← Plugin catalog
Developer Tools

NaCl

ITSalt v0.2.2

Publisher description

From the marketplace listing

NaCl (reading as Natrium Chloride) is an open-source full-SDLC framework, and its core innovation is how it solves the hardest problem in agentic development: storing and retrieving project knowledge. Instead of markdown specs that agents must re-read every session, all project knowledge — requirements, architecture decisions, entities, rules, and their relationships — lives in a Neo4j knowledge graph as first-class queryable objects. The measured effect: planning a single use case takes ~550 tokens (one targeted Cypher query) instead of ~150,000 tokens (reading a ~70-file markdown spec, because the agent doesn't know in advance where the relevant facts live) — a 99.6% reduction in context per use case, repeated in every planning session. Around the graph we've built the full tooling for agentic development and testing: 57 skills covering BA → SA → TDD development → review → QA → release, quality gates before production, and an autonomous goal orchestrator (/nacl-goal). The framework answers "how is this built and why" for any part of the system, regardless of project scale or iteration count. Benchmarked on a real production project (EV charging station management): a classical team was estimated at 5,831 person-hours; running fully on NaCl the same scope takes 1,480 person-hours — 4x fewer person-hours and 60% lower cost.

Language: English · Automatically detected from descriptions.

Files & skills

File archives

Plugin package163 files · 372 KBBrowse files →
Skill instructions
nacl-ba1.26 KB

View saved version →

---
name: nacl-ba
description: Route NaCl business analysis across context, processes, entities, roles, rules, workflows, validation, sync, and handoff. Use for graph-first BA work.
---

# NaCl Business Analysis

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the BA contract](resources/workflows/references/ba-codex-contract.md), and
[the core methodology](resources/workflows/nacl-core/SKILL.md).

Require a loaded project `nacl_neo4j` MCP and verified read canary. Otherwise return
`BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`.

Choose exactly one relevant packaged leaf under `resources/workflows/`:
`nacl-ba-full`, `nacl-ba-context`, `nacl-ba-import-doc`,
`nacl-ba-from-board`, `nacl-ba-roles`, `nacl-ba-process`, `nacl-ba-entities`,
`nacl-ba-rules`, `nacl-ba-glossary`, `nacl-ba-workflow`, `nacl-ba-analyze`,
`nacl-ba-validate`, `nacl-ba-sync`, or `nacl-ba-handoff`. State the leaf.

Use only project-local Neo4j MCP Cypher tools. Preserve explicit project
identity, BA write approval, parameterization, lease/fence/revision rules,
transaction/idempotency, and read-back from the leaf and runtime contract.
Missing graph primitives stay `BLOCKED`; confirmed file-only preparation may
report only its own honest status.

Referenced files: 19

nacl-diagnose1.84 KB

View saved version →

---
name: nacl-diagnose
description: Diagnose NaCl project health, drift, status, reconciliation, or next work using read-only evidence and actionable closed outcomes.
---

# NaCl Diagnose

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md).
Before requiring MCP, invoke the bundle-relative
[plan runner](resources/bootstrap/plan-project-graph.mjs) once with
`--diagnose-only` and the explicit absolute project root. This inspection is
file-only: never call Docker, use the network, mutate a file, or infer graph
truth.

Preserve its exact `status`, `code`, `initializationState`, canonical root, and
per-file digest/absence evidence:

- `NOT_RUN/PROJECT_MCP_NOT_CONFIGURED` + `UNINITIALIZED`: report the local
  state and route to `nacl-init`; do not turn it into an error.
- `BLOCKED/*` + `BLOCKED`: stop on malformed, unsafe, or partial local state.
- `PARTIALLY_VERIFIED/PROJECT_MCP_VERIFICATION_REQUIRED` +
  `INITIALIZED_LOCAL_FILES`: report that files exist but graph truth and
  overall initialization remain unverified. If the project MCP is absent, ask
  for a new task and stop without replacing this with
  `BLOCKED/PROJECT_MCP_NOT_CONFIGURED`.

Only after local initialized files and a loaded project `nacl_neo4j` MCP are
both present, read
[the diagnostic workflow](resources/workflows/nacl-tl-diagnose/SKILL.md)
and [the evidence taxonomy](resources/workflows/references/verification-evidence.md).
Use MCP reads for graph truth. If the initialization ceremony in `nacl-init`
has not completed, route there before ordinary diagnosis.

