Vibe coding that survives contact with reality.
Drop into a new project to scaffold from scratch — or into an existing one to bring it under sane conventions without rewriting it. The same bootstrap I use on consulting engagements, priced so you get a stable setup from day one without hiring me.
One-time · yours forever · works with Claude, Codex, Cursor, Copilot & Gemini.
The problem
The fast part is easy. Keeping it maintainable isn't.
The demo works. Then the codebase grows faster than its conventions, the agent loses the thread, and changes start breaking things you'd already finished.
No conventions to follow
Without steering docs, every session re-litigates structure, naming, and tests — and contradicts decisions you made last week.
Hard to vouch for
You end up shipping code you can't fully stand behind, and hoping it holds.
Fast or solid, pick one
It starts to feel like you have to choose between moving fast and ending up with something you can maintain.
Why listen to me
This is the setup I actually use.
This is how I bootstrap vibe-coding projects for myself and my customers. It's the same setup I drop into consulting work — packaged so you get a stable start from day one without hiring me.
The plan
Three steps to a setup that holds
Drop it in
Add the bootstrap folder to a new project or an existing one. Takes a minute.
Your agent picks it up
It picks up the rules, skills, and conventions automatically — every session, every tool.
Build with confidence
Ship features that hold up — and a codebase you'd be glad to hand to someone else.
Inside the kit
7 items · 5 free · 2 with purchase
Skills your agent learns
Reusable commands your agent already knows how to run. Type one by name; the ones that only look and report also kick in when you ask in plain language.
/jgl-checkRuns every check the project has — dependency audit, type check, tests, build, and the optional structure, complexity and secrets-manifest checks — and reports them grouped into gates and drift signals, with an explicit SKIPPED line for anything not installed./jgl-commitStages the relevant changes and makes a local commit with a specific message and no AI attribution; never pushes. On a long session it also refreshes docs/PROGRESS.md so the next session can pick up./jgl-initSets up a repo that just received this kit — works out greenfield vs brownfield, merges any existing AGENTS.md/CLAUDE.md, fills in the Commands table, installs the commit-msg hook, offers the agent guards, then runs the matching greenfield or brownfield playbook./jgl-pushPushes committed work to the remote, asking first before any push to main, master, or a production branch, and never forcing or skipping hooks./jgl-review-codeReviews the whole codebase's structure — change shape from git history, duplication, dead code, logic tangled into framework code, type gaps, dependency health — and produces a prioritized refactor plan if one is warranted. A repo-wide structural review, not a review of the current diff./jgl-review-testingAudits the test suite for substance — weak assertions, untested logic, AI-written tests that assert the implementation instead of the requirement, and CI gates that can't actually fail — and produces a prioritized testing plan if one is warranted./jgl-scopeRuns a 15–20 minute guided interview about what you're building, for whom, constraints, brand and stack, then writes docs/SCOPE.md (and docs/BRAND.md when there's a brand), adds a Project context section to AGENTS.md, and picks the first milestone./jgl-setup-harnessInstalls the structural and complexity sensors (dependency-cruiser and ESLint complexity rules), proves each structural rule fires, and wires them into the existing pre-push hook and CI./jgl-setup-secretsSets up encrypted-in-repo secrets with SOPS + age — separate dev and prod keys, verified rotation, a keyless manifest check, a pre-commit guard, and deploy sync./jgl-setup-testingInstalls a test framework where none exists, writes a real starter test, and wires coverage, CI, and a pre-push hook./jgl-statusGives a short, read-only session checkpoint — what's committed, staged, and in progress, what's still open, anything risky left uncommitted, and whether enough has been generated since the last commit to checkpoint.
Wait, what's a "skill"?
From Napoleon Dynamite (2004): “I don't even have any good skills. You know like num-chuk skills, bow hunting skills, computer hacking skills. Girls only want boyfriends who have great skills!”
Modern AI coding tools let you teach your agent skills — named playbooks it can recognize and follow. Each card above is one your agent gets when you install the kit.
What's new in this version
Rebuilt for how today's coding agents read instructions — and checked against them before release.
- One rules file. Every major tool reads
AGENTS.md; Claude Code imports it. Nothing to keep in sync per tool. - Checks, not just rules. A commit hook stops AI attribution in every tool, and optional guards for Claude Code and Codex block secret-file reads, force pushes, and pasted keys.
- Leaner skills. Trimmed for current models, and the ones that change things run only when you ask.
Upgrading from an earlier download? Delete the old GEMINI.md, Copilot instructions file, and .cursor/rules/ — those tools read AGENTS.md now, and the old copies would load the same rules twice.
What's at stake
The difference a system makes
Without a system
- A rewrite at every milestone
- Security holes you find in production
- An agent that contradicts itself
- An app you're reluctant to change
With the Starter Kit
- Conventions that survive scale
- A security baseline from day one
- An agent that stays on-rails
- An app you can hand off and trust
Get started
A stable setup from day one.
Drop in the same bootstrap I use on consulting work and get a stable, maintainable setup from the start — without hiring me.
Already own this kit? The Code Review & Security Audit drops to a bundle price — automatically.
Pairs well with
Building Fusion 360 add-ins instead of (or alongside) regular web/backend projects? The Fusion Add-in kit applies the same playbook to that domain.