Sponsor Suno AI Music arrow_forward
Slash Command

Bulletproof Skill

Harden skills against rationalization and bypass behaviors

Type
Slash Command
GitHub stars
339
License
MIT
Repo last updated
Sep 24, 2026
Source file
README.md

What Bulletproof Skill is

Bulletproof Skill is a slash command published in the athola/claude-night-market repository on GitHub, which has about 339 stars. The repository describes itself as: “23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context optimization, research, and multi-LLM delegation. 186 skills, 128 commands, 54 agents.”

A slash command is a reusable prompt saved as a markdown file and run by typing its name after a slash. In Claude Code, custom commands have been merged into skills: a file in .claude/commands/ and a skill folder in .claude/skills/ both create the same kind of command, and existing command files keep working.

Bulletproof Skill gives you a repeatable way to run the same instructions without retyping them, optionally with arguments.

How to install Bulletproof Skill

Claude Code

  1. Download README.md from the repository.
  2. Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md.
  3. Run it by typing / followed by its name.

Claude Cowork

  1. Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it.
  2. In Customize → Skills, click +, then upload the ZIP.
  3. Run it from any task with / and the skill name.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from README.md, shared under the repository's MIT license. Read the full file on GitHub.

A plugin marketplace for Claude Code. Install only the plugins you need to run git workflows, code review, spec-driven development, and autonomous agents from inside your Claude Code session.

Written for a practitioner: someone who already uses Claude Code and wants to know what these plugins do and whether to install them. If you are new to Claude Code, start with the official docs. For the design rationale behind a plugin, see the book.

Install

Requires Claude Code 2.1.16+ and Python 3.9+ for hooks.

# Add the marketplace, then install the plugins you want
/plugin marketplace add athola/claude-night-market
/plugin install sanctum@claude-night-market    # Git workflows
/plugin install pensive@claude-night-market    # Code review
/plugin install spec-kit@claude-night-market   # Spec-driven dev

Run claude --init once after installing. Two other paths exist: [npx skills][skills-cli] pulls the skill files alone into .claude/skills/, without commands, agents, or hooks, and opkg i gh@athola/claude-night-market --plugins sanctum,pensive installs whole plugins from the openpackage.yml each one ships. Full options are in the Installation Guide.

> If the Skill tool is unavailable, read skill files directly > at plugins/{plugin}/skills/{skill-name}/SKILL.md.

Everyday Use

Night Market is built around the loop you already work in. A typical feature runs end to end on a handful of commands:

  1. Start a feature. /attune:mission routes you through brainstorm, specify, plan, and execute phases.
  2. Write the code. imbue enforces a failing test first, so the test is written before the implementation.
  3. Review before you push. /full-review runs a multi-discipline pass; /refine-code cleans up duplication and dead code.
  4. Ship it. /prepare-pr runs quality gates and drafts a description that says who the change is for, where it lands inside and outside the codebase, and when it is fully integrated.
  5. Pick up where you left off. /catchup rebuilds context from recent git history after a break.

The commands you reach for most:

Full task-by-task walkthroughs are in the [Common Workflows Guide][workflows].

What's Inside

23 plugins in four layers. Each installs independently, and dependencies pull their shared runtime automatically.

Foundation is the base every other layer builds on: leyline (auth, quotas, error patterns, trust verification), sanctum (git, commits, PR prep, sessions), and imbue (TDD enforcement, proof-of-work, scope guarding).

Utility handles cross-cutting concerns: conserve (context and token optimization), conjure (delegation to seven external model CLIs plus a local runner), hookify (a behavioral rules engine with a security catalog), egregore (autonomous agent orchestration), herald (notifications), and oracle (local ML inference).

Domain is where the day-to-day work happens: pensive (code and architecture review), attune (project lifecycle), spec-kit (spec-driven development), parseltongue (Python), minister (GitHub issues and DORA metrics), memory-palace (knowledge organization), archetypes (architecture paradigms), gauntlet (codebase learning), phantom (computer use), scribe (documentation and slop detection), scry (recordings), tome (research), and cartograph (codebase visualization).

Meta improves the system itself: abstract (skill authoring, hook development, evaluation, and skill-stability tracking).

The full skill, command, and agent inventory is in the Capabilities Reference.

Safety

> ⚠️ Plugins run inside your Claude Code session and can read or > edit your repo, run shell commands, and call external services. > Review any plugin before installing it.

Three guards reduce the blast radius, but none replace your own review:

  • TDD gates (imbue) block implementation writes that lack a failing test.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Bulletproof Skill?

Bulletproof Skill is a slash command for Claude Code and Claude Cowork from the athola/claude-night-market repository on GitHub. Harden skills against rationalization and bypass behaviors

How do I install Bulletproof Skill in Claude Code?

Download README.md from the repository. Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md. Run it by typing / followed by its name.

Can I use Bulletproof Skill in Claude Cowork?

Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it. In Customize → Skills, click +, then upload the ZIP. Run it from any task with / and the skill name.

Is Bulletproof Skill safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.