How To Vibe Code: Q4 2026 Update

By Kurt Wuckert Jr.

Holy smokes, these updates are going to have to come out every two weeks from now on! Parts of my March guide already read like they were written ten years ago. Anthropic, OpenAI and xAI are shipping tooling for vibe coders faster every month, and some of what I told you about planning in the spring is flat wrong now.

In one quarter, Anthropic released Claude Opus 5 on July 24, Claude Fable 5.1 on September 1, Claude Opus 5.5 on September 22 and Claude Sonnet 5.5 on September 28, each with a new API string you have to pin by hand.¹ OpenAI shipped gpt-6-sol on September 22 and had a newer Sol, gpt-6.1-sol, out a week later.² The Model Context Protocol published a new revision dated 2026-07-28 that made the protocol stateless, so the old initialize handshake and the Mcp-Session-Id header are gone.³ Claude Code itself went from 2.1.198 on July 1 to 2.1.289 on October 3, about 92 releases. Version 2.1.284 on September 28 changed new interactive sessions to start in auto mode on every plan when no permission mode is configured.⁴

That is roughly one release a day, and any one of them can move a default you rely on!

This is the manual for the next ninety days, whether you are opening Claude Code for the first time or shipping with it every day. Every command in it comes from a vendor's docs or from bOpen's own plugin files, dated and footnoted, and a few of them will be stale before the next update lands. That is the business now.

What I told you in the spring, and what is dead

The March guide, Vibe Code 10X Better With 1 Unbreakable Rule, is still up, and it stays up so you can grade me. Four of its lines, against what the vendors publish today.

A table of nine practices from the March 2026 guide, each marked Keep, Revise or Retire, with what replaced it in October 2026

"Never feed Claude Code instructions you wrote yourself. Let Claude Chat write them for you." Retired, or at least the venue is. March had you plan in a separate chat window, then "copy it and paste it into Claude Code." The planning step lives inside Claude Code now, as plan mode, and Anthropic describes it in a single line: "Claude reads files and proposes a plan but makes no edits until you approve."⁵ The March trick worked because a clean context got a finished prompt. Anthropic now says it better than I did: "A clean session with a better prompt almost always outperforms a long session with accumulated corrections."⁶

"This is the secret weapon. Negative prompts tell Code what to NEVER do, regardless of how tempting it might seem." Revised, and hard. A NEVER line in a prompt or in CLAUDE.md steers the agent, and the memory docs say Claude treats those instructions as "context, not enforced configuration. To block an action regardless of what Claude decides, use a PreToolUse hook instead."⁷ Think of the NEVER line as a note taped to the fridge and the hook as the lock on the liquor cabinet. Keep writing the NEVER lines, then move the ones that would hurt you into a hook.

"Make sure you are talking to Claude Opus, the reasoning model." Revised. There is a lineup now. Anthropic's models page describes Claude Fable 5.1 as "For demanding reasoning and long-horizon agentic work" and tells most people to "start with Claude Opus 5.5 for most workloads." Fable for the hard thinking, Opus 5.5 as the starting point, Sonnet 5.5 and Haiku 4.5 for the cheap lanes.

"You go from prompt-engineering-per-task to prompt-engineering-once, encoded into reusable systems." Keep. This is the line that aged best! Skills are a first-class Claude Code feature: a SKILL.md file that Claude uses "when relevant, or you can invoke ... directly with /skill-name". The format also escaped Anthropic's yard. The Agent Skills site calls SKILL.md "originally developed by Anthropic, released as an open standard," and lists Claude Code, Codex, Gemini CLI, Cursor and GitHub Copilot among the hosts that read it.⁸ A skill you write once for one harness now travels to the others.

The figure grades five more March lines, including my claim that Claude Code "never forgets what you told it three hours ago." The memory docs contradict that in plain words, "Each Claude Code session begins with a fresh context window," and I stand corrected. Anything you need remembered goes in a file.

Plan first, and let the strongest model do it

The most expensive mistake I still see is letting the agent start typing code before anyone agreed on what the code is for. Anthropic's best-practices page says it flat: "Letting Claude jump straight to coding can produce code that solves the wrong problem. Use plan mode to separate exploration from execution." You enter plan mode by pressing Shift+Tab or by prefixing a single prompt with /plan, and you can start a whole session in it from the terminal.⁹

claude --permission-mode plan

For anything bigger than a bug fix, we at bOpen use the interview pattern from Anthropic's own docs. You describe the idea in a sentence and let the model pull the rest out of you. This is the prompt, verbatim:

I want to build [brief description]. Interview me in detail using the AskUserQuestion tool.

Ask about technical implementation, UI/UX, edge cases, concerns, and tradeoffs. Don't ask obvious questions, dig into the hard parts I might not have considered.

Keep interviewing until we've covered everything, then write a complete spec to SPEC.md.

Then the step most people skip: "Once the spec is complete, start a fresh session to execute it."

The docs also say what a good spec contains: "The most useful specs are self-contained: they name the files and interfaces involved, state what is out of scope, and end with an end-to-end verification step that proves the feature works." bOpen's coordinator applies the same test before it hands anything to a worker: "If the spec cannot be completed, the decision is not ready to delegate."¹⁰

Treat CLAUDE.md as context the model reads, and keep it short. Run /init to generate a starter file, then prune it with Anthropic's own test: "For each line, ask: 'Would removing this cause Claude to make mistakes?' If not, cut it. Bloated CLAUDE.md files cause Claude to ignore your actual instructions!" The same page says it again about hooks: "Unlike CLAUDE.md instructions which are advisory, hooks are deterministic and guarantee the action happens."

At bOpen we also run a few read-only commands from our core plugin before planning in an unfamiliar repo. /core:question answers "questions about the codebase without making any changes," and /core:impact maps the "full blast radius before changing a file or function," listing "importers, tests, CI, docs, owners." Claude Code also accepts the bare name, such as /question, when nothing else uses it.¹¹

/core:question <question>
/core:impact src/auth/middleware.ts
/core:diagnose "API returns 500 on /users endpoint after deploying"

For big jobs, two tools from the orchestra module are worth the install. Ask for the visual coordinator ("show me the workflow before running it") and it will "Turn a large multi-agent job into an editable graph before it runs." Type /orchestra:advisor for "an independent read-only second opinion at a commitment boundary," and remember that "One clear consult is the default."¹²

The bOpen pattern in four stages, plan, build with workers, review adversarially, gate and ship, with the documented model for each role

Now, which model should do the planning? My advice, and not bOpen's policy, is the most capable model you can afford. On a Max plan that means Claude Fable 5.1, because Max lets you "use up to 50% of your weekly usage limits on Fable models at no extra cost."¹³ On Pro, Fable runs on usage credits at standard API rates, which as of October 5, 2026 means $10 per million input tokens and $50 per million output against $4 and $20 for claude-opus-5-5. Opus 5.5 is the sensible planner there.

bOpen's documented policy is strict about the workers and silent about your seat. The core README says "The main model is always the model selected for the current session; the skill does not pin or rename it," while the advisor skill says "Fable is out of policy and is never an advisor, even on request."¹⁴ The orchestra policy governs the lanes the coordinator dispatches. The seat you type into is your call.

Let the workers do the typing

Nothing installed yet? Start with the card. Thirty minutes is my estimate, not a vendor's. The slash lines run inside a Claude Code session, marketplace first.

The thirty-minute setup in nine steps, from installing Claude Code to adding the bOpen marketplace, installing core and orchestra, optional Codex, and starting in plan mode
/plugin marketplace add b-open-io/claude-plugins
/plugin install core@b-open-io
/plugin install orchestra@b-open-io
/plugin install review@b-open-io

Then run /core:setup and start a fresh session. Third-party marketplaces, bOpen's included, are "Off by default" for auto-update, so claude plugin update core@b-open-io belongs in your weekly routine.¹⁵

The pattern we run at bOpen is the coordinator, and its contract fits in three sentences: "Keep the current session in the main seat. The main owns the plan, interfaces, review, verification, and final decision. Workers implement bounded units; they do not own git or silently change the plan."¹⁶ Ask for the coordinator by name, or type /orchestra:coordinator. Four rules from its dispatch contract do the real work. First, "Concurrent writable workers use isolated worktrees, even when their intended files are disjoint." Second, a hard barrier: "Every maker must reach a terminal state before the barrier lifts." Third, "The reviewer and test path share one corrective allowance. A second failure returns control to the main to fix or stop." Fourth, every worker must end with a FINAL REPORT in the format shown in the skeleton below. The contract is blunt about trust: "The worker's final report is a claim, not proof," and "An exit code of 0 is not a terminal-success signal by itself."

