CLAUDE-CODE-ULTIMATE-GUIDE(1)

NAME

claude-code-ultimate-guide β€” A tremendous feat of documentation, this guide covers Claude Code from beginner to power user, with production-ready…

SYNOPSIS

INFO

2.9k stars
420 forks
0 views

DESCRIPTION

A tremendous feat of documentation, this guide covers Claude Code from beginner to power user, with production-ready templates for Claude Code features, guides on agentic workflows, and a lot of great learning materials, including quizzes and a handy "cheatsheet". Whether it's the "ultimate" guide to Claude Code will be up to the reader :)

README

Claude Code Ultimate Guide

Website

Stars Last Update Quiz Templates Threat Database MCP Server

Mentioned in Awesome Claude Code License: CC BY-SA 4.0 SkillHub Skills Ask Zread

6 months of daily practice distilled into a guide that teaches you the WHY, not just the what. From core concepts to production security, you learn to design your own agentic workflows instead of copy-pasting configs.

If this guide helps you, give it a star ⭐ β€” it helps others discover it too.


🎯 What You'll Learn

This guide teaches you to think differently about AI-assisted development:

  • βœ… Understand trade-offs β€” When to use agents vs skills vs commands (not just how to configure them)
  • βœ… Build mental models β€” How Claude Code works internally (architecture, context flow, tool orchestration)
  • βœ… Visualize concepts β€” 41 Mermaid diagrams covering model selection, master loop, memory hierarchy, multi-agent patterns, security threats, AI fluency paths
  • βœ… Master methodologies β€” TDD, SDD, BDD with AI collaboration (not just templates)
  • βœ… Security mindset β€” Threat modeling for AI systems (only guide with 24 CVEs + 655 malicious skills database)
  • βœ… Test your knowledge β€” 274-question quiz to validate understanding (no other resource offers this)

Outcome: Go from copy-pasting configs to designing your own agentic workflows with confidence.


πŸ“Š When to Use This Guide vs Everything-CC

Both guides serve different needs. Choose based on your priority.

Your GoalThis Guideeverything-claude-code
Understand why patterns workDeep explanations + architectureConfig-focused
Quick setup for projectsAvailable but not the priorityBattle-tested production configs
Learn trade-offs (agents vs skills)Decision frameworks + comparisonsLists patterns, no trade-off analysis
Security hardeningOnly threat database (24 CVEs)Basic patterns only
Test understanding274-question quizNot available
Methodologies (TDD/SDD/BDD)Full workflow guidesNot covered
Copy-paste ready templates175 templates200+ templates

Ecosystem Positioning

                    EDUCATIONAL DEPTH
                           β–²
                           β”‚
                           β”‚  β˜… This Guide
                           β”‚  Security + Methodologies + 20K lines
                           β”‚
                           β”‚  [Everything-You-Need-to-Know]
                           β”‚  SDLC/BMAD beginner
  ─────────────────────────┼─────────────────────────► READY-TO-USE
  [awesome-claude-code]    β”‚            [everything-claude-code]
  (discovery, curation)    β”‚            (plugin, 1-cmd install)
                           β”‚
                           β”‚  [claude-code-studio]
                           β”‚  Context management
                           β”‚
                      SPECIALIZED

4 unique gaps no competitor covers:

  1. Security-First β€” 24 CVEs + 655 malicious skills tracked (no competitor has this depth)
  2. Methodology Workflows β€” TDD/SDD/BDD comparison + step-by-step guides
  3. Comprehensive Reference β€” 20K lines across 16 specialized guides (24Γ— more reference material than everything-cc)
  4. Educational Progression β€” 274-question quiz, beginner β†’ expert path

Recommended workflow:

  1. Learn concepts here (mental models, trade-offs, security)
  2. Use battle-tested configs there (quick project setup)
  3. Return here for deep dives (when something doesn't work or to design custom workflows)

Both resources are complementary, not competitive. Use what fits your current need.


⚑ Quick Start

Quickest path: Cheat Sheet β€” 1 printable page with daily essentials

Interactive onboarding (no setup needed):

claude "Fetch and follow the onboarding instructions from: https://raw.githubusercontent.com/FlorianBruniaux/claude-code-ultimate-guide/main/tools/onboarding-prompt.md"

Browse directly: Full Guide | Visual Diagrams | Examples | Quiz


πŸ”Œ MCP Server β€” Use the guide from any Claude Code session

No cloning needed. Add to ~/.claude.json and ask questions directly from any session:

{
  "mcpServers": {
    "claude-code-guide": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "claude-code-ultimate-guide-mcp"]
    }
  }
}

12 tools: search_guide, read_section, get_cheatsheet, get_digest, get_example, list_examples, get_release, get_changelog, list_topics, compare_versions, get_threat, list_threats, search_examples β€” plus 8 slash commands /ccguide:* and a Haiku agent.

Onboarding one-liner (once MCP is configured):

claude "Use the claude-code-guide MCP server. Activate the claude-code-expert prompt, then run a personalized onboarding: ask me 3 questions about my goal, experience level, and preferred tone β€” then build a custom learning path using search_guide and read_section to navigate the guide with live source links."

β†’ MCP Server README


πŸ“ Repository Structure

graph LR
    root[πŸ“¦ Repository<br/>Root]
root --&gt; guide[πŸ“– guide/&lt;br/&gt;20K lines]
root --&gt; examples[πŸ“‹ examples/&lt;br/&gt;175 templates]
root --&gt; quiz[🧠 quiz/&lt;br/&gt;274 questions]
root --&gt; tools[πŸ”§ tools/&lt;br/&gt;utils]
root --&gt; machine[πŸ€– machine-readable/&lt;br/&gt;AI index]
root --&gt; docs[πŸ“š docs/&lt;br/&gt;84 evaluations]

style root fill:#d35400,stroke:#e67e22,stroke-width:3px,color:#fff
style guide fill:#2980b9,stroke:#3498db,stroke-width:2px,color:#fff
style examples fill:#8e44ad,stroke:#9b59b6,stroke-width:2px,color:#fff
style quiz fill:#d68910,stroke:#f39c12,stroke-width:2px,color:#fff
style tools fill:#5d6d7e,stroke:#7f8c8d,stroke-width:2px,color:#fff
style machine fill:#138d75,stroke:#16a085,stroke-width:2px,color:#fff
style docs fill:#c0392b,stroke:#e74c3c,stroke-width:2px,color:#fff

Detailed Structure (Text View)
πŸ“¦ claude-code-ultimate-guide/
β”‚
β”œβ”€ πŸ“– guide/              Core Documentation (20K+ lines)
β”‚  β”œβ”€ ultimate-guide.md   Complete reference, 10 sections
β”‚  β”œβ”€ cheatsheet.md       1-page printable
β”‚  β”œβ”€ architecture.md     How Claude Code works internally
β”‚  β”œβ”€ methodologies.md    TDD, SDD, BDD workflows
β”‚  β”œβ”€ diagrams/           41 Mermaid diagrams (10 thematic files)
β”‚  β”œβ”€ third-party-tools.md  Community tools (RTK, ccusage, Entire CLI)
β”‚  β”œβ”€ mcp-servers-ecosystem.md  Official & community MCP servers
β”‚  └─ workflows/          Step-by-step guides
β”‚
β”œβ”€ πŸ“‹ examples/           175 Production Templates
β”‚  β”œβ”€ agents/             9 custom AI personas
β”‚  β”œβ”€ commands/           26 slash commands
β”‚  β”œβ”€ hooks/              31 hooks (bash + PowerShell)
β”‚  β”œβ”€ skills/             14 skills (9 on SkillHub)
β”‚  └─ scripts/            Utility scripts (audit, search)
β”‚
β”œβ”€ 🧠 quiz/               274 Questions
β”‚  β”œβ”€ 9 categories        Setup, Agents, MCP, Trust, Advanced...
β”‚  β”œβ”€ 4 profiles          Junior, Senior, Power User, PM
β”‚  └─ Instant feedback    Doc links + score tracking
β”‚
β”œβ”€ πŸ”§ tools/              Interactive Utilities
β”‚  β”œβ”€ onboarding-prompt   Personalized guided tour
β”‚  └─ audit-prompt        Setup audit & recommendations
β”‚
β”œβ”€ πŸ€– machine-readable/   AI-Optimized Index
β”‚  β”œβ”€ reference.yaml      Structured index (~2K tokens) β€” powers landing site CMD+K search
β”‚  β”œβ”€ claude-code-releases.yaml  Structured releases changelog
β”‚  └─ llms.txt            Standard LLM context file
β”‚
└─ πŸ“š docs/               84 Resource Evaluations
   └─ resource-evaluations/  5-point scoring, source attribution

🎯 What Makes This Guide Unique

πŸŽ“ Deep Understanding Over Configuration

Outcome: Design your own workflows instead of copy-pasting blindly.

We teach how Claude Code works and why patterns matter:

  • Architecture β€” Internal mechanics (context flow, tool orchestration, memory management)
  • Trade-offs β€” Decision frameworks for agents vs skills vs commands
  • Configuration Decision Guide β€” Unified "which mechanism for what?" map across all 7 config layers
  • Pitfalls β€” Common failure modes + prevention strategies

What this means for you: Troubleshoot issues independently, optimize for your specific use case, know when to deviate from patterns.


πŸ–ΌοΈ Visual Diagrams Series (41 Mermaid Diagrams)

Outcome: Grasp complex concepts instantly through visual mental models.

41 interactive diagrams across 10 thematic files β€” GitHub-native Mermaid rendering + ASCII fallback for every diagram:

  • Foundations β€” 4-layer context model, 9-step pipeline, permission modes
  • Architecture β€” Master loop, tool categories, system prompt assembly
  • Multi-Agent β€” 3 topologies, worktrees, dual-instance, horizontal scaling
  • Security β€” 3-layer defense, MCP rug pull attack chain, verification paradox
  • Cost & Models β€” Model selection tree, token reduction pipeline

Browse all 41 diagrams β†’

What this means for you: Understand the master loop before reading 20K lines, see multi-agent topologies at a glance, share visual security threat models with your team.


πŸ›‘οΈ Security Threat Intelligence (Only Comprehensive Database)

Outcome: Protect production systems from AI-specific attacks.

Only guide with systematic threat tracking:

  • 24 CVE-mapped vulnerabilities β€” Prompt injection, data exfiltration, code injection
  • 655 malicious skills catalogued β€” Unicode injection, hidden instructions, auto-execute patterns
  • Production hardening workflows β€” MCP vetting, injection defense, audit automation

Threat Database β†’ | Security Guide β†’

What this means for you: Vet MCP servers before trusting them, detect attack patterns in configs, comply with security audits.


πŸ“ 274-Question Knowledge Validation (Unique in Ecosystem)

Outcome: Verify your understanding + identify knowledge gaps.

Only comprehensive assessment available β€” test across 9 categories:

  • Setup & Configuration, Agents & Sub-Agents, MCP Servers, Trust & Verification, Advanced Patterns

Features: 4 skill profiles (Junior/Senior/Power User/PM), instant feedback with doc links, weak area identification

Try Quiz Online β†’ | Run Locally

What this means for you: Know what you don't know, track learning progress, prepare for team adoption discussions.


πŸ€– Agent Teams Coverage (v2.1.32+ Experimental)

Outcome: Parallelize work on large codebases (Fountain: 50% faster, CRED: 2x speed).

Only comprehensive guide to Anthropic's multi-agent coordination:

  • Production metrics from real companies (autonomous C compiler, 500K hours saved)
  • 5 validated workflows (multi-layer review, parallel debugging, large-scale refactoring)
  • Decision framework: Teams vs Multi-Instance vs Dual-Instance vs Beads

Agent Teams Workflow β†’ | Section 9.20 β†’

What this means for you: Break monolithic tasks into parallelizable work, coordinate multi-file refactors, review your own AI-generated code.


πŸ”¬ Methodologies (Structured Development Workflows)

Outcome: Maintain code quality while working with AI.

Complete guides with rationale and examples:

  • TDD β€” Test-Driven Development (Red-Green-Refactor with AI)
  • SDD β€” Specification-Driven Development (Design before code)
  • BDD β€” Behavior-Driven Development (User stories β†’ tests)
  • GSD β€” Get Shit Done (Pragmatic delivery)

What this means for you: Choose the right workflow for your team culture, integrate AI into existing processes, avoid technical debt from AI over-reliance.


πŸ“š 175 Annotated Templates

Outcome: Learn patterns, not just configs.

Educational templates with explanations:

  • Agents (6), Commands (26), Hooks (31), Skills
  • Comments explaining why each pattern works (not just what it does)
  • Gradual complexity progression (simple β†’ advanced)

Browse Catalog β†’

What this means for you: Understand the reasoning behind patterns, adapt templates to your context, create your own custom patterns.


πŸ” 84 Resource Evaluations

Outcome: Trust our recommendations are evidence-based.

Systematic assessment of external resources (5-point scoring):

  • Articles, videos, tools, frameworks
  • Honest assessments with source attribution (no marketing fluff)
  • Integration recommendations with trade-offs

See Evaluations β†’

What this means for you: Save time vetting resources, understand limitations before adopting tools, make informed decisions.


🎯 Learning Paths

Junior Developer β€” Foundation path (7 steps)
  1. Quick Start β€” Install & first workflow
  2. Essential Commands β€” The 7 commands
  3. Context Management β€” Critical concept
  4. Memory Files β€” Your first CLAUDE.md
  5. Learning with AI β€” Use AI without becoming dependent ⭐
  6. TDD Workflow β€” Test-first development
  7. Cheat Sheet β€” Print this
Senior Developer β€” Intermediate path (6 steps)
  1. Core Concepts β€” Mental model
  2. Plan Mode β€” Safe exploration
  3. Methodologies β€” TDD, SDD, BDD reference
  4. Agents β€” Custom AI personas
  5. Hooks β€” Event automation
  6. CI/CD Integration β€” Pipelines
Power User β€” Comprehensive path (8 steps)
  1. Complete Guide β€” End-to-end
  2. Architecture β€” How Claude Code works
  3. Security Hardening β€” MCP vetting, injection defense
  4. MCP Servers β€” Extended capabilities
  5. Trinity Pattern β€” Advanced workflows
  6. Observability β€” Monitor costs & sessions
  7. Agent Teams β€” Multi-agent coordination (Opus 4.6 experimental)
  8. Examples β€” Production templates
Product Manager / DevOps / Designer

Product Manager (5 steps):

  1. What's Inside β€” Scope overview
  2. Golden Rules β€” Key principles
  3. Data Privacy β€” Retention & compliance
  4. Adoption Approaches β€” Team strategies
  5. PM FAQ β€” Code-adjacent vs non-coding PMs

Note: Non-coding PMs should consider Claude Cowork Guide instead.

DevOps / SRE (5 steps):

  1. DevOps & SRE Guide β€” FIRE framework
  2. K8s Troubleshooting β€” Symptom-based prompts
  3. Incident Response β€” Workflows
  4. IaC Patterns β€” Terraform, Ansible
  5. Guardrails β€” Security boundaries

Product Designer (5 steps):

  1. Working with Images β€” Image analysis
  2. Wireframing Tools β€” ASCII/Excalidraw
  3. Figma MCP β€” Design file access
  4. Design-to-Code Workflow β€” Figma β†’ Claude
  5. Cheat Sheet β€” Print this

Progressive Journey

  • Week 1: Foundations (install, CLAUDE.md, first agent)
  • Week 2: Core Features (skills, hooks, trust calibration)
  • Week 3: Advanced (MCP servers, methodologies)
  • Month 2+: Production mastery (CI/CD, observability)

πŸ”§ Rate Limits & Cost Savings

cc-copilot-bridge routes Claude Code through GitHub Copilot Pro+ for flat-rate access ($10/month instead of per-token billing).

# Install
git clone https://github.com/FlorianBruniaux/cc-copilot-bridge.git && cd cc-copilot-bridge && ./install.sh

Use

ccc # Copilot mode (flat $10/month) ccd # Direct Anthropic mode (per-token) cco # Offline mode (Ollama, 100% local)

Benefits: Multi-provider switching, rate limit bypass, 99%+ cost savings on heavy usage.

β†’ cc-copilot-bridge


πŸ”‘ Golden Rules

1. Verify Trust Before Use

Claude Code can generate 1.75x more logic errors than human-written code (ACM 2025). Every output must be verified. Use /insights commands and verify patterns through tests.

