Get you fly like a g6 — one founder, a whole engineering team's worth of skills.
"A small practice building, teaching, and securing software that belongs to the people using it." — Capitalism Killed Software
g6 is a set of AI engineering skills for Claude Code. You type a command like /review or /privacy-audit and Claude runs a full workflow for you — planning a feature, auditing security, shipping a PR, watching the burn rate, teaching a junior dev what just happened.
I'm Bij4n, and I built g6 around how I actually work: mostly solo, privacy-first, shipping to real users on Rails, FastAPI, and Supabase. The point is to give one person building a product the coverage a whole team would — the reviewer, the security lead, the ops on-call, the person who remembers where you left off. But none of that is required. Most of the skills here don't care what stack you use, and you can pick up as many or as few as you want.
You don't have to adopt the whole thing. People use g6 in a few different ways:
- Shipping a side project alone. Plan it (
/office-hours), build and review it (/review), and get it out the door (/ship) without a team. - Securing an app before launch. Run
/cso,/privacy-audit, and whatever stack-specific audit fits (/stripe-audit,/supabase-audit,/api-audit) and fix what they find. - Keeping something in production healthy.
/health,/rails-health,/node-health,/sidekiq-monitor, and/canaryare dashboards you run when you want to know what's actually going on. - Teaching or learning.
/mentorexplains what just happened in plain language, tuned to the level of whoever's reading. - Automating browser work.
/browseand/scrapedrive a real headless Chromium for QA, testing, and data collection. - Running the whole thing solo.
/solo-standupcatches you up each morning,/cost-audittells you what you're burning, and/kill-switchis the map you want before something's on fire.
Jump to all skills for the full list, grouped by what they're for.
The skills aren't a random toolbox. They map to the loop a solo founder actually runs — from an idea to, eventually, an incident — so that at every stage there's a command covering the hat you'd otherwise be wearing alone:
| Stage | You're doing | Reach for |
|---|---|---|
| Think & plan | deciding what's worth building | /office-hours → /plan-ceo-review, /plan-eng-review, /autoplan |
| Build & review | writing it and catching your own mistakes | /review, /investigate, /codex, the design skills |
| Secure | closing holes before anyone sees it | /cso, /privacy-audit, and the stack audits (/stripe-audit, /supabase-audit, …) |
| Ship | getting it out and confirming it's healthy | /ship, /land-and-deploy, /canary |
| Operate | keeping it alive and staying on track | /solo-standup, /cost-audit, /health, /retro |
| Contain | when something breaks at 3am | /kill-switch stops the bleeding, /incident runs the recovery |
You can still pick up any one on its own — nothing here requires the rest. But run together, they cover the full arc of shipping and operating a product when there's no one else to hand a piece to.
g6 started as a fork of gstack (credit below). These are the ones I added — mostly security and health audits for the stacks I ship on, plus a teaching mode:
| Skill | What it checks |
|---|---|
/phi-audit |
Health-data (PHI) compliance pre-check: PHI in logs/URLs, encryption, audit-log coverage, BAA-required vendors, minimum-necessary collection. Engineering pass, not legal advice. |
/privacy-audit |
Third-party phone-homes, PII exposure, and anything blocking you from self-hosting. |
/rails-health |
Rails 8 + Sidekiq: credentials, N+1s, schema drift, gem CVEs, Stripe webhook security. |
/api-audit |
FastAPI/REST: auth coverage, rate limiting, key exposure, CORS, TILA compliance for financial APIs. |
/stripe-audit |
Stripe for anyone running multiple products on one account. Catches the mistakes that cost real money. |
/supabase-audit |
RLS coverage, storage bucket policies, service_role key isolation, Edge Function auth, pg_cron. One RLS gap exposes every user's records. |
/self-host-audit |
Scores how locked-in you are to managed SaaS and writes a phased plan to get off it. Inventories every hosted dependency, rates data portability, checks for a Docker path. |
/degoogle |
Finds every Google dependency (Fonts, Analytics, reCAPTCHA, Maps, Firebase, GTM) and swaps each for a self-hosted or privacy-respecting equivalent. |
/env-audit |
Every env var pulled from source, diffed against .env.example, plus hardcoded secrets and .gitignore gaps. |
/db-audit |
Postgres health: missing indexes, table bloat, connection pool sizing, N+1 patterns. Static analysis, or live psql if it's available. |
/crypto-audit |
Bitcoin and crypto code: key generation entropy, seed phrase storage, private key exposure, wallet encryption. |
/node-health |
Node/Express: npm CVEs, security middleware (helmet, rate-limit, CORS, CSRF), SQL and MongoDB injection, auth hygiene. |
/sidekiq-monitor |
Live Sidekiq: queue depths, busy workers, dead jobs, retry exhaustion, scheduled backlog. Run it when jobs are actually failing. |
/supabase-deploy |
Safe migration deploys: diff what's pending, flag destructive statements, confirm, apply, re-check RLS. |
/multi-tenant-audit |
Cross-tenant leakage across Rails, Next.js, and FastAPI: DB scoping, RLS filters, cache key isolation, IDOR checks. |
/mentor |
Teaching mode. Explains what just happened at whatever level the reader needs. |
/explain-diff |
Walks through a diff or PR in plain language at the reader's level: what changed, why, what could break, what to test. |
/walkthrough |
An interactive tour of a codebase or subsystem for a newcomer: entry points, how a request flows, the mental model, the gotchas. |
/quiz-me |
Generates grounded questions about the code (or a topic you name), grades your answers with explanations, and adapts the difficulty. |
/solo-standup |
A daily standup for a team of one: what moved, what's in flight, what's blocking you, and the one thing most worth doing today. |
/cost-audit |
Every recurring cost the code implies — hosts, managed services, LLM API spend, SaaS, payment fees — with a rough monthly burn and a ranked plan to cut it. |
/kill-switch |
The emergency lever map: rotate secrets, revoke sessions, roll back a deploy, cap a runaway bill. Report-first, confirmation-gated, and it flags the switches you don't have yet. |
Everything else comes from gstack and is listed further down.
Auto-updates from Bij4n/g6. Run /g6-upgrade to pull the latest.
Once it's installed (below), a typical first run looks like this:
/office-hours— talk through what you're building and find the smallest thing worth shipping./privacy-audit— catch any third-party phone-homes before you launch./cso— full OWASP + STRIDE security pass./review— run this on any branch before you push it.
None of these depend on each other, so start with whichever one matches what you're doing today.
1. Claude Code — install here
2. Bun — g6's build tool. Install it:
curl -fsSL https://bun.sh/install | bash
source ~/.bashrc # or restart your terminal3. Git — already installed on most systems. Check with git --version.
Run this in your terminal (not inside Claude Code — just a regular terminal):
mkdir -p ~/.claude/skills && git clone --single-branch --depth 1 https://github.com/Bij4n/g6.git ~/.claude/skills/g6 && cd ~/.claude/skills/g6 && ./setupSetup compiles the browser binary, downloads Chromium, and links every skill into Claude Code. It runs for about a minute and then you're done.
The extension adds a live sidebar to your browser — activity feed, CSS inspector, and a Claude terminal that can see what tab you're on.
Supports Firefox, LibreWolf, and Chromium. No Chrome required.
| Browser | How to load |
|---|---|
| Firefox / LibreWolf | Go to about:debugging → This Firefox → Load Temporary Add-on → pick ~/.claude/skills/g6/extension/manifest.json |
| Chromium | Go to chrome://extensions → Enable Developer mode → Load unpacked → pick ~/.claude/skills/g6/extension/ |
The sidebar opens automatically after loading. Click the g6 icon in the toolbar to toggle it.
Open Claude Code and paste this prompt exactly:
Add a "g6" section to CLAUDE.md that says: use the /browse skill from g6 for all web browsing, never use mcp__claude-in-chrome__* tools, no Google services (Fonts, Analytics, reCAPTCHA) anywhere. List these available skills: /office-hours, /plan-ceo-review, /plan-eng-review, /plan-design-review, /plan-devex-review, /autoplan, /review, /codex, /investigate, /incident, /onboard, /design-consultation, /design-shotgun, /design-html, /design-review, /qa, /qa-only, /devex-review, /ship, /land-and-deploy, /canary, /setup-deploy, /document-release, /document-generate, /cso, /phi-audit, /privacy-audit, /self-host-audit, /degoogle, /rails-health, /api-audit, /stripe-audit, /supabase-audit, /env-audit, /db-audit, /crypto-audit, /supabase-deploy, /multi-tenant-audit, /node-health, /mentor, /explain-diff, /walkthrough, /quiz-me, /solo-standup, /cost-audit, /kill-switch, /retro, /health, /sidekiq-monitor, /benchmark, /benchmark-models, /make-pdf, /learn, /context-save, /context-restore, /browse, /scrape, /skillify, /pair-agent, /open-g6-browser, /setup-browser-cookies, /careful, /freeze, /guard, /unfreeze, /g6-upgrade.
If you want everyone working in a repo to get g6 automatically, run this from inside that repo:
(cd ~/.claude/skills/g6 && ./setup --team) && ~/.claude/skills/g6/bin/gstack-team-init optional && git add .claude/ CLAUDE.md && git commit -m "add g6 AI workflow skills"This commits the skill config. Any teammate who opens Claude Code in that repo gets g6 without doing anything.
The full set, grouped by what you're doing. Skills marked ★ are ones I built; the rest come from gstack.
| Skill | What it does |
|---|---|
/office-hours |
Start here. Six forcing questions that expose demand reality and the narrowest wedge to ship. |
/plan-ceo-review |
CEO-level review: find the 10-star product in the request. |
/plan-eng-review |
Lock architecture, data flow, edge cases, and tests before a line is written. |
/plan-design-review |
Rate each design dimension 0-10, explain what a 10 looks like. |
/plan-devex-review |
Developer experience plan review: personas, competitor benchmarks, friction points, magic moments. |
/autoplan |
One command runs CEO → design → eng review in sequence. |
| Skill | What it does |
|---|---|
/review |
Pre-landing PR review. Finds bugs that pass CI but break in production. |
/codex |
Independent second opinion from OpenAI Codex: review, challenge (adversarial break attempt), or consult. |
/investigate |
Systematic root-cause debugging. No fixes without investigation. |
/incident |
Production incident response: triage, scope, fix, communicate, post-mortem. For live fires. |
/onboard |
Generate a structured ONBOARDING.md for a new developer: architecture map, local setup, key files, gotchas. |
/design-consultation |
Full design system from scratch: aesthetic, typography, color, layout, motion, font+color previews. |
/design-shotgun |
Generate multiple design variants, open a comparison board, collect feedback, iterate. |
/design-html |
Turn approved designs into production-quality HTML/CSS. |
/design-review |
Live-site visual audit + fix loop with atomic commits. |
/qa |
Open a real browser, find bugs, fix them, re-verify. |
/qa-only |
QA report only — no code changes. |
/devex-review |
Measures real time-to-first-success for APIs and developer-facing products. |
| Skill | What it does |
|---|---|
/ship |
Run tests, review diff, push, open PR. |
/land-and-deploy |
Merge the PR, wait for CI and deploy, verify production health. |
/canary |
Post-deploy monitoring loop using the browser daemon. |
/setup-deploy |
One-time deploy config detection (Render, Vercel, Fly.io, etc.). |
/document-release |
Update all docs to match what you just shipped. |
/document-generate |
Generate Diataxis-structured docs (tutorial, how-to, reference, explanation). |
| Skill | What it does |
|---|---|
/cso |
OWASP Top 10 + STRIDE threat modeling. Full security audit. |
/phi-audit |
★ g6 original. Health-data (PHI) compliance pre-check: PHI in logs/URLs, encryption at rest/transit, audit-log coverage, BAA-required vendors, minimum-necessary + retention. |
/privacy-audit |
★ g6 original. Find phone-homes, PII exposure, data minimization gaps, self-hosting blockers. |
/self-host-audit |
★ g6 original. Portability score + phased exit plan off managed SaaS: dependency inventory, data-export path, Docker readiness, hardcoded-provider hunt. |
/degoogle |
★ g6 original. Locate every Google dependency and swap it for a self-hosted / privacy-respecting equivalent (Bunny Fonts, Plausible, hCaptcha, MapLibre). Report or apply. |
/rails-health |
★ g6 original. Rails 8 health: credentials, Sidekiq, N+1s, schema drift, gem CVEs. |
/api-audit |
★ g6 original. REST/FastAPI: auth, rate limiting, key exposure, CORS, TILA compliance. |
/stripe-audit |
★ g6 original. Stripe: webhook verification, key hygiene, idempotency, multi-product isolation. |
/supabase-audit |
★ g6 original. RLS coverage, storage policies, service_role isolation, Edge Function auth, pg_cron. |
/supabase-deploy |
★ g6 original. Safe migration deployment: diff, flag destructive changes, confirm, apply, verify RLS post-deploy. |
/multi-tenant-audit |
★ g6 original. Cross-tenant leakage: DB scoping, RLS tenant filters, cache key isolation, IDOR checks. |
/env-audit |
★ g6 original. Env var hygiene: extract from code, diff against .env.example, find hardcoded secrets. |
/db-audit |
★ g6 original. Postgres: missing indexes, table bloat, connection pool sizing, N+1 patterns. |
/crypto-audit |
★ g6 original. Bitcoin/crypto: key generation entropy, seed phrase storage, wallet encryption. |
/node-health |
★ g6 original. Node.js/Express: npm CVEs, security middleware (helmet, rate-limit, CORS, CSRF), SQL/MongoDB injection, auth hygiene, error handling. |
| Skill | What it does |
|---|---|
/mentor |
★ g6 original. Explains what just happened in plain language. Beginner → advanced. |
/explain-diff |
★ g6 original. Plain-language walkthrough of a diff or PR at the reader's level: what changed, why, blast radius, what to test. |
/walkthrough |
★ g6 original. Interactive tour of a codebase or subsystem: entry points, request flow, mental model, key files, gotchas. Pairs with /onboard. |
/quiz-me |
★ g6 original. Grounded questions about the code or a named topic, graded with explanations, adaptive difficulty. |
The team you don't have. Run these to stay oriented, watch what you're spending, and know which levers to pull when something breaks.
| Skill | What it does |
|---|---|
/solo-standup |
★ g6 original. A daily standup for a team of one: what shipped, what's in flight, what's blocked, and today's single highest-leverage action. Daily companion to /retro. |
/cost-audit |
★ g6 original. Finds every recurring cost the code implies — deploy hosts, managed services, LLM/AI API spend, SaaS, payment fees — estimates monthly burn, and ranks the cuts by dollars saved per hour of effort. Pairs with /self-host-audit and /degoogle. |
/kill-switch |
★ g6 original. Maps every emergency lever (rotate secrets, revoke sessions, roll back a deploy, cap a runaway bill), gives an ordered playbook per situation, and flags the switches you're missing. Report-first, confirmation-gated. Hands off to /incident for full recovery. |
| Skill | What it does |
|---|---|
/retro |
Weekly retrospective with shipping streaks and per-project breakdowns. |
/health |
Code quality dashboard (type checker, linter, tests, dead code). |
/sidekiq-monitor |
★ g6 original. Live Sidekiq: queue depths, busy workers, dead jobs, retry exhaustion, cron health. |
/benchmark |
Performance regression detection (Core Web Vitals, page load). |
/benchmark-models |
Cross-model benchmark: run the same prompt through Claude, Codex, and Gemini side-by-side. |
/make-pdf |
Turn any markdown file into a publication-quality PDF (margins, TOC, page numbers, watermark). |
/learn |
Manage what g6 learned across sessions. |
/context-save |
Save working context (git state, decisions, remaining work). |
/context-restore |
Resume from a saved context across sessions. |
| Skill | What it does |
|---|---|
/browse |
Headless browser — real Chromium, persistent state, ~100ms/command. |
/scrape |
Pull structured data from a web page. First run prototypes the flow; repeat calls use a codified script (~200ms). |
/skillify |
Codify a successful /scrape flow into a permanent browser skill for instant future reuse. |
/pair-agent |
Pair a remote AI agent (Codex, Cursor, OpenClaw) with your local browser via a secure connection. |
/open-g6-browser |
Launch the visible browser with sidebar. |
/setup-browser-cookies |
Import cookies from your real browser for authenticated testing. |
| Skill | What it does |
|---|---|
/careful |
Warn before destructive commands. |
/freeze |
Lock edits to one directory. |
/guard |
Activate both careful + freeze. |
/unfreeze |
Remove restrictions. |
A few defaults are baked into the skills. You can ignore them, but they're why g6 looks the way it does.
No Google services. I don't pull in Fonts, Analytics, reCAPTCHA, or Tag Manager. Each one is a dependency and a tracking surface I didn't choose, so /privacy-audit flags them and the design skills avoid them. Self-host what you reasonably can.
Run the security audits early. /cso, /privacy-audit, and /stripe-audit are fast enough to run before a deploy instead of after an incident. That's the whole point of packaging them as one command.
Software should stay with the people using it. Self-hosting paths, minimal data collection, encryption at rest, no behavioral tracking. The audit skills treat these as the default expectation, not a nice-to-have.
The g6-original skills know my stack best, so that's what they assume out of the box:
- Backend: Ruby on Rails 8, FastAPI, Sidekiq, Postgres
- Frontend: React/Vite, plain HTML/CSS
- Deploy: Vercel, Render
- Payments: Stripe (one account, several products)
- Languages: Python, Ruby, TypeScript
The workflow skills (planning, review, ship, browse) don't care about any of this and work anywhere.
Run /g6-upgrade — checks and pulls from Bij4n/g6, then re-runs ./setup.
MIT. Fork it, extend it, share it.
g6 is a fork of gstack by Garry Tan. The core workflow — the skill system, the browse binary, the ship pipeline — is his work, and it's genuinely good. What I added on top is the audit and health suite, the teaching mode, the solo-founder ops, and the stack defaults I ship with. Those are marked ★ throughout this README so it's clear which is which.