Every worker gets a spec file. Here is a generic skeleton built on those rules; fill the brackets and keep it untracked at the repo root.

SPEC-<ticket>-<slug>.md

Objective: <one sentence>. Evidence: <failing test, log line, or issue>.
May edit: <paths>
Must not edit: <paths>
Interfaces (pinned by the main): <exact signatures>
Constraints: <runtime, dependencies, what is out of scope>
Acceptance:
  1. <exact command> exits 0
  2. <exact command> prints <expected output>
End with a FINAL REPORT: files changed, commands run and their
pass/fail result, status of every acceptance criterion, and
anything you could not do and why.

On Claude Code, the native way to isolate a worker is one line of subagent frontmatter, which runs the subagent "in a temporary git worktree" that "is automatically cleaned up if the subagent makes no changes." It needs a git repository when the session starts.¹⁷

isolation: worktree

This is how bOpen's coordinator launches a Claude worker under the hood. Not a beginner command, but note the model spelled out in full.

cd <repo> && claude -p --model claude-opus-5-5 --effort high \
  --permission-mode acceptEdits --output-format stream-json --verbose \
  "<imperative; details in SPEC file>" \
  > /tmp/dispatch-<id>.log 2>&1 &

Outside workers come from the other two labs. Codex installs from OpenAI's script and reads the same bOpen marketplace under the same plugin ids. Grok Build installs from xAI's script, and xAI calls grok-4.7 "the default model of the coding agent." xAI also says "Grok is fully compatible with Claude Code with zero configuration needed," so it picks up the plugins you already installed.¹⁸

curl -fsSL https://chatgpt.com/codex/install.sh | sh
codex plugin marketplace add b-open-io/claude-plugins --ref master
codex plugin add core@b-open-io
curl -fsSL https://x.ai/cli/install.sh | bash
grok -p "Explain this codebase"

bOpen's model policy, straight from the file:

The preferred coding worker is Claude Opus 5.5 (claude-opus-5-5). Independent code review runs on GPT-6 Sol (gpt-6-sol) or GPT-6 Astra (gpt-6-astra) at xhigh reasoning, never at default effort. ... Grok is not a normal worker lane: use it only under usage-credit pressure, pin grok-4.7, and never use Grok 4.6.

A shared policy script backs that up by refusing Fable ids, any gpt-5.5 or gpt-5.6 id, and grok-4.6 for any lane it dispatches.

The rule behind all of that is one line in bOpen's changelog, entry 1.1.138 from August 19: "pin every model (a loop inheriting a mutable CLI default silently ran weeks on a stale model)".¹⁹ Claude Code's own --help text says the --model flag accepts "an alias for the latest model (e.g. 'sonnet' or 'opus') or a model's full name," and an alias is exactly the mutable default that line warns about. Pass the full string.

Workers also eat your subscription.

As of October 5, 2026, Claude Pro is $20 a month and Max runs $100 or $200, each with a five-hour session limit plus a weekly limit across models.²⁰ When the Anthropic allowance runs dry mid-task, bOpen ships its own workaround, claudex, which runs the Claude Code harness, with the same tools, skills, UI and session, "driven by OpenAI's GPT-6 Sol," "billed against an existing ChatGPT/Codex subscription." It replaces the main seat; the coordinator docs say "It is not a worker and must not be used as one."²¹ The smoke test:

claudex -p "Reply with exactly: claudex works."

Verify adversarially, every time

The agent that wrote the code is the worst judge of it, because it remembers why every line seemed like a good idea.

Anthropic's best-practices page now has a section titled "Add an adversarial review step," and the reason is one sentence: "A fresh context improves code review since Claude won't be biased toward code it just wrote."²² Boris Cherny, quoted by Simon Willison in September, set the bar where I would set it: "Production code written by Claude should have a higher bar than if it was written by a human."²³ The cheapest version needs no plugins at all, and the prompt comes straight from the same page:

Use a subagent to review the rate limiter diff against PLAN.md. Check that
every requirement is implemented, the listed edge cases have tests, and
nothing outside the task's scope changed. Report gaps, not style preferences.

