NaCl
ITSalt v0.2.2
Publisher description
From the marketplace listing
NaCl (reading as Natrium Chloride) is an open-source full-SDLC framework, and its core innovation is how it solves the hardest problem in agentic development: storing and retrieving project knowledge. Instead of markdown specs that agents must re-read every session, all project knowledge — requirements, architecture decisions, entities, rules, and their relationships — lives in a Neo4j knowledge graph as first-class queryable objects. The measured effect: planning a single use case takes ~550 tokens (one targeted Cypher query) instead of ~150,000 tokens (reading a ~70-file markdown spec, because the agent doesn't know in advance where the relevant facts live) — a 99.6% reduction in context per use case, repeated in every planning session. Around the graph we've built the full tooling for agentic development and testing: 57 skills covering BA → SA → TDD development → review → QA → release, quality gates before production, and an autonomous goal orchestrator (/nacl-goal). The framework answers "how is this built and why" for any part of the system, regardless of project scale or iteration count. Benchmarked on a real production project (EV charging station management): a classical team was estimated at 5,831 person-hours; running fully on NaCl the same scope takes 1,480 person-hours — 4x fewer person-hours and 60% lower cost.
Language: English · Automatically detected from descriptions.
Publisher keywords
Search terms declared by the publisher.
Matches for “developer-tools”
Exact text from the indicated source. A mention alone does not establish support for your task.
Publisher keywords · listing
developer-tools software-delivery systems-analysis verification
Files & skills
File archives
Skill instructions
nacl-ba1.26 KB
--- name: nacl-ba description: Route NaCl business analysis across context, processes, entities, roles, rules, workflows, validation, sync, and handoff. Use for graph-first BA work. --- # NaCl Business Analysis Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the BA contract](resources/workflows/references/ba-codex-contract.md), and [the core methodology](resources/workflows/nacl-core/SKILL.md). Require a loaded project `nacl_neo4j` MCP and verified read canary. Otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Choose exactly one relevant packaged leaf under `resources/workflows/`: `nacl-ba-full`, `nacl-ba-context`, `nacl-ba-import-doc`, `nacl-ba-from-board`, `nacl-ba-roles`, `nacl-ba-process`, `nacl-ba-entities`, `nacl-ba-rules`, `nacl-ba-glossary`, `nacl-ba-workflow`, `nacl-ba-analyze`, `nacl-ba-validate`, `nacl-ba-sync`, or `nacl-ba-handoff`. State the leaf. Use only project-local Neo4j MCP Cypher tools. Preserve explicit project identity, BA write approval, parameterization, lease/fence/revision rules, transaction/idempotency, and read-back from the leaf and runtime contract. Missing graph primitives stay `BLOCKED`; confirmed file-only preparation may report only its own honest status.
Referenced files: 19
nacl-diagnose1.84 KB
--- name: nacl-diagnose description: Diagnose NaCl project health, drift, status, reconciliation, or next work using read-only evidence and actionable closed outcomes. --- # NaCl Diagnose Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md). Before requiring MCP, invoke the bundle-relative [plan runner](resources/bootstrap/plan-project-graph.mjs) once with `--diagnose-only` and the explicit absolute project root. This inspection is file-only: never call Docker, use the network, mutate a file, or infer graph truth. Preserve its exact `status`, `code`, `initializationState`, canonical root, and per-file digest/absence evidence: - `NOT_RUN/PROJECT_MCP_NOT_CONFIGURED` + `UNINITIALIZED`: report the local state and route to `nacl-init`; do not turn it into an error. - `BLOCKED/*` + `BLOCKED`: stop on malformed, unsafe, or partial local state. - `PARTIALLY_VERIFIED/PROJECT_MCP_VERIFICATION_REQUIRED` + `INITIALIZED_LOCAL_FILES`: report that files exist but graph truth and overall initialization remain unverified. If the project MCP is absent, ask for a new task and stop without replacing this with `BLOCKED/PROJECT_MCP_NOT_CONFIGURED`. Only after local initialized files and a loaded project `nacl_neo4j` MCP are both present, read [the diagnostic workflow](resources/workflows/nacl-tl-diagnose/SKILL.md) and [the evidence taxonomy](resources/workflows/references/verification-evidence.md). Use MCP reads for graph truth. If the initialization ceremony in `nacl-init` has not completed, route there before ordinary diagnosis. Route to one packaged diagnostic leaf. Keep the run read-only unless the user separately requests an artifact. Use only project-local Neo4j MCP reads and preserve exact graph status. Never infer graph truth from a stale local status file; missing named evidence is an honest closed non-success.
