Engineering standards the agent follows — no negotiation.
Normative skill packs for Claude Code. Non-negotiable floors for architecture, security and testing — one shared floor for all code, human or AI. Install with one command; works in Claude Code, Claude.ai and the API.
$ curl -fsSL https://github.com/schematizeme/schematize-cli/releases/latest/download/install.sh | bash$ schematize install --allOne CLI for the whole catalog.
schematize is a Rust CLI — desktop app included — that installs and versions every skill from a live remote index. New skills show up without reinstalling anything.
- Install & version skills — from a remote catalog; one command pulls the whole set and keeps it current.
- Desktop app included — a window to browse, install and update skills — ships prebuilt, no build tools.
- doctor · upgrade · status — diagnose your setup, self-update, and see everything at a glance.
- Resident agent — watches for new skill versions and blog posts and notifies you natively.
Get the app
Install schematize on macOS, Linux or Windows — the desktop app ships with it.
v0.8.1 · github.com/schematizeme/schematize-cli
Download the app, unzip and right-click → Open (Apple Silicon; an Intel build is on the release page).
schematize-macos-arm64-app.zip- unzip → Ctrl-click → Open
Debian, Ubuntu and Linux Mint. One command installs the .deb (CLI + desktop app) and pulls the GUI libraries.
In a terminal:
$ curl -fsSL https://github.com/schematizeme/schematize-cli/releases/latest/download/install.sh | bashopenSUSE, Fedora and RHEL. One command installs the .rpm (CLI + desktop app).
In a terminal:
$ curl -fsSL https://github.com/schematizeme/schematize-cli/releases/latest/download/install.sh | bashDownload the zip, extract and run schematize-gui.exe. Add schematize.exe to your PATH for the CLI.
schematize-windows-x86_64.zip- extract → run
schematize-gui.exe
The macOS app and the Windows .exe are not code-signed yet — the OS shows a one-time “unverified” warning on first launch (macOS: right-click → Open; Windows: More info → Run anyway).
Don't want to install?
Read the full standards and copy them straight into your project — or install the skill so the agent enforces it for you.
Packs
Each pack is a skill in the open Agent Skills standard, versioned and served over a CDN.
schematize-go
Go/Rust backend engineering standards: server-side security, tests that prove, an index as source of truth and mandatory archiving.
schematize-web
Next.js/Astro frontend standards: secrets server-side, WCAG 2.2 AA accessibility, Core Web Vitals as a contract, SEO + structured data and i18n. The frontend sibling of schematize-go.
schematize-rust
Normative engineering standards for backends with Rust as the primary language (Go auxiliary).
schematize-node
Normative standards for maintaining legacy Node.js/TypeScript and migrating out to Go/Rust — no new Node backends.
schematize-engineering
The house's shared, language-agnostic engineering base: architecture/DDD, MAP+graph+endpoints, security, data, observability, delivery/DoD/archive, and orchestration (split into mini-tasks + parallelize with subagents — time over tokens). The language skills specialize it.
schematize-pentest
House security testing: defensive AppSec (per-route rejection, IDOR/BOLA, BFLA, injection, SSRF, JWT/OAuth) and authorized red-team (concrete attack chains, ATT&CK). Arsenal by class + OWASP Web/API Top 10 coverage + STRIDE threat modeling + authz matrix — always under authorization + scope + RoE.
schematize-seo
Normative SEO standards: technical, on-page, content/keywords, structured data, international/multi-domain (no cannibalization), AIO/LLMO/GEO, authority/E-E-A-T and measurement.
schematize-elixir
Normative engineering standards for Elixir backends — Phoenix/Ecto/OTP on the BEAM, realtime and fault-tolerant high concurrency.
schematize-csharp
Normative engineering standards for C# / .NET backends (ASP.NET Core, EF Core).
schematize-zig
Normative engineering standards for systems in Zig — low-level, performance and manual memory control.
schematize-ruby
Normative engineering standards for Ruby backends, services and scripts (Rails/Sinatra).
schematize-audit
House history audit: enumerates and COUNTS every checklist created (overdev, QA, handoffs, plans, ADRs, parked questions, premature-stops) and proves each item was actually RESOLVED — finds RED orphans, reopens 'done' without proof, generates a remediation checklist and blocks the verdict if any orphan remains.
schematize-ai
House AI/LLM systems engineering: provider-agnostic (Claude default, pluggable), prompt & context engineering, RAG (chunking/embeddings/retrieval/evaluation), agents & tool-use (loop/function-calling/MCP), evals & guardrails (red-team, jailbreak, PII, validated structured output, deny-by-default), cost/caching and LLM observability. Floors: no LLM decides authorization, every AI output is untrusted until validated, prompt injection is a first-line attack, secrets never in the prompt/client, RAG isolated per tenant.
schematize-data
House data engineering: treats data as a CONTRACT — versioned schema with compatibility (back/forward/full), batch and streaming ETL/ELT pipelines, event sourcing/CDC via Outbox (dual-write forbidden), quality with quarantine and dead-letter (bad data never contaminates downstream), lineage & catalog, reversible expand-contract migrations, idempotency/replay and PII governance (deny-by-default, legal basis + retention, GDPR/LGPD).
schematize-mobile
House mobile app engineering: the same floor (security, IAM, testing, ops, DoD, archive) on the hostile client that is the device — platform choice native (Swift/Kotlin) vs cross (KMP/Flutter/RN) by fit + ADR; offline-first & sync (durable outbox, idempotency, delta sync, explicit conflict resolution, server as source of truth); mobile IAM matching iam.md (OIDC/PKCE delegating to auth.<domain>, passkeys+biometrics, secure storage, irreversible logout, NEVER a secret in the bundle, authz on the server); push (APNs/FCM), performance/battery/network, store delivery (signing, staged rollout, in-policy OTA, review), observability/crash and security (SPKI pinning, root/jailbreak as signal, sensible obfuscation).
schematize-infra
House Infra/DevOps/SRE: run production with minimal blast radius — per-app isolation (dedicated Linux user + hardened systemd + container per service), declarative/idempotent/reviewable IaC, GATED deploy (nothing skips a stage; front is manual/gated), secrets never in the repo (vault + rotation), built-in observability (SLO/alerts), backup & DR with TESTED restore, deny-by-default networking/TLS/hardening, and supply-chain (SBOM/pinning/signing). Deny-by-default, least-privilege, everything audited.
schematize-docs
House documentation as a discipline: docs are part of the Definition of Done (not optional), docs-as-code (in the repo, reviewed, versioned, TESTED), an ADR for every relevant decision (proposed → accepted/rejected), operational runbooks, API docs/OpenAPI generated from code, changelog + SemVer, C4/mermaid diagrams, and the index/archive the audit consumes.
schematize-scaffold
The house scaffolder: the executable blueprint of a 'new house project', the backing for `schematize new <project>`. Creates a project that is BORN with the day-0 floor — repos per context (`<project>_<ctx>_<lang>`), IAM as a separate app (`<project>_auth_<lang>` + `authfront`, OIDC delegation), separate frontend, `<project>_ops` with per-app isolation, CI with gated deploy, tests/pentest, DoD, archive/index and overdev; language by fit + ADR. Ships scaffold-new (create) and scaffold-check (audit an existing project's floor). No project 'without IAM/without ops for later' — the floor is day 0.
How it works
The app reads a live index (catalog.json) on GitHub, so publishing a new skill is just adding an entry — no CLI rebuild.
1 · install the app
One command installs the schematize CLI and its desktop app on Linux (.deb / .rpm / binary).
2 · install skills
Run schematize install --all to pull every skill into .claude/, or install one by slug.
3 · stay current
The resident agent notifies you when a skill or the app updates; schematize upgrade self-updates.