AI governance framework for secure software delivery
Project description
53 skills · 9 agents · 6 surfaces · 1 governed flow
{ai} engineering installs a deterministic governance layer into any repository: specs, decisions, skills, agents, runbooks, hooks, and audit trails as versioned local files. No hosted control plane. No provider lock-in. Every IDE follows the same rules.
Install
1.1 — Prerequisites
Python 3.11+ and Git.
1.2 — Install ai-engineering
- If you use
uv, install the published PyPI release as a managed tool:
uv tool install --force ai-engineering
uv tool update-shell
exec "$SHELL" -l
- If you do not use
uv, install withpipx:
pipx install ai-engineering
- If you do not use
uvorpipx, install withpip:
python -m pip install --user ai-engineering
If ai-eng is not available after the pip install, add Python's user scripts directory to your PATH, then reopen your shell.
- Verify the CLI:
ai-eng version
- Install governance into a repository:
cd your-project
ai-eng install .
ai-eng doctor
[PASS] doctor confirms hooks, mirrors, manifest defaults, and required tools.
To update later from PyPI:
- Upgrade the installed CLI with the command that matches your install method:
uv tool upgrade ai-engineering
# or
pipx upgrade ai-engineering
# or
python -m pip install --user --upgrade ai-engineering
These commands fetch the latest published ai-engineering release from PyPI.
- Verify that the new version is available:
ai-eng version
- In each governed project, refresh the installed framework files:
cd your-project
ai-eng update
ai-eng doctor
Governed Flow
The canonical chain is:
/ai-brainstorm → /ai-plan → /ai-build → /ai-pr
Use it when work changes product behavior, framework behavior, security posture, public docs, or release state. /ai-commit remains available for WIP checkpoints; it is not part of the canonical delivery chain.
Supported Surfaces
One canonical payload is mirrored into all enabled surfaces:
| Surface | Entry point |
|---|---|
| Claude Code | CLAUDE.md |
| GitHub Copilot | .github/copilot-instructions.md |
| OpenAI Codex | AGENTS.md |
| Antigravity | AGENTS.md + .agents/ skills and agents |
| OpenCode | .opencode/ skills and commands |
| Cursor | .cursor/ skills |
The ruleset lives in AGENTS.md. Project identity and hard prohibitions live in CONSTITUTION.md. Release history and breakage notes live in CHANGELOG.md.
Why Governance Matters
- Spec-driven work keeps LLM output tied to approved scope.
- Deterministic gates catch secrets, broken mirrors, missing docs, and policy drift.
- The local NDJSON audit chain records what happened without sending telemetry by default.
- Skills and agents are file-backed, reviewable, and synchronized across IDEs.
Standing on the shoulders of...
ai-engineering builds on ideas, patterns, and principles from these projects:
| Project | What we learned |
|---|---|
| Superpowers | Brainstorm hard-gate, TDD-for-skills patterns |
| review-code | Handler-as-workflow architecture, parallel specialist agents, finding-validator |
| dotfiles/ai | Agent matrix, SDLC coverage patterns |
| autoresearch | Radical simplicity as a design principle |
| Emil Kowalski | Motion principles, spring physics, easing strategy |
| SpecKit | Spec-driven workflow inspiration |
| GSD | Autonomous execution patterns |
| Anthropic Skills | Frontend-design, canvas, skill-creator — absorbed and extended |
Contributing
Contributions are welcome. See CONTRIBUTING.md for development setup, code style, testing, and the pull request process.
Code of conduct
This project follows the Contributor Covenant Code of Conduct. See CODE_OF_CONDUCT.md.
License
MIT. See LICENSE.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ai_engineering-0.8.4.tar.gz.
File metadata
- Download URL: ai_engineering-0.8.4.tar.gz
- Upload date:
- Size: 9.4 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a84a16bbd8627a80a04bb1c5824144f3550e4c6499d29af64a58e5fe9ab911fe
|
|
| MD5 |
38da9c04c68b6c1cad9a5e13b5c12413
|
|
| BLAKE2b-256 |
abd880b2027395e6e0ccd9de1ccf45f159b9cfde28d1aa20fc5754e636bcebca
|
Provenance
The following attestation bundles were made for ai_engineering-0.8.4.tar.gz:
Publisher:
release.yml on arcasilesgroup/ai-engineering
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_engineering-0.8.4.tar.gz -
Subject digest:
a84a16bbd8627a80a04bb1c5824144f3550e4c6499d29af64a58e5fe9ab911fe - Sigstore transparency entry: 1672539889
- Sigstore integration time:
-
Permalink:
arcasilesgroup/ai-engineering@d118c3dbfdea0dd65d357c547f2704631c1b17ab -
Branch / Tag:
refs/tags/v0.8.4 - Owner: https://github.com/arcasilesgroup
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@d118c3dbfdea0dd65d357c547f2704631c1b17ab -
Trigger Event:
push
-
Statement type:
File details
Details for the file ai_engineering-0.8.4-py3-none-any.whl.
File metadata
- Download URL: ai_engineering-0.8.4-py3-none-any.whl
- Upload date:
- Size: 3.2 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1c7104d24264555323eb07a075b222e69d4fb521e8216385b7deadaa6c9b9aac
|
|
| MD5 |
0aa1ff8d2d17d27c4cec0554bfe362bc
|
|
| BLAKE2b-256 |
c6edafe068d3ec5bba6105283da4b103d01c9ddb55e490c49ec02042a9582bdc
|
Provenance
The following attestation bundles were made for ai_engineering-0.8.4-py3-none-any.whl:
Publisher:
release.yml on arcasilesgroup/ai-engineering
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ai_engineering-0.8.4-py3-none-any.whl -
Subject digest:
1c7104d24264555323eb07a075b222e69d4fb521e8216385b7deadaa6c9b9aac - Sigstore transparency entry: 1672539892
- Sigstore integration time:
-
Permalink:
arcasilesgroup/ai-engineering@d118c3dbfdea0dd65d357c547f2704631c1b17ab -
Branch / Tag:
refs/tags/v0.8.4 - Owner: https://github.com/arcasilesgroup
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@d118c3dbfdea0dd65d357c547f2704631c1b17ab -
Trigger Event:
push
-
Statement type: