{"_id":"@alealle62/task-flow-ai","_rev":"4-7888fe9131085e0d959b0fc36ce09090","name":"@alealle62/task-flow-ai","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@alealle62/task-flow-ai","version":"0.1.0","license":"MIT","_id":"@alealle62/task-flow-ai@0.1.0","maintainers":[{"name":"alealle62","email":"basketallegrini@gmail.com"}],"bin":{"task-flow-ai":"dist/cli.js"},"dist":{"shasum":"0e581b3e194a0a06fae22b840db12176c7b3b54c","tarball":"https://registry.npmjs.org/@alealle62/task-flow-ai/-/task-flow-ai-0.1.0.tgz","fileCount":119,"integrity":"sha512-K9CJsED9OSYqxEX03hb5kdrqfNQITCR3saNEff+2iS6NJM4jj9WRv+Q5vre0qqYUyheq61FuCrijKAi3ilDBkQ==","signatures":[{"sig":"MEQCIBqpd1ot9F0WF9FxB15Ta1x+JnnsNa1S5WrcfypQbv09AiAg6mM7c5z/zLBXYl46C7SdhYGl/DQyftCbmLmZ+tGMuQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":314434},"type":"module","engines":{"node":">=20"},"gitHead":"cc352c053973db9c7719e100cf6ac80b3888deab","scripts":{"dev":"tsx cli/cli.ts","build":"npm run build:cli && npm run build:web","dev:web":"npm run dev --workspace @task-flow-ai/web","build:cli":"tsc && chmod +x dist/cli.js","build:web":"npm run build --workspace @task-flow-ai/web","typecheck":"tsc --noEmit && npm run typecheck --workspace @task-flow-ai/web","prepublishOnly":"npm run build"},"_npmUser":{"name":"alealle62","email":"basketallegrini@gmail.com"},"workspaces":["web"],"_npmVersion":"11.11.1","description":"A six-phase agent pipeline you approve from the browser.","directories":{},"_nodeVersion":"25.8.2","dependencies":{"yaml":"^2.6.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","typescript":"^5.7.3","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/task-flow-ai_0.1.0_1787046098018_0.7646272009958854","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@alealle62/task-flow-ai","version":"0.1.1","license":"MIT","_id":"@alealle62/task-flow-ai@0.1.1","maintainers":[{"name":"alealle62","email":"basketallegrini@gmail.com"}],"bin":{"task-flow-ai":"dist/cli.js"},"dist":{"shasum":"748529695e71a76860ecb35101cf8e061782b585","tarball":"https://registry.npmjs.org/@alealle62/task-flow-ai/-/task-flow-ai-0.1.1.tgz","fileCount":121,"integrity":"sha512-8ChXkPzNiPgLUIEdMhfEBpLWiXDdi8ydSCdvcjmrdhpZfzIG/jwHubt1LZyrD7eLym/gAzyB6sO3ZQss8y6QAA==","signatures":[{"sig":"MEQCIFpPTD1cOYbm7mvq4LrX7rcwosz1F7elyfefBR2Ce9IsAiA4aA3OrECors1U+l0Cd3txTLjsFILHhvoFKZiTJg5DEA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":322742},"type":"module","engines":{"node":">=20"},"gitHead":"454b901f67421151a9cf7d52e4fd508fa60326c8","scripts":{"dev":"tsx cli/cli.ts","build":"npm run build:cli && npm run build:web","dev:web":"npm run dev --workspace @task-flow-ai/web","build:cli":"tsc && chmod +x dist/cli.js","build:web":"npm run build --workspace @task-flow-ai/web","typecheck":"tsc --noEmit && npm run typecheck --workspace @task-flow-ai/web","prepublishOnly":"npm run build"},"_npmUser":{"name":"alealle62","email":"basketallegrini@gmail.com"},"workspaces":["web"],"_npmVersion":"11.11.1","description":"A six-phase agent pipeline you approve from the browser.","directories":{},"_nodeVersion":"25.8.2","dependencies":{"yaml":"^2.6.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","typescript":"^5.7.3","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/task-flow-ai_0.1.1_1787074039230_0.6765534051535556","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@alealle62/task-flow-ai","version":"0.1.2","license":"MIT","_id":"@alealle62/task-flow-ai@0.1.2","maintainers":[{"name":"alealle62","email":"basketallegrini@gmail.com"}],"bin":{"task-flow-ai":"dist/cli.js"},"dist":{"shasum":"3e572d77ebf0046c1cd84895ba1d8f956a5e73d7","tarball":"https://registry.npmjs.org/@alealle62/task-flow-ai/-/task-flow-ai-0.1.2.tgz","fileCount":123,"integrity":"sha512-R1uJ98cdxmhDcLqJfmSYeGagZFCHKS2pbWSvR+AT+3uOf1KhV+aUuVCfn7fC6Q0EnsQcctTFCiwfH9kcx2IudQ==","signatures":[{"sig":"MEYCIQCUpDeZqHqXkwKGi3PlN2GyyHDqAm6SzD4ts0/KpBkvPgIhAOxlIfgqq7h/NsyuT2i3c5qavZwij/pgV1vROhtgr31I","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":327354},"type":"module","engines":{"node":">=20"},"gitHead":"2501288fb8348cd3b3b3dce205fb3ba7f93aa6a2","scripts":{"dev":"tsx cli/cli.ts","build":"npm run build:cli && npm run build:web","dev:web":"npm run dev --workspace @task-flow-ai/web","build:cli":"tsc && chmod +x dist/cli.js","build:web":"npm run build --workspace @task-flow-ai/web","typecheck":"tsc --noEmit && npm run typecheck --workspace @task-flow-ai/web","prepublishOnly":"npm run build"},"_npmUser":{"name":"alealle62","email":"basketallegrini@gmail.com"},"workspaces":["web"],"_npmVersion":"11.11.1","description":"A six-phase agent pipeline you approve from the browser.","directories":{},"_nodeVersion":"25.8.2","dependencies":{"yaml":"^2.6.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","typescript":"^5.7.3","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/task-flow-ai_0.1.2_1787076227461_0.6905729279562483","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@alealle62/task-flow-ai","version":"0.1.3","description":"A six-phase agent pipeline you approve from the browser.","license":"MIT","type":"module","bin":{"task-flow-ai":"dist/cli.js"},"engines":{"node":">=20"},"workspaces":["web"],"scripts":{"build":"npm run build:cli && npm run build:web","prepublishOnly":"npm run build","build:cli":"tsc && chmod +x dist/cli.js","build:web":"npm run build --workspace @task-flow-ai/web","dev":"tsx cli/cli.ts","dev:web":"npm run dev --workspace @task-flow-ai/web","typecheck":"tsc --noEmit && npm run typecheck --workspace @task-flow-ai/web"},"dependencies":{"yaml":"^2.6.1"},"devDependencies":{"@types/node":"^22.10.2","tsx":"^4.19.2","typescript":"^5.7.3"},"gitHead":"5d2431fb1c6b289bbabbac08ee1e77040d9d8f74","_id":"@alealle62/task-flow-ai@0.1.3","_nodeVersion":"25.8.2","_npmVersion":"11.11.1","dist":{"integrity":"sha512-6ATHkpN9/VaK2g7PqB98Kw/mKqPSpq1AoZdAx7P8i7w/GGD0ca7LDeaN+aUM0Db8yiredbwRodoE6wGZlrHiBw==","shasum":"38c893b1b2346ff051561d16828da18cdeb8199b","tarball":"https://registry.npmjs.org/@alealle62/task-flow-ai/-/task-flow-ai-0.1.3.tgz","fileCount":69,"unpackedSize":244642,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC6Xu1I90SolU6An+H+wUlkwfF9lVXVvb/2HSQ4Z1dJ2QIgFu6Xf51ZXWoufdCagxY+OvkuYE62tvOKpZT8QqdHljo="}]},"_npmUser":{"name":"alealle62","email":"basketallegrini@gmail.com"},"directories":{},"maintainers":[{"name":"alealle62","email":"basketallegrini@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/task-flow-ai_0.1.3_1787082893271_0.7194494292598219"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-18T09:41:37.819Z","modified":"2026-08-18T19:54:53.654Z","0.1.0":"2026-08-18T09:41:38.167Z","0.1.1":"2026-08-18T17:27:19.437Z","0.1.2":"2026-08-18T18:03:47.614Z","0.1.3":"2026-08-18T19:54:53.465Z"},"license":"MIT","description":"A six-phase agent pipeline you approve from the browser.","maintainers":[{"name":"alealle62","email":"basketallegrini@gmail.com"}],"readme":"# task-flow-ai\n\n**A coding agent that stops and asks before it writes.**\n\n## The problem\n\nYou give a coding agent a task. It reads, decides, and edits — all in one go,\ncarrying two hundred messages of context. By the time it touches your code you\nhave no idea what it decided, and by the time you find out, it is already done.\n\n`task-flow-ai` splits that into six phases. Each is a fresh agent that reads\nonly what the phase before it wrote down. It stops in the middle and shows you\nthe plan. Nothing is written until you say so.\n\n```mermaid\nflowchart LR\n    A(intake) --> B(explore) --> C(plan) --> STOP{you approve} --> D(implement) --> E(review) --> F(security)\n\n    classDef writer fill:#fbe9ec,stroke:#9c2b3c,stroke-width:2px,color:#7d2231\n    classDef gate fill:#fdf3e0,stroke:#9a6a12,stroke-width:2px,color:#7a520c\n    class D writer\n    class STOP gate\n```\n\nOnly **implement** can change your code. One of the other five has no writing\ntool at all; the four that need a shell to read — `git log`, `grep`, `cat` —\nare refused a write anywhere in your project by the filesystem itself. It is\nnot a rule any of them is asked to follow.\n\n## Install\n\nNeeds [Claude Code](https://claude.com/claude-code) installed and signed in, and\nNode 20 or newer.\n\n```bash\nnpm install -g @alealle62/task-flow-ai\n```\n\nOr, if you use an agent that reads skills — Claude Code, Cursor, Copilot and a\ndozen others — install it as one:\n\n```bash\nnpx skills add https://github.com/AleAlle62/task-flow-ai\n```\n\nOr as a Claude Code plugin:\n\n```bash\nclaude plugin marketplace add AleAlle62/task-flow-ai\n```\n\nTo work on it rather than with it, clone and build:\n\n```bash\ngit clone https://github.com/AleAlle62/task-flow-ai\ncd task-flow-ai\nnpm install && npm run build && npm link\n```\n\n## Use it\n\nOne command. Go to your project and run it:\n\n```bash\ntask-flow-ai run\n```\n\nYour browser opens, you type what needs doing, and the run starts. The plan\nwaits for you there.\n\n```bash\ntask-flow-ai run \"fix the empty cart bug\"     # say it up front\ntask-flow-ai run --model claude-haiku-4-5     # the only option there is\n```\n\nEverything else it works out for itself:\n\n| | |\n| --- | --- |\n| An unfinished run in this project | offers to continue it |\n| Port `4179` busy | takes a free one |\n| No browser | asks in the terminal |\n| A project carrying its own phases | names the files and asks first |\n\n## How it works\n\n```mermaid\nflowchart LR\n    A[you say what<br/>needs doing] --> B[six phases run<br/>each writes a document] --> C[you read the plan<br/>and approve] --> D[the code<br/>gets written]\n\n    classDef gate fill:#fdf3e0,stroke:#9a6a12,stroke-width:2px,color:#7a520c\n    class C gate\n```\n\nThree parts, and the arrows only point one way:\n\n```mermaid\nflowchart LR\n    Page[browser page<br/><i>read the plan, decide</i>] <--> Tool[task-flow-ai<br/><i>holds the order</i>]\n    Tool --> Agent[your coding agent<br/><i>does the thinking</i>]\n    Agent --> Repo[(your project)]\n\n    classDef quiet fill:#f4f6f9,stroke:#c3ccd6,color:#3c4753\n    class Repo quiet\n```\n\nThe tool never sees a model. The agent is the one you already installed, on your\naccount — this project has no service of its own, so nothing goes anywhere it\nwas not already going. The page is served on your machine only and disappears\nwhen the run ends.\n\nEvery phase leaves its document in `.taskflow/runs/<id>/`, so a run can be\nreread tomorrow and resumed after a crash. Nothing removes old ones on its own —\nrun `task-flow-ai clean` when the folder gets big; it keeps the 20 most recent\nfinished runs and never touches one still unfinished.\n\n## The boundary\n\nOne phase may change your code, checked in six places:\n\n| When | What happens |\n| --- | --- |\n| you write a phase | it declares what it may do |\n| before anything runs | a pipeline with two writing phases is refused |\n| while a phase runs | it is handed only its own tools |\n| every command it runs | only the ones its phase was granted, with no exception for being sandboxed |\n| around every command | no network, no credentials, no machine startup files |\n| for the five that only read | the filesystem refuses them a write anywhere in your project |\n\nThe sandbox is the one that matters most: allowing `cat` says nothing about\n`cat ~/.ssh/id_rsa`, and the writing phase has to run your tests, which means\ncommands nobody listed in advance. So it runs walled in — a phase talked into\nrunning `curl` runs it, and it fails.\n\nThe last two rows are there because of what turning the sandbox on used to do.\nClaude Code treats being sandboxed as reason enough to stop checking which\ncommands a phase may run, and that is its default, so switching the wall on\nquietly switched the list off: a phase allowed `ls` and `cat` could run\nanything, and four of the five read-only phases hold a shell. Both rows now\nsay no independently — one at the permission layer, one at the filesystem —\nbecause the lock that failed here was a default nobody had to change.\n\n## Before you rely on it\n\n- **Claude Code only.** One provider adapter exists.\n- **Needs a working sandbox.** If one cannot start, the run stops rather than\n  going ahead without it.\n- **Your repo's content reaches the phases**, and a file in it can contain\n  sentences aimed at the agent. They end up in the plan, and the plan is what\n  you approve. Read it.\n- **Write paths are checked after the fact**, not prevented.\n- **The dashboard is local only.** It binds to `127.0.0.1`.\n- **Version 0.1.3.**\n\n## The repository\n\n```mermaid\nflowchart LR\n    Files[\"agents/ · pipelines/<br/><i>the phases and their order</i>\"] --> Engine[\"cli/<br/><i>runs them, holds the boundary</i>\"] --> Page[\"web/<br/><i>the page you decide on</i>\"]\n\n    classDef plain fill:#f4f6f9,stroke:#c3ccd6,color:#3c4753\n    class Files,Page plain\n```\n\nThe phases are markdown files and the order is one YAML file — edit them without\ntouching code. Everything vendor-specific lives in one folder, which is why\nswapping the agent underneath touches only that.\n\nThere is an illustrated map of the whole thing in [`docs/index.html`](docs/index.html)\n— clone the repo and open it in a browser, GitHub will only show you its source.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}