◑ LunaStack
249 protocols · 27 disciplines · 55 specialist roles · one file
The most comprehensive AI development methodology open-sourced.
Sourced from Superpowers (94K★), GStack (66K★), Boris Cherny (Claude Code creator),
Anthropic official docs, HumanLayer research, and OpenClaw lessons.
Quick Start · All Protocols · What's New · Sources
Method 1 — Claude Projects (recommended)
- Download
LunaStack.md - Go to claude.ai → Projects → New Project → Add to Project Knowledge
- Type any
/commandand Claude follows the protocol
Method 2 — Claude Code CLI
git clone https://github.com/moonshineaitech/LunaStack ~/lunastack
cd ~/lunastack && ./setup.sh --global # symlinks 239 skills
claude "/luna" # startMethod 3 — Team Install (auto-updating)
./setup.sh --team # SessionStart hook auto-updates from originThis release integrates everything from the latest research scan (April 2026):
The full obra/superpowers v5.0.7 methodology — /1pct-rule, /no-placeholders, /subagent-driven, /skill-priority, /tool-mapping, /find-duplicates, /verify-completion, /yagni-enforce, /evidence-over-claims, /linear-pipeline, /skill-test-loop, /visual-companion.
Garry Tan's exact production setup — /office-hours (YC partner mode), /design-consultation, /design-shotgun, /design-html, /design-review (80-item visual audit with letter grades), /codex-review (cross-model independent review), /cso-audit (OWASP Top 10 + STRIDE), /careful-mode, /freeze, /unfreeze, /investigate-frozen, /team-install, /readiness-dashboard, /test-plan-handoff, /global-retro, /devex-review.
Lessons from the fastest-growing repo in GitHub history — /skill-security-audit (the "12% of community skills are malicious" lesson), /sandbox-design, /memory-isolation, /skill-review-system, /multi-llm-routing, /persistent-memory, /messaging-interface, /vibe-coding-warnings, /local-model-fallback, /platform-skills-architecture.
Run LunaStack across all major AI coding harnesses — /platform-detect, /tool-translate, /session-bootstrap, /worktree-aware, /sandbox-fallback, /env-detection, /universal-skill, /host-config. Works on Claude Code, Codex, Cursor, Gemini CLI, Copilot CLI, OpenCode.
Hardened development from Trail of Bits + CVE lessons — /cve-scan, /supply-chain-audit, /codeql-semgrep, /threat-db, /malicious-skill-detection, /sbom, /dependency-typosquat, /secret-rotation-plan.
27 disciplines · 249 protocols · 55 specialist roles · 30 Gotchas sections
| Discipline | # | Highlights |
|---|---|---|
| ◑ Meta | 8 | /luna /guard /onboard /second-opinion |
| ◍ Inquiry | 7 | /inquiry /premortem /spike /thesis |
| △ Architecture | 8 | /architect /api-contract /cost /dependency |
| ▭ Specification | 6 | /spec /plan /autoplan /estimate |
| ⬡ Construction | 13 | /tdd /build /debug /pair /reflexion |
| ◇ Verification | 5 | /verify (6 agents) /threat-model /chaos |
| ◎ Craft | 7 | /design-critique /design-variants /friction |
| ▸ Delivery | 8 | /ship /rollback /monitor /incident |
| ∞ Memory | 7 | /retro /learn /compound /handoff |
| 👔 Leadership | 8 | /cfo /pitch /hiring /compete |
| 🔬 Research | 5 | /user-interview /persona /jobs-to-be-done |
| 🔧 Infrastructure | 8 | /auth /cache /queue /payments |
| 📝 Content | 4 | /write /email /error-message |
| 📊 Growth | 5 | /ab-test /funnel /retention /seo |
| 🔐 Compliance | 3 | /privacy /legal /security-response |
| 🧠 Decisions | 4 | /decision /rfc /negotiate /delegate |
| ⚡ Performance | 3 | /perf-budget /load-test /query |
| 🎯 Best Practices | 11 | /interview-me /fresh /redo /grill |
| 🧰 Workflows | 5 | /plan-mode /worktree /test-time-compute |
| 🔥 Latest (Boris) | 9 | /self-improve /babysit /verify-loop |
| 🌀 Superpowers Pipeline | 12 | /1pct-rule /no-placeholders /linear-pipeline |
| 🏗️ GStack Team | 15 | /office-hours /design-shotgun /codex-review /cso-audit |
| 🔬 OpenClaw Patterns | 10 | /skill-security-audit /multi-llm-routing |
| 🌐 Multi-Host | 8 | /platform-detect /tool-translate /universal-skill |
| 🛡️ Security Skills | 8 | /cve-scan /supply-chain-audit /threat-db |
| 🧬 Frontier (Original) | 10 | /ralph-loop /context-budget-check /security-review /agent-orchestra /drift-detect /cost-tracker /silent-failure-audit /ai-provenance /graceful-escalation /perception-gap |
| 🎭 Specialist Roles | 55 | See below |
NEW FEATURE (full pipeline):
/office-hours → /interview-me → /inquiry → /spec → /plan
→ /no-placeholders → /linear-pipeline → /tdd → /verify-completion
→ /codex-review → /cso-audit → /readiness-dashboard → /ship
→ /global-retro → /compound
QUICK SHIP:
/spec → /plan → /tdd → /build → /verify → /ship
EMERGENCY FIX:
/investigate-frozen → /debug → /tdd → /verify-completion → /ship
DESIGN SPRINT:
/office-hours → /design-consultation → /design-shotgun
→ /design-html → /design-review → /implement-design
SECURITY RELEASE:
/threat-model → /cso-audit → /supply-chain-audit → /codeql-semgrep
→ /codex-review → /readiness-dashboard → /ship
POST-INCIDENT:
/incident → /learn → /compound → /threat-db → /guard
| Domain | Roles |
|---|---|
| Engineering (10) | /frontend-lead /backend-lead /dba /sre /mobile-lead /ml-engineer /devrel /data-engineer /qa-lead /platform-lead |
| Business (8) | /ceo /coo /cmo /vp-sales /bd /investor /pm-lead /account-mgr |
| Creative (5) | /copywriter /brand /content-strategist /ux-writer /creative-director |
| Data (3) | /data-analyst /data-scientist /bi-analyst |
| People (5) | /recruiter /hr-lead /coach /facilitator /l-and-d |
| Marketing (5) | /paid-ads /social-media /email-marketing /pr /growth-hacker |
| Customer (3) | /support-lead /cs-lead /community-mgr |
| Legal (3) | /ip-lawyer /employment-lawyer /compliance-officer |
| Domain (6) | /saas-advisor /marketplace-advisor /fintech-advisor /ecommerce-advisor /healthcare-advisor /ai-product |
| Operations (3) | /scrum-master /ops-manager /procurement |
| Source | Stars/Authority | What LunaStack took |
|---|---|---|
| obra/superpowers | 94K★ (137K dev) | Full linear pipeline, 1% rule, no-placeholders, subagent-driven dev, skill priority, tool mapping, TDD-for-skills |
| garrytan/gstack | 66K★ (v0.15.14.0) | Office hours, design pipeline, 80-item review, cross-model review, CSO audit, freeze/guard, team install |
| Boris Cherny | CC creator | Self-improvement loop, /loop+skill, verify-loop (2-3x quality), parallel sessions |
| shanraisshan/best-practice | 17K★ | Gotchas sections, goals+constraints, /redo, /grill, comprehensive workflow patterns |
| Anthropic official docs | Authoritative | /interview-me, fresh sessions, subagent delegation, context management |
| HumanLayer research | Production | CLAUDE.md ~80% compliance, hooks 100%, ~150-200 instruction limit |
| OpenClaw | 247K★ (fastest growing) | Skill security lessons, multi-LLM routing, vibe coding warnings |
| Trail of Bits | Security firm | CodeQL/Semgrep, supply chain audit, CVE-mapped threats |
| NeoLabHQ/reflexion | Open source | Self-correction loops |
| Compound Engineering | Every.to | Plan → work → review → compound learning loop |
| o16g Manifesto | Cory Ondrejka | Outcome engineering: define outcomes, let AI implement |
| File | Purpose | Size |
|---|---|---|
LunaStack.md |
The single file. Upload to Claude Project. Everything works. | 197KB |
*/SKILL.md |
239 individual skill files for Claude Code CLI | — |
setup.sh |
Symlinks all skills into ~/.claude/skills/ |
0.5KB |
uninstall.sh |
Removes symlinks | 0.3KB |
Don't try all 239 protocols at once. Start with these 7:
/office-hours— YC partner interrogation. Make sure you're building the right thing./interview-me— Have Claude interview YOU. Surface edge cases you haven't considered./no-placeholders— Validate any plan before execution. Zero tolerance for TBD./verify-completion— Never mark anything done without proof./codex-review— Independent review from a different model. Catches Claude's blind spots./self-improve— After every correction, write a prevention rule. Compound smarter every session./global-retro— Weekly aggregation across all your AI tools and projects.
MIT — same as Superpowers, GStack, and OpenClaw.
Software development is a discipline. Treat it like one.
239 protocols · 26 disciplines · 55 roles · 4,810 lines · 197KB · MIT