Agent skill

AI Rulez

by Goldziher in Goldziher/ai-rulez

Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)…

MITAuto-check passedSecurity

Install AI Rulez

skills CLI
$ npx skills add Goldziher/ai-rulez --skill ai-rulez -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Goldziher/ai-rulez ai-rulez --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ai-rulez .claude/skills/ai-rulez && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-rulez
GitHub stars
159
Token cost
~3.3k tokens
SKILL.md length
1,138 words
Files
5 (incl. references)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)…

  • Configuring rules
  • SKILL.md covers Installation, Quick Start, Lifecycle commands and Configuration Structure, plus 11 more sections
  • Calls npx, uvx and go; reaches github.com
  • Generating tool-specific outputs

What it does

AI Rulez is an agent skill from Goldziher/ai-rulez. Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more), bundle (OKF, Agent Plugins, ARD), validate, govern (lock, approvals, signing, SBOM) and publish. Use when configuring rules, context, skills, checks, hooks, permissions, domains, profiles, includes, plugins, or generating tool-specific outputs.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/cli-reference.md`, `references/configuration.md` and `references/includes-and-skills.md`).

It sits in Security, covering Hooks and plugins and Supply chain security. The repository describes itself as: Standards-compliant lifecycle tool for agent knowledge and capabilities: author, generate, bundle, validate, govern, publish. The licence is MIT.

When your agent uses it

  • Configuring rules
  • Generating tool-specific outputs

Example prompts

  • “/ai-rulez”

Requirements

  • Python 3
  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit d0d05e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • uvx
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • goldziher.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Rulez loads about 3.3k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 1,138 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Goldziher/ai-rulez at commit d0d05e8, republished under its MIT licence (© Goldziher). 1,138 words, ~3,339 tokens.

Download SKILL.mdSave it as .claude/skills/ai-rulez/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
ai-rulez
description
Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more), bundle (OKF, Agent Plugins, ARD), validate, govern (lock, approvals, signing, SBOM) and publish. Use when configuring rules, context, skills, checks, hooks, permissions, domains, profiles, includes, plugins, or generating tool-specific outputs.
license
MIT
metadata.author
Goldziher
metadata.version
5.0.0
metadata.repository
https://github.com/Goldziher/ai-rulez

AI-Rulez

AI-Rulez is a standards-compliant lifecycle tool for agent knowledge and capabilities. It keeps one source of truth in a config directory (default .ai-rulez/) and takes it through author, generate (52 built-in harness presets: Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and others), bundle (OKF, Agent Plugins, ARD), lint and validate, govern (lock, approvals, Sigstore signing, policy, SBOM) and publish.

Use this skill when:

  • Setting up or modifying .ai-rulez/ configuration
  • Writing rules, context, skills, agents, commands, or checks for AI assistants
  • Declaring [[hooks]] or [permissions] once for every harness
  • Generating a personal config into the home directory with generate --user
  • Configuring domains, profiles, or includes
  • Using custom config directory names via --config-dir
  • Generating outputs for specific AI tools
  • Auditing planned writes/deletes with --dry-run
  • Installing or managing external skills

Installation

bash
# npm (no install)
npx ai-rulez@latest

# Python (no install)
uvx ai-rulez

# Go (the module path needs /v5; without it @latest resolves to an old 1.x build)
go install github.com/Goldziher/ai-rulez/v5/cmd/ai-rulez@latest

Quick Start

bash
# Initialize a new project
ai-rulez init

# Add rules and context
ai-rulez add rule my-rule --priority high
ai-rulez add context my-context

# Generate outputs for all configured presets
ai-rulez generate

# Regenerate whenever .ai-rulez/ changes
ai-rulez generate --watch

# Validate configuration
ai-rulez validate

# Read-only diagnostics: drift, removed presets, missing tools
ai-rulez doctor

Lifecycle commands

bash
ai-rulez generate --plugin              # bundle: plugin bundles from the [plugin] block
ai-rulez export okf                     # bundle: an OKF bundle of the knowledge
ai-rulez validate --strict              # validate: warnings fail
ai-rulez okf validate docs/okf          # validate: any OKF bundle
ai-rulez lock                           # govern: pin includes, skills and content
ai-rulez sign --lock                    # govern: Sigstore attestation of the lock
ai-rulez sbom -o ai-bom.cdx.json        # govern: CycloneDX SBOM
ai-rulez publish --dry-run              # publish: preview release artifacts

Supported and planned standards, with pinned versions and test status, are in https://goldziher.github.io/ai-rulez/standards/.

Configuration Structure

text
.ai-rulez/
  config.toml          # Main configuration
  rules/               # Governance rules (.md files with frontmatter)
  context/             # Contextual information (.md files)
  skills/              # Specialized capabilities (name/SKILL.md plus resources)
  agents/              # Agent definitions (.md files)
  commands/            # Custom commands (.md files)
  checks/              # Code-review guidelines (.md files)
  domains/             # Domain-scoped content
    backend/
      rules/
      context/
      skills/

config.toml

toml
version = "5.0"
name = "my-project"
description = "Project description"

presets = ["claude", "cursor", "gemini"]
default = "backend"
builtins = ["go", "security", "testing"]

[profiles]
backend = ["backend", "shared"]
frontend = ["frontend", "shared"]

[[includes]]
name = "shared-rules"
source = "https://github.com/org/shared-rules"

[[installed_skills]]
name = "kreuzberg"
source = "https://github.com/kreuzberg-dev/kreuzberg"

[[mcp_servers]]
name = "ai-rulez"
command = "npx"
args = ["-y", "ai-rulez@latest", "mcp"]

[[scopes]]
path = "packages/web"
profile = "frontend"
presets = ["codex", "claude"]

Content Frontmatter

Rules, context, skills, and agents support YAML frontmatter:

yaml
---
priority: high # critical, high, medium, low, minimal
targets: # Limit to specific presets
  - CLAUDE.md
  - .cursor/rules/*
description: Brief description
---
Agent-only fields

Agent files under .ai-rulez/agents/ accept additional frontmatter that maps to Claude Code's subagent spec. Each is optional and only emitted into .claude/agents/*.md (other presets skip fields they do not support):

yaml
---
name: security-reviewer
description: Reviews code for security regressions
model: opus # haiku | sonnet | opus | inherit
effort: high # low | medium | high | xhigh | max | inherit
permissionMode: default
tools: # Restrict tool access
  - Read
  - Grep
  - Glob
---

effort controls reasoning depth. Set a project-wide default and per-preset overrides in config.toml:

toml
[defaults]
effort = "medium"

[defaults.effort_by_preset]
codex = "high"      # Codex applies it globally and per agent
claude = "xhigh"    # Claude applies it as `effort` per agent
amp = "max"         # Amp writes amp.anthropic.effort to .amp/settings.json

Resolution order (per preset, per agent): per-agent effort → defaults.effort_by_preset[<preset>] → defaults.effort → omit.

Per-preset support:

  • Claude: per-agent in .claude/agents/*.md (full vocabulary including max; inherit is not a Claude value and is dropped)
  • Codex: global in .codex/config.toml and per-agent in .codex/agents/*.toml (max → high; inherit dropped)
  • Amp: global in .amp/settings.json (xhigh → high)
  • Devin: per-agent in .devin/agents/*.md frontmatter (max → high)
  • Opencode: per-agent variant in .opencode/agents/*.md (joins the agent's model as model#variant)
  • Cursor, Copilot, Gemini, Junie, Antigravity, Cline: silently skipped (those tools expose effort via UI toggles or user-managed config files we don't generate).

Domains and Profiles

Domains group content for different teams or concerns. Profiles select which domains are active.

bash
ai-rulez domain add backend
ai-rulez add rule api-standards --domain backend
ai-rulez profile add backend-team backend shared
ai-rulez generate --profile backend-team

Includes

Share rules across projects using git repositories or local paths:

bash
ai-rulez include add shared-rules https://github.com/org/shared-rules
ai-rulez include add local-rules ./path/to/local --merge-strategy include-override

Installed Skills

Install named skills from external repositories:

bash
ai-rulez skill install kreuzberg --source https://github.com/kreuzberg-dev/kreuzberg
ai-rulez skill install ai-rulez --source https://github.com/Goldziher/ai-rulez
ai-rulez skill list
ai-rulez skill remove kreuzberg

Skills are fetched dynamically at generation time and included in outputs. Skill references/, scripts/, and assets/ directories are preserved as separate generated resource files when the target preset supports skill directories.

Built-in Presets

52 presets are available (ai-rulez init --help prints them): aiassistant, amp, antigravity, augment, baz, bob, claude, cline, codebuddy, codebuff, codewhale, codex, commandcode, copilot, copilot-cli, cortex, crush, cursor, deepagents, devin, dsh, factory, gemini, gitlab-duo, goose, grok, hermes, junie, kilo, kimi, kiro, letta, mimocode, muse, omp, openclaw, opencode, pi, poolside, qoder, qwen, reasonix, replit, rovodev, takt, trae, vibe, warp, xum, zcode, zed, zoocode, plus the opt-in okf preset (an Open Knowledge Format bundle in docs/okf/, see ai-rulez export okf). The mcp preset is a shared utility (the generic .mcp.json) invoked automatically when MCP servers are configured.

windsurf is now devin and continue-dev was removed; ai-rulez doctor reports both. docs/harnesses.md has the per-preset feature matrix (rules folder, skills, agents, commands, MCP, hooks, permissions, checks, user scope).