Route to one packaged diagnostic leaf. Keep the run read-only unless the user
separately requests an artifact. Use only project-local Neo4j MCP reads and
preserve exact graph status. Never infer graph truth from a stale local status
file; missing named evidence is an honest closed non-success.

Referenced files: 6

nacl-fix931 Bytes

View saved version →

---
name: nacl-fix
description: Diagnose and repair a bounded NaCl defect with spec-first classification, a regression test, verification, and honest status propagation.
---

# NaCl Fix

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the fix workflow](resources/workflows/nacl-tl-fix/SKILL.md), and
[the TL contract](resources/workflows/nacl-tl-core/references/tl-codex-contract.md).
Require a loaded project `nacl_neo4j` MCP and verified read canary; otherwise return
`BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`.

Use the narrower hotfix/reopened/regression leaf only when its trigger applies.
Use only project-local Neo4j MCP tools and preserve diagnostic/spec versus
implementation/review separation, Task claim/fence/revision/idempotency,
`APPROVE_TL_WRITE`, RED-to-GREEN evidence, read-back and release. Missing proof
or a required primitive stays `BLOCKED`.

Referenced files: 4

nacl-goal846 Bytes

View saved version →

---
name: nacl-goal
description: Plan or conduct a bounded NaCl objective with explicit checks and closed statuses. Use for multi-step goals and resumable orchestration.
---

# NaCl Goal

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the goal workflow](resources/workflows/nacl-goal/SKILL.md), and
[the goal contract](resources/workflows/references/goal-codex-contract.md).
Require a loaded project `nacl_neo4j` MCP and verified read canary for graph-backed
work; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to
`nacl-init`.

Select one bounded alias/leaf and state its checks. Use only project-local
Neo4j MCP tools. Preserve preview, proof, refusal, confirmation, identity,
lease/fence/revision and read-back gates. A goal never promotes a child
non-success into `VERIFIED`.

Referenced files: 5

nacl-init6.23 KB

View saved version →

---
name: nacl-init
description: Inspect or initialize a NaCl project with a per-project Neo4j Community graph and project-local MCP. Use for first setup, bootstrap, and repair planning.
---

# NaCl Init

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md).

This entry must work before any project MCP exists. Never call an installation
doctor, a package gateway, or a checkout-relative/global skill path.

Resolve one explicit absolute project root. For an empty new project without
`config.yaml`, invoke the bundle-relative
[project-creation planner](resources/bootstrap/plan-project-creation.mjs)
with the root, project name, optional one-line description, and optional stack.
It performs no writes. Present its exact `config.yaml`, `AGENTS.md`, Git action,
`planHash`, and `CREATE_NACL_PROJECT:<sha256>` confirmation, then stop.

After the user repeats that exact confirmation, invoke the bundle-relative
[project-creation applier](resources/bootstrap/apply-project-creation.mjs)
with the same inputs, `plan-hash`, and confirmation. It recomputes the plan
under a create lock before writing. For a genuinely empty non-Git directory it
creates `config.yaml` and concise repository-specific `AGENTS.md`, initializes
Git and commits only those initial artifacts. It preserves an existing
`AGENTS.md` and never auto-adopts a non-Git directory containing files or a
linked worktree. Stop on any non-success result.

`AGENTS.md` records durable project context, constraints, and verified commands;
keep it concise and use a closer nested `AGENTS.md` for directory-specific
rules. Never put credentials in it. For an existing `config.yaml` without a
stable `project.id`, present the exact add-only config change and stop for
confirmation before writing it; never derive identity during a read.

Before bootstrap, invoke the bundle-relative
[plan runner](resources/bootstrap/plan-project-graph.mjs) with the
explicit root, ID, database, and chosen loopback Bolt/HTTP ports. This command
is read-only: it performs no Docker call, network request, or mutation. Show
its exact plan fields, `planHash`, and fresh
`INIT_LOCAL_GRAPH:<project-id>:<sha256>` token, then stop. Never accept the old
static token or reconstruct a token manually.

After the user repeats that exact token, invoke the bundled POSIX or PowerShell
runner, respectively the
[POSIX runner](resources/bootstrap/setup-project-graph.sh) or
[PowerShell runner](resources/bootstrap/setup-project-graph.ps1), with
the same root, ID, database, ports, and token. Never pass a password. The
runner recomputes the plan immediately before its first mutation; stale or
mismatched state is `BLOCKED/PLAN_TOKEN_STALE` with zero mutation.

Treat the exact token as an execution request, not as a reason to re-plan,
diagnose, or ask for another confirmation. Run the selected runner exactly
once, capture its complete stdout and stderr, and do not infer project state
while it is running. The runner's terminal machine-readable line is the sole
authority for the outcome:

- `NACL_SKILLS_ONLY_BOOTSTRAP: status=... code=...` is the successful
  bootstrap receipt.
- `NACL_GRAPH_RESULT: status=... code=...` is a blocked, failed, or
  partially verified bootstrap receipt.

Report those fields verbatim. Never claim `PARTIAL_BOOTSTRAP_STATE`, missing
files, or an incomplete bootstrap from an LLM inference, a directory name, or
a prior message. If the runner reports `FAILED` with `rollback=VERIFIED`,
report that failure and rollback; the graph bootstrap is not partial and no
recovery plan is needed. A retry requires a newly generated plan and fresh
user confirmation. Only if the runner reports `PARTIALLY_VERIFIED` with
`rollback=INCOMPLETE`, invoke `plan-project-graph.mjs --diagnose-only` once,
then report the returned JSON evidence without embellishment. If no terminal
receipt is produced, report `RUNNER_RECEIPT_MISSING` and run that same
read-only diagnosis; do not assert a state before its result.

Preserve the runner's status/code. A successful runner returns
`PARTIALLY_VERIFIED/RESTART_REQUIRED` with `bootstrap=VERIFIED` and
`initialization=NOT_RUN`. Then stop and ask the user to open a new task in this
project so Codex loads the newly created project `.codex/config.toml`. The
current task must never report overall initialization `VERIFIED`.

In the new task, overall initialization is `VERIFIED` only after all of these
same-task gates succeed through the actual project `nacl_neo4j` MCP:

1. Record real MCP `initialize` and `tools/list` discovery, requiring the exact
   `read-cypher` and `write-cypher` tool names. Missing discovery is closed
   non-success.
2. Run graph connectivity health, read the complete
   `nacl-graph-gateway` schema ledger, require versions 1–3 with their packaged
   checksums, and read back every required constraint.
3. Execute the bundled named read `sa_statistics_extensions` unchanged and
   record its result. A generic `RETURN 1` alone is insufficient.
4. Invoke the plan runner with `--verification-plan`, show its random
   idempotency key, parameterized write/read-back statements, `planHash`, and
   exact `VERIFY_NACL_INITIALIZATION:<project-id>:<sha256>` token, then stop.
5. After the user freshly repeats that token, make exactly one parameterized
   write-canary call with the plan's statement/parameters, followed by a
   separate read call with the read-back statement. Require matching project
   ID, idempotency key, and integer revision. Never accept a static, old, or
   reconstructed verification token. Never automatically retry the write; any
   failure requires a new verification plan, new idempotency key, and fresh
   user confirmation.

Return these exact result fields: `status`, `code`, `initializationState`,
`mcpServerKey`, `mcpInitialize`, `mcpToolsList`, `readTool`, `writeTool`,
`graphHealth`, `schemaVersion`, `schemaChecksum`, `namedRead`, `writeCanary`,
and `writeReadback`. Set `status=VERIFIED`, `code=INITIALIZATION_VERIFIED`, and
`initializationState=VERIFIED` only when every field is verified; otherwise
preserve the closed failing status/code.

Optional agent profiles remain create-only and require a separate path-by-path
plan and confirmation. On `AGENT_PROFILE_CONFLICT`, never overwrite: ask the
user to move or back up the conflicting file, then produce a fresh plan before
any retry.

Referenced files: 39

nacl-migrate978 Bytes

View saved version →

---
name: nacl-migrate
description: Plan or execute confirmed NaCl methodology migrations for legacy, BA, or SA artifacts with backups, validation, and read-back.
---

# NaCl Migrate

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the migration workflow](resources/workflows/nacl-migrate/SKILL.md), and
[the migration rules](resources/workflows/references/migration-rules.md).
Require a loaded project `nacl_neo4j` MCP and verified read canary for graph
migration; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to
`nacl-init`.

Choose the exact migration leaf. Present before-state, backup, write plan,
confirmation and validation before mutation. Use only project-local Neo4j MCP
tools and packaged scripts. Preserve schema lease/fence, additive ordered
migrations, checksum ledger and read-back. File-only conversion retains its
own backup and confirmation. An unrepresented domain migration stays
`BLOCKED`.

Referenced files: 7

nacl-publish924 Bytes

View saved version →

---
name: nacl-publish
description: Render, package, ship, release, deploy, or publish NaCl outputs with explicit external-write authorization and verified evidence.
---

# NaCl Publish

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the publish workflow](resources/workflows/nacl-publish/SKILL.md), and
[the render workflow](resources/workflows/nacl-render/SKILL.md).
For graph-derived evidence, require a loaded project `nacl_neo4j` MCP and verified
read canary; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to
`nacl-init`.

Route to one packaged publish/release leaf. Use only project-local Neo4j MCP
tools. Preserve release lease/fence/revision, confirmation, read-back and
release. Every Git, deployment, documentation, messaging or other external
write requires separate explicit user authority. Missing graph evidence never
becomes release success.

Referenced files: 9

nacl-sa1.14 KB

View saved version →

---
name: nacl-sa
description: Route NaCl system analysis across architecture, domains, roles, use cases, UI, features, validation, and finalization. Use for graph-first SA work.
---

# NaCl System Analysis

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the core methodology](resources/workflows/nacl-core/SKILL.md), and
[the migration rules](resources/workflows/references/migration-rules.md).
Require a loaded project `nacl_neo4j` MCP and verified read canary; otherwise return
`BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`.

Choose exactly one relevant packaged leaf under `resources/workflows/`:
`nacl-sa-full`, `nacl-sa-architect`, `nacl-sa-domain`, `nacl-sa-roles`,
`nacl-sa-uc`, `nacl-sa-ui`, `nacl-sa-feature`, `nacl-sa-flags`,
`nacl-sa-validate`, or `nacl-sa-finalize`. State the leaf and intended writes.

Use only project-local Neo4j MCP Cypher tools. Preserve SA approval,
parameterization, identity, allocate-or-claim, lease/fence, revision CAS,
idempotency and read-back. Required relations or validation evidence that
cannot be produced safely stay `BLOCKED`; never substitute a stale file.

Referenced files: 16

nacl-tl1019 Bytes

View saved version →

---
name: nacl-tl
description: Route NaCl team-lead work across intake, planning, development, review, QA, status, release, and deployment. Use for graph-aware delivery work.
---

# NaCl Team Lead

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the TL core](resources/workflows/nacl-tl-core/SKILL.md), and
[the TL contract](resources/workflows/nacl-tl-core/references/tl-codex-contract.md).
Require a loaded project `nacl_neo4j` MCP and verified read canary; otherwise return
`BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`.

Select one packaged TL leaf and load no unrelated leaf. Use only project-local
Neo4j MCP Cypher tools. Protected Task work keeps the exact project and worker
identity, allocate-or-claim, heartbeat, live fence, expected revision,
`APPROVE_TL_WRITE`, idempotency, same-mutation evidence, read-back and release
or explicit handoff. Missing concurrency or Task evidence is `BLOCKED`, never
an unfenced write or local-status fallback.

Referenced files: 35

nacl-verify971 Bytes

View saved version →

---
name: nacl-verify
description: Verify NaCl code, tests, QA, synchronization, review evidence, or stubs without converting missing runtime proof into success.
---

# NaCl Verify

Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md),
[the verification workflow](resources/workflows/nacl-tl-verify/SKILL.md),
and [the evidence taxonomy](resources/workflows/references/verification-evidence.md).
Require a loaded project `nacl_neo4j` MCP and verified read canary for graph-backed
verification; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route
to `nacl-init`.

Select one verification leaf and report its exact commands and exit codes. Use
only project-local Neo4j MCP tools. Verification stays read-only except for an
explicit evidence artifact or confirmed Task evidence update with claim,
fence/revision, same-mutation evidence, read-back and release. Missing runtime
or graph proof never becomes a vacuous pass.

Referenced files: 4

Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
MIT
Package author
ITSalt
Keywords
developer-tools, software-delivery, systems-analysis, verification

Declared capabilities

  • Analysis
  • Planning
  • Delivery
  • Verification
  • Read
  • Write

Package observed Oct 2, 2026.

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 2, 2026 · 12:00 UTC
Collection status
Collected

plugins_6a5e37e544648191aae6a3ac7d59f4e8

Download plugin data (JSON)