Referenced files: 6
nacl-fix931 Bytes
--- name: nacl-fix description: Diagnose and repair a bounded NaCl defect with spec-first classification, a regression test, verification, and honest status propagation. --- # NaCl Fix Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the fix workflow](resources/workflows/nacl-tl-fix/SKILL.md), and [the TL contract](resources/workflows/nacl-tl-core/references/tl-codex-contract.md). Require a loaded project `nacl_neo4j` MCP and verified read canary; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Use the narrower hotfix/reopened/regression leaf only when its trigger applies. Use only project-local Neo4j MCP tools and preserve diagnostic/spec versus implementation/review separation, Task claim/fence/revision/idempotency, `APPROVE_TL_WRITE`, RED-to-GREEN evidence, read-back and release. Missing proof or a required primitive stays `BLOCKED`.
Referenced files: 4
nacl-goal846 Bytes
--- name: nacl-goal description: Plan or conduct a bounded NaCl objective with explicit checks and closed statuses. Use for multi-step goals and resumable orchestration. --- # NaCl Goal Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the goal workflow](resources/workflows/nacl-goal/SKILL.md), and [the goal contract](resources/workflows/references/goal-codex-contract.md). Require a loaded project `nacl_neo4j` MCP and verified read canary for graph-backed work; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Select one bounded alias/leaf and state its checks. Use only project-local Neo4j MCP tools. Preserve preview, proof, refusal, confirmation, identity, lease/fence/revision and read-back gates. A goal never promotes a child non-success into `VERIFIED`.
Referenced files: 5
nacl-init6.23 KB
--- name: nacl-init description: Inspect or initialize a NaCl project with a per-project Neo4j Community graph and project-local MCP. Use for first setup, bootstrap, and repair planning. --- # NaCl Init Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md). This entry must work before any project MCP exists. Never call an installation doctor, a package gateway, or a checkout-relative/global skill path. Resolve one explicit absolute project root. For an empty new project without `config.yaml`, invoke the bundle-relative [project-creation planner](resources/bootstrap/plan-project-creation.mjs) with the root, project name, optional one-line description, and optional stack. It performs no writes. Present its exact `config.yaml`, `AGENTS.md`, Git action, `planHash`, and `CREATE_NACL_PROJECT:<sha256>` confirmation, then stop. After the user repeats that exact confirmation, invoke the bundle-relative [project-creation applier](resources/bootstrap/apply-project-creation.mjs) with the same inputs, `plan-hash`, and confirmation. It recomputes the plan under a create lock before writing. For a genuinely empty non-Git directory it creates `config.yaml` and concise repository-specific `AGENTS.md`, initializes Git and commits only those initial artifacts. It preserves an existing `AGENTS.md` and never auto-adopts a non-Git directory containing files or a linked worktree. Stop on any non-success result. `AGENTS.md` records durable project context, constraints, and verified commands; keep it concise and use a closer nested `AGENTS.md` for directory-specific rules. Never put credentials in it. For an existing `config.yaml` without a stable `project.id`, present the exact add-only config change and stop for confirmation before writing it; never derive identity during a read. Before bootstrap, invoke the bundle-relative [plan runner](resources/bootstrap/plan-project-graph.mjs) with the explicit root, ID, database, and chosen loopback Bolt/HTTP ports. This command is read-only: it performs no Docker call, network request, or mutation. Show its exact plan fields, `planHash`, and fresh `INIT_LOCAL_GRAPH:<project-id>:<sha256>` token, then stop. Never accept the old static token or reconstruct a token manually. After the user repeats that exact token, invoke the bundled POSIX or PowerShell runner, respectively the [POSIX runner](resources/bootstrap/setup-project-graph.sh) or [PowerShell runner](resources/bootstrap/setup-project-graph.ps1), with the same root, ID, database, ports, and token. Never pass a password. The runner recomputes the plan immediately before its first mutation; stale or mismatched state is `BLOCKED/PLAN_TOKEN_STALE` with zero mutation. Treat the exact token as an execution request, not as a reason to re-plan, diagnose, or ask for another confirmation. Run the selected runner exactly once, capture its complete stdout and stderr, and do not infer project state while it is running. The runner's terminal machine-readable line is the sole authority for the outcome: - `NACL_SKILLS_ONLY_BOOTSTRAP: status=... code=...` is the successful bootstrap receipt. - `NACL_GRAPH_RESULT: status=... code=...