Install
$ agentstack add skill-omarsaleh506-skills-ai-os-init ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
ai-os-init
Scaffolds the five-layer AI Operating System structure into any project directory. Non-destructive by design: existing files are never touched, hook entries are never duplicated, source trees are never imposed.
No dependencies — needs only Python 3 and bash, both already present on any machine running Claude Code. The hooks that call formatters or type checkers (ruff, prettier, tsc, mypy, …) degrade silently when those tools aren't installed, so nothing ever breaks.
The Five Layers It Wires Up
| # | Layer | What gets created | |---|---|---| | 01 | Memory | CLAUDE.md — always-loaded project map, conventions, links | | 02 | Knowledge | .claude/skills/new-adr/ + .claude/skills/clean-tests/ — on-demand skills | | 03 | Guardrails | .claude/hooks/ — six PreToolUse/PostToolUse hooks (see below) | | 04 | Delegation | .claude/agents/docs-auditor.md — read-only docs drift subagent | | 05 | Docs | docs/ architecture + decisions (ADR log) + runbooks |
Hooks installed (wired into .claude/settings.json)
| Hook | Event | What it does | |---|---|---| | guard-secrets.sh | PreToolUse (Edit/Write) | Blocks writes to secret-looking files (.env, keys, credentials) | | branch-guard.sh | PreToolUse (Bash) | Blocks force-push and direct commit/push to protected branches; runs CI before push | | auto-format.sh | PostToolUse (Edit/Write) | Formats the edited file (ruff/black/prettier/gofmt/rustfmt), best-effort | | typecheck.sh | PostToolUse (Edit/Write) | Surfaces type errors (tsc/mypy) if the project is configured for them | | n+1-guard.sh | PostToolUse (Edit/Write) | Warns on likely N+1 query patterns (DB call inside a loop) | | audit-log.sh | PostToolUse (Bash) | Silently appends every bash command to .claude/command-audit.log |
> Two of these change git/agent behaviour out of the box: branch-guard.sh > will block commits on main/master/develop/staging/production and force > pushes, and audit-log.sh logs every command. Tell your team these are > active, or drop the hooks you don't want from templates/.claude/hooks/ > before sharing.
How to Run
Tell Claude to run the scaffold on the current project:
python3 "${CLAUDE_PLUGIN_ROOT}/skills/ai-os-init/scaffold.py"
# or for a specific path:
python3 "${CLAUDE_PLUGIN_ROOT}/skills/ai-os-init/scaffold.py" /path/to/project
Report the created/skipped/merged summary to the user.
Non-Destructive Contract
- File exists → skip it, report it as "already present"
- File missing → create it from the template
.claude/settings.json→ load and merge; append each hook entry **only
if** a hook with the same command isn't already there — then write back preserving all existing keys
CLAUDE.mdexists → leave it byte-identical; note which recommended
sections are absent so the user can fill them in
- No
src/imposed — if the project hassrc/,lib/, orapp/but
no nested CLAUDE.md, suggest adding one; never create source dirs
What to Do After Scaffolding
After running, guide the user through:
- Fill in
CLAUDE.md— project name, conventions, key commands - Fill in
docs/architecture.md— tech stack, components, data flow - Try
new-adr: say "create an ADR about [decision]" - Try
clean-tests: say "clean up the tests" - Try
docs-auditor: say "audit the docs" guard-secretsis already active — it blocks writes to secret-looking files
Template Source
All templates live alongside this skill in templates/. To customise what gets created in future projects, fork the repo and edit the templates there (editing the installed plugin cache directly gets overwritten on the next update).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: OmarSaleh506
- Source: OmarSaleh506/skills
- License: MIT
- Homepage: https://skills.sh/OmarSaleh506/skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.