
| infra-reviewer | infra/main.tf · helm/values.yaml |
| web-store-reviewer | extension/manifest.json · src/mv3-worker.ts |
| performance-engineer | tests/k6/load.js · src/perf-budget.ts |
| library-reviewer | Cargo.toml · pyproject.toml |
| cli-reviewer | bin/great-cto · src/cli/main.ts |
| mcp-server-reviewer | mcp-servers/llm-router/server.py · src/mcp.ts |
Every agent: what it does, and why it is there.
Open a card for when it runs; “Technical details” inside shows what it may touch and what it can stop.
Main path (9)
The nine that work on every feature, in this order.
Product owner product-owner Turns a raw idea into a product brief: the problem, the options, a recommendation.
Why it is thereSo you decide what gets built before anyone designs or codes it.
When it runsMain path · stage 01
Technical details
- Model
- claude-opus-5
- Shell
- none
- Web
- yes
- Spawns agents
- yes
- Skills
- brainstorming · writing-plans [external · superpowers]
- Produces
- brief
- Blocks
- next step waits for your approval: gate:product
on NO_BUILD → the run stops - Example
log-verdict.sh product-owner <APPROVED|NO_BUILD> auto feature=<slug> brief=docs/product/BRIEF-<slug>.md- Source
- agents/product-owner.md ↗
- Link
- /team.html#product-owner
Architect architect Designs how the feature will be built: components, key decisions, a cost estimate.
Why it is thereSo the hard choices are made once, on paper, instead of being discovered in code.
When it runsMain path · stage 02
Technical details
- Model
- claude-opus-5
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- decision-eval · writing-plans [external · superpowers] · requesting-code-review [external · superpowers] · skeptical-triage · done-blocked · well-architected · discovery · migration-ready-schema · stack-baseline
- Produces
- arch
- Blocks
- next step waits for your approval: gate:arch
- Example
log-verdict.sh architect APPROVED auto- Source
- agents/architect.md ↗
- Link
- /team.html#architect
Project manager pm Breaks the design into tasks with dependencies, an order and a timeline.
Why it is thereSo work can run in parallel, and you see the plan before it starts.
When it runsMain path · stage 03
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- pm-planning · pre-mortem · cost-model · anti-patterns
- Produces
- plan · briefs
- Blocks
- next step waits for your approval: gate:plan
- Example
log-verdict.sh pm PLAN_READY auto- Source
- agents/pm.md ↗
- Link
- /team.html#pm
Developer senior-dev Writes the code for each task, tests first.
Why it is thereThis is where the feature actually gets built.
When it runsMain path · stage 04
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- test-driven-development [external · superpowers] · requesting-code-review [external · superpowers] · done-blocked · stack-baseline · signing-preflight
- Produces
- receipt
- Blocks
- next step waits for your approval: gate:code
on SPEC-OBJECTION → pm
stops the chain on BLOCKED - Example
log-verdict.sh senior-dev <TASK_DONE|BLOCKED> auto task=<bd-id> pr=#<n> feature=<slug>- Source
- agents/senior-dev.md ↗
- Link
- /team.html#senior-dev
Code reviewer code-reviewer Reads every change for bugs, security, speed and clarity, and files what it finds.
Why it is thereSo the code is checked by someone who did not write it.
When it runsMain path · stage 05
Technical details
- Model
- haiku
- Shell
- full
- Web
- no
- Spawns agents
- no
- Skills
- not declared
- Produces
- receipt
- Blocks
- next step waits for your approval: gate:ship
stops the chain on BLOCKED - Example
log-verdict.sh code-reviewer <APPROVED|BLOCKED> auto feature=<slug> review=docs/reviews/REVIEW-<slug>.md need=<implementer|decision> finding=<id>- Source
- agents/code-reviewer.md ↗
- Link
- /team.html#code-reviewer
QA engineer qa-engineer Tests the finished feature the way its kind of product demands, and writes a report.
Why it is thereSo you learn what breaks before your users do.
When it runsMain path · stage 06
Technical details
- Model
- haiku
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- skeptical-triage · done-blocked · prose-style · test-strategy
- Produces
- report
- Blocks
- next step waits for your approval: gate:qa · gate:ship
stops the chain on FAIL - Example
log-verdict.sh qa-engineer <PASS|FAIL> auto- Source
- agents/qa-engineer.md ↗
- Link
- /team.html#qa-engineer
Security officer security-officer Audits the feature for security holes and writes a report.
Why it is thereNothing ships until the security check is done.
When it runsMain path · stage 07
suggested when files change: src/auth/session.ts · api/oauth-callback.ts
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- skeptical-triage · done-blocked · prose-style · secrets-rotation
- Produces
- report
- Blocks
- next step waits for your approval: gate:security · gate:compliance · gate:ship
stops the chain on BLOCKED - Example
log-verdict.sh security-officer <APPROVED|BLOCKED> auto- Source
- agents/security-officer.md ↗
- Link
- /team.html#security-officer
DevOps devops Deploys the release you approved.
Why it is thereSo shipping is a repeatable step, not a manual ritual.
When it runsMain path · stage 08
Technical details
- Model
- haiku
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- done-blocked · observability-baseline · deploy-landed · signing-preflight
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh devops <DEPLOYED|BLOCKED> auto env=<staging|prod> version=<v> feature=<slug>- Source
- agents/devops.md ↗
- Link
- /team.html#devops
Production support l3-support Watches logs, triages incidents and opens tasks; for an outage, investigates and writes the postmortem.
Why it is thereSo a problem in production gets an owner right away.
When it runsMain path · stage 09
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- systematic-debugging [external · superpowers] · done-blocked · observability-baseline · deploy-landed · secrets-rotation
- Produces
- not declared
- Blocks
- on INCIDENT → senior-dev
- Example
log-verdict.sh l3-support <OK|INCIDENT> auto window=<min>m pm=<postmortem-path-if-any>- Source
- agents/l3-support.md ↗
- Link
- /team.html#l3-support
Prototyper (2)
Shape the idea before code: compare options, design the interface.
Decision scorer decision-scorer Scores two or more design options against your project’s criteria and recommends one.
Why it is thereSo a choice between options comes with reasons, not a gut feeling.
When it runswith architect
Technical details
- Model
- claude-sonnet-5
- Shell
- none
- Web
- no
- Spawns agents
- no
- Skills
- not declared
- Produces
- not declared
- Blocks
- not declared
- Example
log-verdict.sh decision-scorer <DONE|SKIPPED> auto decision=docs/decisions/DECISION-<slug>-<date>.md- Source
- agents/decision-scorer.md ↗
- Link
- /team.html#decision-scorer
Design advisor design-advisor Picks the design system, lists the screens and components, writes wireframes in text, sets accessibility rules.
Why it is thereSo the interface is planned before it is coded.
When it runsbefore senior-dev
Technical details
- Model
- claude-opus-5
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- ui-ux-pro-max · anydesign · committed-aesthetic · aesthetic-instrument · writing-plans [external · superpowers] · decision-eval · skeptical-triage · done-blocked
- Produces
- design
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh design-advisor <DONE|BLOCKED> auto design=docs/design/DESIGN-<slug>.md- Source
- agents/design-advisor.md ↗
- Link
- /team.html#design-advisor
Builder (11)
Specialists who build one hard part, so the developer does not reinvent it. They join when your product needs that part.
AI eval engineer ai-eval-engineer Builds the tests that measure an AI feature: right answers, refusals, prompt injection, cost.
Why it is thereSo a prompt or model change that makes things worse gets caught.
When it runsbefore senior-dev
suggested when files change: tests/eval/runner.mjs · data/golden_set.jsonl
Technical details
- Model
- haiku
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · test-driven-development [external · superpowers] · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh ai-eval-engineer <PASS|BLOCKED> auto evals=tests/eval/ feature=<slug>- Source
- agents/ai-eval-engineer.md ↗
- Link
- /team.html#ai-eval-engineer
Prompt architect ai-prompt-architect Designs and versions the system prompts, with tests against jailbreaks.
Why it is thereSo prompts are reviewed and tracked the way code is.
When it runsbefore senior-dev via ai-eval-engineer
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh ai-prompt-architect <APPROVED|BLOCKED> auto adr=docs/adr/ADR-<NN>-PROMPT-<name>.md- Source
- agents/ai-prompt-architect.md ↗
- Link
- /team.html#ai-prompt-architect
App scaffolder app-scaffolder Sets up a working, deployable base app: framework, database, sign-in, CI.
Why it is thereSo the developer builds features instead of boilerplate.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- stack-baseline · migration-ready-schema · observability-baseline · test-driven-development [external · superpowers] · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh app-scaffolder <DONE|BLOCKED> auto scaffold=docs/SCAFFOLD-<slug>.md- Source
- agents/app-scaffolder.md ↗
- Link
- /team.html#app-scaffolder
Auth engineer auth-engineer Designs sign-in, sessions, roles and the separation between customers’ data.
Why it is thereSo “who can see what” is decided once, and correctly.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- stack-baseline · migration-ready-schema · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh auth-engineer <DONE|BLOCKED> auto auth=docs/auth/AUTH-<slug>.md- Source
- agents/auth-engineer.md ↗
- Link
- /team.html#auth-engineer
Connector builder connector-builder Designs how data is pulled in from sources like Stripe or Google Analytics: sync, backfill, freshness.
Why it is thereSo dashboards show complete, current data.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- migration-ready-schema · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh connector-builder <DONE|BLOCKED> auto contract=docs/connectors/CONNECT-<slug>.md- Source
- agents/connector-builder.md ↗
- Link
- /team.html#connector-builder
Routing engineer geo-routing-engineer Designs geocoding, route optimization and ETAs, and keeps the cost of map API calls in check.
Why it is thereFor products with maps, dispatch or delivery routes.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- cost-model · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh geo-routing-engineer <DONE|BLOCKED> auto contract=docs/routing/ROUTE-<slug>.md- Source
- agents/geo-routing-engineer.md ↗
- Link
- /team.html#geo-routing-engineer
Integrations engineer integrations-engineer Designs connections to third-party services: authorization, webhooks, retries, rate limits.
Why it is thereSo payments, messages and calendars keep working when the other side hiccups.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- lifecycle-messaging · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh integrations-engineer <DONE|BLOCKED> auto contract=docs/integrations/INTEGRATE-<slug>.md- Source
- agents/integrations-engineer.md ↗
- Link
- /team.html#integrations-engineer
Media engineer media-pipeline-engineer Designs upload, video transcoding, storage and delivery of media.
Why it is thereFor products built on video or images.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- cost-model · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh media-pipeline-engineer <DONE|BLOCKED> auto contract=docs/media/MEDIA-<slug>.md- Source
- agents/media-pipeline-engineer.md ↗
- Link
- /team.html#media-pipeline-engineer
Data import engineer migration-import-engineer Designs how a customer’s data moves in from their old tool: mapping, validation, dry run, rollback.
Why it is thereSo a new customer can switch to you without losing data.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- vertical-onboarding · migration-ready-schema · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- next step waits for your approval: gate:import
stops the chain on BLOCKED - Example
log-verdict.sh migration-import-engineer <DONE|BLOCKED> auto contract=docs/data-import/IMPORT-<slug>.md- Source
- agents/migration-import-engineer.md ↗
- Link
- /team.html#migration-import-engineer
Mobile app builder mobile-app-builder Builds the React Native app: offline sync, camera, location, push notifications.
Why it is thereFor products whose users work in the field, on a phone.
When it runsbefore code-reviewer
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- test-driven-development [external · superpowers] · requesting-code-review [external · superpowers] · done-blocked · ui-ux-pro-max · signing-preflight
- Produces
- not declared
- Blocks
- next step waits for your approval: gate:code
stops the chain on BLOCKED - Example
log-verdict.sh mobile-app-builder <DONE|BLOCKED> auto tasks=<bd-ids> feature=<slug>- Source
- agents/mobile-app-builder.md ↗
- Link
- /team.html#mobile-app-builder
Billing engineer subscription-billing-engineer Designs plans, usage metering, proration, failed-payment handling and tax.
Why it is thereSo you get paid, and correctly.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- cost-model · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh subscription-billing-engineer <DONE|BLOCKED> auto contract=docs/billing/BILLING-<slug>.md- Source
- agents/subscription-billing-engineer.md ↗
- Link
- /team.html#subscription-billing-engineer
Sweeper (1)
Checks the shipped product the way a user would.
End-to-end tester e2e-test-engineer Writes browser tests for the key user journey and replays them against the live site after each deploy.
Why it is thereProof that the shipped product works for a real user.
When it runsbefore devops
Technical details
- Model
- haiku
- Shell
- full
- Web
- no
- Spawns agents
- no
- Skills
- stack-baseline
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh e2e-test-engineer <PASSED|BLOCKED> auto feature=<slug> live=<url> e2e=docs/e2e/PLAYWRIGHT-<slug>.md- Source
- agents/e2e-test-engineer.md ↗
- Link
- /team.html#e2e-test-engineer
Grower (2)
Make a working product faster, and help it grow.
