Vibe Coding Production Kit turns AI chat into an engineering lifecycle

laptop screen displaying colorful code

Most AI coding workflows are optimized for the first demo. Vibe Coding Production Kit (VCP) is built for the 100th feature, the second developer, production incidents, security reviews, and years of maintenance.

It’s a zero-runtime-dependency CLI that wraps any AI coding agent (Codex, Claude Code, Cursor, GitHub Copilot, or others) in a repeatable engineering lifecycle. MIT licensed. Free. Requires Node.js 22+.

️ What the lifecycle looks like

VCP enforces a structured flow rather than letting an agent start writing code the moment you describe an idea:

  1. Initialize the repo with vcp init
  2. Create a bounded task with vcp task
  3. Gate readiness before planning (vcp ready --stage plan)
  4. Build a phase-specific context pack (vcp context --mode plan)
  5. Plan without editing code first
  6. Gate readiness before implementation (vcp ready --stage implement)
  7. Implement within the bounded scope
  8. Run verification and capture evidence (vcp verify --run)
  9. Run an independent review
  10. Run vcp doctor for a health audit
  11. Release, observe, and update safely

The planning gate requires a real outcome, a resolvable source of truth, concrete acceptance criteria, and an explicit scope. The implementation gate adds resolved architecture, data, and integration boundaries, security considerations, failure modes, and a concrete plan before a single line gets written.

Key CLI commands

Run without a global install:

npx vibe-coding-production init . --agent all --stack auto --yes

Preview without writing any files:

npx vibe-coding-production init . --agent all --stack auto --dry-run

Create a bounded task:

npx vibe-coding-production task accept-invite --title "Accept invitation"

That generates docs/tasks/accept-invite.md with source-of-truth links, acceptance criteria, scope boundaries, security and privacy questions, failure modes, observability requirements, tests, rollout and recovery notes, and the verification commands configured in AGENTS.md.

Audit an existing repo without touching anything:

npx vibe-coding-production doctor .

The doctor reports concrete PASS, WARN, or FAIL findings for agent instructions, unresolved verification commands, source-of-truth documents, untouched templates, CI, plan and review workflow, manifest compatibility, baseline integrity, and interrupted update transactions. Use --strict to make warnings return a non-zero exit code.

‍ What goes in the repo

VCP scaffolds a full documentation structure alongside the CLI:

  • AGENTS.md: repository-wide rules for coding agents
  • Product templates: product brief, PRD, user flows, acceptance criteria
  • Architecture templates: domain model, system design, data model, ADRs
  • Security template: threat modeling before implementation
  • Test strategy: unit, integration, contract, and E2E decision framework
  • Agent prompts for discovery, planning, implementation, review, security, refactoring, and release
  • GitHub hygiene: issue templates, PR template, contributing guide, security policy

Safe updates (v0.9)

vcp init now creates .vcp/manifest.json and persistent baseline snapshots. Once a repo is initialized, VCP refuses to overwrite lifecycle state with init --force. Upgrades go through the update engine, which uses persistent baseline hashes, three-way merge for independent edits, explicit CONFLICT markers instead of silent overwrites, versioned migration declarations, transaction state, backups, post-apply verification, and automatic rollback.

The design principle

Do not ask AI to build your project. Build a system that makes it difficult for AI to build your project incorrectly.

A well-formed VCP task has one primary outcome, a narrow set of affected modules, explicit acceptance criteria, known tests, no unrelated refactor, and a diff small enough for a human to understand. If a task needs a long explanation of “and while you’re there,” it gets split.

The kit is model-agnostic by design. Universal rules go in AGENTS.md. Tool-specific instruction files are added only when they provide real value. No duplicate conflicting rules across agent config files.

A reference example (examples/reference-saas-invite/) ships with the kit, modeling a security-sensitive multi-tenant invitation slice with completed product, domain, architecture, and data artifacts, an ADR, a threat model, a test strategy, a bounded task, and negative-path tests for authorization, tenant boundaries, token hashing, expiry, replay, and email binding.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo