Agent skill

AI SAFE2 Development Method

by CyberStrategyInstitute in CyberStrategyInstitute/ai-safe2-framework

Plans and runs material repository changes with the AI SAFE2 method: classify delivery shape and risk, isolate the work, collect test evidence and finish with a completion receipt.

Custom licenceAuto-check passedDevelopment

Install AI SAFE2 Development Method

skills CLI
$ npx skills add CyberStrategyInstitute/ai-safe2-framework --skill ai-safe2-development-method -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CyberStrategyInstitute/ai-safe2-framework ai-safe2-development-method --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CyberStrategyInstitute/ai-safe2-framework.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codex/ai-safe2-development-method .claude/skills/ai-safe2-development-method && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-safe2-development-method
GitHub stars
146
Token cost
~833 tokens
SKILL.md length
362 words
Files
5 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
Custom licence

At a glance

Plans and runs material repository changes with the AI SAFE2 method: classify delivery shape and risk, isolate the work, collect test evidence and finish with a completion receipt.

  • Works in 10 steps: Read the nearest repository instructions… → Classify delivery shape independently… → Create a… → …
  • Planning a risky repository change that needs a recorded design depth
  • SKILL.md covers Workflow, Decision Rules and References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

This skill turns software-development discipline into decision evidence, keeping policy, implementation, verification, semantic review and human authority separate. The agent reads repository instructions and policy, classifies the delivery shape as spike, bounded or architectural independently of risk, writes a plan source and runs safe2 dev plan to produce a plan. A review_required plan pauses only for the named missing decision, and an invalid plan is never worked around.

Repository-changing work is isolated and unrelated user changes are preserved. The evidence mode depends on the work: observe a failing then passing behavior for code, characterize ambiguous existing behavior first, establish the invalid and valid boundary for contracts and configuration, use render or interaction checks for documents and UI, and record hypothesis, result and discard decision for a spike. A failing check is localized before any fix, and reviews follow the cadence in the plan, with model reviewers treated as attributed evidence and a provider failure reported as unavailable rather than passing.

Before claiming completion the agent runs fresh verification on the final revision and produces a receipt with safe2 dev receipt. Architectural work and high or critical risk require explicit human design approval, and critical risk needs a threat model. It is not for read-only explanations or trivial edits, and it gives no authority to merge, release, deploy, accept risk or change policy.

When your agent uses it

  • Planning a risky repository change that needs a recorded design depth
  • Producing a completion receipt with fresh verification evidence
  • Deciding whether a task is a spike, a bounded change or architectural work
  • Gathering before-and-after evidence for a change

Example prompts

  • “Plan the payment-webhook refactor with the SAFE2 method and tell me which delivery shape it is.”
  • “Run the SAFE2 plan for this change and produce the completion receipt once the tests pass.”
  • “Classify this auth change by delivery shape and risk before we write any code.”

Requirements

  • The safe2 command line tool

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Read the nearest repository instructions and current policy before acting.
  2. Classify delivery shape independently from risk
  3. Create a safe2.development-plan-source.v1 source and run
  4. If the plan is review_required, pause only for the named missing decision.
  5. Isolate repository-changing work. Preserve unrelated user changes.
  6. Use the selected evidence mode
  7. When a check fails, localize the cause before proposing a fix. Do not stack
  8. Review at the cadence in the plan. Treat PR-Agent, Greptile, and other model
  9. Capture comparable before/after evidence when required. If no safe baseline
  10. Before any completion claim, run fresh verification against the final revision

What it can do on your machine

Read from SKILL.md and the folder at commit 9f92160. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI SAFE2 Development Method loads about 833 tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 362 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~833
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 362 words (~833 tokens).

“Convert software-development discipline into decision evidence. Keep policy, implementation, verification, semantic review, and human authority separate.”

— opening of SKILL.md by CyberStrategyInstitute, Custom licence
name
ai-safe2-development-method

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (references) in skills/codex/ai-safe2-development-method of CyberStrategyInstitute/ai-safe2-framework.

  • SKILL.md
  • SKILL-CARD.md
  • agents/openai.yaml
  • references/evaluation.md
  • references/method.md

Open the folder on GitHubat commit 9f92160

Compare with similar skills

AI SAFE2 Development Method next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI SAFE2 Development Method compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI SAFE2 Development Method this skillCyberStrategyInstitute/ai-safe2-framework146—~833Automated safety check: PassCustom licence
Fable Disciplineassafkip/kipi-system112—~2.9kAutomated safety check: PassMIT
Bulletproof Workflowartemiimillier/bulletproof153—~3.5kAutomated safety check: PassMIT
TiDB Verification Profilespingcap/tidb41k—~496Automated safety check: PassApache-2.0
NIC Task Planningnginx/kubernetes-ingress5.1k—~1.7kAutomated safety check: PassApache-2.0
Feature Development WorkflowQwenLM/qwen-code28k—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Fable Discipline

    assafkip/kipi-system

    Teaches staged, verifiable coding habits for multi-file tasks and ships a hook that blocks tests from touching live data.

    112 GitHub stars~2.9k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Bulletproof Workflow

    artemiimillier/bulletproof

    Applies a 12-stage verified workflow, from research to deploy, to non-trivial coding tasks, scaled to lightweight, standard or full mode by task size.

    153 GitHub stars~3.5k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Chooses how much validation a TiDB change needs: scoped checks while iterating, required checks at delivery, and expensive runs only when explicitly needed.

    41k GitHub stars~496 tokensUpdated today
    DevelopmentAuto-check passed
  • NIC Task Planning

    nginx/kubernetes-ingress

    Plans a change to the NGINX Ingress Controller before any code: acceptance criteria, security impact, affected layers, invariants, test surface and an ordered file list.

    5.1k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Phased workflow for non-trivial qwen-code features: investigate, design doc, E2E test plan, baseline dry-run, implement, verify, self-audit, review and iterate.

    28k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Reviews an execution plan or design doc before coding, covering architecture, data flow, edge cases, test coverage and performance, one issue at a time.

    136k GitHub stars~13k tokensUpdated today
    DevelopmentAuto-check: notes

More from CyberStrategyInstitute/ai-safe2-framework

  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers.

    146 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure.

    146 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Questions about AI SAFE2 Development Method

What does AI SAFE2 Development Method do?

Plans and runs material repository changes with the AI SAFE2 method: classify delivery shape and risk, isolate the work, collect test evidence and finish with a completion receipt. This skill turns software-development discipline into decision evidence, keeping policy, implementation, verification, semantic review and human authority separate. The agent reads repository instructions and policy, classifies the delivery shape as spike, bounded or architectural independently of risk, writes a plan source and runs safe2 dev plan to produce a plan.

When should I use AI SAFE2 Development Method?

AI SAFE2 Development Method fits situations like: planning a risky repository change that needs a recorded design depth; producing a completion receipt with fresh verification evidence; deciding whether a task is a spike, a bounded change or architectural work; gathering before-and-after evidence for a change.

How do I install AI SAFE2 Development Method in Claude Code?

Run `npx skills add CyberStrategyInstitute/ai-safe2-framework --skill ai-safe2-development-method -a claude-code`. Or copy the skill folder (skills/codex/ai-safe2-development-method in CyberStrategyInstitute/ai-safe2-framework) into .claude/skills/ai-safe2-development-method in your project. Claude Code loads it when a task matches its description.

How do I install AI SAFE2 Development Method in Codex?

Run `npx skills add CyberStrategyInstitute/ai-safe2-framework --skill ai-safe2-development-method -a codex`. Or copy the skill folder (skills/codex/ai-safe2-development-method in CyberStrategyInstitute/ai-safe2-framework) into .agents/skills/ai-safe2-development-method in your project. Codex loads it when a task matches its description.

Can I use AI SAFE2 Development Method in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CyberStrategyInstitute/ai-safe2-framework --skill ai-safe2-development-method -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-safe2-development-method, .gemini/skills/ai-safe2-development-method, .github/skills/ai-safe2-development-method and .opencode/skills/ai-safe2-development-method in your project.

What does AI SAFE2 Development Method need to run?

SKILL.md names no scripts, command-line tools or credentials: AI SAFE2 Development Method is instructions for the agent only. Our summary lists: The safe2 command line tool.

Does AI SAFE2 Development Method access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI SAFE2 Development Method safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI SAFE2 Development Method use?

AI SAFE2 Development Method has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does AI SAFE2 Development Method use?

About 833 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 761 tokens, read only when the agent opens those files.

What are the alternatives to AI SAFE2 Development Method?

Skills that share tags, products or a category with AI SAFE2 Development Method: Fable Discipline (assafkip/kipi-system, 112 stars), Bulletproof Workflow (artemiimillier/bulletproof, 153 stars), TiDB Verification Profiles (pingcap/tidb, 41k stars) and NIC Task Planning (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI SAFE2 Development Method?

CyberStrategyInstitute (a GitHub organization) maintains it in CyberStrategyInstitute/ai-safe2-framework, which has 146 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 9, 2026.

Source: CyberStrategyInstitute/ai-safe2-framework on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.