Growth engineer growth-engineer Defines the key metric, instruments the funnel, designs growth loops and experiments.
Why it is thereTo get from “it works” to “it grows”.
When it runsbefore devops
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh growth-engineer <READY|BLOCKED> auto growth=docs/growth/GROWTH-<slug>.md- Source
- agents/growth-engineer.md ↗
- Link
- /team.html#growth-engineer
Performance engineer performance-engineer Sets speed targets, runs load tests and finds what is slow.
Why it is thereSo the product stays fast under real traffic.
When it runsbefore qa-engineer
suggested when files change: tests/k6/load.js · src/perf-budget.ts
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- prose-style
- Produces
- not declared
- Blocks
- on REGRESSION → senior-dev
- Example
log-verdict.sh performance-engineer <PASS|REGRESSION> auto perf=docs/performance/PERF-<slug>.md- Source
- agents/performance-engineer.md ↗
- Link
- /team.html#performance-engineer
Maintainer (2)
Keep it running: fix red builds, set up hosting.
CI fixer ci-resolver When a build is red, names the cause of each failure and lands a minimal fix. Never skips a check.
Why it is thereSo a red build gets fixed, not ignored.
When it runsaround the pipeline
Technical details
- Model
- sonnet
- Shell
- full
- Web
- no
- Spawns agents
- no
- Skills
- done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh ci-resolver <PASS|BLOCKED> auto checks=<n> fixed=<n> need=<implementer|decision>- Source
- agents/ci-resolver.md ↗
- Link
- /team.html#ci-resolver
Infrastructure provisioner infra-provisioner Sets up the database, hosting, secrets and domain — after showing you the plan and its cost.
Why it is thereSo the product reaches a live URL.
When it runsbefore devops via e2e-test-engineer
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- stack-baseline · cost-model · prose-style · done-blocked · observability-baseline · deploy-landed
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh infra-provisioner <DONE|BLOCKED> auto provision=docs/infra/PROVISION-<slug>.md- Source
- agents/infra-provisioner.md ↗
- Link
- /team.html#infra-provisioner
Reviewers & Safety (40)
Experts who check the plan against the rules before code is written. Only the ones your project needs join.
Privacy and regional law 4
Join by where your users are.
EU privacy reviewer gdpr-reviewer Checks the plan against GDPR, the EU AI Act and NIS2.
Why it is thereFor products with users in the EU, the UK or Brazil.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh gdpr-reviewer <APPROVED|BLOCKED> auto- Source
- agents/gdpr-reviewer.md ↗
- Link
- /team.html#gdpr-reviewer
US privacy reviewer us-privacy-reviewer Checks the plan against CCPA and other US state privacy laws, COPPA and FTC rules.
Why it is thereFor products with users in the United States.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh us-privacy-reviewer <APPROVED|BLOCKED> auto- Source
- agents/us-privacy-reviewer.md ↗
- Link
- /team.html#us-privacy-reviewer
India privacy reviewer dpdpa-reviewer Checks the plan against India’s DPDPA 2023 and the central bank’s data rules.
Why it is thereFor products with users in India.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh dpdpa-reviewer <APPROVED|BLOCKED> auto- Source
- agents/dpdpa-reviewer.md ↗
- Link
- /team.html#dpdpa-reviewer
Ad-tracking privacy reviewer adtech-privacy-reviewer Checks tracking pixels and analytics against US consent rules and privacy-lawsuit risk.
Why it is thereTracking without consent is a common source of lawsuits.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh adtech-privacy-reviewer <APPROVED|BLOCKED> auto- Source
- agents/adtech-privacy-reviewer.md ↗
- Link
- /team.html#adtech-privacy-reviewer
Industry rules 18
Join by the industry your product is in.
Payments reviewer pci-reviewer Checks how card data flows and how much of the system falls under PCI DSS.
Why it is thereHandling card numbers carelessly puts the whole system under a PCI audit.
When it runsbefore senior-dev
suggested when files change: src/billing/stripe-webhook.ts · api/refund.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh pci-reviewer <APPROVED|BLOCKED> auto- Source
- agents/pci-reviewer.md ↗
- Link
- /team.html#pci-reviewer
Regulated-industry reviewer regulated-reviewer Checks fintech and other regulated systems against rules such as SOX, DORA and NIS2.
Why it is thereSo the controls a regulator will ask about exist from the start.