At bOpen the default is /core:bug-hunt, which runs three isolated agents in sequence. The Hunter (review:code-auditor) is told to "Find every possible bug. Maximize recall. False positives OK." The Skeptic (review:architecture-reviewer) must "Challenge every finding." The Referee (review:tester) is the "Final arbiter," told to "Read code independently." The isolation is the point: "The Skeptic cannot see the Hunter's enthusiasm. The Referee cannot see the Skeptic's skepticism." For a wider pass, /core:review-wave sends "4 specialized reviewers" at a change at once, covering "security, perf, correctness, style." Both need the review module beside core.²⁴

/core:bug-hunt -b feature-xyz --base dev
/core:review-wave HEAD~5..HEAD

Anthropic's built-in /code-review "reviews a diff in your terminal without installing the GitHub App. It reports correctness bugs," and it runs as a background subagent with its own context window. It takes --fix and --comment, and --max-findings <n> needs v2.1.288 or later.²⁵ On the OpenAI side, codex review runs a local review.²⁶

The last step before anyone says "done" is confess, a core skill you trigger in words ("audit your work," "are you sure?"). Its central instruction is the best review advice I know: stop asking "what did I miss?", because "that question invites rationalization." Instead, "assume something was missed, then hunt to prove it."²⁷

The same shape works for research and writing, and it is the best ten minutes a beginner will spend all week. Three fresh subagents run in sequence, each writing a file the next one reads.

The three-lane recipe: research, falsify and write, each a fresh subagent with its prompt and what it returns
Use a subagent to research "What is a Merkle tree and why does Bitcoin use one?"
Rules: primary sources only (the Bitcoin whitepaper, the original patent, vendor docs).
Return exactly 6 numbered facts, each with the source URL and the exact supporting
quote. Flag any fact that rests on a secondary source. Write the result to
stage1-research.md and stop.
Use a new subagent as an adversarial reviewer. Give it only stage1-research.md.
Its job is to disprove each fact: re-fetch every cited source, compare the quote
character by character, check every date and number. Verdict per fact: PASS or
FAIL with the evidence. Assume at least one fact is wrong and hunt for it.
Write stage2-review.md and stop.
Use a new subagent to write a 250-word explainer for beginners using only the
facts marked PASS in stage2-review.md. Tag every sentence with the fact number
it rests on, like [F3]. If a sentence is not supported by its tagged fact, say
so at the end instead of hiding it. Write stage3-article.md.

The falsifier pays for itself on the boring stuff: wrong dates, trimmed quotes, and sentences leaning on a source that does not say what they claim. The Merkle question is a good trap, because a research lane will happily write "patented 1979" when the patent was filed in 1979 and granted in 1982.²⁸ Also, tell the reviewer to quote the page itself, because a fetch tool can hand back its own summary instead.

A falsifier lane's verdict table on the Merkle tree facts, with two FAIL rows for a wrong patent date and a trimmed quote, and a second table where two planted claims are marked FAIL

Put real locks on it

A line in CLAUDE.md that says "never force push" is a request. The model usually honors it, until the session where it does not. Anthropic's permissions page says it in one line: "Permission rules are enforced by Claude Code, not by the model." Hooks are the other half of the lock, what Anthropic calls "deterministic control": a PreToolUse script that exits 2 kills the call before it runs.²⁹

At bOpen, three of those locks ship in the core plugin, and each is narrower than its nickname. bouncer hard-blocks the git commands that destroy uncommitted work: a hard reset, git clean with -f, git checkout -f, git checkout with the double-dash separator, git restore of worktree files and git stash clear, while still allowing git restore --staged. damage-control denies a list of destructive commands outright, including rm -rf /, drop database, git push --force and git push -f, while git push --force-with-lease is allowed. It asks before the double-dash git checkout of the whole tree, git stash drop and rm -rf node_modules, and it refuses reads and writes of secret paths such as .env, ~/.ssh/ and *.pem (but not .env.example). publish-gate intercepts npm publish, bun publish and pushes to main whose latest commit begins "Release v"; with a Linear key configured it wants an Approved ticket labeled publish, and without one an ordinary npm publish goes through with a warning.³⁰ All three are pattern matches on command text. They catch the common ways to wreck a repo, and nobody should mistake them for a sandbox.

Permissions also changed under everybody this quarter.

Anthropic's docs say "A separate classifier model reviews actions before they run, blocking anything that escalates beyond your request," and add that "With Claude Code v2.1.283 or later, auto mode is the built-in starting permission mode for interactive terminal and VS Code sessions on every plan and provider," and the every-plan change landed in 2.1.284 on September 28.³¹ My advice: open /permissions and write your never-do list as deny rules, because "Deny rules block in every mode, including bypassPermissions."