Strategy: Solo dev (verify logic + edge cases). Team (systematic peer review). Production (mandatory gating tests).


2. Never Approve MCPs from Unknown Sources

24 CVEs identified in Claude Code ecosystem. 655 malicious skills in supply chain. MCP servers can read/write your codebase.

Strategy: Systematic audit (5-min checklist). Community-vetted MCP Safe List. Vetting workflow documented in guide.


3. Context Pressure Changes Behavior

At 70% context, Claude starts losing precision. At 85%, hallucinations increase. At 90%+, responses become erratic.

Strategy: 0-50% (work freely). 50-70% (attention). 70-90% (/compact). 90%+ (/clear mandatory).


4. Start Simple, Scale Smart

Start with basic CLAUDE.md + a few commands. Test in production for 2 weeks. Add agents/skills only if need is proven.

Strategy: Phase 1 (basic). Phase 2 (commands + hooks if needed). Phase 3 (agents if multi-context). Phase 4 (MCP servers if truly required).


5. Methodologies Matter More with AI

TDD/SDD/BDD are not optional with Claude Code. AI accelerates bad code as much as good code.

Strategy: TDD (critical logic). SDD (architecture upfront). BDD (PM/dev collaboration). GSD (throwaway prototypes).


Quick Reference

#RuleKey MetricAction
1Verify Trust1.75x more logic errorsTest everything, peer review
2Vet MCPs24 CVEs, 655 malicious skills5-min audit checklist
3Manage Context70% = precision loss/compact at 70%, /clear at 90%
4Start Simple2-week test periodPhase 1β†’4 progressive adoption
5Use MethodologiesAI amplifies good AND badTDD/SDD/BDD by context

Context management is critical. See the Cheat Sheet for thresholds and actions.


πŸ€– For AI Assistants

ResourcePurposeTokens
llms.txtStandard context file~1K
reference.yamlStructured index with line numbers~2K

Quick load: curl -sL https://raw.githubusercontent.com/FlorianBruniaux/claude-code-ultimate-guide/main/machine-readable/reference.yaml

reference.yaml β€” Structure & Landing Site Search

reference.yaml is organized into several top-level sections:

SectionContent
linesLine number references for key sections in ultimate-guide.md
deep_diveKey β†’ file path mappings for all guides, examples, hooks, agents, commands
decideDecision tree (when to use what)
statsCounters (templates, questions, CVEs…)

The deep_dive section powers the landing site CMD+K search. The build script (scripts/build-guide-index.mjs) parses it to generate 160 search entries.

How the search index works

The CMD+K search on the landing site is an explicit index β€” not a full-text search. Only entries listed in deep_dive are indexed. Keywords are derived mechanically from the key name and file path, not from the file content.

Consequence: adding a new guide section requires explicitly adding an entry to deep_dive, then running pnpm build:search in the landing repo.

Maintaining reference.yaml

Adding a new entry to deep_dive:

deep_dive:
  # existing entries...
  my_new_section: "guide/my-new-file.md"          # local guide file
  my_hook_example: "examples/hooks/bash/foo.sh"   # example file
  my_section_ref: "guide/ultimate-guide.md:1234"  # with line number anchor

Critical: avoid duplicate keys. If a key appears twice in deep_dive, the YAML parser fails and the landing site search index becomes empty (0 entries). The build exits with a warning but no hard error:

[build-guide-index] ERROR: Failed to parse YAML: duplicated mapping key
[build-guide-index] Generating empty guide-search-entries.ts

Use distinct names β€” e.g. if you need both a line-number reference and a file path for the same concept, suffix the line-number key with _line:

security_gate_hook_line: 6907                              # line number ref
security_gate_hook: "examples/hooks/bash/security-gate.sh" # file path ref

πŸ“„ Whitepapers (FR + EN)

A series of 9 focused whitepapers covering Claude Code in depth. Each covers a specific topic and is available in both French and English.

  • 00 β€” De ZΓ©ro Γ  Productif / From Zero to Productive β€” Foundations, first steps
  • 01 β€” Prompts qui Marchent / Prompts That Work β€” Prompting method, context, hooks
  • 02 β€” Personnaliser Claude / Customizing Claude β€” CLAUDE.md, custom agents, skills
  • 03 β€” SΓ©curitΓ© en Production / Security in Production β€” 17 security hooks, threat DB, permissions
  • 04 β€” L'Architecture DΓ©mystifiΓ©e / Architecture Demystified β€” Agent loop, context, token pricing
  • 05 β€” DΓ©ployer en Γ‰quipe / Team Deployment β€” CI/CD, observability, 50+ devs adoption
  • 06 β€” Privacy & Compliance β€” Anthropic data, ZDR, retention policies
  • 07 β€” Guide de RΓ©fΓ©rence / Reference Guide β€” Complete synthesis + advanced workflows
  • 08 β€” Agent Teams β€” Multi-agent orchestration and coordination

β†’ Download all whitepapers


🌍 Ecosystem

Claude Cowork (Non-Developers)

Claude Cowork is the companion guide for non-technical users (knowledge workers, assistants, managers).

Same agentic capabilities as Claude Code, but through a visual interface with no coding required.

β†’ Claude Cowork Guide β€” File organization, document generation, automated workflows

Status: Research preview (Pro $20/mo or Max $100-200/mo, macOS only, VPN incompatible)

Claude Code Plugins (Marketplace)

Production-ready plugins from this guide, installable in one command:

claude plugin marketplace add FlorianBruniaux/claude-code-plugins
claude plugin install session-summary@florian-claude-tools

FlorianBruniaux/claude-code-plugins β€” Session analytics, more plugins coming

Complementary Resources

ProjectFocusBest For
everything-claude-codeProduction configs (45k+ stars)Quick setup, battle-tested patterns
claude-code-templatesDistribution (200+ templates)CLI installation (17k stars)
anthropics/skillsOfficial Anthropic skills (60K+ stars)Documents, design, dev templates
anthropics/claude-plugins-officialPlugin dev tools (3.1K installs)CLAUDE.md audit, automation discovery
skills.shSkills marketplaceOne-command install (Vercel Labs)
awesome-claude-codeCurationResource discovery
awesome-claude-skillsSkills taxonomy62 skills across 12 categories
awesome-claude-mdCLAUDE.md examplesAnnotated configs with scoring
AI Coding Agents MatrixTechnical comparisonComparing 23+ alternatives

Community: πŸ‡«πŸ‡· Dev With AI β€” 1500+ devs on Slack, meetups in Paris, Bordeaux, Lyon

β†’ AI Ecosystem Guide β€” Complete integration patterns with complementary AI tools


πŸ›‘οΈ Security

Comprehensive MCP security coverage β€” the only guide with a threat intelligence database and production hardening workflows.

Official Security Tools

ToolPurposeMaintained By
claude-code-security-reviewGitHub Action for automated security scanningAnthropic (official)
This Guide's Threat DBIntelligence layer (24 CVEs, 655 malicious skills)Community

Workflow: Use GitHub Action for automation β†’ Consult Threat DB for threat intelligence.

Threat Database

24 CVE-mapped vulnerabilities and 655 malicious skills tracked in machine-readable/threat-db.yaml:

Threat CategoryCountExamples
Code/Command Injection5 CVEsCLI bypass (CVE-2025-66032), child_process exec
Path Traversal & Access4 CVEsSymlink escape (CVE-2025-53109), prefix bypass
RCE & Prompt Hijacking4 CVEsMCP Inspector RCE (CVE-2025-49596), session hijack
SSRF & DNS Rebinding4 CVEsWebFetch SSRF (CVE-2026-24052), DNS rebinding
Data Leakage1 CVECross-client response leak (CVE-2026-25536)
Malicious Skills341 patternsUnicode injection, hidden instructions, auto-execute

Taxonomies: 10 attack surfaces Γ— 11 threat types Γ— 8 impact levels

Hardening Resources

ResourcePurposeTime
Security Hardening GuideMCP vetting, injection defense, audit workflow25 min
Data Privacy GuideRetention policies (5yr β†’ 30d β†’ 0), GDPR compliance10 min
Sandbox IsolationDocker sandboxes for untrusted MCP servers10 min
Production SafetyInfrastructure locks, port stability, DB safety20 min

Security Commands

/security-check      # Quick scan config vs known threats (~30s)
/security-audit      # Full 6-phase audit with score /100 (2-5min)
/update-threat-db    # Research & update threat intelligence
/audit-agents-skills # Quality audit with security checks

Security Hooks

30 production hooks (bash + PowerShell) in examples/hooks/:

HookPurpose
dangerous-actions-blockerBlock rm -rf, force-push, production ops
prompt-injection-detectorDetect injection patterns in CLAUDE.md/prompts
unicode-injection-scannerDetect hidden Unicode (zero-width, RTL override)
output-secrets-scannerPrevent API keys/tokens in Claude responses

Browse All Security Hooks β†’

MCP Vetting Workflow

Systematic evaluation before trusting MCP servers:

  1. Provenance: GitHub verified, 100+ stars, active maintenance
  2. Code Review: Minimal privileges, no obfuscation, open-source
  3. Permissions: Whitelist-only filesystem access, network restrictions
  4. Testing: Isolated Docker sandbox first, monitor tool calls
  5. Monitoring: Session logs, error tracking, regular re-audits

Full MCP Security Workflow β†’


πŸ“– About

This guide is the result of 6 months of daily practice with Claude Code. The goal isn't to be exhaustive (the tool evolves too fast), but to share what works in production.

What you'll find:

  • Patterns verified in production (not theory)
  • Trade-off explanations (not just "here's how to do it")
  • Security first (24 CVEs tracked)
  • Transparency on limitations (Claude Code isn't magic)

What you won't find:

  • Definitive answers (tool is too new)
  • Universal configs (every project is different)
  • Marketing promises (zero bullshit)

Use this guide critically. Experiment. Share what works for you.

Feedback welcome: GitHub Issues

About the Author

Florian Bruniaux β€” Founding Engineer @ MΓ©thode Aristote (EdTech + AI). 12 years in tech (Dev β†’ Lead β†’ EM β†’ VP Eng β†’ CTO). Current focus: Rust CLI tools, MCP servers, AI developer tooling.

ProjectDescriptionLinks
RTKCLI proxy β€” 60-90% LLM token reductionGitHub Β· Site
ccboardReal-time TUI/Web dashboard for Claude CodeGitHub Β· Demo
Claude Cowork Guide26 business workflows for non-codersGitHub Β· Site
cc-copilot-bridgeBridge between Claude Code & GitHub CopilotGitHub Β· Site
Agent AcademyMCP server for AI agent learningGitHub
techmapperTech stack mapping & visualizationGitHub

GitHub Β· LinkedIn Β· Portfolio


πŸ“š What's Inside

Core Documentation

FilePurposeTime
Ultimate GuideComplete reference (20K+ lines), 10 sections30-40h (full) β€’ Most consult sections
Cheat Sheet1-page printable reference5 min
Visual Reference20 ASCII diagrams for key concepts5 min
ArchitectureHow Claude Code works internally25 min
MethodologiesTDD, SDD, BDD reference20 min
WorkflowsPractical guides (TDD, Plan-Driven, Task Management)30 min
Data PrivacyRetention & compliance10 min
Security HardeningMCP vetting, injection defense25 min
Sandbox IsolationDocker Sandboxes, cloud alternatives, safe autonomy10 min
Production SafetyPort stability, DB safety, infrastructure lock20 min
DevOps & SREFIRE framework, K8s troubleshooting, incident response30 min
AI EcosystemComplementary AI tools & integration patterns20 min
AI TraceabilityCode attribution & provenance tracking15 min
Search Tools CheatsheetGrep, Serena, ast-grep, grepai comparison5 min
Learning with AIUse AI without becoming dependent15 min
Claude Code ReleasesOfficial release history10 min
Examples Library (175 templates)

Agents (6): code-reviewer, test-writer, security-auditor, refactoring-specialist, output-evaluator, devops-sre ⭐

Slash Commands (26): /pr, /commit, /release-notes, /diagnose, /security, /security-check **, /security-audit **, /update-threat-db **, /refactor, /explain, /optimize, /ship...

Security Hooks (31): dangerous-actions-blocker, prompt-injection-detector, unicode-injection-scanner, output-secrets-scanner...

Skills (1): Claudeception β€” Meta-skill that auto-generates skills from session discoveries ⭐

Plugins (1): SE-CoVe β€” Chain-of-Verification for independent code review (Meta AI, ACL 2024)

Utility Scripts: session-search.sh, audit-scan.sh

GitHub Actions: claude-pr-auto-review.yml, claude-security-review.yml, claude-issue-triage.yml

Integrations (1): Agent Vibes TTS - Text-to-speech narration for Claude Code responses

Browse Complete Catalog | Interactive Catalog

Knowledge Quiz (274 questions)

Test your Claude Code knowledge with an interactive CLI quiz covering all guide sections.

cd quiz && npm install && npm start

Features: 4 profiles (Junior/Senior/Power User/PM), 10 topic categories, immediate feedback with doc links, score tracking with weak area identification.

Quiz Documentation | Contribute Questions

Resource Evaluations (84 assessments)

Systematic evaluation of external resources (tools, methodologies, articles) before integration into the guide.

Methodology: 5-point scoring system (Critical β†’ Low) with technical review and challenge phase for objectivity.

Evaluations: GSD methodology, Worktrunk, Boris Cowork video, AST-grep, ClawdBot analysis, and more.

Browse Evaluations | Evaluation Methodology


🀝 Contributing

We welcome:

  • βœ… Corrections and clarifications
  • βœ… New quiz questions
  • βœ… Methodologies and workflows
  • βœ… Resource evaluations (see process)
  • βœ… Educational content improvements

See CONTRIBUTING.md for guidelines.

Ways to Help: Star the repo β€’ Report issues β€’ Submit PRs β€’ Share workflows in Discussions


πŸ“„ License & Support

Guide: CC BY-SA 4.0 β€” Educational content is open for reuse with attribution.

Templates: CC0 1.0 β€” Copy-paste freely, no attribution needed.

Author: Florian BRUNIAUX | Founding Engineer @MΓ©thode Aristote

Stay Updated: Watch releases | Discussions | Connect on LinkedIn


πŸ“š Further Reading

This Guide

Official Resources

Research & Industry Reports

  • 2026 Agentic Coding Trends Report (Anthropic, Feb 2026)

    • 8 trends prospectifs (foundation/capability/impact)
    • Case studies: Fountain (50% faster), Rakuten (7h autonomous), CRED (2x speed), TELUS (500K hours saved)
    • Research data: 60% AI usage, 0-20% full delegation, 67% more PRs merged/day
    • Evaluation: docs/resource-evaluations/anthropic-2026-agentic-coding-trends.md (score 4/5)
    • Integration: Diffused across sections 9.17 (Multi-Instance ROI), 9.20 (Agent Teams adoption), 9.11 (Enterprise Anti-Patterns), Section 9 intro
  • AI Fluency Index (Anthropic, Feb 23, 2026)

    • Research on 9,830 Claude.ai conversations: iteration multiplies fluency behaviors 2Γ— (2.67 vs 1.33)
    • Artifact Paradox: polished outputs (code, files) reduce critical evaluation β€” βˆ’5.2pp missing context, βˆ’3.7pp fact-checking, βˆ’3.1pp reasoning challenge
    • Only 30% of users set collaboration terms explicitly β€” CLAUDE.md addresses this structurally
    • Evaluation: docs/resource-evaluations/2026-02-23-anthropic-ai-fluency-index.md (score 4/5)
    • Integration: 3 callouts in Β§2.3 (plan review), Β§3.1 (CLAUDE.md), Β§9.11 (Artifact Paradox) + diagram
  • Outcome Engineering β€” o16g Manifesto (Cory Ondrejka, Feb 2026)

    • 16 principles for shifting from "software engineering" to "outcome engineering"
    • Author: CTO Onebrief, co-creator Second Life, ex-VP Google/Meta
    • Cultural positioning: numeronym naming (o16g like i18n, k8s), Honeycomb endorsement
    • Status: Emerging β€” on watch list for community adoption tracking

Community Resources

Tools


Version 3.30.1 | Updated daily Β· Mar 4, 2026 | Crafted with Claude

SEE ALSO

clihub3/4/2026CLAUDE-CODE-ULTIMATE-GUIDE(1)