` is a blocked, failed, or partially verified bootstrap receipt. Report those fields verbatim. Never claim `PARTIAL_BOOTSTRAP_STATE`, missing files, or an incomplete bootstrap from an LLM inference, a directory name, or a prior message. If the runner reports `FAILED` with `rollback=VERIFIED`, report that failure and rollback; the graph bootstrap is not partial and no recovery plan is needed. A retry requires a newly generated plan and fresh user confirmation. Only if the runner reports `PARTIALLY_VERIFIED` with `rollback=INCOMPLETE`, invoke `plan-project-graph.mjs --diagnose-only` once, then report the returned JSON evidence without embellishment. If no terminal receipt is produced, report `RUNNER_RECEIPT_MISSING` and run that same read-only diagnosis; do not assert a state before its result. Preserve the runner's status/code. A successful runner returns `PARTIALLY_VERIFIED/RESTART_REQUIRED` with `bootstrap=VERIFIED` and `initialization=NOT_RUN`. Then stop and ask the user to open a new task in this project so Codex loads the newly created project `.codex/config.toml`. The current task must never report overall initialization `VERIFIED`. In the new task, overall initialization is `VERIFIED` only after all of these same-task gates succeed through the actual project `nacl_neo4j` MCP: 1. Record real MCP `initialize` and `tools/list` discovery, requiring the exact `read-cypher` and `write-cypher` tool names. Missing discovery is closed non-success. 2. Run graph connectivity health, read the complete `nacl-graph-gateway` schema ledger, require versions 1–3 with their packaged checksums, and read back every required constraint. 3. Execute the bundled named read `sa_statistics_extensions` unchanged and record its result. A generic `RETURN 1` alone is insufficient. 4. Invoke the plan runner with `--verification-plan`, show its random idempotency key, parameterized write/read-back statements, `planHash`, and exact `VERIFY_NACL_INITIALIZATION:<project-id>:<sha256>` token, then stop. 5. After the user freshly repeats that token, make exactly one parameterized write-canary call with the plan's statement/parameters, followed by a separate read call with the read-back statement. Require matching project ID, idempotency key, and integer revision. Never accept a static, old, or reconstructed verification token. Never automatically retry the write; any failure requires a new verification plan, new idempotency key, and fresh user confirmation. Return these exact result fields: `status`, `code`, `initializationState`, `mcpServerKey`, `mcpInitialize`, `mcpToolsList`, `readTool`, `writeTool`, `graphHealth`, `schemaVersion`, `schemaChecksum`, `namedRead`, `writeCanary`, and `writeReadback`. Set `status=VERIFIED`, `code=INITIALIZATION_VERIFIED`, and `initializationState=VERIFIED` only when every field is verified; otherwise preserve the closed failing status/code. Optional agent profiles remain create-only and require a separate path-by-path plan and confirmation. On `AGENT_PROFILE_CONFLICT`, never overwrite: ask the user to move or back up the conflicting file, then produce a fresh plan before any retry.
Referenced files: 39
nacl-migrate978 Bytes
--- name: nacl-migrate description: Plan or execute confirmed NaCl methodology migrations for legacy, BA, or SA artifacts with backups, validation, and read-back. --- # NaCl Migrate Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the migration workflow](resources/workflows/nacl-migrate/SKILL.md), and [the migration rules](resources/workflows/references/migration-rules.md). Require a loaded project `nacl_neo4j` MCP and verified read canary for graph migration; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Choose the exact migration leaf. Present before-state, backup, write plan, confirmation and validation before mutation. Use only project-local Neo4j MCP tools and packaged scripts. Preserve schema lease/fence, additive ordered migrations, checksum ledger and read-back. File-only conversion retains its own backup and confirmation. An unrepresented domain migration stays `BLOCKED`.
Referenced files: 7
nacl-publish924 Bytes
--- name: nacl-publish description: Render, package, ship, release, deploy, or publish NaCl outputs with explicit external-write authorization and verified evidence. --- # NaCl Publish Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the publish workflow](resources/workflows/nacl-publish/SKILL.md), and [the render workflow](resources/workflows/nacl-render/SKILL.md). For graph-derived evidence, require a loaded project `nacl_neo4j` MCP and verified read canary; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Route to one packaged publish/release leaf. Use only project-local Neo4j MCP tools. Preserve release lease/fence/revision, confirmation, read-back and release. Every Git, deployment, documentation, messaging or other external write requires separate explicit user authority. Missing graph evidence never becomes release success.
Referenced files: 9
nacl-sa1.14 KB
--- name: nacl-sa description: Route NaCl system analysis across architecture, domains, roles, use cases, UI, features, validation, and finalization. Use for graph-first SA work. --- # NaCl System Analysis Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the core methodology](resources/workflows/nacl-core/SKILL.md), and [the migration rules](resources/workflows/references/migration-rules.md). Require a loaded project `nacl_neo4j` MCP and verified read canary; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Choose exactly one relevant packaged leaf under `resources/workflows/`: `nacl-sa-full`, `nacl-sa-architect`, `nacl-sa-domain`, `nacl-sa-roles`, `nacl-sa-uc`, `nacl-sa-ui`, `nacl-sa-feature`, `nacl-sa-flags`, `nacl-sa-validate`, or `nacl-sa-finalize`. State the leaf and intended writes. Use only project-local Neo4j MCP Cypher tools. Preserve SA approval, parameterization, identity, allocate-or-claim, lease/fence, revision CAS, idempotency and read-back. Required relations or validation evidence that cannot be produced safely stay `BLOCKED`; never substitute a stale file.
Referenced files: 16
nacl-tl1019 Bytes
--- name: nacl-tl description: Route NaCl team-lead work across intake, planning, development, review, QA, status, release, and deployment. Use for graph-aware delivery work. --- # NaCl Team Lead Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the TL core](resources/workflows/nacl-tl-core/SKILL.md), and [the TL contract](resources/workflows/nacl-tl-core/references/tl-codex-contract.md). Require a loaded project `nacl_neo4j` MCP and verified read canary; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Select one packaged TL leaf and load no unrelated leaf. Use only project-local Neo4j MCP Cypher tools. Protected Task work keeps the exact project and worker identity, allocate-or-claim, heartbeat, live fence, expected revision, `APPROVE_TL_WRITE`, idempotency, same-mutation evidence, read-back and release or explicit handoff. Missing concurrency or Task evidence is `BLOCKED`, never an unfenced write or local-status fallback.
Referenced files: 35
nacl-verify971 Bytes
--- name: nacl-verify description: Verify NaCl code, tests, QA, synchronization, review evidence, or stubs without converting missing runtime proof into success. --- # NaCl Verify Read [the Skills-only runtime contract](resources/references/skills-only-runtime-contract.md), [the verification workflow](resources/workflows/nacl-tl-verify/SKILL.md), and [the evidence taxonomy](resources/workflows/references/verification-evidence.md). Require a loaded project `nacl_neo4j` MCP and verified read canary for graph-backed verification; otherwise return `BLOCKED/PROJECT_MCP_NOT_CONFIGURED` and route to `nacl-init`. Select one verification leaf and report its exact commands and exit codes. Use only project-local Neo4j MCP tools. Verification stays read-only except for an explicit evidence artifact or confirmed Task evidence update with claim, fence/revision, same-mutation evidence, read-back and release. Missing runtime or graph proof never becomes a vacuous pass.
Referenced files: 4
Package details
Publisher declarations from the archived package. These are separate from our research and the live service's terms.
- Package license
- MIT
- Package author
- ITSalt
- Keywords
- See publisher keywords
Declared capabilities
- Analysis
- Planning
- Delivery
- Verification
- Read
- Write
Package observed Oct 3, 2026.
Technical details
- First seen
- Sep 30, 2026 · 22:02 UTC
- Last seen
- Oct 3, 2026 · 18:00 UTC
- Collection status
- Collected
plugins_6a5e37e544648191aae6a3ac7d59f4e8
Download plugin data (JSON)Before you connect NaCl
How do I connect it?
Open the publisher's marketplace listing to check current availability and follow its connection instructions. This directory does not install plugins. Check the requested access and any account requirements before connecting.
Check marketplace availability ↗
Does it require paid access?
We have not established the pricing or subscription requirements for this plugin. An absent price does not mean free access.
Compare researched pricing and access models →
How can I evaluate it?
Check the declared skills and available files, then try a small task whose result you can verify. Our archived descriptions and instructions establish publisher claims, not tested runtime quality. Review sources and coverage limits.