AI governance framework for secure software delivery
Project description
Turn AI-assisted delivery into a governed local workflow — in any repo, any IDE.
54 skills · 9 agents · 6 surfaces · 1 governed flow
{ai} engineering installs a deterministic governance layer into any repository — specs, decisions, skills, agents, hooks, and an audit trail, all as versioned local files. No hosted control plane. No provider lock-in. Every IDE follows the same rules.
Quickstart
Get a governed repo in under a minute — {ai} engineering is uv-first:
uv tool install ai-engineering # install the CLI
ai-eng install . # add governance to your repo
ai-eng doctor # [PASS] hooks, mirrors, manifest, required tools
Prefer pip or pipx?
pipx install ai-engineering
# or
python -m pip install --user ai-engineering
Then open your editor and type /ai-start. Prefer to ease in? Start in observe mode and enforce only what proves useful.
What you get: 54 skills and 9 agents you invoke with /ai-<name> · a spec-driven workflow · automatic checks on every change · versioned local files you own. Update any time with ai-eng update.
The governed workflow
You drive the intent and approve each step; the gates catch the rest — no secrets, broken docs, or untested changes reach a merge.
The canonical chain is /ai-brainstorm → /ai-plan → /ai-build → /ai-pr. Use it whenever work changes product behavior, framework behavior, security posture, public docs, or release state. /ai-commit stays available for WIP checkpoints; it is not part of the chain.
Your toolkit
Fifty-four skills and nine agents cover the whole delivery loop — and the same commands work in every supported editor.
Need evidence? /ai-research returns cited findings from local context, the web, and async deep research. And because plans carry ready-to-apply patches, mechanical work routes to a smaller model — routine edits stay cheap.
Supported surfaces
One canonical payload is mirrored, byte-for-byte, into every enabled surface.
| Surface | Entry point |
|---|---|
| Claude Code | CLAUDE.md |
| GitHub Copilot | .github/copilot-instructions.md |
| OpenAI Codex | AGENTS.md |
| Antigravity | AGENTS.md + .agents/ |
| OpenCode | .opencode/ |
| Cursor | .cursor/ |
The ruleset lives in AGENTS.md. Project identity and hard prohibitions live in CONSTITUTION.md. Release history lives in CHANGELOG.md.
Highlights
- Ship a whole spec in one run —
/ai-autopilotdecomposes it, builds a dependency DAG, runs parallel waves, and converges on a reviewed PR. - What you approved is what shipped — a brainstorm hard-gate plus a spec-lifecycle state machine keep every change anchored to the approved spec (Rung 2 SDD — spec and code stay in sync, not just spec-first that drifts).
- An audit trail you own — every AI action lands in a hash-chained NDJSON log you can verify offline, with no telemetry by default.
- Every bypass has an owner and an expiry — no
# noqaor@ts-ignore; findings are refactored or formally risk-accepted with a severity-based TTL. - Every tool call is screened before it runs — a deterministic guard checks each edit, write, and shell command and stops risky ones.
- AI quality is a tested property — skills are measured with pass@k, and a regression beyond five points blocks the pull request.
Documentation
- docs/ — architecture, getting started, and the diagram set
- CONSTITUTION.md — mission, stakeholders, prohibitions
- CHANGELOG.md — release history and breakage notes
Standing on the shoulders of
{ai} engineering builds on ideas and patterns from these projects:
| Project | What we learned |
|---|---|
| Superpowers | Brainstorm hard-gate, TDD-for-skills patterns |
| review-code | Handler-as-workflow, parallel specialist agents |
| dotfiles/ai | Agent matrix, SDLC coverage |
| autoresearch | Radical simplicity as a design principle |
| SpecKit | Spec-driven workflow inspiration |
| Anthropic Skills | Frontend-design, skill-creator — absorbed and extended |
Contributing
Contributions are welcome. See CONTRIBUTING.md for development setup, code style, testing, and the pull request process. This project follows the Contributor Covenant Code of Conduct.
License
MIT. See LICENSE.
Star history
Contributors
Made with contrib.rocks.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ai_engineering-0.12.2.tar.gz.
File metadata
- Download URL: ai_engineering-0.12.2.tar.gz
- Upload date:
- Size: 12.7 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
40e5dd8c836a1edab955d3cd9c1f542c01d635d16be7cf3728bdb385d9203077
|
|
| MD5 |
b46744041ae8a3228d465c865c8b95a3
|
|
| BLAKE2b-256 |
285934cf2b5d05c7ae7cdbb441d7b224d4f8215ea75f0964bf2fae3149e9191a
|
Provenance
The following attestation bundles were made for ai_engineering-0.12.2.tar.gz:
Publisher:
release.yml on arcasilesgroup/ai-engineering
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_engineering-0.12.2.tar.gz -
Subject digest:
40e5dd8c836a1edab955d3cd9c1f542c01d635d16be7cf3728bdb385d9203077 - Sigstore transparency entry: 1981227094
- Sigstore integration time:
-
Permalink:
arcasilesgroup/ai-engineering@5c9af9cdd5f4d6bdd9f98bdd42d77754e291c7a6 -
Branch / Tag:
refs/tags/v0.12.2 - Owner: https://github.com/arcasilesgroup
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@5c9af9cdd5f4d6bdd9f98bdd42d77754e291c7a6 -
Trigger Event:
push
-
Statement type:
File details
Details for the file ai_engineering-0.12.2-py3-none-any.whl.
File metadata
- Download URL: ai_engineering-0.12.2-py3-none-any.whl
- Upload date:
- Size: 3.3 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a3656ff551b5cdc8d6e75d7a233198298da6fbcba502ab3213eea0f048c65eaa
|
|
| MD5 |
8d02eabb06c9af2cf7676401eff5dbaa
|
|
| BLAKE2b-256 |
c2c382a65d3f8f85365dc438daf36529b2b414a2b351abb173d2ae4dcf3ec64d
|
Provenance
The following attestation bundles were made for ai_engineering-0.12.2-py3-none-any.whl:
Publisher:
release.yml on arcasilesgroup/ai-engineering
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_engineering-0.12.2-py3-none-any.whl -
Subject digest:
a3656ff551b5cdc8d6e75d7a233198298da6fbcba502ab3213eea0f048c65eaa - Sigstore transparency entry: 1981227207
- Sigstore integration time:
-
Permalink:
arcasilesgroup/ai-engineering@5c9af9cdd5f4d6bdd9f98bdd42d77754e291c7a6 -
Branch / Tag:
refs/tags/v0.12.2 - Owner: https://github.com/arcasilesgroup
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@5c9af9cdd5f4d6bdd9f98bdd42d77754e291c7a6 -
Trigger Event:
push
-
Statement type: