Agent Supply Chain
github/awesome-copilot
Verify supply chain integrity for AI agent plugins, tools, and dependencies.
Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)…
$ npx skills add Goldziher/ai-rulez --skill ai-rulez -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Goldziher/ai-rulez ai-rulez --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ai-rulez .claude/skills/ai-rulez && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ai-rulez" agent skill from https://github.com/Goldziher/ai-rulez/tree/main/skills/ai-rulez into .claude/skills/ai-rulez/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-rulez", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Goldziher/ai-rulez/tree/main/skills/ai-rulezType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Goldziher/ai-rulez --skill ai-rulez -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Goldziher/ai-rulez ai-rulez --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ai-rulez .agents/skills/ai-rulez && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ai-rulez" agent skill from https://github.com/Goldziher/ai-rulez/tree/main/skills/ai-rulez into .agents/skills/ai-rulez/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-rulez", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Goldziher/ai-rulez --skill ai-rulez -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Goldziher/ai-rulez ai-rulez --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ai-rulez .cursor/skills/ai-rulez && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ai-rulez" agent skill from https://github.com/Goldziher/ai-rulez/tree/main/skills/ai-rulez into .cursor/skills/ai-rulez/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-rulez", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Goldziher/ai-rulez.git --path skills/ai-rulez--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Goldziher/ai-rulez --skill ai-rulez -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Goldziher/ai-rulez ai-rulez --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ai-rulez .gemini/skills/ai-rulez && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ai-rulez" agent skill from https://github.com/Goldziher/ai-rulez/tree/main/skills/ai-rulez into .gemini/skills/ai-rulez/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-rulez", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Goldziher/ai-rulez ai-rulezInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Goldziher/ai-rulez --skill ai-rulez -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ai-rulez .github/skills/ai-rulez && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ai-rulez" agent skill from https://github.com/Goldziher/ai-rulez/tree/main/skills/ai-rulez into .github/skills/ai-rulez/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-rulez", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Goldziher/ai-rulez --skill ai-rulez -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Goldziher/ai-rulez ai-rulez --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ai-rulez .opencode/skills/ai-rulez && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ai-rulez" agent skill from https://github.com/Goldziher/ai-rulez/tree/main/skills/ai-rulez into .opencode/skills/ai-rulez/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-rulez", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ai-rulezStandards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)…
AI Rulez is an agent skill from Goldziher/ai-rulez. Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more), bundle (OKF, Agent Plugins, ARD), validate, govern (lock, approvals, signing, SBOM) and publish. Use when configuring rules, context, skills, checks, hooks, permissions, domains, profiles, includes, plugins, or generating tool-specific outputs.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/cli-reference.md`, `references/configuration.md` and `references/includes-and-skills.md`).
It sits in Security, covering Hooks and plugins and Supply chain security. The repository describes itself as: Standards-compliant lifecycle tool for agent knowledge and capabilities: author, generate, bundle, validate, govern, publish. The licence is MIT.
Read from SKILL.md and the folder at commit d0d05e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxuvxgoFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
goldziher.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AI Rulez loads about 3.3k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 1,138 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Goldziher/ai-rulez at commit d0d05e8, republished under its MIT licence (© Goldziher). 1,138 words, ~3,339 tokens.
.claude/skills/ai-rulez/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.AI-Rulez is a standards-compliant lifecycle tool for agent knowledge and capabilities. It keeps one source of truth in a config directory (default .ai-rulez/) and takes it through author, generate (52 built-in harness presets: Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and others), bundle (OKF, Agent Plugins, ARD), lint and validate, govern (lock, approvals, Sigstore signing, policy, SBOM) and publish.
Use this skill when:
.ai-rulez/ configuration[[hooks]] or [permissions] once for every harnessgenerate --user--config-dir--dry-run# npm (no install)
npx ai-rulez@latest
# Python (no install)
uvx ai-rulez
# Go (the module path needs /v5; without it @latest resolves to an old 1.x build)
go install github.com/Goldziher/ai-rulez/v5/cmd/ai-rulez@latest# Initialize a new project
ai-rulez init
# Add rules and context
ai-rulez add rule my-rule --priority high
ai-rulez add context my-context
# Generate outputs for all configured presets
ai-rulez generate
# Regenerate whenever .ai-rulez/ changes
ai-rulez generate --watch
# Validate configuration
ai-rulez validate
# Read-only diagnostics: drift, removed presets, missing tools
ai-rulez doctorai-rulez generate --plugin # bundle: plugin bundles from the [plugin] block
ai-rulez export okf # bundle: an OKF bundle of the knowledge
ai-rulez validate --strict # validate: warnings fail
ai-rulez okf validate docs/okf # validate: any OKF bundle
ai-rulez lock # govern: pin includes, skills and content
ai-rulez sign --lock # govern: Sigstore attestation of the lock
ai-rulez sbom -o ai-bom.cdx.json # govern: CycloneDX SBOM
ai-rulez publish --dry-run # publish: preview release artifactsSupported and planned standards, with pinned versions and test status, are in https://goldziher.github.io/ai-rulez/standards/.
.ai-rulez/
config.toml # Main configuration
rules/ # Governance rules (.md files with frontmatter)
context/ # Contextual information (.md files)
skills/ # Specialized capabilities (name/SKILL.md plus resources)
agents/ # Agent definitions (.md files)
commands/ # Custom commands (.md files)
checks/ # Code-review guidelines (.md files)
domains/ # Domain-scoped content
backend/
rules/
context/
skills/version = "5.0"
name = "my-project"
description = "Project description"
presets = ["claude", "cursor", "gemini"]
default = "backend"
builtins = ["go", "security", "testing"]
[profiles]
backend = ["backend", "shared"]
frontend = ["frontend", "shared"]
[[includes]]
name = "shared-rules"
source = "https://github.com/org/shared-rules"
[[installed_skills]]
name = "kreuzberg"
source = "https://github.com/kreuzberg-dev/kreuzberg"
[[mcp_servers]]
name = "ai-rulez"
command = "npx"
args = ["-y", "ai-rulez@latest", "mcp"]
[[scopes]]
path = "packages/web"
profile = "frontend"
presets = ["codex", "claude"]Rules, context, skills, and agents support YAML frontmatter:
---
priority: high # critical, high, medium, low, minimal
targets: # Limit to specific presets
- CLAUDE.md
- .cursor/rules/*
description: Brief description
---Agent files under .ai-rulez/agents/ accept additional frontmatter that maps to
Claude Code's subagent spec. Each is optional and only emitted into
.claude/agents/*.md (other presets skip fields they do not support):
---
name: security-reviewer
description: Reviews code for security regressions
model: opus # haiku | sonnet | opus | inherit
effort: high # low | medium | high | xhigh | max | inherit
permissionMode: default
tools: # Restrict tool access
- Read
- Grep
- Glob
---effort controls reasoning depth. Set a project-wide default and per-preset
overrides in config.toml:
[defaults]
effort = "medium"
[defaults.effort_by_preset]
codex = "high" # Codex applies it globally and per agent
claude = "xhigh" # Claude applies it as `effort` per agent
amp = "max" # Amp writes amp.anthropic.effort to .amp/settings.jsonResolution order (per preset, per agent): per-agent effort →
defaults.effort_by_preset[<preset>] → defaults.effort → omit.
Per-preset support:
.claude/agents/*.md (full vocabulary including max; inherit is not a Claude value and is dropped).codex/config.toml and per-agent in .codex/agents/*.toml (max → high; inherit dropped).amp/settings.json (xhigh → high).devin/agents/*.md frontmatter (max → high)variant in .opencode/agents/*.md (joins the agent's model as model#variant)Domains group content for different teams or concerns. Profiles select which domains are active.
ai-rulez domain add backend
ai-rulez add rule api-standards --domain backend
ai-rulez profile add backend-team backend shared
ai-rulez generate --profile backend-teamShare rules across projects using git repositories or local paths:
ai-rulez include add shared-rules https://github.com/org/shared-rules
ai-rulez include add local-rules ./path/to/local --merge-strategy include-overrideInstall named skills from external repositories:
ai-rulez skill install kreuzberg --source https://github.com/kreuzberg-dev/kreuzberg
ai-rulez skill install ai-rulez --source https://github.com/Goldziher/ai-rulez
ai-rulez skill list
ai-rulez skill remove kreuzbergSkills are fetched dynamically at generation time and included in outputs.
Skill references/, scripts/, and assets/ directories are preserved as separate generated resource files when the target preset supports skill directories.
52 presets are available (ai-rulez init --help prints them): aiassistant, amp, antigravity, augment, baz, bob, claude, cline, codebuddy, codebuff, codewhale, codex, commandcode, copilot, copilot-cli, cortex, crush, cursor, deepagents, devin, dsh, factory, gemini, gitlab-duo, goose, grok, hermes, junie, kilo, kimi, kiro, letta, mimocode, muse, omp, openclaw, opencode, pi, poolside, qoder, qwen, reasonix, replit, rovodev, takt, trae, vibe, warp, xum, zcode, zed, zoocode, plus the opt-in okf preset (an Open Knowledge Format bundle in docs/okf/, see ai-rulez export okf). The mcp preset is a shared utility (the generic .mcp.json) invoked automatically when MCP servers are configured.
windsurf is now devin and continue-dev was removed; ai-rulez doctor reports both. docs/harnesses.md has the per-preset feature matrix (rules folder, skills, agents, commands, MCP, hooks, permissions, checks, user scope).
[[hooks]] in config.toml renders into the native hooks file of 36 harnesses (a generated plugin module for opencode, kilo, mimocode, pi and amp). Events, matchers and timeouts are translated per harness; a group a harness cannot express is skipped with a warning. See docs/settings.md.[permissions] (allow, ask, deny, Claude Code rule syntax) is translated for 24 harnesses. A rule that cannot be expressed is skipped, never widened, and an unenforced deny is reported. See docs/permissions.md..ai-rulez/checks/<name>.md (frontmatter description, severity, tools, targets), rendered for cursor, kilo, qwen, factory, rovodev, amp, augment and gitlab-duo. Manage them with ai-rulez add|remove|list check. See docs/checks.md.ai-rulez generate --user renders a user config (~/.config/ai-rulez) into the home directories of 47 harnesses; clean --user removes what it wrote. See docs/user-scope.md.generate and clean.[guard] generated = true adds a PreToolUse hook (ai-rulez guard) that blocks agent edits to generated files and points at the source under .ai-rulez/.ai-rulez lock writes ai-rulez.lock: commits and digests of remote includes, installed skills and skill sources, plus every authored item and generated output. It is enforced whenever the file exists ([lock] enforce = false opts out). lock --check verifies offline, --diff previews, --subject prints the digest to sign with cosign, generate --locked/--frozen are the CI modes. Exit codes: 0 ok, 1 could not run, 2 drift, 3 served skills left unpinned by the security scan. See docs/lockfile.md.version = "^1.2"; ai-rulez lock --outdated lists newer tags and ai-rulez update moves range pins (codes AR730, AR731, AR732, AR735).ai-rulez validate runs deep content checks with stable AR codes (--fix, --since, --baseline, --format json|sarif|github|junit|markdown); ai-rulez scan runs only the security checks; validate --explain AR001 explains a rule. See docs/strict-validation.md.[[verifiers]] and .ai-rulez/verifiers/*.toml declare deterministic repo checks run by ai-rulez verifiers run (--since, --staged, --format sarif|junit).ai-rulez sbom prints a CycloneDX bill of materials, ai-rulez catalog lists every item with owner, version, tokens and lock status (--html <dir> writes a static site), ai-rulez tokens and cost report prompt-token cost, ai-rulez search <query> ranks skills.ai-rulez convert imports existing tool files, a rulesync project or a skills-lock.json into .ai-rulez/ with a lossiness report.[[roles]] map a job to a slice of the content (domains, include/exclude selectors, skill_mode); generate --role <name> renders it and ai-rulez roles list|show|resolve inspects it. See docs/roles.md.delivery: static|served|both on a skill (or [skills] delivery) serves a skill over MCP on demand instead of writing it to the harness trees: run ai-rulez mcp --serve-skills (find_skill, load_skill, list_skill_resources). [[skill_sources]] serve skills from a git repository or directory. See docs/mcp-server.md.A tool that isn't built in can be supported at full parity with a provider-backed custom preset: set provider = "<project-relative spec.toml>" and point it at a declarative spec validated against schema/provider.schema.json. See the ai-rulez references for the spec shape.
MCP servers are configured inline in config.toml with [[mcp_servers]]. ai-rulez exposes an MCP server for AI assistants to read, create, update, validate, dry-run, and generate configuration:
ai-rulez mcpConfigure in your AI tool's MCP settings to enable CRUD operations from within the assistant.
MCP server env values can use ${VAR} placeholders. ai-rulez generate resolves them from --env,
process env, and dotenv files, then refuses to write secret-bearing generated MCP configs unless the
target paths are gitignored (gitignore = true or generate --gitignore adds them to the managed block).
ai-rulez can package the same source (skills, commands, agents, MCP servers) as distributable plugin bundles and a marketplace index for Claude, Cursor, Codex, Gemini, Kimi, OpenCode, Factory, and Hermes via ai-rulez generate --plugin. Consumer [[plugins]]/[[marketplaces]] arrays declare plugins to install from a marketplace (no output file is written for them: generate warns that [[plugins]] has no effect; enable plugins through [claude.settings] for Claude Code and .codex/config.toml for Codex).
© Goldziher, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/ai-rulez of Goldziher/ai-rulez.
Open the folder on GitHubat commit d0d05e8
AI Rulez next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AI Rulez this skillGoldziher/ai-rulez | 159 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Agent Supply Chaingithub/awesome-copilot | 40k | 1 repos | ~2.7k | Automated safety check: Pass | MIT | |
| Plugin Scanneriflytek/skillhub | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Skill InspectorNVIDIA/SkillSpector | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None |
github/awesome-copilot
Verify supply chain integrity for AI agent plugins, tools, and dependencies.
iflytek/skillhub
Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Goldziher/ai-rulez
Concrete code-quality thresholds and anti-patterns: 120-char lines, max 20 cyclomatic complexity, max 4 nesting levels, max 50 lines per function, no magic numbers, no global state, composition over…
Goldziher/ai-rulez
Rust code conventions covering edition 2024, cargo fmt/clippy, Result-based error handling, unsafe discipline, async with tokio, API-guideline naming, trait implementations, benchmarking, and…
Goldziher/ai-rulez
How to write a good test: behaviour-describing names (shouldreturnerrorwheninputisempty, givenwhenthen), exact-value assertions over truthiness, snapshot and property-based testing…
Goldziher/ai-rulez
vite+ unified TypeScript toolchain conventions: the vp CLI for package/node management, oxlint/oxfmt, type-aware linting, vitest, rolldown/tsdown bundling, task caching, and migration.
Goldziher/ai-rulez
Cross-language binding architecture rules: bindings as minimal glue, canonical API surface ordering (core, ABI, language), per-language test suites in CI, generated-code discipline, and error/async…
Goldziher/ai-rulez
cgo conventions for linking Go to a C or Rust static library: import "C" directives, type/string conversion, CString memory management, thread safety, and Go pointer pinning.
Categories
Standards-compliant lifecycle tool for agent knowledge and capabilities: author in .ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more)…. AI Rulez is an agent skill from Goldziher/ai-rulez.ai-rulez/, generate for 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more), bundle (OKF, Agent Plugins, ARD), validate, govern (lock, approvals, signing, SBOM) and publish.
AI Rulez fits situations like: configuring rules; generating tool-specific outputs.
Run `npx skills add Goldziher/ai-rulez --skill ai-rulez -a claude-code`. Or copy the skill folder (skills/ai-rulez in Goldziher/ai-rulez) into .claude/skills/ai-rulez in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Goldziher/ai-rulez --skill ai-rulez -a codex`. Or copy the skill folder (skills/ai-rulez in Goldziher/ai-rulez) into .agents/skills/ai-rulez in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Goldziher/ai-rulez --skill ai-rulez -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-rulez, .gemini/skills/ai-rulez, .github/skills/ai-rulez and .opencode/skills/ai-rulez in your project.
Going by SKILL.md and its folder, AI Rulez needs the command-line tools its instructions call (npx, uvx and go). Our summary lists: Python 3; Node.js.
SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: goldziher.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AI Rulez is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AI Rulez: Agent Supply Chain (github/awesome-copilot, 40k stars), Plugin Scanner (iflytek/skillhub, 5.2k stars), Skill Inspector (NVIDIA/SkillSpector, 20k stars) and Skill Scanner (getsentry/skills, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Goldziher (a GitHub user) maintains it in Goldziher/ai-rulez, which has 159 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 11, 2026.
Source: Goldziher/ai-rulez on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.