Skip to content

Catalogue — seeds, never the ceiling

Load when: you already know how to choose (./choosing-tools) and want a starting point rather than a blank search.

Load the row, not the file. This is the longest document here and almost none of it is about your task: reading it whole to answer "what do we use for email" spends a large slice of a context window on ninety categories nobody asked about, and everything after it in the session pays. A row serves every flow that meets its need — the shelf is scoped to no flow (./resources). Search for the need and read what matchesgrep -i "<need>" over this file, or the site's own search. Every category is a row that begins | **Name** |, so one line is the whole answer, and the four headed sections below say which neighbourhood to look in. Read more than one row only when the choice genuinely spans them — a stack decision, or a tool that could sit in either of two categories.

This is the fastest-rotting file here, and it knows it. Prices move, free tiers close, projects get acquired, licences change. So two rules govern it:

A row whose claim can rot — a price, a licence, a measured behaviour — carries a check-date, and past its recheck it is unknown, not fine. The freshness checker reads this file, and a release does not go out with entries past the threshold — scripts/check-freshness.py.

Prices are not recorded here; whether a free tier exists is. They rot at different speeds and lumping them together cost this file its most useful fact. A number moves every quarter — a per-seat rate, a request ceiling, an egress charge — and a cached one is worse than none, because it makes someone skip the check they should have run. Whether the thing can be used for nothing at all is close to stable: a project that has a free tier on the day it is listed almost always still has one a year later, and it is the single fact that decides whether a small team can start today.

So a row says free tier or OSS, self-host and stops there — never the limit, never the price. The ceiling is verified when you wire the thing, in the unit that will actually bite, and recorded in the project's tooling register with its date (./choosing-tools).

A row is a seed. For this project, go and look: awesome-{topic}, registries, the craft's own English terms. A frozen list reconstructs worse than a search, and the reason to keep any row at all is that it carries a licensing or fallback decision worth not rediscovering.

No per-industry section, deliberately. The moment one domain gets its own list, this stops being a method and becomes one author's project → ./choosing-tools.

Contents

Services by need

NeedDefaultWhat you'd use it for
Spec-driven workflow (a spec_mode binding)OpenSpec (MIT) · Spec Kit (MIT)only when the owner binds a format./writing-work. OpenSpec is the default here for a structural reason, not a taste one: a change is a folder of plain markdown — proposal, spec, design, task checklist — archived when done, which is project = f(repo) already. Its loop is /opsx:explore · propose · apply · archive. Spec Kit is the phase-gated alternative — constitution → specify → plan → tasks → implement → analyze — worth it where a project genuinely wants those gates, at the cost of a heavier setup. Both drive 30+ agents by slash command, so neither binds you to a runtime. The three binding questions are unchanged by either choice./writing-work. Both are software tools; elsewhere the format already has a craft name — a creative brief, an editorial policy, a recipe card — and binds by the same three answers, no tool needed. Check-date: 2026-08-01
Product & behaviour frames (craft lenses, never core machinery)by purpose, not one winner: Hunt's awareness ladder (five stages of awareness, after Schwartz) — outward content and campaign strategy · See-Think-Do-Care (intent-based content planning — the successor to reach for where an awareness ladder feels dated) · Fogg B=MAP — onboarding and interface micro-transitions · Hook Model (Eyal) — engagement and habit products · PLG flywheel — growth and monetisation architecture · AARRR (McClure) — funnel metrics · JTBD timeline — deep interviews and CJM (./audience) · Opportunity Solution Tree (Torres) — the product-discovery spine, and it starves without an interview cadence; how its layers land here → ./process-discoverythe type's wave proposes the matching frame with provenance when a product/content type is born — a frame is a lens a craft reasons with, so it lands in the type's bars and the spec's fields (funnel stage, north-star), never as a project-wide law. Not to be confused with the description ladder (./glossary). Check-date: 2026-08-06
Feature flags & progressive deliveryOpenFeature (CNCF — the vendor-neutral SDK standard: wire it once, swap providers freely) · Unleash (open-source, self-host — the flags default) · GrowthBook (MIT — flags and experiments in one, where the rollout is also the A/B) · Flagsmith (open-core)serves ./shipping's rollout axis — canary · staged · flag-gated need a switch that is not a deploy. A flag nobody removes is configuration debt wearing a feature's name: flags carry an expiry like grants, and the audit reads expired ones as findings. The kill switch is a flag with an owner, rehearsed before the first percent. Checked 2026-08-06
Hypothesis & usability test methods (ordered by the cost of being wrong)before anything is built: fake door (a click on a thing that does not exist yet — measures intent as CTR; it spends trust, so the click is told the truth immediately) · hallway / corridor test (five passers-by catch most of the gross problems for the price of an hour) · moderated usability (the richest signal per session — and the observed perform: Hawthorne and social-desirability ride along, named in the read-out) · unmoderated batteries (5-second · first-click · tree test · card sorting · preference test, scored by task-completion rate and time-on-task — scale cheaply, explain nothing by themselves) · in production: A/B (only where traffic can power it; the spec's guardrail measures judge it, not the winning variant's cheer) — framed against abtest.design (~50 real tests from named apps with measured lifts; free, no licence stated — cite, never mirror; a shelf of survivors: published wins carrying no powers or durations, so it calibrates what to try, never what to expect — in a build, a consultation or a review alike; checked 2026-08-07) · progressive rollout — which is ./shipping's own axis, not a testeach method carries its bias on its face, and the read-out names it — the same law as personas' named biases. The plan per outcome says which of these kills the hypothesis (templates/SPEC-template.md), the experiment type's wave proposes the set, and the survey ladder in the row below is what you ask where these are what you watch. Checked 2026-08-07
Experience measurement instruments (a ladder by layer, not one winner)micro — a step: CES (effort, asked right after the hard step: card linked, form survived) · SEQ (one question after a test task — the usability-test standard, CES's lab sibling) · point-CSAT (one touchpoint, right after it) · meso — a scenario: CSI / scenario-CSAT (the whole JTBD walked, asked shortly after it closes) · macro, the software: UMUX-Lite (two questions — useful · easy — the quarterly pulse, and the product team's shield: NPS falling while UMUX-Lite holds says the problem is the business, not the interface) · macro, the product: the Sean Ellis test (how disappointed if it disappeared — the 40%-"very" line is the working PMF bar; the layer between the software and the brand that most ladders skip) · the lab: SUS (ten questions, prototypes and usability tests, never production) · NASA-TLX (workload, for dense professional interfaces) · UEQ-S / SUPR-Q where the study wants hedonic or normed scores · macro, the brand: NPS (twice a year, detached from any action — a top-floor number that explains nothing about why)the instrument matches the layer, the trap is reading one layer with another's tool — and all of these are attitudes: they sit beside the behavioural numbers (retention, completion, the spec's own measures), never instead of them: a mean CSAT masks the furious tail (watch DSAT, not the average) · SUS in production kills its own response rate · NPS handed to a designer is a question with no address. Proposed by the type's wave for product types, and a measure window without a named instrument is a window nobody will read (./shipping). Checked 2026-08-06
Strategy & defensibility frames (craft lenses, like the row above)by purpose: 7 Powers (Helmer) — the current canon for why this position endures: scale economies · network economies · counter-positioning · switching costs · branding · cornered resource · process power · Morningstar's five moats (Stoffel's teaching version circulates widely) — the older valuation lens: intangibles · switching costs · network effect · cost advantage · efficient scale · Porter's five forces — industry pressure, where the two above are firm-levela moat claim is a claim like any other — it carries its evidence or it is positioning copy: "network effect" with flat retention curves is a wish. Lands where strategy is actually decided: the decide loop's criteria, a spec's Why-now, a competitive brief — proposed by the wave when a strategy-shaped type is born, never a project-wide law. Checked 2026-08-06
Prompt-pattern library (a skill import source)Fabric (MIT) — 200+ patterns as markdown system prompts, most of them non-software: summarize, extract wisdom, analyze claims, write essaysan import source, never a bundle: patterns come in one at a time through the screen (./skills, ./security) — and the screen flags any pattern whose body executes anything, which Fabric's extension mechanism legitimises upstream. The three-part body shape (identity → steps → output) is already folded into templates/SKILL-SCAFFOLD.md. Licence and shape checked 2026-08-05
Version control — where the repository livesGitHub · self-host: GitLab · Gitea / Forgejo — verify the edition's licence at adoptionone repository is one project — several deliverables inside it are areas, other repositories are dependencies. Pull requests are the merge gate; their events can trigger automations. A local repository with no remote stays a legitimate end state (./starting) — and every enforced_by: git-host gate then honestly resolves to prose-only or validator, said in the manifest rather than assumed (./permissions, ./runtimes). Check-date: 2026-07-28
Backend / DBSupabase · Convex (reactive TS backend — functions + realtime DB, strong for agent-written code) · Prisma when the shape you want is an ORM over your own Postgres rather than a backend platform — typed schema and migrations agents write well. Read the licence at the repo, not the site: the site now sells a managed Postgres-and-compute platform and reads proprietary, while the ORM has its own terms — the two are not the same product. Free tier on the hosted side. Checked 2026-08-02Postgres + auth + storage + realtime + edge functions in one; RLS for permissions; good MCP
Offline-first syncPowerSyncsyncs Postgres/MongoDB/MySQL/SQL Server into in-app SQLite; kills hand-rolled state-over-API plumbing; web, RN/Expo, Flutter, Swift, Kotlin
Deploy / hostingVercel (web) · Railway (backends/workers/DBs)web apps & sites with preview deploys per PR (Design QA loves them), edge functions, cron; Railway when you need long-running services, queues, or a hosted Postgres/Redis beyond serverless
CI/CD & release automationGitHub Actions + the official GitHub MCP serverbuild/test/deploy on push/PR — and, via MCP, agents read workflow runs, analyze build failures, manage releases (the feedback loop that lets the QA gate fix its own red builds). Alternatives with agent-readable CI: CircleCI (official MCP — pipeline graph, build history, failure logs, artifacts) · Buildkite (heavy parallelism, managed Anthropic model provider) · Dagger (containerized pipelines that run identically locally and in CI, so an agent reproduces a failure on its own machine). Publishing: Fastlane (OSS, store submission/signing) · EAS Build/Submit (Expo) · Xcode Cloud · electron-builder / tauri-action + notarization (desktop). Versioning: Changesets or semantic-release. Gates the launch checklist
CDN & media deliveryCloudflare (CDN + R2 storage with no egress fees — the differentiator, not the tier) · bunny.net (cheap, pay-as-you-go, image optimizer + video) · jsDelivr (free for public/OSS assets)serving images, video, downloads and static assets fast and cheaply — egress is what actually bills you, so start with a no-egress-fee or free-tier origin; Vercel/Netlify already CDN their own deploys, this is for your media, which is where the assets-home decision lands
Video hosting & streamingPeerTube (AGPL-3.0 — self-host, name the copyleft) · Owncast (MIT — self-host live streaming) · Mux · Cloudflare Stream (SaaS)delivering video — adaptive streaming, a player, live — which the CDN and ffmpeg rows don't cover (they move and transcode bytes, they don't run a video platform). AGPL is fine for a service you self-host, not embed. Licences checked 2026-07-26
Containers & serversDocker + Compose (dev parity, the default) · a VPS (Hetzner · DigitalOcean) or Fly.io when you need a long-running box · Kubernetes only past real scale (it is an ops job, not a default)packaging and running things that aren't serverless. Jamstack (static build + APIs) stays the cheapest shape for content sites. Where data lives: a database for rows, object storage (S3/R2) for files and big blobs — never the DB, never the repo, and a CDN in front of anything users download repeatedly
Where to run the OSS tools you pickCoolify (Apache-2.0 — self-host on your own VPS, 280+ apps: the free-first default) · PikaPods (cheap managed, per-app) · Elestio (premium managed — a VM per app, backups/updates/SSL handled) · RepoCloud · CapRover (Apache-2.0)standing up the OSS tools you chose (Grafana, Penpot, Metabase…) without hand-rolling a box — distinct from Deploy / hosting (that is for your code). The 200–400-app catalogues double as a discovery source (what one-click installs even exist). Local vs managed is the owner's call; name the cost shape of both. Licences checked 2026-07-26
Headless CMSSanity · Strapi · Payload · Directus (all OSS or free-tier)when non-engineers must edit content without a deploy; repo-first markdown stays better for docs and for content only engineers touch
Product / site searchMeilisearch (core MIT; Enterprise Edition BUSL-1.1 — verify per component; the self-hostable core is the licence-cleanest default) · Typesense (GPL-3.0 — self-host, name the copyleft) · Algolia (SaaS, free tier)instant, typo-tolerant search over a product's content or catalogue — anything past a handful of items needs it. Both OSS options self-host, so start there before a hosted index; the CDP/analytics rows tell you what people search for. Licences checked 2026-07-26
CDP / event pipelineJitsu (MIT, re-verified alive 2026-07-26 — vendor-neutral default) · RudderStack (Elastic License 2.0 — read 2026-09-10 from the repository, not the site: not OSI open source, and it forbids offering the thing to others as a managed service, which is the clause that decides it the moment an agency considers running it for a client) · Snowplow (licence split — core Apache-2.0, newer components SLULA; verify per component) · Segment (managed). PostHog is itself a full CDP (sources · transformations · realtime-webhook + batch destinations, per posthog.com/docs/cdp, checked 2026-07-26) — legitimate as the layer inside its own ecosystem; a dedicated pipeline is for when the layer must be vendor-neutralone place events are defined and fanned out to analytics/warehouse/ads — so swapping a destination is a config change, not a re-instrumentation. Worth it once two or more destinations exist, or events arrive from 2+ platforms (web + mobile + desktop)
CRM & salesTwenty (OSS, native MCP — agents read and write the CRM in natural language, which makes it the default) · SuiteCRM (AGPL-3.0 — the most feature-complete OSS) · EspoCRM (OSS) · HubSpot (free tier) · Attio (SaaS, no self-host)only when someone is actually selling to named humans; before that a spreadsheet is honest. Twenty leads because its MCP lets agents operate it — a CRM they can drive beats one they can't. Licences checked 2026-07-26
Marketing automationMautic (GPL-3.0, the mature OSS default — self-host) · Listmonk (AGPL-3.0 — newsletters at scale) · SendPortal (MIT — ⚠ dormant, last push 2024; flag per the stale-map rule) · Dittofeed (MIT — customer messaging/journeys) · Apache Unomi (Apache-2.0 — CDP)drip sequences and lifecycle messaging once a product markets to a list — wire to what's already here, don't duplicate: posting (Postiz/Buffer), transactional send (Resend), the event pipeline (Jitsu/PostHog). Opt-in; surfaces only for a project that produces marketing. Licences checked 2026-07-26
Media, image & video toolingsharp · ImageMagick · ffmpeg (conversion, resizing, transcode — scriptable, so agents can run them) · Squoosh · generative tools for product shots/video when the brand allows · PhotoRoom (background removal, free) · Lexica (AI-image gallery/search, free)asset pipelines, format conversion, thumbnails, social crops; pairs with ComfyUI for generated imagery. Checked 2026-07-26
Generative media (hosted inference)fal.ai (verified 2026-07-26 — 1000+ models across image/video/audio/3D behind one API; pay-per-output or GPU-hourly — fetch live prices at decision time) · Apiframe (70+ models incl. Midjourney and Suno behind one interface; free tier, then paid; credits per model — fetch the number at decision time — and its licence grants nothing the underlying model withholds: commercial use is permitted "subject to each model provider's content policy", so the question is always which model made the asset, recorded beside it with a date; checked 2026-09-10) · Replicate (the breadth peer — run or fine-tune community models over an API). Self-host end of the same ladder: ComfyUI (graphs on your own GPU)hosted image/video/audio/3D generation for content and marketing pipelines when you don't want to run a GPU — an API an agent drives, not a dashboard. Generated output is logged like any other asset (_ops/assets.md) under the same free-assets/licence discipline. Prices are the vendors' claims, re-fetched at use
Style presets — a vocabulary, not a machineFooocus sdxl_styles/*.json is the de-facto format everyone else ports: a named style, a positive and a negative fragment, a {prompt} placeholder. Ports and collections: ComfyUi_PromptStylers (nodes for ComfyUI, which is already the self-host rung above) · MK-Styles. Checked 2026-08-09use them for the words, not for the incantation. A preset library is a shared vocabulary for the conversation with the owner — a couple of hundred named looks you can point at instead of describing one in adjectives, which is genuinely the hard part of a first brief. What it is not is a style system. These are SDXL-era prompt suffixes, and the models behind the hosted rung answer to plain description and to a reference image, not to , trending on artstation, 8k, masterpiecedate this claim and re-read it, because it is the fastest-moving fact in this neighbourhood. And by ./visual's own law a project has one style, recorded once, not a menu of two hundred: a preset picked per image is a moodboard folder in JSON, and it drifts exactly the way a moodboard folder drifts. What actually makes two images match is the recipe, and the recipe is a field./visual §A generated asset carries its recipe
Image → prompt (describing a picture in words)Start with the model you already pay for: Claude or GPT-4o vision describes any image in editable language, free at low volume, no install. Below that, and only for a reason: CLIP Interrogator (BLIP + CLIP, local, open source) · JoyCaption (a captioning VLM on Hugging Face) · Midjourney's own /describe, strongest on Midjourney-shaped images, four candidates per upload. Checked 2026-08-09the reasons to go past the vision model you have are the same two as for local Whisper: a batch big enough that per-call pricing bites, or images that must not leave the machine. Otherwise this is a GPU dependency for something already in your hand. Three uses that are actually ours, and none of them is copying somebody's style: recovering the recipe for an asset whose provenance was lost (the failure ./visual §A generated asset carries its recipe exists to prevent — recovery is the expensive repair, the field is the cheap one) · turning a client's reference deck or moodboard into words the register can hold, so taste stops living in a folder nobody can query · alt text, which is also exactly what anydoc leaves behind when a deck's argument was in its pictures
Voice and transcripts — speech-to-text / text-to-speechA ladder, because the top rung is usually free. 1 · the words already exist — YouTube and most platforms ship a caption track: youtube-transcript-api (Python, no key, captions only) · yt-dlp (Unlicense — sturdier, batches, more edge cases, and the one that pulls the audio when there is no caption track). 2 · no captions, or you need timings you trustWhisper (MIT — runs locally, the default). 3 · scale or synthetic voiceDeepgram · ElevenLabs (both SaaS). Checked 2026-08-09transcription and voiceover — load-bearing for content pipelines: interview audio → transcript feeds the QDA/persona chain (./audience), a talk or a competitor's video becomes readable evidence, video gets narration, podcasts get captions. Transcribing a video that already has a caption track is paying twice, in GPU time and in wall clock, which is the whole reason this is a ladder and not a list. Rung 1 is unofficial and that is its real limit: RequestBlocked, cloud-IP blocks and parser breakage when the markup moves — fine for a research pass on a laptop, an operational risk in a standing pipeline, where it needs proxies and retries or it needs to be Whisper. Local Whisper also keeps the audio on the machine and off a meter, which is sometimes the deciding fact rather than the cost
Public-domain graphics — engravings, botanical plates, maps, ornamentPD Image Archive11,206 out-of-copyright works, in its own words free for all to browse, download, and reuse (read 2026-08-23; the screenshot that brought it said 10,000). Out of copyright is a claim about a jurisdiction, not a licence text — there is no terms page, so record the work's own origin and date in _ops/assets.md rather than citing the archive as the licence. Genuinely a source: the material may ship in a producthistorical texture nobody else has, at zero licence cost, for the one category where stock libraries are weakest
Free assets / stock — where to sourceEvery source here carries two contracts, and they do not have to agree: the licence on the content, and the terms on the way you reached it. Worked example, verified 2026-07-31 — Pexels: the content licence requires no attribution (and forbids selling unmodified copies, implying endorsement, or re-listing on other stock sites), while the API terms require prominent attribution to Pexels in your app and cap you at 200 requests/hour and 20,000/month. Same photo, opposite obligation, decided by whether a human downloaded it or an agent fetched it. So: read the licence page and the API/terms page, and where an API reports its own ceiling in response headers (Pexels sends X-Ratelimit-Limit, -Remaining, -Reset) read the ceiling at runtime instead of recalling it. licence-first: prefer CC0 / public-domain / permissive, verify per item. Photos Pexels · Unsplash · Pixabay · Video Mixkit · Coverr · Pexels · Audio Pixabay Music · Mixkit (⚠ FMA/Uppbeat/Freesound need credit) · Public-domain art The Met · Art Institute Chicago · Rijksmuseum · Smithsonian · Cleveland · Getty · SMK (search "museum + open access") · Icons Lucide · Heroicons · Tabler · Simple Icons · Iconify · Illustrations unDraw · Open Peeps · 3D/textures Poly Haven · ambientCG · Kenney · Fonts Google Fonts · Fontshare · Meta-search Openverse (filter CC0) · Patterns/gradients Hero Patterns · SVGBackgrounds · Haikei · GradientHunt (⚠ usage terms unverified — check before shipping an asset)sourcing images/video/audio/icons/3D you can edit and ship commercially without credit; this is where to get, distinct from the processing row above and from generation. The owner's own brand kit / licensed stock / named source wins — never push free stock over it, and their assets stay theirs. Discipline: log every asset actually used in _ops/assets.md (what · source · licence · where) — provenance is portability, and the licence must be provable; name the source in use ("search icon from Lucide, MIT"); commit to one chosen set (icon pack · illustration style · photo look) for consistency, widening only on a real gap
Animation & motionGSAP (web, now free incl. plugins) · Rive (interactive, runtime state machines) · Lottie (After-Effects export) · Framer Motion (React) · Cavalry (designer-side, AE alternative) · Jitter (SaaS, free tier — quick motion by hand for social/marketing clips; the OSS default for automated video stays Revideo / Motion Canvas, see Programmatic video) · Motion Prompts (200+ GSAP/WebGL animation components written to be regenerated by an agent rather than copied — licence not stated) · GodUI (MIT, React motion components) · transitions.dev (curated UI transitions — modals, cards, loaders — free tier, with a paid tier) · single-effect drops: Border Beam and Thinking Orbs (npm, React/SwiftUI/RN — licence not stated). Checked 2026-08-02motion in product and marketing; Rive/Lottie ship as data the app plays, GSAP for direct control. Checked 2026-07-26
Programmatic video (video-as-code)Revideo (MIT — render API, server rendering, templates: the default for automated pipelines) · Motion Canvas (MIT — hand-authored explainer animation) · Remotion (⚠ custom source-available "Remotion License" — free for individuals and small orgs, paid Company Licence beyond; not BUSL, no change date; fetch current terms; video as React components) · MoviePy · Editly (both MIT — scripted assembly over ffmpeg)rendering video from code for automated content pipelines — distinct from the ffmpeg row (conversion/transcode) and from Animation & motion (interactive/runtime). Default OSS by the ladder; the most popular pick, Remotion, is the one that isn't free — say the licence out loud. Licences checked 2026-07-26
Presentations — slides, decks, pptxThe question is who owns the deck afterwards, and it picks the tool. Nobody but the repoMarp (MIT, whole family — markdown in, self-contained HTML plus pptx and pdf out; the CLI runs in CI, so a deck is reviewed in a pull request like anything else): the default here, because it is the only rung where project = f(repo) still holds. The deck runs codeSlidev (live components, line-by-line listing animation — dev talks). A paper and a deck share one sourceQuarto (.qmd → RevealJS, Beamer, PowerPoint). A human edits it in PowerPoint tomorrow → Anthropic's pptx skill (create/edit/read, design-QA pass, palettes — heavy on dependencies: markitdown, Pillow, pptxgenjs, LibreOffice, Poppler) or claude-office-skills for the whole office set. What goes on the slidesacademic-pptx-skill, which is content discipline rather than file plumbing and layers over the official one. Checked 2026-08-09a deck is a deliverable like any other, and the moment it stops being text it stops being reviewable — no diff, no blame, no gate, and the last edit lives on somebody's laptop. So start at Marp and move down the list only when a named reason pushes you: the slides execute, a paper shares the source, or a person outside the repo must edit the file. The interesting rule is academic-pptx-skill's and it is worth stealing whatever you generate with: action titles — a slide's heading states the finding, not the topic ("Churn doubles after the third failed sync", never "Churn analysis") — plus structured argument, exhibit discipline and citation standards. That is a form, not an exhortation, which is why it works. The other direction of the same door is anydoc (above): decks arrive as .pptx and leave as markdown
Canvas / WebGL effect componentsPaper Shaders (Apache-2.0 — licence-cleanest default; 30+ animated WebGL shader effects, zero-dep, vanilla + React) · Canvas UI (MIT + Commons Clause — free, no reselling the components themselves; effects render over live DOM via the experimental html-in-canvas API, so name the browser caveat; React/Solid/Preact/Vue/Svelte/vanilla, shadcn-CLI model, ships an MCP server so agents drive it out of the box) · tsParticles (MIT — particles/animated backgrounds, every major framework) · Vanta.js (MIT, dormant since 2024-03 — list only with the flag) · OpenShaders (WebGPU effects directory, frontier flag — browser support). Liquid Metal (npm, a single liquid-metal shader wrapping a button or shape — licence not stated, checked 2026-08-02) · Compose-your-own layer below: three.js + drei · OGL · PixiJS. Facts checked 2026-07-25generative shader & particle effects — hero/marketing backgrounds, ambient product motion — composed from a library, not hand-written GLSL; distinct from Animation & motion above, which is timeline/interactive motion, a different craft
2D graphics — canvas & SVG (programmatic)canvas: Konva (interactive scene-graph, best framework bindings — react-konva etc.; licence field NOASSERTION, historically MIT — verify) · Fabric.js (MIT — design-editor object model, SVG import/export bridge) · PixiJS (MIT — WebGL-accelerated when performance is the point). SVG: svg.js (licence field NOASSERTION — verify; manipulation/animation) · two.js (MIT — one API over SVG/canvas/WebGL renderers) · D3 (ISC — data-driven documents) · SVGO (MIT — the optimization step in any SVG pipeline). Hand-drawn: rough.js (MIT, stable/low-churn). Creative coding: p5.js (LGPL-2.1 — name the licence). Dormant/legacy, flag per the stale-map rule: Paper.js · Snap.svg. Whiteboard SDKs: Excalidraw (MIT) vs tldraw (custom licence — watermark unless paid) — licence-first favours Excalidraw. Facts checked 2026-07-25programmatic 2D — Fabric for design editors, Konva for interactive UIs/dashboards, Pixi for high-perf/games (≈500K/400K/200K weekly downloads, pkgpulse 2026-02 — re-verify) · SVG generation, animation and optimization · whiteboards; distinct from Mermaid (diagrams-as-text)
Game enginesGodot (MIT — the free-first default) · Bevy (Rust, Apache-2.0) · Phaser (MIT — web games) · LÖVE (zlib) · Defold (source-available, custom Defold licence — verify) · Unity / Unreal (proprietary, royalty terms — only if the owner names them)building a game or an interactive real-time surface; the OSS engines carry no per-title royalty, the trap in the proprietary two. Licences checked 2026-07-26 via GitHub API
Secrets management & KMSInfisical (core MIT, open-core — RBAC, versioning and SSO past Google/GitHub are Pro, dynamic secrets/SCIM Enterprise even self-hosted; verify per feature; Postgres+Redis, .env/k8s sync, a CLI and API an agent can drive — the free-first default) · OpenBao (MPL-2.0, Linux Foundation — the open fork of the last MPL Vault, API-compatible; for Vault-class machinery: dynamic secrets, leases, policies. Vault itself is BUSL-1.1 — flag) · SOPS + age (MPL-2.0, CNCF — encrypted secrets as files in the repository, which is this system's own shape; the GitOps default) · External Secrets Operator (Apache-2.0, CNCF — Kubernetes sync from any backend) · Cosmian KMS (BUSL-1.1, source-available — flag; KMIP-compliant, FIPS 140-3, Rust — a KMS proper: key lifecycle, not value distribution) · Bitwarden Secrets Manager (licence split per component — verify) · Doppler (managed SaaS). Licences checked 2026-07-30one audited place a project's keys live and rotate — CI, deploy targets, the product's backend. The register still records where a secret lives, never its value (./permissions): a secrets manager is the grown-up form of "the environment or a keychain", not an exemption from the register. A secrets store ≠ a KMS — the first distributes values, the second manages key lifecycle (KMIP/HSM); most projects need the first, compliance names the second. A key that has appeared in a chat or a log is rotated, not debated
Local AI modelsOllama · LM Studio · llama.cppwhen data must not leave the machine, or a cheap local model is enough for bulk/offline work; the AI gateway stays for the heavy calls
Colour & palettesexploration: Coolors · Color Hunt · Realtime Colors (all free) · the science, when "looks right" has to become a number: Björn Ottosson — author of Oklab/Oklch, and the argument rather than a tool · Atmos · cielab.io · Hueplot (see a ramp's lightness rather than guess it) · Eva Design colours (checked 2026-09-10)palette exploration that then becomes design-system tokens — inspiration is an input to the system, never a substitute for it. The decision underneath is the colour space, and oklch() moved it from tooling into CSS: a ramp can be generated where equal lightness steps look equal, which is what makes contrast survive a dark-mode flip and a brand tint at once. Read Ottosson before reaching for a generator — a palette whose author cannot say why the ramp is even gets re-picked by the next person
A council for expensive questionskarpathy/llm-council (24k★ — the original: several models answer, peer-review anonymized, a chairman synthesizes; licence unstated — flag) · claude-skills-llm-council (1.5k★ — the same shape packaged as a Claude skill with five thinking lenses inside one model; licence unstated, dormant since 2026-04; checked 2026-08-14)the method's home here is ./consulting, implemented in house prose because neither upstream states a licence. The distinction that decides which shape you want: the packaged skill's five lenses are one bias five ways — cheap, and honest about being angles; the original's many-model form buys diversity of failure, at the price of keys and a gateway. Either way consensus is not a rung — a council surfaces angles the way personas do, and its verdict cites or it is a judgement call
Marketing skills, as a poolcoreyhaines31/marketingskills (MIT, 44k★, active — 49 skills: pricing · cro · copywriting · seo-audit · launch · customer-research · churn-prevention · attribution · offers · paywalls and thirty-nine more, versioned, cross-referenced; checked 2026-08-14)a pool to draw from, never an attachment — a role carrying twelve skills is worse at each of them, so a marketing role takes the two or three its tasks name, through the skill screen like any import (./skills). Taking three, concretely: clone the pack at a pinned commit, copy those three directories into _ops/skills/, and record the pack and the commit as their source — the pack stays upstream, the three copies are what the project runs (./skills §Import). The trim has two moves, not one. The pack is cross-referenced, which is a virtue in the pack and a defect in a subset: three skills lifted out of forty-nine still point at the forty-six that did not come, so cut the dangling references as the first move. The trim step has one extra move here: the pack's own context convention (.agents/product-marketing.md) duplicates registers this system already keeps — point the trimmed copy at _ops/brand/, _ops/audience/ and the competitor register instead, or every marketing skill re-asks what the project already recorded. Its defaults are US-SaaS-flavoured (seat pricing, Van Westendorp) — usable elsewhere, said out loud. Its own marketing-council is a domain instance of the council form (./consulting)
Early signals — builders in public, and the corpsesthe pass, not a vendor list (a frozen directory records what was true when someone submitted it): accelerator and launch-platform archives — including what closed, pivoted or never took off · people building the same thing in public: changelogs, demo threads, personal sites, pitch posts · the freshest window split out and dated as a claim"grew in the last 12 months" is a trajectory claim and carries its source and check-date like any other, or it is an opinionthe research pass competitor registers miss twice over: a dead analog is first-class evidence — why it died is the cheapest risk register you will ever read — and a builder in public is a demand signal and a competitor sighting in one. Findings land as rows in the competitor register with the stage/outcome named (live · pivoted · dead — dated, sourced); the corpses feed risks, the builders feed watch
Where the demand signal livespick by category, not by habit: developer tools → Reddit, then GitHub issues · consumer goods → Amazon reviews, then YouTube comments · B2B/professional → LinkedIn and community Slacks · anything visual → TikTok/Instagram comments. One tool runs this method across sources at once: last30days (MIT, data stays local — Reddit · X · YouTube transcripts · TikTok · Polymarket · HN · GitHub · arXiv, merged into one cited brief; its own line is "searches people, not editors"). Checked 2026-08-09listening in the wrong place returns confident nonsense. Two or three sources per question, chosen deliberately, beat scraping everything. Feeds research, audience and the support role. Aggregators exist (RequestHunt and similar) but are credit-priced — start with the free reads. Two things to know before last30days is the answer. "No keys" is true of a slice: Reddit, HN, Polymarket and GitHub are free reads; X wants browser cookies or a key, TikTok/Instagram/LinkedIn go through a paid third party, YouTube goes through yt-dlp — so what you actually get depends on which of those you have. And engagement weighting is not representativeness: upvotes and likes are a loud minority, which makes this the top of the signal pyramid handed to you as if it were the base → ./audience. Excellent for what is being said this month; not evidence of what most people want
Deep research, run as a jobWebhound — an agent that runs a bounded web-research pass and returns a sourced report or a dataset, with the budget as an input. Free to start; licence not stated. Checked 2026-08-02for the shape of question where the answer is a survey rather than a fact — a landscape, a list of players, a dataset that does not exist yet. It is a search tool, not a source: what comes back is graded by the row below like anything else, and a claim that matters is followed to its primary source. A budget cap is the feature to notice — an unbounded research agent is the classic way to spend a week's tokens on a question worth ten minutes
Academic & research sourcesGeneral index: OpenAlex (data CC0, ~2× Scopus coverage and better on non-English work — but the API now requires a free key and meters a $1/day free budget, so it is free-with-a-ceiling, not free-forever; verified 2026-07-31) · Semantic Scholar (+ a free API) · ACM Digital Library (much of it now Open Access) · Scinapse. Preprints: arXiv (CS/physics/math) / bioRxiv · medRxiv (clinical). Open-access resolution: Unpaywall — free REST API over ~50M open versions of paywalled articles, keyed by DOI; the step between having a citation and having the text, and the one that decides whether a licence tier lets us hold anything at all (added 2026-09-10). Life sciences & medicine: Europe PMC (EMBL-EBI, free, REST API, ~48.5M records including preprints; verified 2026-07-31) · PubMed · ClinicalTrials.gov for a trial's own record — phase, endpoints, statuswhen research needs a primary source for an evidence-backed claim, not a web-search paraphrase — pairs with an argument without a source is an opinion. Free reads; cite the paper, don't launder it. Match the source to the field, or the rule is followed and the answer is still wrong: arXiv/ACM settle a CS claim and say nothing about a drug, a clinical or regulatory claim is settled at Europe PMC / PubMed / ClinicalTrials.gov, and a news story or an industry site reporting a study is not the study — cite what it paraphrases. Row rechecked 2026-07-31 (OpenAlex, Europe PMC verified live; the rest carried from 2026-07-26)
Structured comparison dataVersus — 90+ categories side by side, and far past gadgets: cities and countries (demographics, salary, unemployment, public healthcare, rents by room count and centre/outskirts, climate, museums and theatres, commute time and the Commuter Pain Index, tourists per year) · universities and law/medical/business schools · foods down to oils and legumes · apps and operating systems. Free. Measured by browsing it 2026-07-31, not by trusting its own page: it 403s any plain agent fetch and reads normally in a browser — this is the row above's use case, not a fetch-tool one · its stated process is official authorities for cities and countries, manufacturers for products, DxOMark/Geekbench secondary, with sources listed per comparison · product pages carry affiliate links and commission, disclosed — a bias to hold for products and not for cities · and the listing's "Versus score" publishes no weighting: its world top ten came back Sochi · Da Nang · Navi Mumbai · Jamshedpur, so it measures something specific and is not a "best city" ranking however it readsthe fast way to find which axes even differ between two options — the framing step, not the evidence step. And the data has visible holes: on one listing pass Thane showed 1.16 people/km² beside Vasai-Virar's 3,900, and several cities carried no temperature at all. So frame the comparison here and re-fetch from the authority any figure a decision rests on — which is where their own accuracy note points anyway. Feeds the comparison shape in ./consulting and the market side of research
Reading and choosing a licenceSPDX License List (Linux Foundation, v3.28.0 at check — the identifier authority: MIT, Apache-2.0, GPL-2.0-only, and the deprecated ids kept for history) · choosealicense.com (GitHub, CC BY 3.0 — picking one, including the "my project isn't software" path for docs, data and art). Both free, verified 2026-07-31this file flags a licence in nearly every row and had nowhere to send anyone to read one — the gap only shows when the answer is "which licence should this be" rather than "what licence is this". An identifier is not a reading: SPDX settles which licence is meant, the text settles what it permits, and neither is a lawyer — a copyleft obligation on something a client will ship is where that stops being a formality. Custom and source-available terms (BUSL, Commons Clause, "Remotion License") have no identifier to look up and are read in full, at the moment of use
Behavioural & cognitive referenceReusable index — licence-clean: Wikipedia's list of cognitive biases (CC BY-SA, grouped by task and by mechanism; the working-language edition is the door to useru.wikipedia.org/wiki/Список_когнитивных_искажений and its siblings carry the same licence and their own history, which every offline mirror of them has lost) · the Cognitive Bias Codex (180+, Benson's categorisation drawn by Manoogian, CC BY-SA 4.0 — attribution and share-alike, so a derivative carries the licence with it). Bigger, and not reusable: The Decision Lab (~150, free reads, copyrighted) · Growth.Design (106 entries, many still Coming Soon, all rights reserved, no per-entry citations — built on the Codex and trade books) — its applied half is the 53 case studies (free comic-format teardowns of real onboarding/retention/revenue/ethics decisions; same all-rights-reserved — point at them, never mirror; checked 2026-08-07) · Laws of UX (30 principles, CC BY-NC-ND 4.0 — non-commercial and no derivatives, which rules out both a client project and a reworded copy). The largest one is gone: Neurofied's 200+ database was open-sourced and taken offline, its author citing AI companies copying it without credit — a fact worth carrying, since it is the exact use this row must not become. Deceptive patterns: deceptive.design (18 named types mapped to laws and enforcement actions; Testimonium Ltd, no open licence stated — cite, don't reproduce). Whether an effect holds: never here — the paper, through the Academic & research sources row. All verified 2026-07-31the instrument behind a rule that already exists: every persona carries two to four named biases and a proto's grounding is published literature, source named (./audience). An index answers what it is called; it does not answer whether the effect survives — and a persona built on a finding that failed to replicate is a caricature with a citation on it, which is the same failure the demographics ban exists to prevent. Product-side the split repeats: the taxonomy names what a design is doing, and the law it maps to is what makes it a risk rather than a style. This row is not where the conversational ones live: sycophancy, response-order effects and silicon sampling are a closed set this system acts on itself, each already pinned to its own paper in ./sources. An index is needed only for the open set — a persona may name any bias at all, and that is the one with nowhere to look it up. And a worked case beats recited theory wherever the need arises: a build shaping an onboarding, a consultation weighing a paywall, a review naming what fired — each points at a teardown where the principle moved a real product, and the shelf is for citing, never for mirroring into docs
Codebase orientationa maintained map in the repo (_ops/ARCHITECTURE.md: what lives where, entry points, the paths a change usually touches). Past a large codebase, a generated index — graphify (dual-licensed Apache-2.0 / MIT — two licence files, re-verified 2026-09-10; Tree-sitter AST parsing; "nothing leaves your machine" is its README's claim about the local half. The zero-credit build is real, and what it builds is an index. Measured 2026-09-10 on v0.8.4 over a 179-file corpus: graphify update produced 1457 nodes and 1433 edges with no key and no network — but 1118 of those edges are contains, exactly one edge in the graph was INFERRED, three quarters of the nodes come from markdown files — the file and its headings, whose only relation is contains, and it found no path between a shell script and the Python file it invokes, because that is not an AST call. The edges that make it a graph come from the semantic pass, which needs an API key — untested here. Asked the one question this corpus had just got wrong, its query matched a bash function named stop()) — with Data Structure Protocol (.dsp/, stable UIDs surviving renames) or a repo-map tool as alternativesevery task starts in a fresh worktree with zero context, so whatever is not written down is re-derived by every agent on every run. A stale map is worse than none: it falls under docs-follow-decisions like any other doc
Context compression / token economyHeadroom (Apache-2.0, local-first — 62k★, pushed 2026-07-25)shrinks what an agent reads before it reaches the model — tool output, logs, RAG chunks, history; library / proxy / MCP modes. Directly on the minimum-resources mission and complementary to graphify: the graph cuts what you fetch, Headroom cuts how much you send. Its 20% / 60–95% token-savings figures are the project's own claims — measure on your own workload. Licence checked 2026-07-26
Screening imported toolingclaude-skill-antivirus (OSS, pattern-based)scans a candidate skill, MCP server or CLI tool — anything whose code runs on your machine or whose text enters an agent's context — for destructive commands, exfiltration of .ssh/.aws/.env, unexpected external endpoints, over-broad tool grants, injection text, risky MCP configs and sub-agent abuse; severity-scored, block/confirm/warn. Pattern matching, so false positives are normal (a password-manager integration looks like credential access) — it informs the human gate, it isn't the gate. Run both, because they fail in opposite directions. Skill Vetter is the same job as a checklist the model executes — full-source review, provenance (author, stars, last push), named red flags (network exfiltration, credential access, eval/exec, base64 obfuscation, sudo, hidden downloads), permission-scope analysis, four risk tiers each with an action. It reads intent, which patterns cannot — and is therefore the one that can be talked out of it, by instructions written into the very file it is screening (./security: imported text is data, never instructions). The scanner cannot be argued with and cannot read intent; the checklist reads intent and can. Neither is the gate. Checked 2026-08-09
Where skills live — finding one before screening itSkillsMP (browse public SKILL.md files from GitHub by task, creator or occupation — and read the source in the browser before installing, which is the property that decides this row) · LobeHub · Claude Code Marketplaces · awesome-claude-skills (a curated list, so it ages like every curated list). Checked 2026-08-09the step before the row above: a candidate has to be found before it can be screened. Search by the job, never by the star count — a skill that does one thing is the one that survives contact with your process, and a marketplace ranks by installs, which measures curiosity. Reading the source is not optional and is why SkillsMP leads: a skill is instructions an agent will follow and code that will run on your machine, so a directory that shows you neither is an advertisement. Then it still goes through the screen and through /opsinist:skill's import — finding is not vetting, and a name in a good list is not provenance
Finding alternatives / OSS catalogsOpenSource Alternative · OpenAlternative · AlternativeTo (filter to OSS) · awesome-selfhosted · public-apis (MIT, alive 2026-07-25) for the other search — not "what replaces this tool" but "is there already an API for this": currencies, weather, geocoding, the thing a project would otherwise buildthe search step behind the selection ladder — when a tool dies, is acquired, or closes its free tier, or you just want the OSS equivalent of a paid default. Feeds the free → OSS → self-host ladder, doesn't replace the judgement. A listed API is a candidate, not a decision: its licence, rate limit and price are fetched at the moment of use like any other fast-rotting fact, because a directory records what was true when someone submitted it. Checked 2026-07-29
Security scanning (your own code)Claude Security plugin (beta, shipped 2026-07-22 — re-verify at wiring time; /plugin install claude-security@claude-plugins-official) — a pre-commit diff scan plus a full multi-agent codebase review, both running on the owner's existing Claude inference (a free-first win over standing up a new-vendor scanner). Code projects only — it needs a Claude Code runtime, and it is not for audit of a markdown skill repo. The free OSS set it complements, which is what most projects actually wire: gitleaks / trufflehog (secrets, in CI) · semgrep OSS (static analysis) · CodeQL + Dependabot (free on GitHub) · npm audit / osv-scanner (dependencies) · Arcjet (free tier — fetch its current ceiling at decision time; rate limiting, bot protection, email validation as an SDK, which closes the no rate limiting on public endpoints classic miss) · OWASP ZAP and nuclei for the automated pentest pass under a human one. Method and the misses this set exists to catch → ./security. Names carried 2026-07-31; each verified at wiring time like any other rowvulnerabilities caught before they merge and on demand across the codebase; it is the natural tool behind the "security pass before anything public ships" LATER trigger, and a reviewer-side diff-scan option in code companies — installing it on a runtime is a config change, so ask first and log the ledger line
Writing without the AI smellhumanizer (MIT, 35.5k★, v2.9.1 — a Claude/agent skill built on Wikipedia's Signs of AI writing: 24 named anti-patterns, a two-pass audit, voice calibration against the author's own sample, and the load-bearing rule — the rewrite may not contain a fact the source did not; checked 2026-08-14)the deep pass for anything a human will read — deliverables, letters, posts, docs. It attaches through the skill screen like any import (./skills), to roles that write for humans, not to everyone: a 30 KB skill on every role is a load-budget tax the guide's own short ban list already covers. Two limits in the row: its tells are English tells — Russian slop has its own smell («стоит отметить», «давайте разберёмся», «в современном мире») the list does not know, so the house list carries both — and it never runs over quotes, citations or legal verbatim, because a humanized quotation is a fabricated one
Skill compressionskills-optimizer (semantic-compressor, OSS)shrinks a skill or agent file fail-closed: an inventory of concepts that must survive is built first, commands/tools/paths/numbers/errors/security rules are preserved verbatim, an independent reviewer judges equivalence, and nothing is written until --apply. States include NOT_COMPRESSIBLE — an honest outcome, not a failure. An idempotence marker stops re-compression, which is what compounds loss. Point it at the always-loaded body only, and hold the output to prose a person can read — a skill is opened by a human to screen, approve and diagnose it, and a wall of clipped fragments breaks all three gates while looking like a win. Note the divergence from this system: here fitting is selection, never rewording, and it fails open with an announcement
Reading pages agents can't fetchcf-browser (OSS Worker over Cloudflare Browser Rendering) · Crawl4AI (Apache-2.0, self-host, zero keys — LLM-ready markdown with headings/tables/citation hints, deep multi-level crawls; checked 2026-08-06) · Playwright for anything you already test withJS-rendered pages, screenshots, PDFs, accessibility snapshots, multi-page crawls — for research, competitive monitoring and checking your own live page. Crawl4AI is the default when the job is a corpus, not a page — a competitor's docs, a reference site the owner dropped — because clean markdown at depth is the thing the others don't do; Firecrawl (below, AGPL) is its hosted-first sibling. cf-browser's free tier is metered by rendering minutes; interaction tools need the paid plan — fetch current limits and price at decision time
Reading documents agents can't parseanydoc (MIT, Rust — npx @firecrawl/anydoc <file>, or Node/Python/Rust/WASM bindings; runs locally, no key and no model call. It also ships as an agent skill, npx skills add firecrawl/anydocthat route is an import and goes through the screen, never straight off the shelf → ./skills §Import. Checked 2026-08-09)office and e-book files → markdown, so an agent can read them at all: doc/docx · ppt/pptx · xls/xlsx · odt/ods/odp · rtf · epub · csv, and text-based PDFs. Where they actually arrive here: a backlog exported as a spreadsheet (./importing → extract), a source that exists only as a paper (sources/), a segment's own words trapped in someone's deck (the persona chain, ./audience). Two limits decide whether it is the right answer, and they are in the row because a converter that quietly returns nothing is worse than no converter: there is no OCR — an image-only or password-protected file is an explicit Unsupported or Encrypted, never a silent empty result, and the fallback is a real OCR pass or a hosted parse (the same project sells one); and images become their alt text, so a deck whose argument lives in its pictures arrives without it — keep the original attached as the resource. Its speed and coverage numbers are the project's own LLM-judged benchmark against six other converters — a claim measured on their corpus, not a fact about yours. Distinct from Reading pages agents can't fetch: that one is the web
Browser control (for agents)Playwright MCP (Apache-2.0 — local, accessibility-tree driven, free: the default) · Chrome DevTools MCP (Apache-2.0 — profiling, network and console of a live page) · Firecrawl (AGPL-3.0 — others' sites at volume, hosted or self-host) · cf-browser (above)drive from the accessibility snapshot, not a screenshot — cheaper and less brittle. Distinct from Reading pages agents can't fetch: that pulls content, this operates a browser (navigate · fill · test). Licences checked 2026-07-26
Cloning a page you are allowed to cloneDitto (MIT, free, self-hostable or a hosted API) — takes a URL and emits componentised Next.js or Vite code, deterministically rather than by asking a model to guess: it extracts the design system, tokens and interactions. Checked 2026-08-02the honest use is your own site — a rebuild, a migration off a builder, or lifting your live styling into a new stack — and a competitor's layout as a reference you then design away from. Cloning someone else's page and shipping it is a legal question, not a technical one, and this row does not answer it
Prompt-to-code buildersv0 · Bolt · Lovable · Replit Agentthey emit real code into a repo, so an agent picks the work up afterwards — that makes them an accelerator through the blank page, not a platform you live on. Use for a first cut of a screen or a spike, then treat the output as code: reviewed, tested, owned. Their free tiers are generation-capped and change often — check before promising anyone a workflow
No-code site buildersFramer (AI generation, design-first, publishes) · Webflowexcellent when a human designer owns the marketing site and iterates on it directly; the trade is that the canvas is the source of truth, so your agents can't work there — copy changes, A/B tests and SEO fixes queue behind a person. Framer exposes a CMS API, so content can be automated even when layout can't. their own subdomain versus a custom domain is where the boundary sits — price it at decision time
No-code internal tools & dataAppsmith · ToolJet · Budibase (all OSS, self-host) · Retool · Baserow / NocoDB (OSS Airtable-likes) · Airtableadmin panels, ops dashboards and back-office CRUD that would otherwise eat engineering weeks. Prefer the OSS ones: they self-host, their config is files you can commit, and a leaving vendor doesn't take the tool with it
Forms, scheduling, signaturesTally · Formbricks (OSS) · Typeform · Cal.com (OSS scheduling) · Documenso (OSS e-sign)the small pieces every company needs and nobody should build. All have APIs, so submissions can flow into issues instead of a dashboard nobody opens
Competitive monitoringchangedetection.io (OSS) · Visualping · Browse AI (trainable scraper bots, free tier) · Brand24 (mention monitoring + sentiment)watch competitors' pricing/changelog/landing pages and feed research; cheap early warning without a subscription. Brand24 widens it from pages to mentions — brand and demand signal. The watch feeds the register through triage, never directly — a person accepts a detected change into a row of templates/COMPETITORS-template.md, where every cell carries its check-date and a moat claim carries its evidence. Checked 2026-07-26
DomainsNamecheapbuy domains cheap; DNS can stay here or move
DNSVercel DNS or Cloudflareif the site lives on Vercel, its DNS is simplest (per-subdomain, zero config); Cloudflare when you want a proxy/WAF/workers in front or many non-Vercel services
PaymentsStripecards/subscriptions/invoices, full control (needs your own tax handling); for solo digital products a Merchant-of-Record may fit better (MoR handles VAT): Polar (dev-first, OSS-friendly) · Lemon Squeezy · Paddle; pricing/entitlements layer over Stripe → Autumn
E-commerce / storefrontMedusa (MIT) · Saleor (BSD-3-Clause) — both OSS, self-host · Shopify (SaaS)a real storefront (catalogue · cart · checkout) when the product is selling things — Payments above is the money rail, this is the shop around it. Domain-neutral: a physical-goods brand needs it, a SaaS does not. Licences checked 2026-07-26
Auth + billingClerkdrop-in auth UI (social, MFA, orgs) + subscription billing glued to it; fastest path for SaaS
EmailResendtransactional + marketing sends from code; React Email templates
Push / user notificationsNovu (open-source notification infra — gh licence field NOASSERTION, historically MIT; verify) · OneSignal (SaaS)multi-channel notifications to your end users (in-app · push · SMS · email fan-out) — distinct from the support inbox (signal coming in) and from transactional email (one channel). Surfaces only once a product actually notifies people. Checked 2026-07-26
AnalyticsPostHog — product events, funnels, replay, flags, with SDKs across web / mobile / desktop so an app (not just a web page) is captured · cookieless web-only analytics where a script suffices: Umami (MIT — licence-cleanest default) or Plausible (AGPL-3.0 — flag); search further (Matomo…) at write timeproduct events, funnels, session replay, feature flags, A/B; pairs with the Analyst role's whitelist. Pick by platform — a web-only site can run a lightweight script, anything with mobile/desktop apps needs SDK capture. Define events once and route them through the CDP / event-pipeline row so a destination swap (or a warehouse like ClickHouse at volume) is a config change, not a re-instrumentation. Licences checked 2026-07-26
Error trackingSentrycrash/error reports with releases + sourcemaps; wire alerts to an autopilot triage sweep
Cache / queuesUpstashserverless Redis + QStash (queues/cron over HTTP); rate limits, sessions, job fan-out
Vectors / memory / recall (for the product)pgvector (Supabase) for small; Pinecone for scale; mem0 / Supermemory (managed agent memory) or Memori (SQL-native) for per-user recall; Memgraph when relationships dominateRAG, semantic search, long-term/per-user memory, a knowledge graph — only if the app you're building needs it. Pick by shape: vector = similarity, graph = relationships
Dashboards (product + team)Metabase or Grafana (both OSS, self-host) · PostHog's built-in boards for product events · repo-first: a generated _ops/analytics/ pageone place answering "is it working, and what did it cost": product metrics (North Star + supporting, funnels) and team metrics (throughput, cycle time, cost per feature from the ledger, limit-killed runs). Start with the analytics tool's own boards; add Metabase/Grafana when you need to join sources or track team numbers next to product ones
Documentation (all kinds)repo-first markdown, Obsidian-compatible (docs/ opens as a vault) · VitePress/Docusaurus for a published site · Mintlify (managed, free tier) · Scalar or Redoc for OpenAPI reference · Bump.sh publishes that reference and its changelog from the spec on every push, and generates an MCP server from it — so the API becomes agent-callable from the same source (licence not stated, free tier unclear; checked 2026-08-02) · Mermaid for diagrams-as-text · ADRs for decisionsone source of truth in git, rendered wherever needed. Diagrams live as Mermaid in the docs (reviewable in a PR, unlike an exported image); an API gets a generated reference, not a hand-written one. Owner-side knowledge-base apps (a GUI over your own notes — the repo-first docs stay the team's source of truth): AppFlowy (AGPL) · AFFiNE (custom/mixed licence — verify) · SiYuan (AGPL) · Logseq (AGPL) — AGPL is fine for an app you run, not embed. Checked 2026-07-26
Short links & attributionDub (OSS) · short.iocampaign/marketing links with UTM + click analytics; feeds measure alongside product metrics
Where design is drawnPen.dev (.pen, repo-embedded — a full MCP: components, importable libraries (Shadcn/Lunaris/Flux), tokens, export_html, agent-drivable) · Penpot (OSS, self-host, open API) · Figma (cloud, MCP + many figma-* skills) · plain HTML+tokens in-repo (free, but no design affordances — this is what produces gradient placeholders)Compose from a component library, do not hand-write screens. The selection ladder points at Pen.dev for repo-first + free-of-cloud + real agent tooling; Figma when the team already lives there. Pair any of them with Shadcn UI (MCP) for real component code. Run process first — the tool is chosen per design step, not up front. Who pays for the AI is worth checking per tool, and Pen.dev answers it the way to prefer: its MCP server runs on the owner's machine and drives their agent, so generation is billed to a subscription they already hold and can see, rather than to a credit pool inside the product. A design tool that calls a model itself is a second meter — ask which before adopting one, because that spend does not appear in the run records everything else here is measured by. Checked 2026-07-29
Visual hierarchy & predicted attentionMeasurable with no model and no service: contrast ratios by the WCAG formula (from an image or from the DOM) · size, weight and position ordering · spacing and grouping · tap-target sizes. Most of "does the hierarchy work" lives here. Predicted attention is a different claim: the research models are open — the DeepGaze / SALICON-trained families, TranSalNet, SUM — and the UI-specific work is where to look first: Aalto's mobile-UI saliency study and dataset (Leiva et al., MobileHCI 2020, dataset released, licence not stated — check before reuse). Commercial attention services wrap this same class of model. Verified 2026-07-31A heatmap is a prediction, not eye trackingmeasured is reserved for a study with people in it, and the two never merge into one verdict. The Aalto work is the reason to distrust a generic map over a screen: UI attention is expectation-driven — a strong top-left bias, text and images pulling first — while bottom-up colour and size matter less than on natural images, and classic saliency models scored poorly on UIs until retrained on UI data. A natural-image saliency map over a dashboard is a confident picture of the wrong thing. Measure what is measurable, label what is predicted, and put real people on the question that decides something
Design system catalog — rendering your ownStorybookliving catalog of UI components + their states; tokens live as files in the repo (CSS vars / style-dictionary) and Storybook renders them; native apps → SwiftUI Previews / a catalog target; non-digital → template library or brand book in _ops/design-system/; official Storybook MCP (github.com/storybookjs/mcp) lets agents drive the catalog directly
Component libraries — per platformpick ONE per surface and stay in it (mixing kits reads amateur — same rule as icon sets). React: shadcn/ui (default, in the web stack) · Base UI (headless, a11y-first — for building a design system from scratch) · React Aria (Adobe, deepest a11y) · Mantine (120+ components, batteries included) · HeroUI (ex-NextUI, React Aria + Tailwind) · MUI (Material look) · Vue: shadcn-vue · Reka UI (headless) · Naive UI · PrimeVue · Svelte: shadcn-svelte · Melt UI · Cross-framework headless: Ark UI (React/Vue/Svelte, one API) · Extending shadcn rather than replacing it — the ecosystem is where most new work lands, and awesome-shadcn-ui (MIT) is the directory that indexes it: blocks.so (MIT, 60+ copy-paste page sections) · 8bitcn/ui and 8bit/cnlibs (both MIT — retro 8-bit styling, a deliberate look rather than a default one) · 8StarLabs UI (MIT — the niche pieces a kit never ships: timeline, JSON viewer, heatmap, flip clock) · Componentry and Fluid Functionalism (shadcn-CLI installable, motion-first — licence not stated on either, check before shipping) · beUI (MIT, Framer Motion + Tailwind) · Originkit (animated, beta — licence not stated) · ogBlocks (paid, one-time commercial licence — the only non-free entry in this row, listed because a bought block is sometimes the right call). Checked 2026-08-02 · Vue: also NxUI (Vue 3 + Tailwind, licence not stated) · Web Components: Web Awesome (ex-Shoelace) · daisyUI (CSS-only, framework-free) · React Native: react-native-reanimated (MIT, Software Mansion — the animation layer everything else on RN builds on; not a component kit) · AnimateReactNative (a marketplace of Reanimated/Moti/Skia snippets — a few free, the rest licensed; checked 2026-08-02) · Tamagui (perf-first, web+native) · gluestack (NativeBase successor) · React Native Paper (Material) · NativeWind (Tailwind syntax) · iOS/macOS native: the system IS the kit — SwiftUI built-ins + SF Symbols + HIG; catalog via SwiftUI Previews · Android native: Jetpack Compose + Material 3 (official) · Flutter: Material/Cupertino built-in · forui · GetWidget (MIT, 1000+ themable widgets) · the directory for everything else is awesome-flutter (CC0-1.0). Checked 2026-08-02 · Windows native: WinUI 3 / Fluent · CLI/TUI: Ink (React for terminals) · Charm (Go: Bubble Tea/Lip Gloss) · Textual (Python) — agents build CLIs constantly, these make them feel designedReference design systems to learn from (not to copy wholesale): Material 3 · Apple HIG · Fluent 2 · Carbon (IBM) · Polaris (Shopify) · Primer (GitHub) · Spectrum (Adobe) · USWDS / GOV.UK (accessibility gold standard) — mine their tokens, patterns and a11y decisions when designing your own. awesome-design-md (MIT, alive 2026-06-16) is that same list in the form an agent reads: one DESIGN.md per system, dropped in so generated UI matches a house style instead of the model's defaults. Treat it as an imported skill, not a stylesheet — its text joins the agent's context and becomes something it believes, so it goes through screening and the prose diff first (./security), and it is trimmed to the one system this project actually uses rather than attached whole. Checked 2026-07-29
Agent & chat interface componentsassistant-ui (MIT — composable TypeScript/React primitives for chat interfaces; the licence-cleanest default here) · Agent Elements (React components and docs for chat, tool-call and workflow UIs — licence not stated, check before shipping) · Beautiful UI (primitives for AI-native interfaces: streaming text, thinking states, approval cards, composers — licence not stated) · AIcss (free components for rendering an agent's thinking and tool-call output in a chat — licence not stated). All checked 2026-08-02the surface every product in this catalogue's own domain ends up needing: a thread, a streaming answer, a tool call the user can watch, an approval the user must give. Three of the four state no licence, which is a blocker rather than a detail — copy-paste components become your source, so an unlicensed one is unlicensed code in your repo. The approval card is the piece worth stealing conceptually: this system's own rule is that a destructive or outward act is gated, and the UI for that gate is what these libraries have already drawn
Icon setsHeroicons Animated (MIT, 316 animated icons built on Heroicons with Motion, React) · Nucleo (proprietary, 40k+ SVG icons with a management app and React packages — free tier) · and the sets already inside the component libraries above. Checked 2026-08-02pick ONE set per surface and stay in it — the same rule as component kits, and for the same reason: two icon families in one screen is the fastest way to read amateur. An animated icon is a motion decision, not an icon decision — it belongs to the same budget as the rest of the motion on the page, and a page where every icon moves has no hierarchy left to spend
Data tablesAdaptTable (MIT — headless React data table that renders natively into Mantine, MUI, Chakra or shadcn/ui). Checked 2026-08-02the one component nobody wants to write twice, and the one where a kit's own table usually runs out: sorting, grouping, virtualisation, column state. Headless is the point — the table's behaviour stops being a reason to switch component kits, which is the mixing this catalogue warns about everywhere else
Billing & pricing UIBilling SDK (GPL-3.0 — flag the copyleft: fine for something you self-host, a real decision for something you ship to a client) — React/shadcn components for pricing tables, subscriptions, usage meters and the billing screens. Checked 2026-08-02the screens between a working product and a paid one, which every project rebuilds badly. The licence is the whole judgement here — the components are the cheapest part of billing and the copyleft is the expensive part, so this is a row where the free thing may be the wrong thing
Utility layer for the framework you pickedVueUse (MIT — 200+ Vue 3 composables: state, browser, sensors, networking) · useHooks (50+ server-safe React hooks from ui.dev — licence not stated, so read before copying). Checked 2026-08-02the layer between a framework and a component kit: debounce, local storage, media queries, intersection, clipboard — the things every project rewrites badly and an agent writes from memory even worse, because these are exactly where a hallucinated API looks plausible. Prefer the one that ships as source you can read over a black box, and pin it like any other dependency
Calling an API by handInsomnia (Apache-2.0 — REST, GraphQL, gRPC and WebSocket, with the collections in files rather than a vendor's cloud). Checked 2026-08-02the step before any integration is written: see the real response, not the docs' example of it. The licence is the reason this row names one tool — an API client holds your tokens and your staging endpoints, so an OSS one you can self-host beats a free tier that syncs your collections somewhere by default (the API-clients row below lists Hoppscotch/Bruno — MIT peers by the same rule; pick one and stay). Collections belong in the repo like every other entity here, which is what makes them reviewable and what stops them rotting in one person's desktop app
Version control that is not plain gitJujutsu (Apache-2.0, 31.5k stars, Rust — git-backed, so the remote stays git while the local model changes: no staging area, every working copy is a commit, conflicts are first-class objects you can commit and resolve later) · Sapling (GPL-2.0, 7k, Meta) · Pijul (patch-theoretic, not git-backed) — and GitButler in the row above (checked 2026-09-10)the one that matters here is git-backed or not. Jujutsu and Sapling keep the git remote, so a project can adopt either without asking anyone else to change — the repository stays a repository, which is this system's whole premise. Pijul does not, and that is a stack decision, not a preference. Nothing in this system requires any of them: _ops/ is files in a git tree and every validator reads paths, so an alternative client is an ergonomics choice for one person. The reason to look at all is the shape this system produces — a feature cut into tasks whose branches depend on each other — which plain git makes you serialise
LLM observability, and the pipeline around itLangfuse — traces, evals and prompt management, 34.4k stars; copyright ClickHouse, Inc. and licensed in parts (an OSS core with commercial portions — read LICENSE before assuming, and note the acquisition changes who the roadmap answers to) · Trigger.dev (Apache-2.0, 16.2k — durable background jobs, which is what a long agent run actually is) · Modal (serverless compute, proprietary) (checked 2026-09-10)serves the seam this system leaves open on purpose: runs leave a record here, not a dashboard (./runs), and that record is deliberately a file. Reach for a tracer when the question is what did the model actually see across a hundred dispatches — which a run record does not answer and was never meant to. Keep the verdict in the file and the trace in the tool: a dashboard that becomes the record is state that does not survive a clone
Review workflow for stacked changesGraphite — stacked pull requests, merge queues and review chat, with an AI review pass (licence not stated, free tier unclear; checked 2026-08-02) · GitButler — a desktop client whose virtual branches let several independent changes sit in one working tree and be committed to separate branches without switching. Licence: FSL-1.1-MIT — source-available, not OSI open source today, converting to MIT two years after each release; read that before calling it open source in a client's repository (Rust/Tauri, 21.6k stars, checked 2026-09-10)for the shape this system produces constantly: a feature cut into tasks whose branches depend on each other, where one big PR hides the seams and separate PRs each wait on the last. Stacking is the workflow that matches the decomposition. The AI review pass is not the review this system meansreviews here is another craft looking, with a name attached; a machine pass is a linter with better prose, and merging the two into one verdict is how a review becomes a formality
A machine pass over a pull requestGreptile — builds a graph index of the repository and runs parallel agents over a PR; SaaS or self-hosted in your own AWS with your own model providers, which is the axis that decides it for a private codebase. free tier for a single developer, then per-seat; not open source — fetch the rate at decision time (checked 2026-09-10) · CodeRabbit — GitHub and GitLab, no self-host stated, pricing not published on the landing page; claims 17,000+ customers (checked 2026-09-10)this is not the review this system means, and the distinction is load-bearing: reviews here is another craft looking with a name attached (reviewing.md), and a machine pass is a linter with better prose. Run one to catch what a linter cannot and a human would skip; never let its verdict close a task, because §1d requires an acceptance by someone other than the author and a machine is not a someone. The self-host axis is the only thing separating these two for a repository that cannot leave the building
Asking real people, at a scale that still countsunmoderated tests and panels: Lyssna (five-second tests, first-click, preference) · Useberry · Maze · in-product: Sprig · interview operations and the repository: Great Question · Marvin · Dovetail (checked 2026-09-10)the row exists to keep the first ladder from being skipped for the second. ./audience puts live at the top for a reason, and the honest objection to live signal is never quality — it is that recruiting five people takes a fortnight. These collapse that, and that is their whole argument: an unmoderated test on eight real users answers a layout question in a day, at a rung nothing synthetic can reach. Where they mislead is sample size — a panel makes twenty responses feel like a survey; twenty is a direction, and this system refuses the percentage before the run rather than after. The repository tools matter more than they look: an interview nobody can find again was a cost, not an asset
A vertical you are not in: audio and music productionmastering and loudness: Auphonic · loudness.info · Sengpiel audio (the calculators) · sound design and sampling: Sononym · Samplab · ADSR · Sound Particles · transcription: Basic Pitch (Spotify, open source) · distribution and rights: Revelator · Merlin · LabelRadar · spoken word and capture: Podcastle · Riverside · Tella · Descript (checked 2026-09-10)kept as one row on purpose — this is a whole craft with its own vocabulary, and the reason it is on this shelf is that an advisor meets it sideways: a brand needs a sonic identity, a product needs voice, a launch needs a video whose audio is the half everyone notices and nobody budgets. The transferable fact is the rights layer, not the tools: recorded music carries at least two separate copyrights (the composition and the recording), a library track's licence is per-use and usually per-territory, and a sync licence is not implied by having bought the file — which is the same mistake the mockup row describes, in a market with far more litigation
Synthetic respondents — and why the rate is refusedSynthetic Users and the category around it (checked 2026-09-10)the row exists so the answer is ready, and the answer is a bound, not a ban. ./audience already runs a second ladder for signal about people — live · twin · validated persona · proto — and the two are never pooled: three live interviews and twenty synthetic runs are never "23 responses", and a hundred synthetic respondents are one bias repeated a hundred times. So these tools are legitimate for surfacing an angle nobody asked about and illegitimate for any percentage, which this system refuses before the run rather than disclaiming after it. If an owner arrives holding synthetic percentages, the repair is not a better sample — it is naming the rung and re-asking what decision the number was meant to settle
Measuring what an LLM says about your brandPeec AI — tracks brand mentions, impressions and sentiment across ChatGPT, Perplexity and Gemini; free trial, tiers not published on the landing page (checked 2026-09-10)the measurement half of the GEO row below, which covers the production half — that one says how to be cited (crawler access, JSON-LD, llms.txt, answer-first prose); this one is how you find out whether it worked. Treat every number it reports as a claim about a model on a date — the same rule the tier table already applies to our own rates (./runs), because a model update moves the measurement and nothing announces it. Useful for noticing a drift; not evidence about the market, which is ./audience's ladder and a different kind of thing
Sharing a session transcript outside the repositorysharechat — publishes a Claude Code, Codex or Cursor transcript to an unlisted URL; ships as a Claude Code plugin (.claude-plugin, commands, skills), hosted on Val Town or self-hosted. It keeps messages and tool calls, drops hidden reasoning and system prompts, and each share carries a deletion URL. The repository has no LICENSE file — source visible, not licensed for reuse — and 2 stars (checked 2026-09-10)read the gate before the tool. Publishing a transcript is leaving the repository, which is owner-confirmed every time (./permissions), and the tool's own words are the reason: a 128-bit id is unlisted, not access-controlled"viewable by anyone who has the URL" — so a share with one teammate and a share with everyone are the same object. A transcript carries tool calls, which here means paths, task ids, _ops/ contents and whatever a command echoed. And it is usually the wrong fix: nothing load-bearing lives in a session, so the thing a teammate needs is the file — the run record, the task, the thread — already in the repository they can clone. Where an outward send is genuinely right (a vendor bug report, a support case), that door exists and packages a file: /opsinist:report. Self-hosting is what makes this acceptable for a company repository at all
A model API for throwaway experimentsfreellmapi (MIT, 25.2k stars, TypeScript; checked 2026-09-10)for the eval and prototyping seam where a paid key is friction and the work is disposable. Never for anything a claim rests on: this system dates every rate to a named model (./runs), and a free relay does not promise which model answered or that it will answer the same way tomorrow — so a number measured through one is unattributable by construction. Use it to see whether a prompt shape works; re-measure through a named model before the number leaves the session
Finding investors, with contactsShizune — investor database filtered by industry, stage and geography, with contact details; a free tier, paid tiers not published on the landing page (checked 2026-09-10)for the fundraising seam a company advisor meets and this shelf had nothing for. A contact list is not a warm introduction and the difference is the whole outcome — the row exists so the search starts somewhere, not so anyone mass-mails. Verify every entry at the moment of use: funds change thesis, stage and staff faster than any database, and a stale investor record wastes the one send you get
i18n / localizationWeblate (OSS, self-host) · Crowdin / Lokalise (free tiers) · i18next / ICU MessageFormat in codetranslation workflow + the library that actually formats plurals/dates; agents translate, humans review via reviews; string extraction belongs to the build, not to copy-paste
Support & feedback inboxChatwoot (OSS, self-host) · Crisp (hosted)where feedback signal physically arrives — chat/email/social in one inbox; an autopilot triages it into the backlog
Product feedback portal & roadmap (stakeholder-facing)Quackback (AGPL-3.0, self-host, MCP — one tool covering customer intake and a public portal, which is what this row is for. Not /opsinist:report, which packages a defect in this skill into a file you post yourself and involves no service) · Fider (AGPL-3.0 — the leading clean OSS voting portal) · Astuto (AGPL-3.0) · LogChimp (GPL-3.0) · ClearFlask (Apache-2.0) · SaaS: Canny · Featurebase · Productboard (no self-host, data lives with them, per-maker pricing — warn honestly)the PM core is already native (ROADMAP + ICE · feedback · roadmap); a portal is for when external people (customers, stakeholders with no CLI) vote and watch the roadmap. AGPL is fine for a service you self-host. Licences checked 2026-07-26
Team chat (self-host)Zulip (Apache-2.0, verified 2026-07-26 — licence-first default; threaded model) · Mattermost & Rocket.Chat (custom/mixed licences — name it) · Stoat (ex-Revolt, the Discord-shaped community option — licence NOASSERTION, per-crate, predecessor was AGPL-3.0; verify)a self-hosted alternative when the managed Slack / Lark integrations (./tooling) aren't wanted — real-time team comms you own; owner-side, not where agents hand off (that stays issues + @mentions). Licences checked 2026-07-26
Does the design system survive an agent?design-system-agent-tester (Sanity Labs — runs several agents against one prompt, repeatedly, and counts what came out. Licence not stated in the article that announced it; check the repo's own LICENSE before depending on it, and treat its absence as all-rights-reserved. Checked 2026-08-27) · DSDS (a JSON-Schema format for component, token, theme and pattern docs so humans, parsers and agents read one source — draft v0.15.2, one maintainer, no standards body, and no licence stated on the site: look for a LICENSE in its repository, and if there is none, treat the schema as all-rights-reserved and ask the maintainer before shipping anything that embeds it. Checked 2026-08-27)a design system is documentation an agent reads, and whether it reads WELL is measurable rather than arguable. What Sanity counted is the borrowable part — tries to a clean build · accessibility violations · lines of code · visual diffs per iteration · token spend — and it applies to any document written for an agent, not only a component library
Visual review on a live pageSuperflow (pinned comments that survive redeploys, plus automated a11y/link/spelling/OG passes) · BugHerd · Marker.io · Agentation (desktop; click an element, add a note, and it emits structured context you paste into a coding agent — free for internal use, a licence for redistribution; checked 2026-08-02) · Lavish (MIT, 3.1k★, 196 commits — opens an HTML artefact in a sandboxed local browser, the reviewer annotates elements and text and edits Mermaid diagrams as whiteboards, and the agent polls for the queued feedback rather than being handed a paste. Installs as an agent skill or a CLI, state stays local by default. The difference from the others in this row is the loop: no human carries the note across. Checked 2026-08-23)the fastest way for a non-technical reviewer to say "this, here, is wrong"; feeds Design QA and reviews checkpoints without a screenshot round-trip
Sharing a build or a bugcapture a bug someone can seeJam.dev (free tier, ships an official MCP so agents drive it — verified in live use 2026-07-26) · Bird Eats Bug: a shareable link carrying console + network + a repro video, a different craft from the annotate-a-page tools in Visual review on a live page above (those mark up a page, these capture the repro). Tunnel to local devCloudflare Tunnel (cloudflared, Apache-2.0, verified 2026-07-26 — free-first default) · ngrok (freemium) · Tailscale Funnel. Distribute a test buildTestFlight (iOS/macOS, free) · Firebase App Distribution · Sparkle (macOS auto-update; MIT with bundled-component notices — gh field NOASSERTION, verified 2026-07-26)getting a running thing in front of a human fast — a bug they can watch, a local build reachable over a link, or a fresh binary in a tester's hands. A chat-bot channel is a legitimate distribution lane: an autopilot posts each green build to a Telegram/Slack bot (build passes → bot posts the artifact), which beats a store pipeline for a tight tester loop — don't assume everyone ships through TestFlight. Licences checked 2026-07-26
Where feedback and test results accumulatethe repo and the board: raw signal → issues tagged by theme; usability sessions and persona runs → _ops/research/; test output → CI artifacts linked from the issuetools collect, but the analysable record lives in git and issues — that is what measure and audience read later. Avoid a private tool becoming the only place a finding exists
Human-side helper tools (advise the person, not the agent)scrcpy (Apache-2.0 — mirror an Android phone) · SF Symbols (Apple's icon set) · Lookin (inspect a running iOS UI) · Comparably (company/salary data). Versus moved out of this row to Structured comparison data above — it turned out to be an input to research, not a courtesy to the ownertools the advisor recommends to the human when they'd speed up their side of the work — not agent infrastructure. Named on the spot with what it does, never pushed. Checked 2026-07-26
Status page & uptimeUptime Kuma (OSS, self-host) · BetterStack / Instatus (free tiers)post-launch essentials: synthetic checks on key flows + a public status page; failures feed measure and health
Privacy & complianceKlaro (OSS cookie consent) · policy generators · a DPA template; PostHog/Plausible self-host when data must stay yoursGDPR-style basics for anything public: consent, privacy policy, data-processing agreements, retention. Legal Counsel owns the texts, Security the implementation
Agent-web protocols — the site's side of the agentic internetthe open pieces Cloudflare's stack is built on, each usable alone: Web Bot Auth (the agent signs its requests — identity, not a user-agent string) · Content Signals (robots-level permissions split search · agent · training) · Pay-Per-Crawl (HTTP 402 + x402: a page names its price, the signed agent pre-declares willingness; $0.01 floor at launch) · AI Crawl Control (the publisher dashboard over all of it) · PACT / MCP as the callable layertwo sides, both ours: a campaign site declares its signals on purpose — from 2026-09-15 Cloudflare's default blocks agent bots on ad-bearing pages, so an undeclared site is invisible to the assistants that would recommend it (the GEO row below) — and our own watch and crawls respect the signals and expect 402s: a priced page is a cost in the budget, fetched at use, never assumed free. Checked 2026-08-07
Open-source & skill distributionthe listings are the channel, and each has an owner and a bar — verify each at submission time: the runtimes' own plugin marketplaces (Claude Code · Codex · Gemini extensions — being installable is the distribution) · curated awesome-* lists (awesome-claude-skills and siblings — a PR with a one-liner, accepted on the list's own rules) · skill directories (the skills.sh / skills.rest class — indexes agents actually search) · the agentskills spec (conforming is what makes the skill legible to every future index) · Show HN / Product Hunt / r/ClaudeAI-class communities — one launch each, the medium's own etiquette researched, never recalled — ./shipping's launch-completeness rule, the one that reads researched per mediumfor a tool whose users are agents, GEO is not optional — the row below plus llms.txt on the docs site is how an assistant recommends you; the README is the landing page and is written as one (./writing-for-humans); a listing is an outward act — it goes through the owner's gate like any publish, and each landing carries provenance and a check-date in the register. Checked 2026-08-06
SEO & discoverabilityGoogle Search Console (free — the only source of your own real queries) · Ahrefs Webmaster Tools (free) · Google Trends (+ Ahrefs' free keyword tools) for what people search now · sitemap + schema.org in the build; deeper tactics: awesome-seo. Technical crawl: Screaming Frog SEO Spider · OpenSEO — keywords, backlinks, ranks and audits, usage-billed, with an MCP server so an agent reads the data rather than a person pasting it; it calls itself open source and self-hostable, and the repository behind it was not identifiable through the GitHub API on 2026-09-10, so treat that route as unverified until you can point at the repo — 300+ checks, free to 500 URLs, with JS rendering, scheduling, custom extraction and API integrations behind the licence (fetch its current price at decision time; it was an annual per-seat licence at this check). Bing Webmaster Tools — free and no advertising account required, which is the difference that matters: its Keyword Research returns actual search volumes, where Trends gives only relative interest and Google's Keyword Planner sits behind an Ads account. Also Site Scan (on-demand technical audit), a backlink profile, and an API, so an agent drives it instead of a human reading a dashboard. The volumes are Bing's index — directional for Google demand, never a stand-in for it. Open-source, and agent-drivable: OpenSEO — keyword research, backlinks, rank tracking and site audits, self-hostable for free with an MCP server, so an agent drives it rather than a person reading a dashboard (a hosted option exists; checked 2026-08-02). Getting the change seen: IndexNow — a free open protocol that pushes added/updated/deleted URLs to Bing, Naver, Seznam, Yandex and Yep (Google is not on that list; there, the sitemap and Search Console remain the lever). Both verified 2026-07-31complements the seo-audit skill with actual measurement; run before and after ship. The trend sources answer what to write about, not just how a page ranks — and Trends is not volume: per Google's own documentation each point is divided by total searches for that geography and window, then scaled 0–100, so it reads as relative popularity and an absolute number cannot be recovered from it. Quoting a Trends figure as demand is the same error as quoting an aggregator as a source. Checked 2026-07-26; the crawl, protocol and Trends rows 2026-07-31
GEO — being cited by AI assistantsrobots.txt allowing GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot alongside the classic crawlers · FAQPage + Article JSON-LD · a plain /llms.txt indexanswer engines cite sources rather than rank pages, so this is a writing rule before it is a markup one: answer first, then explain; short paragraphs under clear H2/H3; concrete statistics and named sources in the copy, since cited, quantified prose is what gets quoted back — and keep that copy readable (Hemingway, free, flags dense sentences). Owned by the copywriter with the web engineer; measured the same way as SEO, before and after ship. Verify current bot names when you set this up — the list changes. This stopped being a fringe concern while nobody was looking: as of 2026-07-31 Microsoft's own webmaster product brands its features "SEO/GEO tools" outright, so the engine side now names the thing too — check what it exposes before hand-rolling a measurement for it. Checked 2026-07-26; the GEO-branding observation 2026-07-31
Share-preview debuggers (how a link unfurls)force a re-scrape per platform after changing OG / twitter: meta: Facebook Sharing Debugger (OG parse + Scrape Again; its cache also drives WhatsApp) · LinkedIn Post Inspector · Pinterest URL debugger (Rich Pins) · Telegram @WebpageBot (send it the URL to purge Telegram's cache) · VK pages.clearCache (RU-audience projects) · generic tester for local iteration — metatags.io (or opengraph.xyz · socialsharepreview.com). X/Twitter's standalone card validator is retired — verify by posting to a private draft. No official tool for Slack, Discord, Mastodon or Bluesky — they unfurl plain OG through their own caches, so the generic tester + a re-post is the only lever. Checked 2026-07-26previews are cached per platform, so a stale OG tag ships a stale card — an agent preparing a launch or a post runs this sweep before publishing. Adjacent: Google Rich Results Test for structured data (different craft)
Visual / node-based pipelinesComfyUI (OSS — image/video generation graphs) · n8n (fair-code, automation with AI steps) · Flowise · Langflow · Dify (OSS LLM apps + RAG + observability) · Rivet (OSS, local, embeddable agent graphs)two distinct uses: (a) an asset pipeline the design squad runs (ComfyUI for brand/marketing imagery at volume), (b) AI features inside the product you're building. All self-hostable and free
AI gatewayLiteLLM (MIT — the self-host default: proxy or Python SDK over 100+ providers) · OmniRoute (MIT, self-host — local OpenAI-compatible proxy, 4-tier fallback, 19 routing strategies; young and churning — pin versions, a proxy holding every key is supply-chain-sensitive; its throughput/compression numbers are its own marketing, carried dated, never as fact; prompt compression stays off for anything reviewed or measured — a reviewer must receive the artifact verbatim; checked 2026-08-14) · OpenRouter (hosted — per-model data policies are its distinct value)one API over many providers. The need that names this row is provider-independence of the judge — a reviewer preferably not on the author's provider (./requests) — and the first answer is still cross-runtime dispatch, which changes provider with no proxy; the gateway is for judge models with no harness of their own, outages, and bulk persona calls. The model that answered may not be the model requested — 4-tier fallback swaps silently, so the run records what the response says answered, never what was asked for. Free-tier aggregation shows your prompts to 90+ providers with heterogeneous data policies — never route private work through it

Selection ladder — the default preference order. When several options cover the need, prefer in this order, and say out loud when you skip a rung:

  1. Free — no card, no ceiling surprise (then: name the ceiling, below).
  2. Open source — inspectable, forkable, no vendor exit tax.
  3. Self-hostable / local — runs on the owner's machine or box; no third party in the loop, nothing to leak.
  4. Embeddable in the repo — config/tokens/templates live as files under git, so the repo stays the source of truth and everything is versioned and reviewable.
  5. Agent-drivable — an MCP server, a clean CLI, or a documented API, so agents operate it without a human clicking a dashboard.

A managed or paid option is fine — it just has to earn the exception with a stated reason (the free/OSS one can't do it, ops burden outweighs control, compliance demands it). Record the reason in _ops/TOOLING.md next to the tool.

Decision rules the assistant applies:

  • Fewest services that cover the need — Supabase already gives auth/storage/ pgvector; add Clerk/Pinecone only when its specific strength is needed.
  • MoR vs Stripe: selling globally as a solo/indie → MoR handles sales tax; platform features/marketplaces → Stripe.
  • DNS: site on Vercel → Vercel DNS; otherwise Cloudflare.
  • Product memory ≠ team memory. The memory row above is for the product you build. The agent team's own memory is the repo + issues (git-versioned, the source of truth) — never add a memory store as a second source. If a very large history ever needs semantic recall, add a vector index as a derived index rebuilt from the repo/issues, never something agents write to independently.
  • Need an API or a free tier? Check public-apis (github.com/public-apis/public-apis) for a ready data/API source and free-for.dev for free-tier services before paying — both pair with the free-first rule here. APILayer Marketplace is the commercial counterpart — third-party APIs by category, subscribed rather than found (licence and free tier per API, not per marketplace; checked 2026-08-02).
  • Free tier first — and name the ceiling. Default to the free plan, and when proposing a service say where its free tier ends in the unit that will actually bite (build minutes, MAU, rows/storage, events, seats, emails/day) and what happens at that edge — throttle, hard stop, or auto-charge. Record the chosen plan + that ceiling in _ops/TOOLING.md; health watches headroom and audit flags what's close. Crossing into paid is spend — owner-gated like any other, never a silent upgrade.
  • Node-based tools build the product, not the team. ComfyUI/Rivet/Flowise/Dify are for asset pipelines and the AI features you ship — never a second orchestration layer over this one. Wiring a visual flow engine on top creates a competing source of truth, the same anti-pattern as a second memory store. Product-side, they are a normal stack choice.
  • Pick CI your agents can read. The decisive feature is not build speed but whether failures come back as structured, fetchable context. A pipeline agents cannot read turns every red build into a human errand — exactly the bottleneck this system exists to remove.
  • Verify currency at wiring time. These are seeds, and the market moves — before connecting any of them, sanity-check it's still the right pick for this project (same research-first rule as assets-home in the interview).
  • Some tools we deliberately don't stock. AI-text "humanizers" and AI-detectors (Undetectable AI, Originality, and the like) exist to pass AI writing off as human — that contradicts say what you know, and how you know it, so they are neither a default nor a recommendation; if a client insists, that is their call, not our suggestion. (Same logic as n8n over Zapier: the free/OSS/self-host option already wins on our rules.)
  • Anything here can be swapped by naming an alternative — research, compare, wire.

Default libraries — AI-fluent stacks

LLMs write best in what they've seen most; picking mainstream stacks measurably cuts hallucinated APIs and review churn. Defaults (override any via interview):

PlatformDefault stackWhy
Web app / siteTypeScript + React + Next.js + Tailwind + shadcn/ui (Radix under the hood)deepest LLM training coverage; shadcn is copy-in code agents can edit directly; 21st.dev — community shadcn-style components to copy from before building anew
MobileReact Native + Expo (cross-platform) · SwiftUI (iOS-native) · Jetpack Compose (Android-native)Expo for one codebase; native pairs when the product demands platform depth
DesktopTauri (light, Rust shell + web UI) · Electron (max ecosystem) · SwiftUI/AppKit (macOS-native)pick by footprint vs ecosystem vs nativeness
API / backendTypeScript (Next.js API/Hono/Fastify) or Python (FastAPI)both are LLM home turf; match the team's main language
CLI / toolingTypeScript (commander) or Godistribution ease vs single-binary
AI featuresVercel AI SDK (+ OpenRouter as the gateway)streaming/tool-calling glue LLMs know well; patterns & evals reference: awesome-generative-ai-guide

Always pair with live docs — Context7 (MCP/skill) for current library/framework/OS-SDK APIs, so agents code against today's versions, not a frozen training cutoff.

Rule of thumb: deviate from these only when the project itself dictates (a DSP app is C/Swift no matter what LLMs prefer) — and record the deviation in the guide.

Testing — every stage of the loop, per platform

Free/OSS-first defaults; as always, seeds not a closed menu.

PlatformUnit / componentE2EVisual / a11y / perf
Web / PWAVitest + Testing Library; Storybook interaction testsPlaywright (free, cross-browser)Playwright screenshots or Chromatic (free tier) for visual regression; axe-core (a11y); Lighthouse (perf + PWA installability/offline audit)
MobileXCTest (iOS) · JUnit/Robolectric (Android) · Vitest (RN logic)Maestro (free, cross-platform flows) · Detox (RN) · XCUITest / Espresso (native)platform snapshot tests; store-review checklists
Desktopper shell: Vitest (Electron/Tauri web core) · XCTest (native macOS)Playwright (Electron) · WebDriver (Tauri) · XCUITest (macOS)same visual tools as web for web-shells
API / backendVitest/pytest + supertest/httpxcontract/integration suites against a test DB (Supabase branch DBs)k6 (OSS) load tests

Cross-cutting testing tools (beyond the per-platform matrix; licences checked 2026-07-26): API clientsHoppscotch (MIT, default) · Bruno (MIT — offline, git-friendly collections); API mocking / service virtualizationMockoon (MIT) · WireMock (Apache-2.0); LLM / AI-feature testingpromptfoo (MIT) · DeepEval (Apache-2.0), directly relevant to AI products; test datafaker-js (MIT — the LICENSE file is MIT under a custom header, verified 2026-07-26); self-host A/B & flagsGrowthBook (MIT core + commercial enterprise — verify) beside PostHog's built-in.

Where each sits in the loop:

  • Build — unit/component tests are part of the code DoD (tests/review gate).
  • Review — QA gate runs E2E + the platform suite; Design QA reviews visual regression against the design system; a11y (axe) and perf (Lighthouse) budgets here.
  • Ship — smoke E2E on the real build/prod + the launch checklist.
  • Measure — synthetic checks/uptime (e.g. a cron autopilot hitting key flows) + Sentry errors feed measure alongside product metrics.

Research & reference galleries (design · brand · visual)

The method, not the list. Per project, run style discovery: name the feeling in words → collect references → extract what actually carries it (type, spacing, colour, motion) → turn that into tokens. A frozen link list ages faster than anything else in this file, so keep only the anchors that carry a licensing or fallback decision and search awesome-{topic} for the rest.

NeedAnchorWhy this one
Product & growth reading — and who is paying for itindependent, or at least not selling the tool the piece recommends: NN/g (usability research) · SVPG (Cagan) · Shape Up (Basecamp, free to read) · Product Talk (Torres) · Y Combinator Library · First Round Review · Strategyzer · Mind the Product · Built for Mars (teardowns) · Growth.Design · GoPractice · Atlassian Team Playbook · pm-skills · paid courses and memberships, priced accordingly: Reforge · Product School · Pragmatic · Product-Led Alliance · Hustle Badger · Growth Unhinged · Demand Curve · CXL · vendor content — good, and load-bearing to know it is vendor content: Amplitude + Academy · Mixpanel · Intercom · Maze · Dovetail · Contentsquare · ChartMogul · Productboard · Aha! · airfocus · ProdPad · Jira Product Discovery · VC content, which is a third thing again: a16z · Sequoia · flows and onboarding teardowns: Page Flows · UserOnboardthe split is the row. All three groups are worth reading and only one of them is disinterested. Vendor content is written to make the vendor's category feel necessary — an analytics blog will not conclude that you do not need analytics yet, and an experimentation blog will not tell you your sample is too small to bother. VC content selects on survivors and is written to attract deal flow, so its base rate is invisible by construction. Neither is a reason to skip them; both are a reason that the rung travels with the claim (./permissionsthe evidence ladder) — quoting a vendor's benchmark as a market fact is exactly the promotion this system refuses. When an advisor cites one to an owner, name the source's interest in the same sentence. Checked 2026-09-10
Websites, interfaces and the small surfacesA1 (curated web design; free to browse, paid tier for unlimited saves) · recent.design (websites · app icons · app-store screenshots · OG images) · Deck (pitch decks) · OG Image Gallery · Refero · Land-book · Design Spells (the small delightful details) · Art Directed · Mobbin in the row above for product flows (checked 2026-09-10)most of these carry no licensing statement at all — checked on A1, which says nothing about rights to what it shows — so Logosystem's sentence above is the default here rather than an exception: the work belongs to whoever made it, and the gallery is a place to find the direction, not the asset. Their real use is narrower and better than a mood board: the small-surface ones settle arguments cheaply — what an OG image or an app-store screenshot should carry is a question with a hundred visible answers, and looking is faster than theorising
Logos, wordmarks and app iconsLogosystem — 1,300+ marks, filterable by colour, shape, industry and mood, each linked to its source; free (checked 2026-09-10)it states the rule this whole section runs on, better than we would: "The logos themselves belong to their respective brands and designers, so check the original source for licensing before reusing anything. Use them to spark ideas, not to copy." Take that sentence as the default for every gallery below, whether or not the gallery says it
Type tooling, as distinct from the foundries aboveV-Fonts (what a variable font's axes actually are) · Type Scale · Wordmark (see a word in every font installed) · Future Fonts (buy a face mid-development, cheaper, and it grows) · Fonts In Use · Font in Logo · Fontfabric (checked 2026-09-10)the row exists because these answer questions the foundry pages do not. A variable font's axes decide whether one file can carry the whole hierarchy, which is a performance and a licensing question at once — fewer files, but a variable licence is often priced differently. Future Fonts is the one with a real trade: an in-progress face costs less and you get later versions, at the risk that the axes you built on change under you. Cheap for a launch, wrong for a system meant to sit still
Design systems — other people's, for the naming argumentThe Design System Guide · Component Gallery (how many real systems name and shape the same component) · Checklist Design (per-component checklists) · Standards.site (brand guideline collections) (checked 2026-09-10)for the argument that eats weeks: what is this component called, what states does it owe, and where does the guideline live. Component Gallery settles the first cheaply by showing what a dozen shipped systems did; Checklist Design settles the second. Neither is a system and none of them should be copied whole — a design system is a set of decisions a particular team can keep, and importing someone else's vocabulary imports arguments you did not have. Use them to stop re-deriving the obvious parts, then spend the time on the parts that are yours
Developer quick reference — the ones worth a bookmarkDevhints (cheatsheets) · regex101 (explains a pattern, does not merely test it) · Debuggex (a regex as a railroad diagram) · easings.net · Flexbox and Grid cheatsheets · Accessibility Developer Guide · everysize (one page at every viewport at once) (checked 2026-09-10)the two that change an outcome rather than save a minute are the regex pair and the a11y guide. A pattern that looks right is this corpus's oldest documented failure — a guard matched one ordinary spelling of a key and not its twin, and reported finding nothing while a fabricated project sat in the store — so a tool that explains a pattern back to you is a form, in the sense this system means: it makes the mismatch visible where reading could not. The rest are conveniences and rot slowly
Language, editing and the Russian-language setLanguageTool (open source, self-hostable — grammar and style across many languages) · Ditto (UX copy as versioned strings, not screenshots) · Power Thesaurus · Reverso Context (a phrase as people actually use it) · Copyscape · Russian: Типограф (typographic punctuation — the one nobody remembers to run) · Главред-класс проверки · Стопслов · Readability · Грамота (checked 2026-09-10)the one with a mechanical effect is Типограф: hyphens, quotes and non-breaking spaces are the difference between text that looks set and text that looks pasted, and no reviewer catches all of it by eye. LanguageTool self-hosts, which is the difference between a style check and sending a client's unreleased copy to someone else's server — the same axis that decides the code-review row. Ditto matters when copy is a deliverable: strings that live in a design file are strings nobody can diff
Typefaces — and the licence is the decisionfoundries whose own pages carry the terms: Klim · Dinamo · Grilli · Pangram Pangram · Production Type · Sharp · OH no · Lineto · Displaay · Blaze · A2 · Boulevard · XYZ · Toko · 205TF — research: Fonts In Use (what a face has actually done)a typeface is not bought once — it is licensed per use-class, and the classes are the decision: desktop · web · app · broadcast · logo are priced and permitted separately, webfont licences are commonly metered by monthly pageviews, and an app or an embedded product usually needs its own. So the question at hire time is never "did we buy the font" but "which classes, at what volume, and for how long" — and the answer belongs in the brand file with a date, because a traffic tier that outgrows its licence is a breach nobody notices. Read the foundry's own terms; do not take a price page for a licence
Mockups and presentation scenespaid libraries, each with its own terms: LS.graphics · Mockuuups · Mr Mockup · Orbyt · Maneken · Mockup Maison · Bendito · Vitora · Scene Number · Brandacle · SED · index: mockups.directory · mixed goods incl. type and illustration: Supply Familythe licence you need is "use in client work", and the one you almost never get is "redistribute the file" — most of these permit the first and forbid the second, including inside a template you sell on. Check per vendor and per item; a bundle is not one licence. Studying a scene to build your own is not the same act as shipping the vendor's file — direction is not extraction, which is the same line the galleries above draw, and it is also the cheapest way to stay clean when a generated composition would do
Design press — what shipped, and what people said about itIt's Nice That · Dezeen · Designboom · Creative Review · Wallpaper · Frame · Domus · Eye · Slanted · Deem · Design Milk · IDEA · Aperture (photography) · brand-identity specifically: The Brand Identity · BP&O · Brand New (paywalled) · Type-01editorial, copyrighted, and several paywalled — this is reading, not a source of assets. Its value to an advisor is different from a gallery's: it carries the argument about a piece of work, which is what you need when the question is "why did this land", and it is the fastest way to date a visual direction — a look that the press covered two years ago is a look a client has already seen. Cite the article, never the images
Studio work, to argue about directionPentagram · Collins · Koto · DIA · Studio Dumbar · Ragged Edge · Mouthwash · Heydays · Porto Rocha · Bond · Basement · Offgrid · Bruce Maua portfolio is an argument, not a mood board. Read the case text, not only the pictures: what the studio says the problem was is the part that transfers, and the visual answer usually does not. Assume everything is in copyright and in use by a live brand — the risk here is not licensing so much as accidentally proposing someone else's equity to a client. Use to name a direction in words; then run style discovery on the words
UI & product patternsMobbin (paid, has an MCP) — free fallback: search awesome-design-inspirationthe only one worth paying for; the fallback matters when nobody has a licence
Type specimens, posters, graphic design historyLetterform Archive3,500+ items digitised (read 2026-08-23; the screenshot that brought it said 60,000 held, part digitised — the held collection is not the online one). Reference only: its own route for reuse is a request — an Image Rights and Reproductions page, not a licence. Look, extract what carries the feeling, and never let a scan into _ops/assets.mdscans deep enough to read paper texture, which is what makes a type decision arguable rather than a taste claim
Small-format design — labels, packaging, marksMatchbloc — 400+ socialist-bloc matchbox labels, 1950s–80s. Reference only, and assume in copyright: the era is inside most terms, the site states none, and no stated licence is not permissionthe sharpest reference for anything that must read at 20mm — a constraint nothing else in this table covers
UX guidance & rationaleNN/g (research-backed articles)the place to look for a sourced argument behind a design call — pairs with an argument without a source is an opinion. Search at nngroup.com/search and re-apply the Articles filter each time — it doesn't persist in the URL. Free articles
TypographyGoogle Fonts for licensing-safe families · Practical Typography for the ruleslicence clarity is the whole point
Colour → see Colour & palettes in Services by need, which absorbed these anchors and the colour-space decision under themCoolors · Color Huntfast palettes that export as tokens
Web & marketing artifacts, fresh → the same anchor now sits in Websites, interfaces and the small surfaces with its licensing note; this row keeps the older check-daterecent.design — websites · app icons · app-store screenshots · OG images (free to browse, checked 2026-08-14)recency is the point and the trap: the artifact classes the other anchors miss (an OG image and a store screenshot are designed objects too), refreshed daily — and recent means fashion, so it feeds style discovery above as raw references, never as tokens by itself
BoardsAre.nawhere the moodboard lives without becoming a private silo

Visual styles — method, not a baked-in taxonomy: name the style in the owner's own words, gather references, extract the carriers, encode as tokens in _ops/design-system/. What is "clean" to one owner is "sterile" to another; the words are theirs, the extraction is yours.