ph-inspector-seguridad
Access control, checks that fail open, credentials, database functions left executable by the public, secrets, endpoints with no rate limit, exposed personal data. Its yardstick is the OWASP Top 10:2025.
φρόνησις
Claude Code agents
A technical team that looks where you can't: a different area every day, working out what hurts most, fixing it and checking nothing broke. It leaves you a PR and stops there. Merging is publishing, and that one is yours.
v2.5.0 · 11 October 2026
Where it comes from
Phronesis was born running a product in production: a marketplace with real users, real payments and daily deploys. For months these agents inspected it, fixed it and shipped it.
Every mistake they made ended up written into their instructions. When they were packaged up, the stack, the routes and the domain were stripped out; the judgement stayed.
That last number is the one that matters. An agent doesn't learn on its own: the only thing that persists is its instruction file. Every rewrite is a real mistake that got written down, and the agent reads it before every run: what it got wrong once, it doesn't get wrong again.
The name
φρόνησις in Greek, «FRÓ-nē-sis»
Aristotle called it phronesis: practical wisdom, knowing what to do in a particular case. It doesn't come from a book; it is earned through experience, by getting things wrong and correcting them. That is what these agents keep in their instructions.
Aristotle, Nicomachean Ethics, Book VI
The cycle
One run of /ph-ciclo does all of this end to end, and always finishes on a decision of yours.
One area, following the day's rotation. If you've declared a business focus, it looks at that too.
Findings go into a backlog versioned in your repo, after checking they're real.
Up to four items on your integration branch, one commit each.
Typecheck, build and a smoke run with the server up. If something breaks, it fixes it or reverts the commit that caused it.
With everything that changed. You review, merge or reject. Merging is publishing; no agent does it for you.
The week
If a day turns up nothing, it pays down a debt from your register instead. And if there's no debt it can pay on its own, it says so. It doesn't invent work to look busy.
One run
The agents
Install only the ones you need. The mejora plugin is the heart; the rest come in when they're needed.
mejora The continuous improvement loopph-inspector-seguridad
Access control, checks that fail open, credentials, database functions left executable by the public, secrets, endpoints with no rate limit, exposed personal data. Its yardstick is the OWASP Top 10:2025.
ph-inspector-seo
Per-route metadata, structured data, canonicals, sitemap and noindex agreeing with each other. Its yardstick is Google's documentation, not blogs.
ph-inspector-codigo
Your architecture, newborn duplication — the cheapest moment to unify — dead code, types.
ph-inspector-ux
Friction in the main flow, empty, loading and error states, microcopy. It works from Nielsen's heuristics and NN/g severity. It never decides product: that it leaves to you.
ph-inspector-a11y
WCAG 2.2 AA: contrast, focus lost when a modal closes, mouse-only controls, states that are never announced.
ph-inspector-performance
Core Web Vitals, bundle, images, N+1 queries, runtime CPU limits.
ph-inspector-negocio
Looks at what people did, not at the code. Bans percentages over fewer than 30 cases and delivers one finding, not a dashboard.
ph-validador-qa
Typecheck, build and a real smoke run. It holds a veto: fixes the obvious and reverts the rest.
ph-curador-memoria
Routes what was learned. Never copies, and keeps a ceiling of 20 active lessons.
ph-sintetizador-usabilidad
From notes of a user test to backlog items.
ops Deploys and routinesph-gestor-deploy
The full protocol, with an inventory and a gate that waits for your word. Right before merging, it checks again whether anyone is still working, and if it lowers the risk, it tells you why.
ph-verificador-deploy
Checks that what's live is what you approved.
ph-vigilante-rutinas
Watches that the scheduled tasks are actually running.
ph-triage-correo
Sorts the project's mail by urgency and required action.
growth Getting usersph-prospector
Prospects from public sources, categorised and with the address verified. It never invents a contact detail.
ph-copywriter
The personalised email, with an anti-blacklist checklist.
ph-estratega
Reviews the loop, watches sender reputation and delivers one to three improvements a day.
contenido What gets publishedph-director-arte
Checks every piece against the system and proposes how the style should evolve, with the results of what was already published in view.
ph-jefe-copy
Makes sure the text sounds like a person and not like generated marketing. It looks at which posts got saved and shared, not just liked.
The three rules
Honest limits
It's in the repo's README, and it's here for the same reason.
Install
It's added as a Claude Code plugin marketplace. Then /ph-iniciar reads your repo and writes the configuration.
/plugin marketplace add Clagoss/phronesis-v2