A stack that fits your project, and keeps fitting as it changes Manifestack launched a free, MIT-licensed agent skill that installs via `npx skills add manifestack/manifestack` for Claude Code, Cursor, Codex, Copilot, Windsurf, OpenCode and Cline, auditing a project's full stack against budget, user count, data rules and team preferences recorded in a STACK.md file. The tool runs locally with no API keys and read-only access, reading package.json, requirements.txt, go.mod, vercel.json, Dockerfile, infra/*.tf and .env variable names to flag drift such as Supabase Free's 500 MB database cap going read-only, a free-tier Gemini API sending EU user documents, duplicate auth providers (Supabase Auth plus Clerk), and a ~$310/mo Kubernetes setup serving 40 users that a ~$25/mo single host and managed Postgres would cover. Free agent skill for Claude Code, Cursor and Codex A stack that fits your project, and keeps fitting as it changes. For developers and small teams who pick their own services. It fits the stack to your budget, users, data rules and team, then checks every change: new services, plan limits, bills. Then ask the agent to run manifestack in your project. npx manifestack install --agent codex Then run $manifestack in your project. npx manifestack Detects your agents and asks where to install: Copilot, Windsurf, OpenCode, Cline and more. npx skills add manifestack/manifestack Installs the skill without the new-service hook. In Claude Code and Cursor, /manifestack offers to add it. MIT No API keys Read-only Runs locally Stacks don't break on day one. They drift out of fit. A requirement gets missed in a quick setup. The agent adds a service nobody checks. The plan is too small for the load, or the setup far too big. Nobody re-checks the fit until something breaks. Outgrown Read-only Supabase Free caps the database at 500 MB. At 2 MB a day, that's months away. Then a launch, or a log table nobody trims, adds 365 MB in three weeks, and the database goes read-only: no signups, no orders. 500 MB On the +2 MB/day trend: week 33Actual: week 11 Missed requirement EU vs free tier A prototype sent user documents to the Gemini API on the free tier, and production kept it. Free-tier content can go into improving Google's products, and EU users need the paid tier. Your contract promises no training on customer data. requires no training on customer data ai plan Gemini API, free tier ✕ Unchecked change 2 auth providers Asked to add login, the agent installs Clerk. Supabase Auth already signs users in. Now users live in two places, and one of them bills per user. "@supabase/supabase-js": "^2" + "@clerk/nextjs": "^6" Nothing failedNothing was checked Overbuilt ~$310 vs ~$25 A Kubernetes cluster, a multi-zone database, a NAT gateway and a load balancer, serving 40 users. A single app host and managed Postgres would carry them. Big clouds are the right call at scale. Not at forty users. Built for 1M users~$310/mo Right-sized for 40~$25/mo Same app, same 40 users~$3,400/yr extra There's no best stack. There's yours. Budget, users, data rules, what your team prefers and what it won't touch decide the fit, from the framework to the cloud. Manifestack starts there, so the same question gets a different answer. Solo founder, content site and waitlist budget under $25/mo users 500 → 5k requires nothing special yet prefer React, Firebase avoid servers to maintain fits Astro, static pages, no server to run Supabase Free, database and auth in one Resend Free revisit when users 3k Team of four, B2B dashboard behind login budget ~$600/mo users 20k → 100k requires EU database, SOC 2 vendors prefer Postgres, AWS avoid Kubernetes, ops on-call fits React + Vite, client-side app, no SSR needed API and Neon Postgres in Frankfurt Resend Pro revisit when monthly bill $500 Indie mobile app with subscriptions budget under $100/mo users 5k → 50k MAU requires App Store and Google Play billing prefer React Native, Expo avoid running own servers fits Expo with EAS Build and Update RevenueCat for in-app subscriptions Supabase Free, database and auth revisit when mau 40k Illustrative profiles. Your answers go into STACK.md, and every later audit and every new service is checked against them. The whole product, not one package.json. Frontend, backend, workers, infrastructure and every third-party API. Each service is sorted by role and checked against your requirements and the vendor's pages today. 1 · Reads web/package.jsonNext.js · Clerk · Supabase api/requirements.txtFastAPI · OpenAI · Stripe worker/go.modStripe · Resend · Sentry vercel.jsonhosting Dockerfile · infra/ .tfinfrastructure .envvariable names, never values 2 · Sorts by role Hosting Vercel Database Supabase Auth Clerk + Supabase Authsame job twice Payments Stripe Email Resend Monitoring Sentry AI OpenAI 3 · Checks against .manifestack/STACK.md budget, users, requires, prefer, avoid vendor pages, read today pricing, limits, regions, certifications Findings Requirement Overlap Overbuilt Limit Bill Risk Set the fit once. Every change gets checked against it. Know the project budget, users, rules, team Starts from what the stack has to fit: budget, expected users, data region and certifications, what the team prefers and what it avoids. Check the fit /manifestack audit Reads vendor pages today and reports what no longer fits: requirement gaps, overlaps, overbuilt setups, limits and bills, each with a date, a cost and a fix. Remember why .manifestack/STACK.md Keeps the requirements, decisions and their reasons in your repo, so the next session and the next developer start from the same facts. Check every change hook in Claude Code, Cursor When the agent adds a vendor, it is checked against your requirements, your avoid list and the services you already run, before you rely on it. Empty repo Describe what you're building: budget, expected users, data rules, what your team prefers and avoids. Manifestack proposes a stack, explains each pick and prices it as you grow. Example: Next.js on Vercel, Supabase, Resend 1k users $0/mo 10k users $65/mo 100k users ~$420/mo /manifestack init Existing project Point it at any repo, yours or a client's: frontend, backend, workers and infrastructure. It maps what's wired up and checks it against your requirements and usage: data region, duplicated services, overbuilt setups, limits and costs. /manifestack audit Every change Say you ask the agent to add login and it installs Clerk. The hook checks the new SDK against STACK.md, and the agent tells you before it finishes: + "@clerk/nextjs": "^6" Clerk auth added. Supabase Auth already signs users in: an Overlap. Clerk bills per user; check it against the ~$600/mo budget. hook in Claude Code, Cursor Every finding says when it matters and how to fix it. Output of /manifestack audit on a sample product: a Next.js frontend, a Python API and a Go worker, 9,000 monthly users, seven services. Requirement gaps, duplicated services, launch risks, limits and bills, each with a fix you can act on. ~/relaylog/manifestack auditSample output FindingWhenCostFix Requirement Supabase project region vs. EU database rule Project in us-east-1, STACK.md requires EU When Before launch Cost ~1 day of migration Fix Create the production project in an EU region and move the data while it is still small. Overlap Two auth providers: Clerk and Supabase Auth @clerk/nextjs and supabase.auth both in web/src/ When Now Cost $25/mo on Clerk Pro, more past 50,000 MRU Fix Both do the same job here. Keep the one whose features you use and remove the other from the code. Risk OpenAI usage tier 1: tokens per minute api/ summarizes every upload; the launch-day estimate is above the tier limit When Launch day Cost Higher tiers need paid history and time Fix Request a tier increase now, queue uploads in the worker, and use a smaller model for short summaries. Limit Supabase Free: database size 312 / 500 MB, +1.1 MB/day When ETA ~Mar 2027 Cost $25/mo on Pro Fix Archive events rows older than 90 days, or schedule the upgrade for February. Bill Vercel Pro: data transfer 3.4 TB last month, 1 TB included When Every month, growing Cost ~$360/mo overage Fix Cache /og/ images at the edge and set Cache-Control on /api/feed. Fix first EU region, before launch Spend to review $385/mo $4,620/yr Checked against EU, SOC 2 · 7 pages, Oct 6 Usage figures come from numbers you give it, exports in the repo or a read-only vendor MCP. A report is as current as those inputs. Manifestack commands Two to start. Plain /manifestack picks the right one: init for an empty repo, audit for an existing one. In Codex, use $manifestack; in other agents, ask for the skill by name. Command What it does Example Available now /manifestack init New project: asks what the stack has to fit, proposes one priced at 1k, 10k and 100k users, and writes the first STACK.md. /manifestack init "B2B dashboard, EU users" /manifestack audit Existing project: checks every service against your requirements and growth and reports what no longer fits, each with a when, a cost and a fix. /manifestack audit Coming next /manifestack compareplanned Two vendors side by side for your workload: features, limits, region, certifications, lock-in, price. /manifestack compare neon supabase /manifestack migrateplanned A step-by-step plan for a vendor or plan switch, with a rollback. /manifestack migrate supabase --to pro /manifestack watchplanned Re-reads vendor pages for the services in STACK.md and proposes a diff when something changed. /manifestack watch .manifestack/STACK.md Requirements budget: ~$600/mo users: 9k now, 50k by Q3 requires: EU database, SOC 2 vendors prefer: Postgres, Next.js avoid: Kubernetes no ops on-call Database: Supabase plan: free limit: 500 MB database, pauses after 7 days idle source: supabase.com/pricing read 2026-10-06 usage: 312 MB, +1.1 MB/day 2026-10-06 decided: stay on Free until first paying user revisit when: db size 400 MB OR date = 2027-02-01 next: Pro, $25/mo env: SUPABASE URL, SUPABASE ANON KEY names only Email: Resend plan: pro, $20/mo limit: 50,000 emails/month revisit when: monthly sent 45,000 OR before launch One file, versioned with your code. STACK.md lives in .manifestack/, the only folder the skill writes to. The skill tells your agent to read it before changing infrastructure. You review it in pull requests. revisit when A condition, not a reminder. Every audit checks it and flags the section once it's true. Stored Your fit: budget, users, data rules, what the team prefers and avoids Services, plans and the limits that apply Usage snapshots with the date they were taken Decisions and the reason behind each one Env var names, so the agent knows what is wired Never stored Secret values, API keys or tokens Connection strings or passwords Customer data or anything from your database Billing details from vendor accounts Your keys never leave your machine. Neither does your code. By default it needs no account access, and its only network calls read vendors' public pages: pricing, limits, regions and certifications. A read-only vendor MCP is your own connection, used only if you set it up. Your machine Repo scan and analysisruns in your agent session .manifestack/STACK.mdwritten to your repo Usage numbersyou give them, or a read-only vendor MCP Never sent anywhere by Manifestack Source code API keys and .env values Account logins or OAuth access Usage and billing data GET public pagespublic page only Vendor public pages Pricing, regions and security pages, such as supabase.com/pricing. Read during the audit like any visitor would. Requests carry no project data. Your agent's model provider sees what your agent already sees. Manifestack adds no new destination. Pricing, limits and regions, read from the source. Page maps for hosting, database, auth, email, storage, payments, mobile, monitoring and AI. Each audit reads the vendor's current pages for plans, limits, regions and certifications. No rankings, no affiliate links, no "switch to X". The skill finds the vendor's public pages during the audit. A page map makes it faster; new ones ship as releases.Request a map Frequently asked questions Who is it for? Developers, small teams and agencies who build with Claude Code, Cursor or Codex and choose their own services: hosting, database, auth, email, payments, AI APIs. It helps most from the first commit to a few hundred thousand users, when nobody owns infrastructure full-time. How is this different from asking my agent? A plain agent answers from training data that can be a year old, then forgets the answer. Manifestack starts from your project's requirements, reads vendors' current pages, keeps every decision in STACK.md, and checks each later change against them. Will it change my code, config or vendor settings? No. The audit is read-only. The only thing it writes is .manifestack/STACK.md, and decisions in it plan, revisit dates only after your yes. Installing a package or changing a setting happens only when you ask your agent for it. Do I need to give it API keys or account access? No. It reads your repo and env var names, never their values, and asks you for usage numbers. If you've connected a vendor's official MCP in read-only mode, such as Supabase, Neon or PostHog, it can read usage there instead. Manifestack itself never asks for a key or a login. Does it work with Cursor, Codex or my agent? Yes, if your agent reads Agent Skills SKILL.md . Cursor, Codex, GitHub Copilot, Windsurf and OpenCode do, and npx manifestack finds them for you. The new-service check is dependable in Claude Code and Cursor, where a hook flags every vendor SDK the agent adds. In other agents it depends on the agent picking up the check on its own, so run /manifestack audit before you merge a change that adds or swaps a service. Does it work with Python, Go or mobile apps? Yes. It reads dependencies from package.json, requirements.txt, pyproject.toml, Pipfile and go.mod, plus config files and env var names in any project. React Native and Expo apps are covered, including RevenueCat, Adapty and EAS. Native iOS and Android dependencies Podfile, Gradle are not read; the skill asks about services it cannot see. Where do prices and limits come from? From each vendor's public pages pricing, limits, regions, certifications , read during the audit. Every finding cites the page and the date it was read. If a page can't be fetched, the finding says so instead of guessing. Needs an agent with web access. What does it check besides costs? The fit itself: data region and certifications against your requirements, services that do the same job, setups far bigger than the load, and what the team prefers or avoids. init proposes a whole stack and explains each pick, including when Next.js or a big cloud is more than you need. Compliance decisions stay yours. My vendor isn't on the list. Is it still useful? Yes. The skill looks up its public pages and records the service, plan and limits in STACK.md. A page map makes it faster and more reliable. To add one, open an issue with the pricing page. Is it free? Yes. MIT license, no paid tier, no account. There is no Manifestack server to pay for.