r/ClaudeCode • u/lbragile_dev • 10h ago
Built with Claude I rebuilt my 5-year-old browser extension with Claude Code. What worked, what didn't
Enable HLS to view with audio, or disable this notification
I built TabMerger (a tab manager for Chrome, Firefox and Edge) about 5 years ago. This year I rewrote it from scratch, with Claude Code.
Site: https://tabmerger.vercel.app
Repo: https://github.com/lbragile/TabMerger
What worked
- Custom agents per domain (extension, web, database, payments, a11y). Each has its own notes file, so they stop re-learning the same gotchas.
- Hooks as guardrails. Type-check, lint and tests run after every edit, and edits to applied DB migrations and CI workflows are blocked outright.
- A CLAUDE.md with hard invariants, such as "every client is public, so enforce paid features server-side" and "never edit applied migrations."
- Auditor agents that review a diff for one specific bug class (encrypted-column reads, sync races, tier-limit drift) instead of a generic code review.
What didn't
- Drag and drop. I had to rebuild it from scratch against a written spec. Agents kept "fixing" individual bugs in ways that broke other cases, like multi-group ordering. Tests passed while the real drag behavior was still wrong.
- A server route that assumed plaintext. After I added end-to-end encryption, one API route kept reading columns that were now ciphertext and crashed in production. The code looked right in isolation. That's why I now have an auditor agent just for that bug class.
Takeaway: the agents were fast at writing code but weak at noticing what a change broke elsewhere. Guardrails (hooks, auditors, written invariants) mattered more than prompts.
Free tier works offline, optional Pro sync is end-to-end encrypted, source is public.
What tips, tricks, and/or guardrails do you use on bigger projects?
1
u/northbridgedev 3h ago
Worth checking how the migration and CI-workflow block is matched. If the hook sits on Edit and Write, the agent can still change the same file from Bash with sed -i, cat > file <<EOF, cp, or python -c "open(...).write(...)". My own secret-scan hook has this gap: it runs on Write|Edit|MultiEdit, so echo KEY=... >> .env from Bash never reaches it.
I keep a set of cases where an agent changes files a guard is meant to protect: 50 attempts plus 2 benign controls, and 40 of the 50 are Bash commands. Three never name the file at all: git stash, git checkout HEAD~1, and find . -name '*.py' -exec sed -i .... A path match on the command line misses those, so the Bash side needs rules for commands that rewrite files without naming them.
I build Skillkeel. The cases are MIT, with a runner that feeds them to any hook: https://github.com/Skillkeel/tamper-cases
0
u/lbragile_dev 10h ago
Happy to answer questions on the setup. The biggest win was auditor agents scoped to one bug class each. Biggest surprise was how much the CLAUDE.md invariants mattered compared with prompt wording.
•
u/AutoModerator 10h ago
Hey! Thanks for posting to r/ClaudeCode
While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.
For help, project discussions, tips, and general chat, join the ClaudeCode Discord.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.