Two more rules we hold at bOpen. A secret never travels through the chat window; keys live in a .env file the agent cannot read. And code and prose each get a governor. /core:restraint full turns on "YAGNI with a governor: write the least code that is still the right code," with the guard that "Restraint governs size, never correctness." For prose, ask for humanize in words (it is not a slash command); one of its rules begins "Never invent a statistic, customer result, source, quotation" and keeps going.³²

The last lock guards your wallet, because any agent that can call a paid API can also call it in a loop at three in the morning. Our template is bOpen's promo-video pipeline, which spends real money on Higgsfield's video API. It arms the generate call only after the session's init event shows claude-opus-5-5 with 0 MCP servers and 0 skills. It runs that model in the OS sandbox with no network. Each paid call sends its reservation as the Idempotency-Key, so a retry cannot bill twice, and an approval gate sits in front of the video spend.³³ Put the cap in code where the call can see it, and make a human approve the expensive step.

The models and the prices, as of October 5, 2026

A table of twelve frontier models with lab, API string, release date and input and output price per million tokens, as of October 5, 2026

Figure 07 is the table we work from at bOpen this week, priced per million tokens, standard tier, input then output, as of October 5, 2026. From Anthropic, claude-fable-5-1 is $10 / $50, claude-opus-5-5 is $4 / $20, claude-sonnet-5-5 is $2 / $10, and claude-haiku-4-5-20251001 is $1 / $5.³⁴ From OpenAI, gpt-6.1-sol is $2 / $10 and gpt-6-astra is $10 / $50, and on both a prompt over 272K tokens bills at twice the input rate and one and a half times the output rate. From xAI, grok-4.7 is $2 / $6 under a 200K-token prompt and $4 / $12 at or above it, and from Google, gemini-3.8-flash is $0.75 / $3.75 through December 31.³⁵

One string needs its own note. bOpen's documented reviewer is gpt-6-sol, and OpenAI's page now points readers to gpt-6.1-sol, released September 29, as the newer Sol model. Both are generally available at the same price. Claude Code's own default is Opus 5.5 on the Pro, Max, Team and Enterprise plans, and on the API.³⁶

Watch the separators when you type a string into a config file. claude-opus-5-5 uses hyphens throughout, while gpt-6.1-sol, grok-4.7 and gemini-3.8-flash put a dot inside the version number. Copy every string from the vendor's model page, never from memory and never from a chatbot's answer, because a near miss is a different string! The second gotcha is on the bill itself. Anthropic's pricing page says "Claude 4.7 and later models" use a newer tokenizer that "produces approximately 30% more tokens for the same text," which covers Fable 5.1, Opus 5.5 and Sonnet 5.5 but not Haiku 4.5.³⁷ Not a price rise, but a per-token comparison with an older model can understate your bill by about that much.

The standards that moved

The Model Context Protocol changed shape this summer. The current version is 2026-07-28, and it made MCP stateless: the initialize handshake and Mcp-Session-Id are gone, and a mandatory server/discover call now advertises versions and capabilities. The same revision deprecates "the Roots, Sampling, and Logging features," along with HTTP+SSE and Dynamic Client Registration, under a 12-month minimum deprecation window.³⁸ If you run an MCP server, check which protocol version it advertises and stop building new features on Sampling or Roots. The previous 2025-11-25 revision still interoperates, so nothing breaks tomorrow.

Skills over MCP, SEP-2640, reached Final status when its pull request merged on September 13. It says a host "MUST verify the content against that entry's digest" for every file it retrieves. Host support is early, and Claude is not on its client list yet. For a solo builder, the plain SKILL.md file is the unit that matters today. Agent Skills were "originally developed by Anthropic, released as an open standard," and agentskills.io lists Claude Code, Codex, Gemini CLI, Cursor, GitHub Copilot, OpenCode and others as hosts.³⁹ Write a skill once, with the required name and description, and it travels. bOpen's portable form is a single line:

bunx skills add b-open-io/prompts --skill <skill-name>

A2A, the agent-to-agent protocol, was "accepted as a Growth Stage project at the Agentic AI Foundation" on August 27, beside MCP, goose and AGENTS.md. Its CLI shipped on October 1 as something a coding assistant loads as a skill. Unless your agent has to talk to somebody else's agent, you can let it mature. WebMCP is a "Draft Community Group Report, 2 October 2026" with an origin trial from Chrome 149, and a community group draft is not a W3C Recommendation.⁴⁰ My advice is to experiment with it on a side project and keep it out of anything a customer depends on.

The next ninety days

Only dates the vendors have already published go on this list, because predictions age even worse than prices. The calendar we keep at bOpen through the end of the year:

2026-10-14  GPT-5.5 leaves ChatGPT, ChatGPT Work and Codex (the API keeps it)
2026-10-15  Claude Haiku 4.5 retirement floor ("not sooner than")
2026-11-21  gpt-5.6-sol promo price guaranteed "at least through" this date
2026-11-30  claude-sonnet-4-5-20250929 retires; replacement claude-sonnet-5-5
2027-01-01  Gemini 3.6, 3.7 and 3.8 Flash go to $1.50 / $7.50

OpenAI's wording on the first one matters: GPT-5.5 retires "from ChatGPT, ChatGPT Work, and Codex on all plans," and "This retirement does not apply to the OpenAI API."⁴¹ On the standards side, MCP's roadmap names five priority areas and gives no date for the next revision, so no spec change has a published date before the new year.⁴²

That is why the next one of these lands in two weeks, not next quarter: shorter, sharper, and run through the same falsifier before it reaches you. The stream walks all of it live, demo in the middle, questions as we go.

The run of show for the companion livestream: a cold open, six segments each closing in a Q&A pocket, and one live demo, about half an hour

Be good to each other. And pin your models before you go build something.

Kurt Wuckert Jr. is the Chief Bitcoin Historian, founder of GorillaPool and Open Protocol Labs, and host of Kurt's Podcast. He builds AI agent infrastructure with the team at bOpen and ships production software with Claude Code every day.


Footnotes

¹ Anthropic, Models overview, Claude Platform Docs, undated docs page (fetched 2026-10-05).

² OpenAI, GPT-6.1 Sol and GPT-6 Sol, OpenAI API Docs, undated model pages (fetched 2026-10-05).

³ Model Context Protocol, Versioning and 2026-07-28 changelog, modelcontextprotocol.io (fetched 2026-10-05).

⁴ Anthropic, Claude Code changelog, Claude Code Docs, entries 2.1.198 through 2.1.289 (fetched 2026-10-05).

⁵ Anthropic, Common workflows, Claude Code Docs, section "Plan before editing" (fetched 2026-10-05).

⁶ Anthropic, Best practices for Claude Code, Claude Code Docs, undated docs page (fetched 2026-10-05).

⁷ Anthropic, How Claude remembers your project, Claude Code Docs, undated docs page (fetched 2026-10-05).

⁸ Anthropic, Skills, Claude Code Docs (fetched 2026-10-05); Agent Skills, agentskills.io and Specification, agentskills.io (fetched 2026-10-05).

⁹ Anthropic, Permission modes, Claude Code Docs, plan mode section (fetched 2026-10-05).

¹⁰ bOpen, orchestra plugin 0.1.36, skills/coordinator/references/dispatch-contract.md, source at b-open-io/prompts, GitHub (read 2026-10-05).

¹¹ bOpen, core plugin 1.1.177, commands/question.md, commands/impact.md and commands/diagnose.md, source at b-open-io/prompts, GitHub (read 2026-10-05).

¹² bOpen, orchestra plugin 0.1.36, skills/visual-coordinator/SKILL.md and skills/advisor/SKILL.md, and review plugin 0.1.26, skills/visual-proposal/SKILL.md, source at b-open-io/prompts, GitHub (read 2026-10-05).

¹³ Anthropic, Claude Help Center article 15424964, Claude Help Center, Fable models on Claude plans (fetched 2026-10-05).

¹⁴ bOpen, core plugin 1.1.177, README.md (orchestra section), source at b-open-io/prompts, GitHub (read 2026-10-05).

¹⁵ Anthropic, Discover plugins, Claude Code Docs, auto-update section (fetched 2026-10-05).

¹⁶ bOpen, orchestra plugin 0.1.36, skills/coordinator/SKILL.md and its references dispatch-contract.md, workers/cli-dispatch.md, workers/grok.md and scripts/model-policy.sh, source at b-open-io/prompts, GitHub (read 2026-10-05).

¹⁷ Anthropic, Subagents, Claude Code Docs, frontmatter fields (fetched 2026-10-05).

¹⁸ OpenAI, Codex CLI, OpenAI Developers (fetched 2026-10-05); bOpen, marketplace README.md, b-open-io/claude-plugins, GitHub (read 2026-10-05); xAI, Grok Build overview, Skills, plugins and marketplaces and Grok 4.7, xAI Docs (fetched 2026-10-05).

¹⁹ bOpen, core CHANGELOG.md, entry 1.1.138 (2026-08-19), GitHub (read 2026-10-05).

²⁰ Anthropic, Claude pricing, claude.com (fetched 2026-10-05).

²¹ bOpen, orchestra plugin 0.1.36, skills/claudex/SKILL.md and skills/coordinator/references/workers/codex.md, source at b-open-io/prompts, GitHub (read 2026-10-05).

²² Anthropic, Best practices for Claude Code, Claude Code Docs, section "Add an adversarial review step" (fetched 2026-10-05).

²³ Simon Willison, Boris Cherny quote, simonwillison.net, 2026-09-11 (fetched 2026-10-05).

²⁴ bOpen, review plugin 0.1.26, skills/hunter-skeptic-referee/SKILL.md (design credited to danpeguine), and core plugin 1.1.177, commands/bug-hunt.md and commands/review-wave.md, source at b-open-io/prompts, GitHub (read 2026-10-05).

²⁵ Anthropic, Code review, Claude Code Docs, /code-review section (fetched 2026-10-05).

²⁶ OpenAI, Codex CLI and Auto-review, OpenAI Developers (fetched 2026-10-05).

²⁷ bOpen, core plugin 1.1.177, skills/confess/SKILL.md, source at b-open-io/prompts, GitHub (read 2026-10-05).

²⁸ Google Patents, US4309569A, Ralph Merkle's patent, filed 1979-09-05, granted 1982-01-05 (fetched 2026-10-05).

²⁹ Anthropic, Configure permissions and Get started with hooks, Claude Code Docs, undated docs pages (fetched 2026-10-05).

³⁰ bOpen, core plugin README.md and hook scripts bouncer.sh, damage-control.sh (with patterns.yaml) and publish-gate.sh, b-open-io/prompts, GitHub (read 2026-10-05).

³¹ Anthropic, Choose a permission mode and Claude Code changelog, entry 2.1.284 dated 2026-09-28, Claude Code Docs (fetched 2026-10-05).

³² bOpen, core plugin skills restraint/SKILL.md and humanize/SKILL.md, b-open-io/prompts, GitHub (read 2026-10-05).

³³ bOpen, core plugin CHANGELOG.md, promo-video-pipeline entries (2026-09-26 to 2026-10-01), and orchestra plugin software-factory/SKILL.md, b-open-io/prompts, GitHub (read 2026-10-05).

³⁴ Anthropic, Models overview and the per-model pages for Fable 5.1, Opus 5.5 and Sonnet 5.5, Claude Platform Docs (fetched 2026-10-05).

³⁵ OpenAI, GPT-6.1 Sol, GPT-6 Astra and GPT-6 Sol model pages, OpenAI API Docs; xAI, Grok 4.7, xAI Docs; Google, Gemini API pricing, Google AI for Developers (all fetched 2026-10-05).

³⁶ Anthropic, Model configuration, Claude Code Docs, and Claude Help Center article 15424964 (both fetched 2026-10-05).

³⁷ Anthropic, Pricing, Claude Platform Docs, Additional notes (fetched 2026-10-05).

³⁸ Model Context Protocol, Versioning and 2026-07-28 changelog, modelcontextprotocol.io (fetched 2026-10-05).

³⁹ Model Context Protocol, SEP-2640: Skills extension, modelcontextprotocol.io, merged 2026-09-13; Agent Skills, agentskills.io and its specification page (both fetched 2026-10-05).

⁴⁰ A2A Project, a2a-protocol.org blog posts dated 2026-08-27 and 2026-10-01; W3C Web Machine Learning Community Group, WebMCP, Draft Community Group Report, 2026-10-02; Google, WebMCP, Chrome for Developers (all fetched 2026-10-05).

⁴¹ OpenAI, Models, ChatGPT Docs (fetched 2026-10-05).

⁴² Model Context Protocol, The MCP roadmap, MCP blog, 2026-08-22 (fetched 2026-10-05).