{"_id":"@aashirjaved/alchemy-infra","_rev":"2-44e453bd12236da52f0c774977c4db0a","name":"@aashirjaved/alchemy-infra","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@aashirjaved/alchemy-infra","version":"0.1.0","keywords":["claude","claude-code","skill","alchemy","infrastructure-as-code","iac","typescript","cloudflare","aws","workers"],"author":{"name":"aashirjaved"},"license":"MIT","_id":"@aashirjaved/alchemy-infra@0.1.0","maintainers":[{"name":"ashurockx","email":"aas.jav@gmail.com"}],"homepage":"https://github.com/aashirjaved/alchemy-infra","bugs":{"url":"https://github.com/aashirjaved/alchemy-infra/issues"},"bin":{"alchemy-infra":"bin/install.js"},"dist":{"shasum":"43f84f7862461fb5ea76bac427208439d57f9096","tarball":"https://registry.npmjs.org/@aashirjaved/alchemy-infra/-/alchemy-infra-0.1.0.tgz","fileCount":20,"integrity":"sha512-K/HnwGBTW98jrcoXlLMDnbLamM8ZcIdKzZCFiLmBtIpL8J1d3XU90HSa0Y+ElBdfmwjMlO9V+s5BvLqy27ofFQ==","signatures":[{"sig":"MEQCIGlVG031cGYSK4dHwH8/yIevW1BdrAY9qPRvJjlJ91fUAiA3u/xZzEgV8mkElm31HX2EBTDSiH/PmW+GcZ3YPZx/MA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65027},"engines":{"node":">=18"},"gitHead":"7d9f2bda17947bea8d606ce93e3f8b5e78656119","_npmUser":{"name":"ashurockx","email":"aas.jav@gmail.com"},"repository":{"url":"git+https://github.com/aashirjaved/alchemy-infra.git","type":"git"},"_npmVersion":"11.12.1","description":"Claude/agent skill that scaffolds Alchemy (Infrastructure-as-TypeScript) into any codebase with strict secret hygiene.","directories":{},"_nodeVersion":"24.15.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/alchemy-infra_0.1.0_1779472335000_0.8815474565608503","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@aashirjaved/alchemy-infra","version":"0.1.1","description":"Claude/agent skill that scaffolds Alchemy (Infrastructure-as-TypeScript) into any codebase with strict secret hygiene.","keywords":["claude","claude-code","skill","alchemy","infrastructure-as-code","iac","typescript","cloudflare","aws","workers"],"homepage":"https://github.com/aashirjaved/alchemy-infra","license":"MIT","author":{"name":"aashirjaved"},"bin":{"alchemy-infra":"bin/install.js"},"engines":{"node":">=18"},"repository":{"type":"git","url":"git+https://github.com/aashirjaved/alchemy-infra.git"},"gitHead":"94ffc1af290e8be3e50bd95f67fd9b29ce4ec1b9","_id":"@aashirjaved/alchemy-infra@0.1.1","bugs":{"url":"https://github.com/aashirjaved/alchemy-infra/issues"},"_nodeVersion":"22.22.3","_npmVersion":"11.15.0","dist":{"integrity":"sha512-rg2ofE+LPxiVGW231++jIvMwVOqQCNBRE9lNbHRq2c5XPoY0P4G0tGHFLSOvyEGKt4gijaZOE/nMEpxvvD/6mQ==","shasum":"b51d8a544d63290c6d80ce5f83af29f89bf33928","tarball":"https://registry.npmjs.org/@aashirjaved/alchemy-infra/-/alchemy-infra-0.1.1.tgz","fileCount":20,"unpackedSize":64679,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aashirjaved%2falchemy-infra@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIC+ufHEZ20MA6ei1TuoUHwmQ7ikUIGJiNuYMQWOEp/DrAiEA/BoZ+R9BBFxXmWKt+e8nq67/0IIcX8usb7/Er6B0Yy0="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:8aaaa411-e468-4f28-977b-0e5dc4276f97"}},"directories":{},"maintainers":[{"name":"ashurockx","email":"aas.jav@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/alchemy-infra_0.1.1_1779472875589_0.022077967632935458"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-22T17:52:14.822Z","modified":"2026-05-22T18:01:16.135Z","0.1.0":"2026-05-22T17:52:15.176Z","0.1.1":"2026-05-22T18:01:15.772Z"},"bugs":{"url":"https://github.com/aashirjaved/alchemy-infra/issues"},"author":{"name":"aashirjaved"},"license":"MIT","homepage":"https://github.com/aashirjaved/alchemy-infra","keywords":["claude","claude-code","skill","alchemy","infrastructure-as-code","iac","typescript","cloudflare","aws","workers"],"repository":{"type":"git","url":"git+https://github.com/aashirjaved/alchemy-infra.git"},"description":"Claude/agent skill that scaffolds Alchemy (Infrastructure-as-TypeScript) into any codebase with strict secret hygiene.","maintainers":[{"name":"ashurockx","email":"aas.jav@gmail.com"}],"readme":"<div align=\"center\">\n\n# alchemy-infra\n\n**Infrastructure-as-Code for agents. No dashboards, no clicking, no leaked secrets.**\n\nA drop-in skill that lets any AI agent provision real cloud infrastructure (Cloudflare Workers, KV, R2, D1, Queues, Durable Objects, AWS Lambda, DynamoDB) by writing TypeScript instead of navigating a UI.\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)\n[![Pass rate](https://img.shields.io/badge/benchmark-100%25-brightgreen.svg)](#-benchmark)\n[![vs baseline](https://img.shields.io/badge/vs%20baseline-%2B15.5pp-blue.svg)](#-benchmark)\n[![SKILL.md](https://img.shields.io/badge/format-SKILL.md-purple.svg)](SKILL.md)\n[![skills.sh](https://img.shields.io/badge/skills.sh-compatible-black.svg)](https://skills.sh)\n\n[**Install**](#-install) · [**Demo**](#-demo) · [**Benchmark**](#-benchmark) · [**Security**](#-security) · [**FAQ**](#-faq)\n\n![demo](assets/demo.svg)\n\n</div>\n\n---\n\n## Why this exists\n\n> **TL;DR.** Cloud UIs are click-prisons. Alchemy escapes them with TypeScript. Alchemy itself takes 30+ correct decisions to set up safely. This skill encodes those decisions so any agent ships in one prompt.\n\n### The pipeline\n\n```\n  🖱️  Cloud UIs   ──▶   📜  Alchemy (IaC-as-TS)  ──▶   🤖  alchemy-infra\n  click-prison         escapes the UI                  makes setup safe\n  agents can't use     setup is 30+ decisions          for any agent\n```\n\n### Stage by stage\n\n<table>\n<tr>\n<td width=\"33%\" valign=\"top\">\n\n#### 🖱️ Cloud UIs are broken for agents\n\n- 40 clicks per resource\n- Dashboard drift on team edits\n- Copy-pasted IDs go stale\n- Agents physically can't navigate\n- Humans don't want to\n\n</td>\n<td width=\"33%\" valign=\"top\">\n\n#### 📜 Alchemy fixes that\n\n- Pure TypeScript, no DSL\n- Resources are `await`-ed\n- No YAML, no codegen\n- One file as source of truth\n- *Cleanest IaC story today*\n\n</td>\n<td width=\"33%\" valign=\"top\">\n\n#### 🤖 But setup is a minefield\n\n- Template? PM? File layout?\n- Bindings per framework?\n- `ALCHEMY_PASSWORD` rotation?\n- `.gitignore` coverage?\n- CI stage naming, state backend, SSO…\n\n</td>\n</tr>\n</table>\n\n### Where naive agents fail\n\n| Footgun | Consequence | Baseline rate |\n|---|---|---:|\n| Inline a secret in `alchemy.run.ts` | Token shipped to GitHub | common |\n| Skip `await app.finalize()` | Orphan resources, surprise bill | common |\n| Forget to gitignore `.env` / `.alchemy/` | Secrets in git history | **3/3 baselines** |\n| No `ALCHEMY_PASSWORD` generated | Future encryption silently breaks | **3/3 baselines** |\n| Miss AWS SSO instructions | Opaque \"credentials not found\" at deploy | **1/1 AWS baseline** |\n\n> Baseline agents fail **15.5 percentage points** of production-readiness checks. See [§ Benchmark](#-benchmark).\n\n### What this skill is\n\n**`alchemy-infra` is the playbook the Alchemy core team would write for agents.**\n\nIt encodes intake questions, security invariants, framework adapters, and state-backend selection into one `SKILL.md`. Any SKILL.md-aware agent (Claude Code, Cursor, Aider, Cline, Codex, custom GPTs) reads it once and scaffolds production-ready Alchemy projects without touching a cloud console.\n\n> **One prompt → deployable project.** Passwords generated, gitignore enforced, types wired, scripts ready.\n\n---\n\n## ✨ Demo\n\n![demo](assets/demo.svg)\n\nOne prompt drives the entire flow: intake, detection, writes, verify.\n\n---\n\n## 📊 Benchmark\n\nThree scenarios. 32 assertions. Side-by-side runs **with** and **without** the skill.\n\n![benchmark](assets/benchmark.svg)\n\n| Scenario | With skill | Baseline | Delta |\n|---|---:|---:|---:|\n| Cloudflare Worker + KV (new project) | **11/11** | 10/11 | +1 |\n| Next.js → Cloudflare (existing app) | **11/11** | 8/11 | +3 |\n| AWS Lambda + DynamoDB (SSO, strict security) | **10/10** | 9/10 | +1 |\n| **Total** | **32/32 (100%)** | 27/32 (84.5%) | **+15.5pp** |\n\nWhere baselines failed:\n\n- ❌ `ALCHEMY_PASSWORD` never generated. Every secret persisted after this point becomes unrecoverable.\n- ❌ `.gitignore` missing `.env` and `.alchemy/`. One careless `git add .` ships your token to GitHub.\n- ❌ AWS SSO instructions missing. User hits \"credentials not found\" at deploy with no guidance.\n\nTrade-off: **+67% tokens, +75% wall time** for production-ready output.\n\nRe-run the benchmark:\n\n```bash\nbash alchemy-infra-workspace/iteration-1/grade.sh\npython3 alchemy-infra-workspace/iteration-1/aggregate.py\nopen alchemy-infra-workspace/iteration-1/review.html\n```\n\n---\n\n## 🔄 The 10-step flow\n\n![flow](assets/flow.svg)\n\nEvery install runs steps 1 through 9. Step 10 (CI/CD) is opt-in.\n\nThe skill does not mutate files until step 3 confirms the plan with the user. No surprises.\n\n---\n\n## 🔐 Security\n\n![security](assets/security-shield.svg)\n\nFull ruleset in [`references/security.md`](references/security.md). Highlights:\n\n- `ALCHEMY_PASSWORD` generated via `openssl rand -base64 32` (or Node `crypto.randomBytes` fallback). 32 bytes, base64. Written to `.env` with `chmod 600`. Never echoed to stdout.\n- `.gitignore` updated idempotently. The script runs `git ls-files` to surface anything already tracked that shouldn't be.\n- Cloudflare API tokens minted with least-privilege scopes: Workers Scripts:Edit, KV/R2/D1/Queue:Edit, Account:Read. Global API Key is refused unless the user insists.\n- AWS auth defaults to SSO via `AWS_PROFILE`. Long-lived `AKIA...` keys are never written to disk.\n- Pre-commit safety: scans for `.env`, `*.pem`, `*.key`, `credentials.json`, and common token regexes (`sk-`, `xoxb-`, `ghp_`, `AKIA...`) before any `git add`.\n\n---\n\n## 📦 Install\n\n### Claude Code via skills.sh\n\n```bash\nclaude skill install https://github.com/aashirjaved/alchemy-infra\n```\n\n### Direct clone (Claude Code, Cursor, Aider, Cline, Codex)\n\n```bash\n# user-global\ngit clone https://github.com/aashirjaved/alchemy-infra.git \\\n  ~/.claude/skills/alchemy-infra\n\n# project-local\ngit clone https://github.com/aashirjaved/alchemy-infra.git \\\n  ./.claude/skills/alchemy-infra\n```\n\n### npx (no Claude required)\n\n```bash\nnpx @aashirjaved/alchemy-infra install         # ~/.claude/skills/alchemy-infra\nnpx @aashirjaved/alchemy-infra install --here  # ./.claude/skills/alchemy-infra\nnpx @aashirjaved/alchemy-infra install --to ./agents/skills\n```\n\nThe installer is a single dependency-free Node script. It copies the skill, preserves executable bits on shell scripts, and strips its own `bin/` and `package.json` from the installed copy.\n\n### `.skill` archive (31 KB)\n\nDownload from [Releases](https://github.com/aashirjaved/alchemy-infra/releases), then in Claude Code:\n\n```\n/skills install alchemy-infra.skill\n```\n\n---\n\n## 💬 Use\n\nOnce installed, the skill triggers automatically on prompts like:\n\n> \"Set up Alchemy in this Next.js repo with a KV binding.\"\n> \"Deploy a Cloudflare Worker with D1 in pure TypeScript.\"\n> \"Migrate this SST project to Alchemy.\"\n> \"Configure AWS Lambda + DynamoDB via Alchemy using my SSO profile.\"\n> \"Add a Cloudflare Queue and worker consumer to my existing alchemy.run.ts.\"\n\nThe agent asks 8 intake questions, confirms the plan in 3 to 5 bullets, then executes.\n\n---\n\n## 🛠 What's inside\n\n```\nalchemy-infra/\n├── SKILL.md                      # 232 lines · decision flow + invariants\n├── README.md                     # this file\n├── LICENSE                       # MIT\n├── package.json                  # npx entry\n├── bin/\n│   └── install.js                # zero-dep installer\n├── assets/                       # README diagrams (SVG)\n├── references/                   # progressive disclosure\n│   ├── cloudflare.md             # 97 lines · resource catalog\n│   ├── aws.md                    # 70 lines · curated + aws-control\n│   ├── frameworks.md             # 107 lines · Vite/Next/SvelteKit/Astro/Nuxt/TanStack\n│   ├── security.md               # 76 lines · strict ruleset\n│   ├── cicd.md                   # 97 lines · GH Actions templates\n│   ├── custom-resources.md       # 80 lines · authoring your own Resource\n│   └── troubleshooting.md        # 62 lines · failure modes + fixes\n├── scripts/                      # safe shell helpers\n│   ├── gen_password.sh           # openssl rand → .env\n│   ├── gitignore_check.sh        # enforce + audit tracked secrets\n│   └── detect_project.sh         # read-only JSON probe of repo state\n└── evals/\n    └── evals.json                # benchmark prompts\n```\n\nSKILL.md stays under 500 lines. Every reference stays under 300 lines.\n\n---\n\n## 🤝 Compatibility\n\n| Tool / runtime | Status | How |\n|---|---|---|\n| Claude Code (CLI, IDE) | ✓ first-class | autoload from `~/.claude/skills/` |\n| Claude.ai | ✓ | upload skill folder or `.skill` archive |\n| Cursor | ✓ | point Cursor Rules at `SKILL.md` |\n| Aider | ✓ | `/read SKILL.md` then chat |\n| Cline / Continue | ✓ | reference SKILL.md from custom instructions |\n| Codex CLI | ✓ | include SKILL.md in workspace |\n| OpenAI Custom GPTs | ✓ | paste SKILL.md as system prompt; attach references/ |\n| skills.sh registry | ✓ | frontmatter compliant |\n\n---\n\n## ❓ FAQ\n\n<details>\n<summary><strong>Will this overwrite my existing alchemy.run.ts?</strong></summary>\n\nNo. Step 1 reads any existing `alchemy.run.ts`, `wrangler.toml`, `sst.config.ts`, etc. If found, the skill switches to \"modify in place\" mode and confirms before any destructive change.\n</details>\n\n<details>\n<summary><strong>What happens if I lose ALCHEMY_PASSWORD?</strong></summary>\n\nEncrypted secrets in state become unrecoverable. There is no documented rotation procedure. The skill treats the password as permanent and refuses to silently overwrite an existing one. You'd have to remove the line manually first.\n</details>\n\n<details>\n<summary><strong>Does this work with Bun? With Node? With pnpm/yarn/npm?</strong></summary>\n\nAll four. Bun is recommended by Alchemy upstream; everything else works. The skill reads your lockfile to detect package manager.\n</details>\n\n<details>\n<summary><strong>Can I use this without Claude?</strong></summary>\n\nYes. SKILL.md is plain Markdown. Paste it as system prompt for any LLM, or load it as instructions in Cursor, Aider, Continue, Cline, or Codex. Shell scripts and helper files are vanilla bash and Node. No Claude APIs.\n</details>\n\n<details>\n<summary><strong>Does it support providers other than Cloudflare and AWS?</strong></summary>\n\nYes. The skill is cloud-agnostic. It asks during intake and loads `references/<provider>.md` if present. Cloudflare and AWS ship today. Neon, PlanetScale, Stripe, Vercel, GitHub, etc. are documented in [`references/cloudflare.md`](references/cloudflare.md) and the upstream [Alchemy docs](https://alchemy.run/providers/).\n</details>\n\n<details>\n<summary><strong>How do I contribute?</strong></summary>\n\nPRs welcome. Constraints: SKILL.md stays under 500 lines, every reference under 300 lines. Add new evals to `evals/evals.json` and re-run the benchmark before submitting.\n</details>\n\n---\n\n## 📜 License\n\nMIT. See [LICENSE](LICENSE).\n\n---\n\n<div align=\"center\">\n\nBuilt by [@aashirjaved](https://github.com/aashirjaved) · Powered by [Alchemy](https://github.com/alchemy-run/alchemy) · Distributed via [skills.sh](https://skills.sh)\n\n**[Install now →](#-install)**\n\n</div>\n","readmeFilename":"README.md"}