When it runsbefore senior-dev
suggested when files change: config/dora-ict-register.yaml · src/nis2-controls.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh regulated-reviewer <APPROVED|BLOCKED> auto- Source
- agents/regulated-reviewer.md ↗
- Link
- /team.html#regulated-reviewer
Accounting reviewer accounting-reviewer Checks the design of ledger, bookkeeping and financial-close features.
Why it is thereSo the books your product keeps add up.
When it runsbefore senior-dev
suggested when files change: src/journal-entry.ts · lib/general-ledger.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh accounting-reviewer <APPROVED|BLOCKED> auto- Source
- agents/accounting-reviewer.md ↗
- Link
- /team.html#accounting-reviewer
Tax reviewer tax-reviewer Checks tax preparation and filing features.
Why it is thereA wrong filing is your customer’s penalty.
When it runsbefore senior-dev
suggested when files change: src/form-8879.ts · lib/tax-prep.py
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh tax-reviewer <APPROVED|BLOCKED> auto- Source
- agents/tax-reviewer.md ↗
- Link
- /team.html#tax-reviewer
Healthcare reviewer healthcare-reviewer Checks how patient data is stored, accessed and logged against HIPAA.
Why it is thereMistakes with patient data carry heavy penalties.
When it runsbefore senior-dev
suggested when files change: src/hipaa-audit.ts · integrations/fhir/client.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked · discovery
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh healthcare-reviewer <APPROVED|BLOCKED> auto- Source
- agents/healthcare-reviewer.md ↗
- Link
- /team.html#healthcare-reviewer
Medical billing reviewer rcm-reviewer Checks healthcare billing and insurance-claims features.
Why it is thereBilling errors in healthcare become denied claims and compliance findings.
When it runsbefore senior-dev
suggested when files change: src/cms-1500.ts · lib/prior-auth.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh rcm-reviewer <APPROVED|BLOCKED> auto- Source
- agents/rcm-reviewer.md ↗
- Link
- /team.html#rcm-reviewer
Insurance reviewer insurance-reviewer Checks insurance products against US state filing rules and tests for unfair discrimination in pricing.
Why it is thereInsurance pricing and AI use are examined by state regulators.
When it runsbefore senior-dev
suggested when files change: src/naic-filing.ts · lib/actuarial-model.py
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh insurance-reviewer <APPROVED|BLOCKED> auto- Source
- agents/insurance-reviewer.md ↗
- Link
- /team.html#insurance-reviewer
Legal-tech reviewer legal-reviewer Checks products built for law firms and legal services.
Why it is thereA law firm’s data comes with professional duties of confidentiality.
When it runsbefore senior-dev
suggested when files change: src/iolta-ledger.ts · lib/conflict-check.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh legal-reviewer <APPROVED|BLOCKED> auto- Source
- agents/legal-reviewer.md ↗
- Link
- /team.html#legal-reviewer
Government reviewer gov-reviewer Checks public-sector products against government security requirements such as FedRAMP.
Why it is thereFor products sold to government agencies.
When it runsbefore senior-dev
suggested when files change: config/fedramp-boundary.yaml · src/fisma-controls.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh gov-reviewer <APPROVED|BLOCKED> auto- Source
- agents/gov-reviewer.md ↗
- Link
- /team.html#gov-reviewer
Defense contractor reviewer cmmc-reviewer Checks the plan against CMMC, the security standard for US defense contractors.
Why it is thereFor products used in US defense contracts.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh cmmc-reviewer <APPROVED|BLOCKED> auto- Source
- agents/cmmc-reviewer.md ↗
- Link
- /team.html#cmmc-reviewer
EdTech reviewer edtech-reviewer Checks products for students against COPPA, FERPA and accessibility rules.
Why it is thereChildren’s and students’ data has its own laws.
When it runsbefore senior-dev
suggested when files change: src/coppa-consent.ts · lib/student_data.py
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh edtech-reviewer <APPROVED|BLOCKED> auto- Source
- agents/edtech-reviewer.md ↗
- Link
- /team.html#edtech-reviewer
Game reviewer game-reviewer Checks age ratings, children’s privacy and loot-box rules.
Why it is thereGames reach minors, and stores and regulators check for it.
When it runsbefore senior-dev
suggested when files change: src/loot_box.ts · config/esrb.json
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh game-reviewer <APPROVED|BLOCKED> auto- Source
- agents/game-reviewer.md ↗
- Link
- /team.html#game-reviewer
Marketplace reviewer marketplace-reviewer Checks seller onboarding, payouts, escrow and disputes in two-sided marketplaces.
Why it is thereMoney moves between strangers; the rules have to hold.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh marketplace-reviewer <APPROVED|BLOCKED> auto- Source
- agents/marketplace-reviewer.md ↗
- Link
- /team.html#marketplace-reviewer
Procurement reviewer procurement-reviewer Checks purchasing and invoice-to-payment features.
Why it is therePurchase approvals and vendor payments are fraud targets.
When it runsbefore senior-dev
suggested when files change: src/purchase-order.ts · lib/punchout.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh procurement-reviewer <APPROVED|BLOCKED> auto- Source
- agents/procurement-reviewer.md ↗
- Link
- /team.html#procurement-reviewer
IT services reviewer msp-reviewer Checks tools built for managed IT service providers.
Why it is thereSuch a tool holds the keys to every client’s systems.
When it runsbefore senior-dev
suggested when files change: src/rmm-agent.ts · lib/credential-vault.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh msp-reviewer <APPROVED|BLOCKED> auto- Source
- agents/msp-reviewer.md ↗
- Link
- /team.html#msp-reviewer
Voice and telephony reviewer voice-ai-reviewer Checks calling and voice features against consent, call-recording and caller-ID rules.
Why it is thereCalls and recordings are regulated country by country.
When it runsbefore senior-dev
suggested when files change: integrations/twilio-handler.ts · src/ivr/menu.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh voice-ai-reviewer <APPROVED|BLOCKED> auto- Source
- agents/voice-ai-reviewer.md ↗
- Link
- /team.html#voice-ai-reviewer
Web3 design reviewer oracle-reviewer Finds the ways a DeFi design can be attacked — price oracles, flash loans — before contracts are written.
Why it is thereA flaw in the design cannot be fixed by careful coding.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh oracle-reviewer <APPROVED|BLOCKED> auto- Source
- agents/oracle-reviewer.md ↗
- Link
- /team.html#oracle-reviewer
Smart contract auditor smart-contract-auditor Audits the written Solidity contracts with analyzers and tests, and proves each finding.
Why it is thereA bug on-chain is costly and often cannot be patched.
When it runsbefore security-officer
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- skeptical-triage · done-blocked · prose-style
- Produces
- report
- Blocks
- on FAIL → senior-dev
stops the chain on BLOCKED - Example
log-verdict.sh smart-contract-auditor <PASS|FAIL|BLOCKED> auto- Source
- agents/smart-contract-auditor.md ↗
- Link
- /team.html#smart-contract-auditor
AI safety 5
Join when the product uses AI.
AI security reviewer ai-security-reviewer Finds the threats specific to AI features: prompt injection, data leaks, misuse of tools.
Why it is thereSo an AI feature cannot be turned against your users.
When it runsbefore senior-dev
suggested when files change: prompts/system.txt · src/rag/retriever.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh ai-security-reviewer <APPROVED|BLOCKED> auto- Source
- agents/ai-security-reviewer.md ↗
- Link
- /team.html#ai-security-reviewer
US AI governance reviewer us-ai-reviewer Checks AI features against US AI-governance rules.
Why it is thereThe US counterpart of the EU AI Act check.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh us-ai-reviewer <APPROVED|BLOCKED> auto- Source
- agents/us-ai-reviewer.md ↗
- Link
- /team.html#us-ai-reviewer
Hiring AI reviewer hr-ai-reviewer Checks AI that screens or ranks job candidates.
Why it is thereAutomated hiring decisions are regulated in a growing number of places.
When it runsbefore senior-dev
suggested when files change: src/hiring/rank.ts · lib/resume_screen.py
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh hr-ai-reviewer <APPROVED|BLOCKED> auto- Source
- agents/hr-ai-reviewer.md ↗
- Link
- /team.html#hr-ai-reviewer
MLOps reviewer mlops-reviewer Checks how models are trained, versioned and served.
Why it is thereSo a model in production can be traced back and rolled back.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh mlops-reviewer <APPROVED|BLOCKED> auto- Source
- agents/mlops-reviewer.md ↗
- Link
- /team.html#mlops-reviewer
MCP server reviewer mcp-server-reviewer Checks the tools an MCP server exposes to AI agents.
Why it is thereEvery tool is something an AI can be tricked into calling.
When it runsbefore senior-dev
suggested when files change: mcp-servers/llm-router/server.py · src/mcp.ts
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh mcp-server-reviewer <APPROVED|BLOCKED> auto- Source
- agents/mcp-server-reviewer.md ↗
- Link
- /team.html#mcp-server-reviewer
Platform and release 13
Join by what you build and how it ships.
Database migration reviewer db-migration-reviewer Checks each schema change for locks, downtime, rollback and personal data.
Why it is thereA bad migration can take production down.
When it runsbefore qa-engineer
suggested when files change: db/migrations/0007_add_index.sql · prisma/migrations/20260801_init/migration.sql
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh db-migration-reviewer <PASS|BLOCKED> auto migrate=docs/migrations/MIGRATE-<slug>-<date>.md- Source
- agents/db-migration-reviewer.md ↗
- Link
- /team.html#db-migration-reviewer
Infrastructure reviewer infra-reviewer Checks infrastructure-as-code changes, especially destructive ones.
Why it is thereSo a config change does not delete a database.
When it runsbefore senior-dev
suggested when files change: infra/main.tf · helm/values.yaml
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh infra-reviewer <APPROVED|BLOCKED> auto- Source
- agents/infra-reviewer.md ↗
- Link
- /team.html#infra-reviewer
API reviewer api-platform-reviewer Checks a public API’s design before it is built.
Why it is thereA public API is hard to change once others depend on it.
When it runsbefore senior-dev
suggested when files change: api/openapi.yaml · src/webhooks.ts
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · prose-style
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh api-platform-reviewer <APPROVED|BLOCKED> auto- Source
- agents/api-platform-reviewer.md ↗
- Link
- /team.html#api-platform-reviewer
Enterprise SaaS reviewer enterprise-saas-reviewer Checks that one customer’s data can never reach another.
Why it is thereTenant isolation is the first thing enterprise buyers ask about.
When it runsbefore senior-dev
suggested when files change: src/scim/provision.ts · db/row-level-security.sql
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh enterprise-saas-reviewer <APPROVED|BLOCKED> auto- Source
- agents/enterprise-saas-reviewer.md ↗
- Link
- /team.html#enterprise-saas-reviewer
Data platform reviewer data-platform-reviewer Checks data pipelines for retention and lineage.
Why it is thereSo you know where data came from and when it must be deleted.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh data-platform-reviewer <APPROVED|BLOCKED> auto- Source
- agents/data-platform-reviewer.md ↗
- Link
- /team.html#data-platform-reviewer
Streaming reviewer streaming-reviewer Checks event-driven systems for delivery guarantees and ordering.
Why it is thereLost or duplicated events are silent bugs.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh streaming-reviewer <APPROVED|BLOCKED> auto- Source
- agents/streaming-reviewer.md ↗
- Link
- /team.html#streaming-reviewer
App store reviewer mobile-store-reviewer Checks the app against App Store and Play Store policies.
Why it is thereSo the app is not rejected at submission.
When it runsbefore senior-dev
suggested when files change: fastlane/Fastfile · ios/iap-manager.swift
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh mobile-store-reviewer <APPROVED|BLOCKED> auto- Source
- agents/mobile-store-reviewer.md ↗
- Link
- /team.html#mobile-store-reviewer
Browser extension reviewer web-store-reviewer Checks the extension’s manifest and permissions against Chrome, Firefox, Edge and Safari store policies.
Why it is thereSo the extension passes store review.
When it runsbefore senior-dev
suggested when files change: extension/manifest.json · src/mv3-worker.ts
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh web-store-reviewer <APPROVED|BLOCKED> auto- Source
- agents/web-store-reviewer.md ↗
- Link
- /team.html#web-store-reviewer
CMS reviewer cms-reviewer Checks content platforms for SEO, accessibility and content policy.
Why it is thereContent sites live or die by search and by who can read them.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh cms-reviewer <APPROVED|BLOCKED> auto- Source
- agents/cms-reviewer.md ↗
- Link
- /team.html#cms-reviewer
CLI reviewer cli-reviewer Checks a command-line tool’s commands, flags and behaviour before it is built.
Why it is thereSo the tool is safe and predictable to script against.
When it runsbefore senior-dev
suggested when files change: bin/great-cto · src/cli/main.ts
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh cli-reviewer <APPROVED|BLOCKED> auto- Source
- agents/cli-reviewer.md ↗
- Link
- /team.html#cli-reviewer
Library reviewer library-reviewer Checks a library or SDK’s public interface for stability.
Why it is thereA breaking change breaks everyone who depends on you.
When it runsbefore senior-dev
suggested when files change: Cargo.toml · pyproject.toml
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh library-reviewer <APPROVED|BLOCKED> auto- Source
- agents/library-reviewer.md ↗
- Link
- /team.html#library-reviewer
Developer-tools reviewer devtools-reviewer Checks plugins, IDE extensions and SDKs for supply-chain risk.
Why it is thereYour tool runs on other developers’ machines.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh devtools-reviewer <APPROVED|BLOCKED> auto- Source
- agents/devtools-reviewer.md ↗
- Link
- /team.html#devtools-reviewer
Firmware reviewer firmware-reviewer Finds the threats to IoT and embedded devices.
Why it is thereDevices in the field are hard to patch.
When it runsbefore senior-dev
Technical details
- Model
- sonnet
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- archetype-review-base · receiving-code-review [external · superpowers] · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh firmware-reviewer <APPROVED|BLOCKED> auto- Source
- agents/firmware-reviewer.md ↗
- Link
- /team.html#firmware-reviewer
Orchestration & Meta (4)
Work behind the scenes: coordinate big jobs, learn from sessions, audit existing code.
Session learner continuous-learner At the end of a session, writes down the lessons and patterns worth keeping.
Why it is thereSo the next session starts smarter than the last.
When it runsaround the pipeline
Technical details
- Model
- claude-haiku-4-5
- Shell
- none
- Web
- yes
- Spawns agents
- no
- Skills
- not declared
- Produces
- not declared
- Blocks
- not declared
- Example
log-verdict.sh continuous-learner DONE auto wrote=<n> promoted=<n>- Source
- agents/continuous-learner.md ↗
- Link
- /team.html#continuous-learner
Coordinator coordinator Splits a large request into parallel streams and runs agents across them.
Why it is thereFor work too big for one line of tasks.
When it runsaround the pipeline
Technical details
- Model
- sonnet
- Shell
- full
- Web
- no
- Spawns agents
- yes
- Skills
- not declared
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh coordinator <DONE|BLOCKED> auto packets=<n> feature=<slug>- Source
- agents/coordinator.md ↗
- Link
- /team.html#coordinator
Knowledge extractor knowledge-extractor Finds patterns that keep recurring across past sessions and drafts reusable skills from them.
Why it is thereSo a lesson learned three times becomes a rule.
When it runsaround the pipeline
Technical details
- Model
- claude-opus-5
- Shell
- none
- Web
- no
- Spawns agents
- no
- Skills
- not declared
- Produces
- not declared
- Blocks
- not declared
- Example
log-verdict.sh knowledge-extractor DONE auto drafts=<n>- Source
- agents/knowledge-extractor.md ↗
- Link
- /team.html#knowledge-extractor
Project auditor project-auditor Maps an existing codebase: stack, vulnerabilities, outdated dependencies, debt — with a plan.
Why it is thereThe starting point when you bring great_cto to code that already exists.
When it runsaround the pipeline
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- yes
- Skills
- done-blocked · prose-style
- Produces
- audit
- Blocks
- not declared
- Example
log-verdict.sh project-auditor DONE auto- Source
- agents/project-auditor.md ↗
- Link
- /team.html#project-auditor
Role not assigned (1)
Not part of the pipeline; runs when you ask for it.
Quant researcher quant-researcher Forms trading hypotheses and backtests them with the checks that make a backtest evidence. Research only — it never places an order.
Why it is thereFor systematic-trading research.
When it runsaround the pipeline
Technical details
- Model
- sonnet
- Shell
- full
- Web
- yes
- Spawns agents
- no
- Skills
- quant-validation · prose-style · skeptical-triage · done-blocked
- Produces
- not declared
- Blocks
- stops the chain on BLOCKED
- Example
log-verdict.sh quant-researcher <DONE|BLOCKED> auto research=docs/research/QUANT-<slug>.md- Source
- agents/quant-researcher.md ↗
- Link
- /team.html#quant-researcher
Generated from great_cto v3.52.1.
Checks: 72 agents ok · pipeline map ok · file rules 28 ok
Files: agents/*.md · shared/pipeline.toml · shared/lifecycle-map.mjs · scripts/lib/approval-level.mjs · scripts/hooks/auto-attach-reviewers.mjs ↗ GitHub
Known gaps in the source: quant-researcher