Hooks, Permissions, Checks and User Scope

  • [[hooks]] in config.toml renders into the native hooks file of 36 harnesses (a generated plugin module for opencode, kilo, mimocode, pi and amp). Events, matchers and timeouts are translated per harness; a group a harness cannot express is skipped with a warning. See docs/settings.md.
  • [permissions] (allow, ask, deny, Claude Code rule syntax) is translated for 24 harnesses. A rule that cannot be expressed is skipped, never widened, and an unenforced deny is reported. See docs/permissions.md.
  • Checks are code-review guidelines in .ai-rulez/checks/<name>.md (frontmatter description, severity, tools, targets), rendered for cursor, kilo, qwen, factory, rovodev, amp, augment and gitlab-duo. Manage them with ai-rulez add|remove|list check. See docs/checks.md.
  • ai-rulez generate --user renders a user config (~/.config/ai-rulez) into the home directories of 47 harnesses; clean --user removes what it wrote. See docs/user-scope.md.
  • Settings files you also edit (JSON, JSONC, TOML, YAML) are merged key by key, so your own keys and comments survive generate and clean.
  • [guard] generated = true adds a PreToolUse hook (ai-rulez guard) that blocks agent edits to generated files and points at the source under .ai-rulez/.
Show full SKILL.md (471 more words)Show less

Lock, Updates and Verification

  • ai-rulez lock writes ai-rulez.lock: commits and digests of remote includes, installed skills and skill sources, plus every authored item and generated output. It is enforced whenever the file exists ([lock] enforce = false opts out). lock --check verifies offline, --diff previews, --subject prints the digest to sign with cosign, generate --locked/--frozen are the CI modes. Exit codes: 0 ok, 1 could not run, 2 drift, 3 served skills left unpinned by the security scan. See docs/lockfile.md.
  • Sources accept version = "^1.2"; ai-rulez lock --outdated lists newer tags and ai-rulez update moves range pins (codes AR730, AR731, AR732, AR735).
  • ai-rulez validate runs deep content checks with stable AR codes (--fix, --since, --baseline, --format json|sarif|github|junit|markdown); ai-rulez scan runs only the security checks; validate --explain AR001 explains a rule. See docs/strict-validation.md.
  • [[verifiers]] and .ai-rulez/verifiers/*.toml declare deterministic repo checks run by ai-rulez verifiers run (--since, --staged, --format sarif|junit).
  • ai-rulez sbom prints a CycloneDX bill of materials, ai-rulez catalog lists every item with owner, version, tokens and lock status (--html <dir> writes a static site), ai-rulez tokens and cost report prompt-token cost, ai-rulez search <query> ranks skills.
  • ai-rulez convert imports existing tool files, a rulesync project or a skills-lock.json into .ai-rulez/ with a lossiness report.

Roles and Dynamic Skills

  • [[roles]] map a job to a slice of the content (domains, include/exclude selectors, skill_mode); generate --role <name> renders it and ai-rulez roles list|show|resolve inspects it. See docs/roles.md.
  • delivery: static|served|both on a skill (or [skills] delivery) serves a skill over MCP on demand instead of writing it to the harness trees: run ai-rulez mcp --serve-skills (find_skill, load_skill, list_skill_resources). [[skill_sources]] serve skills from a git repository or directory. See docs/mcp-server.md.

A tool that isn't built in can be supported at full parity with a provider-backed custom preset: set provider = "<project-relative spec.toml>" and point it at a declarative spec validated against schema/provider.schema.json. See the ai-rulez references for the spec shape.

MCP Integration

MCP servers are configured inline in config.toml with [[mcp_servers]]. ai-rulez exposes an MCP server for AI assistants to read, create, update, validate, dry-run, and generate configuration:

bash
ai-rulez mcp

Configure in your AI tool's MCP settings to enable CRUD operations from within the assistant.

MCP server env values can use ${VAR} placeholders. ai-rulez generate resolves them from --env, process env, and dotenv files, then refuses to write secret-bearing generated MCP configs unless the target paths are gitignored (gitignore = true or generate --gitignore adds them to the managed block).

Plugins and Marketplaces

ai-rulez can package the same source (skills, commands, agents, MCP servers) as distributable plugin bundles and a marketplace index for Claude, Cursor, Codex, Gemini, Kimi, OpenCode, Factory, and Hermes via ai-rulez generate --plugin. Consumer [[plugins]]/[[marketplaces]] arrays declare plugins to install from a marketplace (no output file is written for them: generate warns that [[plugins]] has no effect; enable plugins through [claude.settings] for Claude Code and .codex/config.toml for Codex).

© Goldziher, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/ai-rulez of Goldziher/ai-rulez.

  • SKILL.md
  • references/cli-reference.md
  • references/configuration.md
  • references/includes-and-skills.md
  • references/presets-and-outputs.md

Open the folder on GitHubat commit d0d05e8

Compare with similar skills

AI Rulez next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Rulez compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Rulez this skillGoldziher/ai-rulez159—~3.3kAutomated safety check: PassMIT
Agent Supply Chaingithub/awesome-copilot40k1 repos~2.7kAutomated safety check: PassMIT
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone

Similar skills

  • Agent Supply Chain

    github/awesome-copilot

    Official

    Verify supply chain integrity for AI agent plugins, tools, and dependencies.

    40k GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed

More from Goldziher/ai-rulez

All 10 skills in this repo
  • Code Quality Standards

    Goldziher/ai-rulez

    Concrete code-quality thresholds and anti-patterns: 120-char lines, max 20 cyclomatic complexity, max 4 nesting levels, max 50 lines per function, no magic numbers, no global state, composition over…

    159 GitHub stars~486 tokensUpdated today
    Auto-check passed
  • Rust Conventions

    Goldziher/ai-rulez

    Rust code conventions covering edition 2024, cargo fmt/clippy, Result-based error handling, unsafe discipline, async with tokio, API-guideline naming, trait implementations, benchmarking, and…

    159 GitHub stars~746 tokensUpdated today
    Auto-check passed
  • Testing Conventions

    Goldziher/ai-rulez

    How to write a good test: behaviour-describing names (shouldreturnerrorwheninputisempty, givenwhenthen), exact-value assertions over truthiness, snapshot and property-based testing…

    159 GitHub stars~473 tokensUpdated today
    Auto-check passed
  • Vite Plus Conventions

    Goldziher/ai-rulez

    vite+ unified TypeScript toolchain conventions: the vp CLI for package/node management, oxlint/oxfmt, type-aware linting, vitest, rolldown/tsdown bundling, task caching, and migration.

    159 GitHub stars~567 tokensUpdated today
    Auto-check passed
  • Bindings

    Goldziher/ai-rulez

    Cross-language binding architecture rules: bindings as minimal glue, canonical API surface ordering (core, ABI, language), per-language test suites in CI, generated-code discipline, and error/async…

    159 GitHub stars~265 tokensUpdated yesterday
    Auto-check passed
  • Cgo Bindings

    Goldziher/ai-rulez

    cgo conventions for linking Go to a C or Rust static library: import "C" directives, type/string conversion, CString memory management, thread safety, and Go pointer pinning.

    159 GitHub stars~371 tokensUpdated yesterday
    Auto-check passed

Questions about AI Rulez

What does AI Rulez do?

Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)…. AI Rulez is an agent skill from Goldziher/ai-rulez.ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more), bundle (OKF, Agent Plugins, ARD), validate, govern (lock, approvals, signing, SBOM) and publish.

When should I use AI Rulez?

AI Rulez fits situations like: configuring rules; generating tool-specific outputs.

How do I install AI Rulez in Claude Code?

Run `npx skills add Goldziher/ai-rulez --skill ai-rulez -a claude-code`. Or copy the skill folder (skills/ai-rulez in Goldziher/ai-rulez) into .claude/skills/ai-rulez in your project. Claude Code loads it when a task matches its description.

How do I install AI Rulez in Codex?

Run `npx skills add Goldziher/ai-rulez --skill ai-rulez -a codex`. Or copy the skill folder (skills/ai-rulez in Goldziher/ai-rulez) into .agents/skills/ai-rulez in your project. Codex loads it when a task matches its description.

Can I use AI Rulez in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Goldziher/ai-rulez --skill ai-rulez -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-rulez, .gemini/skills/ai-rulez, .github/skills/ai-rulez and .opencode/skills/ai-rulez in your project.

What does AI Rulez need to run?

Going by SKILL.md and its folder, AI Rulez needs the command-line tools its instructions call (npx, uvx and go). Our summary lists: Python 3; Node.js.

Does AI Rulez access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: goldziher.github.io. This is read from the text; nothing was executed.

Is AI Rulez safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Rulez use?

AI Rulez is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Rulez use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.5k tokens, read only when the agent opens those files.

What are the alternatives to AI Rulez?

Skills that share tags, products or a category with AI Rulez: Agent Supply Chain (github/awesome-copilot, 40k stars), Plugin Scanner (iflytek/skillhub, 5.2k stars), Skill Inspector (NVIDIA/SkillSpector, 20k stars) and Skill Scanner (getsentry/skills, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Rulez?

Goldziher (a GitHub user) maintains it in Goldziher/ai-rulez, which has 159 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 11, 2026.

Source: Goldziher/ai-rulez on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.