Mugiwara
The Straw Hat crew of AI agents and skills: brainstorm, plan, execute, checkpoint, quality, gates, review, security, self-healing. Installs into Claude Code, opencode, Copilot, Gemini, Codex, Cursor, Kimi, pi, Windsurf, Cline, Kilo, Antigravity.
0
1,964
近 7 天 663
40.2
生态多维模型
6 天前
2026-09-29
快速安装与配置
opencode.json写入当前项目的 opencode.json,只对这个仓库生效。
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@ionivetech/mugiwara@1.0.5"]
}写入 ~/.config/opencode/opencode.json,对所有项目生效。
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@ionivetech/mugiwara@1.0.5"]
}若你要在本地改造这个插件,先装到项目里再从本地路径引用。
shell
pnpm add -D @ionivetech/mugiwaraOpenCode 启动时会通过内嵌运行时自动加载 npm 依赖并缓存至本地目录,无需手动在全局环境执行安装。
Your AI agent already writes the code. Mugiwara makes it reviewable.
A crew of 12 specialists with roles and evidence at every step. The process sizes itself to the work: a typo costs nothing, an auth migration gets all nine stages and a security review. No runtime, no API keys, no servers. Markdown your agent knows how to read.
Works on 12 platforms, including Claude Code and opencode.

The problem
An AI agent can write 400 lines in five minutes. It says "tests pass" and leaves nothing you can open, read, or attach to a PR. Review becomes a formality, and a formality launders the change through a human name.
What you get back
Every mission closes with one file your reviewer reads:
# Mission: invitation-accepted-flow
2026-09-03 · you · branch `feature/invitation-flow` · lane **full** · mode guided
## Verdict
**GO** — all gates passed. 1 finding deferred with an owner.
## What changed
11 files, +340 / -82.
Sensitive paths touched: `src/auth/invitation.ts`, `migrations/004.sql`
## Gates
| Gate | Verdict | Evidence |
|---|---|---|
| Checkpoint (Flow 4) | PASS | `flows/02-audit.md` |
| Quality (Flow 5) | PASS | `flows/03-quality.md` |
| Coverage (Flow 6) | PASS | new 94% / modified 87% |
| Security (Flow 7) | PASS | STRIDE, 0 high -> `review/security.md` |
## Cost
Used **8,781** of 12,000 tokens (73%). Lane `lean`. 1 heal cycle.
Generated from fixture test/fixtures/report-sample.md — 2026-09-03.
Without Mugiwara
Agent: Done: refactored auth, all tests pass.
You: ...which tests? Did anything touch the token check?
Agent: (the context is gone)
With Mugiwara
One file per PR: files changed, gates passed with evidence locations, decisions made, plus what was not verified.
The process fits the work
| Your change | Lane | What runs |
|---|---|---|
| Typo, one file | Direct | nothing, fix it directly |
| Small bug | Lean | execute -> quality |
| A feature | Standard | plan -> execute -> audit -> quality -> review |
Touches auth/, payments/, migrations |
Full | all 9 flow stages + security review |
| Requirements still fuzzy | Spike | brainstorm first, then re-size |
The lane is computed from git diff, never guessed, and it only ever rises.
What is Mugiwara? (30 seconds)
AI agents are fast. They are also unverified: no audit trail, no review, no "who checked this?" when something breaks.
Mugiwara wraps your agent in a Straw Hat crew of named roles (Luffy, Nami, Zoro, Chopper, …) with a ruled pipeline, evidence at every gate, and a cost governor keeping spend visible and bounded.
Three things it does for you:
| You get | Meaning |
|---|---|
| Evidence, not claims | Every flow stage re-runs checks and shows output. "Done" = proof. |
| Process that sizes itself | A typo costs nothing. An auth migration gets the full pipeline. |
| Visible cost | Per-lane budgets, a live slop governor, and a mugiwara cost ledger. |
It runs inline in your chat.
→ Why mugiwara vs asking unaided
Quick start (5 minutes)
Add the plugin, then ask something non-trivial:
# opencode: add to opencode.json, then restart
{ "plugin": ["@ionivetech/mugiwara"] }
# Claude Code
/plugin marketplace add ionivetech/mugiwara && /plugin install mugiwara
# Any platform via npm
npx @ionivetech/mugiwara@latest install --target all --yes
First run writes .mugiwara/config. Then ask, in chat or /mugiwara <request>, never @agent:
> add role-based access control: admin, editor, viewer
> audit the auth middleware for security gaps
> review the last PR for breaking changes
> split this feature across the team: payment gateway, ledger, fraud
You ask; the crew routes. A Standard-lane mission ends with test-first commits, an audit report, a security review, and a PR summary, visible at every step.
| You say | What happens |
|---|---|
add search bar to products page |
Triage, plan, execute, audit, gate, review, then a PR summary |
split payment system: gateway, ledger, fraud |
One plan split into sub-missions, each dev resumes only their own |
Brook, fix the failing login test |
Healer reads the failure ledger, root-cause fixes, proves it in ≤3 cycles |
Jinbe, audit auth middleware |
STRIDE + OWASP + dependency audit. Read-only, never touches code |
How it works (the short version)
Four ideas explain almost everything:
1. The crew pipeline
A mission runs as flow stages, each owned by one crew member: triage,
brainstorm, plan, execute, audit, quality, gates, review, heal, closure. Plans
record a preflight baseline (bun test, tsc --noEmit) before executing.
2. Lanes: process sizes itself
Work is sized to the diff. A typo gets no pipeline; an auth migration gets all nine stages.
| Lane | Flow stages | Typical tokens | Budget |
|---|---|---|---|
| Direct (typo) | 0 | ~0 | — |
| Lean (small bug) | 2 | ~8k | 12k |
| Standard (feature) | 5–7 | ~13k | 25k |
| Full (architecture) | 9–11 | ~22k | 50k |
→ Lanes
3. Modes: how much you participate
guided (approve every step), semi (approve the plan, then auto), auto
(full autonomy within your scope).
→ Modes
4. Cost Governor: what is safe to spend
Per-lane budgets, a live slop governor that flags wasted cost and
attributes it to the crew member that caused it, and a mugiwara cost ledger.
Four host capabilities ride alongside, named for the job with the native name in brackets: terse-output [anti-stuff], minimal-diff [just-enough], waste-guard [anti-slop], scan-format [have-adhd]. They ship with the host, not here.
Adaptive execution
Control mode, execution posture, and Cost Governor stay independent. The crew picks the posture from evidence at each flow boundary. Inline is the default.
What Mugiwara does
| Feature | One line |
|---|---|
| Lane sizing | Process scales to the work. Computed from git diff, never guessed. |
| Evidence gates | A stage passes only if the check actually ran. No output, no pass. |
| Team split | One shared plan, per-person state, file conflicts caught before merge. |
| Resume | Session died? Continues from the exact stage. Never restarts. |
| Feature flags | features= selects the skill set; mugiwara features explain shows why each feature loads. |
| 12 platforms | 11 agents (+3 internal) on 12 harnesses: 9 install full bodies, 3 via marketplace manifest. |
→ all features: Every feature
Team collaboration
Built for a team sharing one repo. Identity is (mission, member), never
branch, so parallel work never collides.
Solo by default (team=off); the first shared mission flips it on at Flow 0.
/mugiwara continue # list every in-flight mission for YOU
/mugiwara continue payment-gateway # solo → resume; team → list members
/mugiwara continue payment-gateway patty # resume exactly patty's work
mugiwara status # computed per-mission position
Auto mode runs your member scope only: your sub-mission ships alone.
→ Multi-actor reference · Adoption guide
When not to use Mugiwara
- Throwaway prototype you will delete tonight: skip the crew; the trail outlives the code otherwise.
- Unattended multi-hour runs with nobody watching chat: the crew runs inline so you can interrupt it; use a batch runner instead.
- Solo script with no reviewer, no PR, no future reader: the trail has no audience, so it is pure overhead.
- Harnesses without agent dispatch (Gemini, Codex, tier 3): you get the workflow and the trail, not enforced role boundaries.
Configuration
Switch mode any time: say mugiwara mode <guided|semi|auto> in session.
| Key | Default | What |
|---|---|---|
mode |
guided | guided / semi / auto |
verbosity |
normal | normal / full |
branch |
feature/{type}-{issue}-{slug} |
Branch naming |
commit |
conventional | conventional / gitmoji / plain / template |
auto_commit |
off | off hands you an uncommitted tree in guided/semi |
coverage_new |
85 | Coverage threshold for new files (%) |
coverage_modified |
90 | Coverage threshold for modified files (%) |
review_depth |
full | full / standard / quick |
quality_depth |
full | full / standard / quick |
verify_merged |
off | re-verify the merged tree before closing |
delegate_threshold |
60 | % of budget at which remaining tasks dispatch to workers |
heal_max_cycles |
3 | Max heal-loop cycles before human escalation |
Project config (.mugiwara/config) overrides global (~/.mugiwara/config).
Commented optionals (features=, team=, sign=, enforce=, scope, budgets,
investigation limits) stay off until set.
Quick reference
| Need | Command / Doc |
|---|---|
| Review a PR diff | /mugiwara-review or "review this PR" |
| Security audit | /mugiwara-security or "Jinbe, audit X" |
| Resume a mission | /mugiwara continue <mission> [member] |
| See mission position | mugiwara status |
| See cost + live slop | mugiwara cost |
| Explain the feature mix | mugiwara features explain |
| Close out a mission | mugiwara archive <mission> |
| Switch mode | mugiwara mode <guided|semi|auto> (in session) |
| All docs | docs/ |
Install
Claude Code
/plugin marketplace add ionivetech/mugiwara && /plugin install mugiwara
Full guide: docs/install/claude.md.
OpenCode
Add "plugin": ["@ionivetech/mugiwara"] to opencode.json and restart.
Full guide: docs/install/opencode.md.
Gemini CLI / Codex / Copilot / Cursor / Antigravity / Kimi / Pi
Each has its own guide: Gemini · Codex · Copilot · Cursor · Antigravity · Kimi · Pi.
Any platform via CLI
npx @ionivetech/mugiwara@latest install --target <id> --yes # windsurf, cline, kilo, codex
Full guide: docs/install/cli.md.
Compact (tier-3) targets install stub pointers, not full bodies; each install page names its side. See the harness matrix.
CLI
mugiwara install # wizard (interactive)
mugiwara install --target all --yes # non-interactive
mugiwara update --target <id> --yes # overwrite to latest
mugiwara uninstall # remove installed files
mugiwara list [--check] # show / health-check installations
mugiwara status # computed mission state
mugiwara continue [mission] [member] # resume / list in-flight (read-only)
mugiwara cost [--mission <id>] [--json] # cost ledger, avoided work, live slop
mugiwara features explain|list # which skills load, and why
mugiwara archive <mission> # fold the trail into report.md
mugiwara clean [--all] [--before <date>] # batch-archive closed missions
mugiwara blame <path> # provenance on the last commit touching path
mugiwara handoff <mission> # engineer-to-engineer handoff report
mugiwara sign <mission> [--verify] # optional report attestation
mugiwara reset --keep-logs # wipe state, keep lessons
Docs
Start here: Getting started · What mugiwara replaces
Concepts: Workflow · Lanes · Modes · Git strategy · Config · Cost · Audit trail · Security · Provenance · Policy as code · Closure tools · Permissions · Memory
Crew: Agents · Skills · Adaptive execution
Reference: Adoption guide · Glossary · Harness matrix · Compliance matrix
Install: Overview · Claude · opencode · Gemini · Codex · Copilot · Cursor · Antigravity · Kimi · Pi · CLI targets
Runbooks: Solo mission · Team mission · Joining mid-mission · Resume after crash · Monorepo · Signing · Policy · Troubleshooting
What is measured, and what is not
| Claim | Status |
|---|---|
| Retrieval routing rank-1 | 95.6%, 272 probes (180 positive, 86 negative, 6 no-skill), in CI |
| Reference pointers resolve | 166/166, 9 targets, in CI |
| Index size published vs measured | doc-gated: validator fails on drift, in CI |
| Lane constants match content load | verified, in CI |
| Slop verdicts | in mugiwara cost and the closing report: Cost |
| Write-scope enforcement | opencode only, rules-based elsewhere |
| Cross-harness mission behavior | 12/12 platforms, in CI |
| Outcome vs other approaches | not measured |
Numbers here are produced by bun run gate. Nothing in this table is an estimate.
License
MIT. Copyright (c) 2026 ionivetech.
同类生态推荐
Matrixx
opencode-matrixx
The Best AI Agent Harness - Batteries-Included OpenCode Plugin with Multi-Model Orchestration, Parallel Background Agents, and Crafted LSP/AST Tools
Herdr
opencode-herdr
Route OpenCode agents through Herdr panes as herdr/<adapter>/<model> (Cursor, Claude, Codex, OpenCode)
Magic Compact
magic-compact
Lossless context compression plugin for OpenCode.