Repository navigation
tools project wizard
pnpm project:new (implemented in tools/project-wizard/src/cli.mjs) scaffolds a new SAFRS project capsule under projects/<slug>/ from the repository template projects/_template/. A capsule is the governance contract for a project — AGENTS.md, README.md, docs/architecture.md, docs/data.md, docs/testing.md, src/README.md, tests/README.md — with placeholders resolved to the wizard's answers. It creates no application code: implementation is a separate, authorized task.
| File | Purpose |
|---|---|
tools/project-wizard/src/cli.mjs |
CLI: argument parsing, prompting, preview/apply, locked publication |
tools/project-wizard/src/model.mjs |
Normalizes untrusted answers into the bounded SAFRS project model |
tools/project-wizard/src/render.mjs |
Renders the capsule files deterministically from the template |
tools/project-wizard/package.json |
Package metadata (@safrs/project-wizard); tests via node --test
|
projects/_template/ |
The template capsule every new project is rendered from |
Untrusted wizard answers are normalized into a bounded model. normalizeProjectAnswers:
- validates
name(non-empty, no control characters),problem, andkind(web|desktop|extension); - slugifies the name (NFKD → lowercase →
[a-z0-9-]), rejects reserved Windows device names (con,prn, …) and unsafe slug sources (paths,.., control/URL-decoded tricks); - normalizes
capabilitiesandsensitiveDomainschoice lists (deduped, slugified, sorted); - validates
appBindingas a bounded path belowapps/(defaultapps/<kind>); - computes the minimum risk from declared fields — any term matching healthcare/finance/auth/payments/migrations/shared-package keywords, or a shared-package impact, forces at least R2; the declared risk can only raise it further.
renderProjectCapsule copies each template file through safeTemplateText — a symlink- and TOCTOU-hardened read that rejects any template path that is a symlink or escapes the template root — substitutes the model values, appends generated capsule context to the docs (app binding, capabilities, sensitive domains, computed risk, topology check command), and fails if any template placeholder marker remains.
applyProjectCapsule publishes with one exclusive per-slug lock and no replacement:
- acquires a per-slug
wxlock with a UUID marker inprojects/, - writes the rendered files into an owned staging directory (with random-UUID ownership markers),
- re-validates the
projects/root and the staging identity before publishing, - moves the staged capsule into
projects/<slug>/without clobbering an existing directory, and - quarantines anything that changed identity mid-operation instead of deleting it.
pnpm project:new # interactive prompts (Nama proyek, masalah, jenis, kemampuan, domain sensitif)
pnpm project:new --preview # render + print preview without writing
pnpm project:new --apply # render, confirm, and write
pnpm project:new --input answers.json --apply
pnpm project:new --input answers.json --preview --confirm "CREATE <slug>"Confirmation must exactly equal CREATE <slug> before anything is written.
-
projects/_template/is the single template source;check_topology.pyverifies every created capsule still satisfies the required capsule layout. -
tools/capabilitiesoperates on the capsule'scapabilities.jsonafterwards. -
tools/safrs/check_topology.pyvalidates the produced capsules (required files, no unresolved<replace-…>placeholders).
node --test tools/project-wizard/test/*.test.mjs
pnpm run doctor # read-only diagnostics before running the wizard- Tools overview
- Capabilities — add optional capabilities to a generated capsule
-
SAFRS governance checkers —
check_topology.pyvalidates capsules - Project capsules — the capsule convention
SAFRS — the Sentra Agent-First Repository Standard — defines how a software repository should be structured, governed, and enforced when autonomous Artificial Intelligence agents perform a substantial share of engineering work by Sentra Artificial Intelligence.
SAFRS v1.1 addresses that problem through five coupled mechanisms:
- a six-layer repository architecture from Trust Boundary to Human Authority;
- a role-based permission model in which capability never implies trust;
- a four-tier risk model with cumulative mandatory controls;
- a multi-agent execution protocol with explicit task states and one mutation owner per bounded scope;
- a knowledge governance model that distinguishes current architecture, historical decisions, execution plans, Git history, and running code.
Built in Indonesia as part of the Sentra Artificial Intelligence ecosystem.
Sentra Artificial Intelligence · Source Repository · Official Website
Dr Ferdi Iskandar — Creator & Maintainer
LinkedIn ·
ORCID ·
Hugging Face ·
Kaggle ·
Medium ·
Substack ·
X ·
Threads
MyPrompt · Sentra Artificial Intelligence · Indonesia
- SentraBot
- Kediri History
- Academic Smartboard
- Avery
- Portfolio Dr. Novia
- Golden Path (legacy demonstrator)
- Control Center
- Capsule template
- Risk model (R0–R3)
- Agent roles and permissions
- Capsule sovereignty
- Multi-agent protocol
- Document lifecycle
- Sensitive paths
- Verification integrity
Lore — how this repository grew
- Schemas (
@safrs/schemas) - Environment (
@safrs/env) - Database (
@safrs/database) - API (
@safrs/api) - UI (
@safrs/ui) - Telemetry (
@safrs/telemetry) - Token (
@sentra/token) - Config (
@safrs/config) - Auth (
packages/auth)
- SAFRS governance checkers
- SAFRS Automation Control Plane
- Gaffer Runtime
- Doctor
- Project wizard
- project-standalone
- Capabilities
- Codegen
- Deps-graph
- Status CLI
- Task CLI