AI governance framework for secure software delivery
Project description
53 skills · 9 agents · 6 surfaces · 1 governed flow
{ai} engineering installs a deterministic governance layer into any repository: specs, decisions, skills, agents, runbooks, hooks, and audit trails as versioned local files. No hosted control plane. No provider lock-in. Every IDE follows the same rules.
Install
Prerequisites: Python 3.11+ and Git.
pipx install ai-engineering
# or: uv tool install ai-engineering
Verify the CLI, then install governance into a repository:
ai-eng version
cd your-project
ai-eng install .
ai-eng doctor
[PASS] doctor confirms hooks, mirrors, manifest defaults, and required tools. Update later with pipx upgrade ai-engineering or uv tool upgrade ai-engineering, then run ai-eng update and ai-eng doctor in each governed project.
Governed Flow
The canonical chain is:
/ai-brainstorm → /ai-plan → /ai-build → /ai-pr
Use it when work changes product behavior, framework behavior, security posture, public docs, or release state. /ai-commit remains available for WIP checkpoints; it is not part of the canonical delivery chain.
Supported Surfaces
One canonical payload is mirrored into all enabled surfaces:
| Surface | Entry point |
|---|---|
| Claude Code | CLAUDE.md |
| GitHub Copilot | .github/copilot-instructions.md |
| OpenAI Codex | AGENTS.md |
| Antigravity | AGENTS.md + .agents/ skills and agents |
| OpenCode | .opencode/ skills and commands |
| Cursor | .cursor/ skills |
The ruleset lives in AGENTS.md. Project identity and hard prohibitions live in CONSTITUTION.md. Release history and breakage notes live in CHANGELOG.md.
Why Governance Matters
- Spec-driven work keeps LLM output tied to approved scope.
- Deterministic gates catch secrets, broken mirrors, missing docs, and policy drift.
- The local NDJSON audit chain records what happened without sending telemetry by default.
- Skills and agents are file-backed, reviewable, and synchronized across IDEs.
Standing on the shoulders of...
ai-engineering builds on ideas, patterns, and principles from these projects:
| Project | What we learned |
|---|---|
| Superpowers | Brainstorm hard-gate, TDD-for-skills patterns |
| review-code | Handler-as-workflow architecture, parallel specialist agents, finding-validator |
| dotfiles/ai | Agent matrix, SDLC coverage patterns |
| autoresearch | Radical simplicity as a design principle |
| Emil Kowalski | Motion principles, spring physics, easing strategy |
| SpecKit | Spec-driven workflow inspiration |
| GSD | Autonomous execution patterns |
| Anthropic Skills | Frontend-design, canvas, skill-creator — absorbed and extended |
Contributing
Contributions are welcome. See CONTRIBUTING.md for development setup, code style, testing, and the pull request process.
Code of conduct
This project follows the Contributor Covenant Code of Conduct. See CODE_OF_CONDUCT.md.
License
MIT. See LICENSE.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ai_engineering-0.8.2.tar.gz.
File metadata
- Download URL: ai_engineering-0.8.2.tar.gz
- Upload date:
- Size: 9.4 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4bfbae73be2165c58e554ad9ac1f28c79a3ee03710047355f5bc84604ccd13d2
|
|
| MD5 |
8f315428eaab7272a3f6471d04590c9f
|
|
| BLAKE2b-256 |
22e7c8c21d7b0f9d4b2280b4df6e427fffcf3118e1e397aa09b9cbfedefe591b
|
Provenance
The following attestation bundles were made for ai_engineering-0.8.2.tar.gz:
Publisher:
release.yml on arcasilesgroup/ai-engineering
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_engineering-0.8.2.tar.gz -
Subject digest:
4bfbae73be2165c58e554ad9ac1f28c79a3ee03710047355f5bc84604ccd13d2 - Sigstore transparency entry: 1629738617
- Sigstore integration time:
-
Permalink:
arcasilesgroup/ai-engineering@24545f97d6c72d3b553c3685527bac16cf2afb38 -
Branch / Tag:
refs/tags/v0.8.2 - Owner: https://github.com/arcasilesgroup
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@24545f97d6c72d3b553c3685527bac16cf2afb38 -
Trigger Event:
push
-
Statement type:
File details
Details for the file ai_engineering-0.8.2-py3-none-any.whl.
File metadata
- Download URL: ai_engineering-0.8.2-py3-none-any.whl
- Upload date:
- Size: 3.2 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
64037c1c26558ff5f0d93a4de8bf7c3cbd742d476f449fa4b07c13c9201adf78
|
|
| MD5 |
c5191177101d2352e1884df753f0147f
|
|
| BLAKE2b-256 |
544e7384c43f87505d2b664f633ce280d05ad50f4fc2006a3d4697bbb632009c
|
Provenance
The following attestation bundles were made for ai_engineering-0.8.2-py3-none-any.whl:
Publisher:
release.yml on arcasilesgroup/ai-engineering
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_engineering-0.8.2-py3-none-any.whl -
Subject digest:
64037c1c26558ff5f0d93a4de8bf7c3cbd742d476f449fa4b07c13c9201adf78 - Sigstore transparency entry: 1629738624
- Sigstore integration time:
-
Permalink:
arcasilesgroup/ai-engineering@24545f97d6c72d3b553c3685527bac16cf2afb38 -
Branch / Tag:
refs/tags/v0.8.2 - Owner: https://github.com/arcasilesgroup
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@24545f97d6c72d3b553c3685527bac16cf2afb38 -
Trigger Event:
push
-
Statement type: