Agent skill

AI Native CLI

by sickn33 in sickn33/agentic-awesome-skills

Design spec with 98 rules for building CLI tools that AI agents can safely use.

MITAuto-check passedAI & LLM Engineering

Install AI Native CLI

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill ai-native-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills ai-native-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ai-native-cli .claude/skills/ai-native-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-native-cli
GitHub stars
47k
Used in
2 other repos
Token cost
~3.3k tokens
SKILL.md length
1,486 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Design spec with 98 rules for building CLI tools that AI agents can safely use.

  • Works in 3 steps: Output Mode → agent/ Directory Convention → Four Levels of Self-Description
  • Tasks that involve LLM guardrails
  • SKILL.md covers Overview, When to Use This Skill, Core Philosophy and Layer Model, plus 9 more sections
  • Calls jq

What it does

AI Native CLI is an agent skill from sickn33/agentic-awesome-skills. Design spec with 98 rules for building CLI tools that AI agents can safely use. Covers structured JSON output, error handling, input contracts, safety guardrails, exit codes, and agent self-description.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering LLM guardrails. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve LLM guardrails

Example prompts

  • “/ai-native-cli”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Output Mode
  2. agent/ Directory Convention
  3. Four Levels of Self-Description

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Native CLI loads about 3.3k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 1,486 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 1,486 words, ~3,280 tokens.

Download SKILL.mdSave it as .claude/skills/ai-native-cli/SKILL.md (or your agent's skills folder).
name
ai-native-cli
description
Design spec with 98 rules for building CLI tools that AI agents can safely use. Covers structured JSON output, error handling, input contracts, safety guardrails, exit codes, and agent self-description.
risk
safe
source
https://github.com/ChaosRealmsAI/agent-cli-spec
date_added
2026-03-15

Agent-Friendly CLI Spec v0.1

When building or modifying CLI tools, follow these rules to make them safe and reliable for AI agents to use.

Overview

A comprehensive design specification for building AI-native CLI tools. It defines 98 rules across three certification levels (Agent-Friendly, Agent-Ready, Agent-Native) with prioritized requirements (P0/P1/P2). The spec covers structured JSON output, error handling, input contracts, safety guardrails, exit codes, self-description, and a feedback loop via a built-in issue system.

When to Use This Skill

  • Use when building a new CLI tool that AI agents will invoke
  • Use when retrofitting an existing CLI to be agent-friendly
  • Use when designing command-line interfaces for automation pipelines
  • Use when auditing a CLI tool's compliance with agent-safety standards

Core Philosophy

  1. Agent-first -- default output is JSON; human-friendly is opt-in via --human
  2. Agent is untrusted -- validate all input at the same level as a public API
  3. Fail-Closed -- when validation logic itself errors, deny by default
  4. Verifiable -- every rule is written so it can be automatically checked

Layer Model

This spec uses two orthogonal axes:

  • Layer answers rollout scope: core, recommended, ecosystem
  • Priority answers severity: P0, P1, P2

Use layers for migration and certification:

  • core -- execution contract: JSON, errors, exit codes, stdout/stderr, safety
  • recommended -- better machine UX: self-description, explicit modes, richer schemas
  • ecosystem -- agent-native integration: agent/, skills, issue, inline context

Certification maps to layers:

  • Agent-Friendly -- all core rules pass
  • Agent-Ready -- all core + recommended rules pass
  • Agent-Native -- all layers pass

How It Works

Step 1: Output Mode

Default is agent mode (JSON). Explicit flags to switch:

bash
$ mycli list              # default = JSON output (agent mode)
$ mycli list --human      # human-friendly: colored, tables, formatted
$ mycli list --agent      # explicit agent mode (override config if needed)
  • Default (no flag) -- JSON to stdout. Agent never needs to add a flag.
  • --human -- human-friendly format (colors, tables, progress bars)
  • --agent -- explicit JSON mode (useful when env/config overrides default)
Step 2: agent/ Directory Convention

Every CLI tool MUST have an agent/ directory at its project root. This is the tool's identity and behavior contract for AI agents.

agent/
  brief.md          # One paragraph: who am I, what can I do
  rules/            # Behavior constraints (auto-registered)
    trigger.md      # When should an agent use this tool
    workflow.md     # Step-by-step usage flow
    writeback.md    # How to write feedback back
  skills/           # Extended capabilities (auto-registered)
    getting-started.md
Step 3: Four Levels of Self-Description
  1. --brief (business card, injected into agent config)
  2. Every Command Response (always-on context: data + rules + skills + issue)
  3. --help (full self-description: brief + commands + rules + skills + issue)
  4. skills <name> (on-demand deep dive into a specific skill)

Certification Requirements

Each level includes all rules from the previous level. Priority tag [P0]=agent breaks without it, [P1]=agent works but poorly, [P2]=nice to have.

Level 1: Agent-Friendly (core -- 20 rules)

Goal: CLI is a stable, callable API. Agent can invoke, parse, and handle errors.

Output -- default is JSON, stable schema

  • [P0] O1: Default output is JSON. No --json flag needed
  • [P0] O2: JSON MUST pass jq . validation
  • [P0] O3: JSON schema MUST NOT change within same version

Error -- structured, to stderr, never interactive

  • [P0] E1: Errors -> {"error":true, "code":"...", "message":"...", "suggestion":"..."} to stderr
  • [P0] E4: Error has machine-readable code (e.g. MISSING_REQUIRED)
  • [P0] E5: Error has human-readable message
  • [P0] E7: On error, NEVER enter interactive mode -- exit immediately
  • [P0] E8: Error codes are API contracts -- MUST NOT rename across versions

Exit Code -- predictable failure signals

  • [P0] X3: Parameter/usage errors MUST exit 2
  • [P0] X9: Failures MUST exit non-zero -- never exit 0 then report error in stdout

Composability -- clean pipe semantics

  • [P0] C1: stdout is for data ONLY
  • [P0] C2: logs, progress, warnings go to stderr ONLY

Input -- fail fast on bad input

  • [P1] I4: Missing required param -> structured error, never interactive prompt
  • [P1] I5: Type mismatch -> exit 2 + structured error

Safety -- protect against agent mistakes

  • [P1] S1: Destructive ops require --yes confirmation
  • [P1] S4: Reject ../../ path traversal, control chars

Guardrails -- runtime input protection

  • [P1] G1: Unknown flags rejected with exit 2
  • [P1] G2: Detect API key / token patterns in args, reject execution
  • [P1] G3: Reject sensitive file paths (*.env, *.key, *.pem)
  • [P1] G8: Reject shell metacharacters in arguments (; | && $())

Goal: CLI is self-describing, well-named, and pipe-friendly. Agent discovers capabilities and chains commands without trial and error.

Self-Description -- agent discovers what CLI can do

  • [P1] D1: --help outputs structured JSON with commands[]
  • [P1] D3: Schema has required fields (help, commands)
  • [P1] D4: All parameters have type declarations
  • [P1] D7: Parameters annotated as required/optional
  • [P1] D9: Every command has a description
  • [P1] D11: --help outputs JSON with help, rules, skills, commands
  • [P1] D15: --brief outputs agent/brief.md content
  • [P1] D16: Default JSON (agent mode), --human for human-friendly
  • [P2] D2/D5/D6/D8/D10: per-command help, enums, defaults, output schema, version

Input -- unambiguous calling convention

  • [P1] I1: All flags use --long-name format
  • [P1] I2: No positional argument ambiguity
  • [P2] I3/I6/I7: --json-input, boolean --no-X, array params

Error

  • [P1] E6: Error includes suggestion field
  • [P2] E2/E3: errors to stderr, error JSON valid

Safety

  • [P1] S8: --sanitize flag for external input
  • [P2] S2/S3/S5/S6/S7: default deny, --dry-run, no auto-update, destructive marking

Exit Code

  • [P1] X1: 0 = success
  • [P2] X2/X4-X8: 1=general, 10=auth, 11=permission, 20=not-found, 30=conflict

Composability

  • [P1] C6: No interactive prompts in pipe mode
  • [P2] C3/C4/C5/C7: pipe-friendly, --quiet, pipe chain, idempotency

Naming -- predictable flag conventions

  • [P1] N4: Reserved flags (--agent, --human, --brief, --help, --version, --yes, --dry-run, --quiet, --fields)
  • [P2] N1/N2/N3/N5/N6: consistent naming, kebab-case, max 3 levels, --version semver

Guardrails

  • [P1] I8/I9: no implicit state, non-interactive auth
  • [P1] G6/G9: precondition checks, fail-closed
  • [P2] G4/G5/G7: permission levels, PII redaction, batch limits
Reserved Flags
FlagSemanticsNotes
--agentJSON output (default)Explicit override
--humanHuman-friendly outputColors, tables, formatted
--briefOne-paragraph identityFor sync into agent config
--helpFull self-description JSONBrief + commands + rules + skills + issue
--versionSemver version string
--yesConfirm destructive opsRequired for delete/destroy
--dry-runPreview without executing
--quietSuppress stderr output
--fieldsFilter output fieldsSave tokens
Show full SKILL.md (583 more words)Show less
Level 3: Agent-Native (+ ecosystem -- 19 rules)

Goal: CLI has identity, behavior contract, skill system, and feedback loop. Agent can learn the tool, extend its use, and report problems -- full closed-loop collaboration.

Agent Directory -- tool identity and behavior contract

  • [P1] D12: agent/brief.md exists
  • [P1] D13: agent/rules/ has trigger.md, workflow.md, writeback.md
  • [P1] D17: agent/rules/*.md have YAML frontmatter (name, description)
  • [P1] D18: agent/skills/*.md have YAML frontmatter (name, description)
  • [P2] D14: agent/skills/ directory + skills subcommand

Response Structure -- inline context on every call

  • [P1] R1: Every response includes rules[] (full content from agent/rules/)
  • [P1] R2: Every response includes skills[] (name + description + command)
  • [P1] R3: Every response includes issue (feedback guide)

Meta -- project-level integration

  • [P2] M1: AGENTS.md at project root
  • [P2] M2: Optional MCP tool schema export
  • [P2] M3: CHANGELOG.md marks breaking changes

Feedback -- built-in issue system

  • [P2] F1: issue subcommand (create/list/show)
  • [P2] F2: Structured submission with version/context/exit_code
  • [P2] F3: Categories: bug / requirement / suggestion / bad-output
  • [P2] F4: Issues stored locally, no external service dependency
  • [P2] F5: issue list / issue show <id> queryable
  • [P2] F6: Issues have status tracking (open/in-progress/resolved/closed)
  • [P2] F7: Issue JSON has all required fields (id, type, status, message, created_at, updated_at)
  • [P2] F8: All issues have status field

Examples

Example 1: JSON Output (Agent Mode)
bash
$ mycli list
{"result": [{"id": 1, "title": "Buy milk", "status": "todo"}], "rules": [...], "skills": [...], "issue": "..."}
Example 2: Structured Error
json
{
  "error": true,
  "code": "AUTH_EXPIRED",
  "message": "Access token expired 2 hours ago",
  "suggestion": "Run 'mycli auth refresh' to get a new token"
}
Example 3: Exit Code Table
0   success         10  auth failed       20  resource not found
1   general error   11  permission denied 30  conflict/precondition
2   param/usage error

Quick Implementation Checklist

Implement by layer -- each phase gets you the next certification level.

Phase 1: Agent-Friendly (core)

  1. Default output is JSON -- no --json flag needed
  2. Error handler: { error, code, message, suggestion } to stderr
  3. Exit codes: 0 success, 2 param error, 1 general
  4. stdout = data only, stderr = logs only
  5. Missing param -> structured error (never interactive)
  6. --yes guard on destructive operations
  7. Guardrails: reject secrets, path traversal, shell metacharacters

Phase 2: Agent-Ready (+ recommended) 8. --help returns structured JSON (help, commands[], rules[], skills[]) 9. --brief reads and outputs agent/brief.md content 10. --human flag switches to human-friendly format 11. Reserved flags: --agent, --version, --dry-run, --quiet, --fields 12. Exit codes: 20 not found, 30 conflict, 10 auth, 11 permission

Phase 3: Agent-Native (+ ecosystem) 13. Create agent/ directory: brief.md, rules/trigger.md, rules/workflow.md, rules/writeback.md 14. Every command response appends: rules[] + skills[] + issue 15. skills subcommand: list all / show one with full content 16. issue subcommand for feedback (create/list/show/close/transition) 17. AGENTS.md at project root

Best Practices

  • Do: Default to JSON output so agents never need to add flags
  • Do: Include suggestion field in every error response
  • Do: Use the three-level certification model for incremental adoption
  • Do: Keep agent/brief.md to one paragraph for token efficiency
  • Don't: Enter interactive mode on errors -- always exit immediately
  • Don't: Change JSON schema or error codes within the same version
  • Don't: Put logs or progress info on stdout -- use stderr only
  • Don't: Accept unknown flags silently -- reject with exit code 2

Common Pitfalls

  • Problem: CLI outputs human-readable text by default, breaking agent parsing Solution: Make JSON the default output format; add --human flag for human-friendly mode

  • Problem: Errors reported in stdout with exit code 0 Solution: Always exit non-zero on failure and write structured error JSON to stderr

  • Problem: CLI prompts for missing input interactively Solution: Return structured error with suggestion field and exit immediately

  • @cli-best-practices - General CLI design patterns (this skill focuses specifically on AI agent compatibility)

Additional Resources

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ai-native-cli of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 2 other repositories

We found 11 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

AI Native CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Native CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Native CLI this skillsickn33/agentic-awesome-skills47k2 repos~3.3kAutomated safety check: PassMIT
Implementation Kickoffopenai/openai-guardrails-js104—~1kAutomated safety check: PassMIT
Manor Coding Guardrailsmanor-os/manor-ai161—~816Automated safety check: PassMIT
Git Guardrails Claude Codefossasia/eventyay-interpretation1.6k12 repos~578Automated safety check: PassApache-2.0
Git Guardrails Claude Codevinvcn/mattpocock-skills-zh-CN4.6k—~474Automated safety check: PassMIT
Wa Guardrailsaws-samples/sample-well-architected-skills-and-steering273—~2.8kAutomated safety check: PassMIT-0

Similar skills

  • Implementation Kickoff

    openai/openai-guardrails-js

    Official

    Start or resume a requested Guardrails implementation or PR takeover in the selected linked worktree with bounded scope and verification.

    104 GitHub stars~1k tokensUpdated 9 days ago
    AI & LLM EngineeringAuto-check passed
  • Manor Coding Guardrails

    manor-os/manor-ai

    A skill your agent uses when writing, reviewing, or refactoring Manor code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.

    161 GitHub stars~816 tokensUpdated 29 days ago
    AI & LLM EngineeringAuto-check passed
  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 12 repos~578 tokens
    AI & LLM EngineeringAuto-check passed
  • Git Guardrails Claude Code

    vinvcn/mattpocock-skills-zh-CN

    设置 Claude Code hooks,在危险 git commands(push、reset --hard、clean、branch -D 等)执行前阻止它们。适用于用户想防止破坏性 git 操作、添加 git safety hooks,或在 Claude Code 中阻止 git push/reset 时。

    4.6k GitHub stars~474 tokensUpdated 9 days ago
    AI & LLM EngineeringAuto-check passed
  • Wa Guardrails

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…

    273 GitHub stars~2.8k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Formax Skill Capture

    yusifeng/formax

    A skill your agent uses when we want to turn a just-finished Formax workflow (e.g.

    195 GitHub stars~530 tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about AI Native CLI

What does AI Native CLI do?

Design spec with 98 rules for building CLI tools that AI agents can safely use. AI Native CLI is an agent skill from sickn33/agentic-awesome-skills. Design spec with 98 rules for building CLI tools that AI agents can safely use.

When should I use AI Native CLI?

AI Native CLI fits situations like: tasks that involve LLM guardrails.

How do I install AI Native CLI in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill ai-native-cli -a claude-code`. Or copy the skill folder (skills/ai-native-cli in sickn33/agentic-awesome-skills) into .claude/skills/ai-native-cli in your project. Claude Code loads it when a task matches its description.

How do I install AI Native CLI in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill ai-native-cli -a codex`. Or copy the skill folder (skills/ai-native-cli in sickn33/agentic-awesome-skills) into .agents/skills/ai-native-cli in your project. Codex loads it when a task matches its description.

Can I use AI Native CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill ai-native-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-native-cli, .gemini/skills/ai-native-cli, .github/skills/ai-native-cli and .opencode/skills/ai-native-cli in your project.

What does AI Native CLI need to run?

Going by SKILL.md and its folder, AI Native CLI needs the command-line tools its instructions call (jq).

Does AI Native CLI access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is AI Native CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Native CLI use?

AI Native CLI is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Native CLI use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Native CLI?

Skills that share tags, products or a category with AI Native CLI: Implementation Kickoff (openai/openai-guardrails-js, 104 stars), Manor Coding Guardrails (manor-os/manor-ai, 161 stars), Git Guardrails Claude Code (fossasia/eventyay-interpretation, 1.6k stars) and Git Guardrails Claude Code (vinvcn/mattpocock-skills-zh-CN, 4.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Native CLI?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.