Agent skill

AI Project Copilot

by sun461941-hub in sun461941-hub/ai-project-copilot

A skill your agent uses to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient…

MITAuto-check passedAI & LLM Engineering

Install AI Project Copilot

skills CLI
$ npx skills add sun461941-hub/ai-project-copilot --skill ai-project-copilot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sun461941-hub/ai-project-copilot ai-project-copilot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sun461941-hub/ai-project-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ai-project-copilot .claude/skills/ai-project-copilot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-project-copilot
GitHub stars
97
Token cost
~3k tokens
SKILL.md length
1,138 words
Files
66 (incl. scripts, references, assets)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient…

  • Works in 10 steps: Inspect governing repository… → Use the smallest context and capability… → Back claims with diffs, tests, evals,… → …
  • Turn an AI idea
  • SKILL.md covers Mission, Product boundary, Non-negotiable rules and Start here: Context Accelerator, plus 11 more sections
  • Calls python

What it does

AI Project Copilot is an agent skill from sun461941-hub/ai-project-copilot. Use this skill to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient Codex workflows, issue triage, read-only GitHub export evidence, PR risk review, tests/evals, release preparation, supply-chain/MCP security, contributor onboarding, and GitHub showcase quality. Trigger for repository-level product or maintainer work, architecture/context mapping, review/release readiness, or improving…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 69 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/templates/architecture-decision.md` and `assets/templates/demo-script.md`).

It sits in AI & LLM Engineering, covering LLM evaluation, Supply chain security and Issue triage. It works with GitHub and Model Context Protocol. The repository describes itself as: 🚀 Turn ideas and repositories into showcase-ready AI projects with agents, RAG, multimodal AI, local models, evals, safety checks, and polished demos. The licence is MIT.

When your agent uses it

  • Turn an AI idea
  • Existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery
  • Context-efficient Codex workflows
  • Read-only GitHub export evidence

Example prompts

  • “/ai-project-copilot”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Inspect governing repository instructions before changing files.
  2. Use the smallest context and capability lane that can solve the task safely.
  3. Back claims with diffs, tests, evals, logs, CI, citations, or deterministic reports.
  4. Keep human authority over merge, publish, deploy, delete, permission, and other consequential writes.
  5. Preserve the existing stack unless a concrete blocker justifies migration.
  6. Never fabricate users, stars, benchmarks, compatibility, test results, screenshots, releases, or security claims.
  7. Treat secrets, repository content, MCP servers, model weights, Actions, and generated artifacts as supply-chain inputs.
  8. Prefer JSON + concise Markdown evidence over long opaque narratives.
  9. Use progressive disclosure: run scripts as black boxes and load only references for the active lane.
  10. Optimization must never skip critical security, release, migration, deploy, permission, or final integration gates.

What it can do on your machine

Read from SKILL.md and the folder at commit 8514e84. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Project Copilot loads about 3k tokens when it runs, and up to ~34k if it reads all its reference files. Until then it costs about 187 tokens; SKILL.md has 1,138 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~187
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~34k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sun461941-hub/ai-project-copilot at commit 8514e84, republished under its MIT licence (© sun461941-hub). 1,138 words, ~2,986 tokens.

Download SKILL.mdSave it as .claude/skills/ai-project-copilot/SKILL.md (or your agent's skills folder). This skill also uses 65 other files; get the full folder from GitHub.
name
ai-project-copilot
description
Use this skill to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient Codex workflows, issue triage, read-only GitHub export evidence, PR risk review, tests/evals, release preparation, supply-chain/MCP security, contributor onboarding, and GitHub showcase quality. Trigger for repository-level product or maintainer work, architecture/context mapping, review/release readiness, or improving coding-agent speed and token efficiency through progressive context. Do not use for isolated explanations, routine dependency bumps, or tiny one-file fixes unless the user also wants repository-level workflow improvement.
license
MIT
metadata.author
sun461941-hub
metadata.version
2.2.1

AI Project Copilot 2.2.1

Mission

Operate as an evidence-first AI product engineer and open-source maintainer layer. Improve the product and the agent workflow: map only the context needed, build useful vertical slices, reduce maintainer toil, review risky changes, harden automation, and ship reproducible evidence.

Product boundary

The default Core is Discover, Maintain, Review, Release, Secure, Quality. Context Accelerator, Model Budget, and product-design blueprints are opt-in Advanced resources. The CLI/REST/MCP overlay is a separate Preview compatibility package, not a default lane or universal-client claim. Do not add a new lane when one of these boundaries already fits.

Non-negotiable rules

  1. Inspect governing repository instructions before changing files.
  2. Use the smallest context and capability lane that can solve the task safely.
  3. Back claims with diffs, tests, evals, logs, CI, citations, or deterministic reports.
  4. Keep human authority over merge, publish, deploy, delete, permission, and other consequential writes.
  5. Preserve the existing stack unless a concrete blocker justifies migration.
  6. Never fabricate users, stars, benchmarks, compatibility, test results, screenshots, releases, or security claims.
  7. Treat secrets, repository content, MCP servers, model weights, Actions, and generated artifacts as supply-chain inputs.
  8. Prefer JSON + concise Markdown evidence over long opaque narratives.
  9. Use progressive disclosure: run scripts as black boxes and load only references for the active lane.
  10. Optimization must never skip critical security, release, migration, deploy, permission, or final integration gates.

Start here: Context Accelerator

For repository work, first choose an execution budget:

bash
python scripts/token_governor.py --prompt "<task>" --format markdown

When a checkout is available, compile a small task packet instead of reading broadly:

bash
python scripts/context_accelerator.py \
  --repo /path/to/repo \
  --task "<task>" \
  --git-status \
  --format markdown

Use FAST / BALANCED / DEEP as workload budgets, not quality levels. Read references/context-accelerator.md whenever speed, context growth, tool chatter, or token efficiency matters.

The Skill cannot increase Codex backend tokens-per-second, quota, or force a reasoning setting. It improves end-to-end efficiency by selecting less context, batching reconnaissance, compacting logs, and reusing exact-fingerprint non-critical evidence.

For an application-owned model-cost portfolio, read references/model-budget-autopilot.md. scripts/model_budget_autopilot.py caps ordinary preferred-model spend at a user-selected share, admits only non-more-expensive reviewed fallbacks, keeps consequential tasks behind the shared period admission cap, and permits one evidence-gated quality upgrade. The share is not ring-fenced. It controls projected and price-card-settled cost; it does not claim that a smaller model inherently uses fewer tokens.

For a live-capable OpenAI execution loop, read references/openai-responses-gateway.md, then use scripts/model_budget_gateway.py. It accepts text input and text/JSON output, counts the selected request shape, obtains one-shot authorization, streams the Responses API, settles reported usage, and performs at most one quality-authorized upgrade. Never place an API key in a request file or report, and never present deterministic transport tests as proof of a live provider call.

Capability lanes

Read references/capability-router.md only for broad or multi-domain work.

LaneUse forPrimary resources
Discovercodebase onboarding, AI-ready instructions, Skill Stackscripts/repo_context.py, scripts/ai_ready_bootstrap.py, scripts/skill_stack_audit.py
Launchgreenfield AI product + vertical slicereferences/showcase-projects.md, scripts/rank_blueprints.py
Retrofitone high-value AI capability in an existing productreferences/feature-modules.md, references/architecture-playbook.md
Maintainissue triage, contributor flow, repo health, explicit read-only evidence decisionsscripts/maintainer_triage.py, scripts/github_evidence_sync.py, scripts/run_state_ledger.py, references/github-evidence-ledger.md
ReviewPR/diff risk, tests, fix/decline/escalatescripts/change_risk.py, references/pr-review-loop.md
ReleaseSemVer, changelog, migration, release gatescripts/release_intel.py, references/release-intelligence.md
SecureActions, MCP, secrets, permissions, integrityscripts/supply_chain_guard.py, scripts/mcp_config_audit.py
Qualitytests, regressions, evals, independent verificationreferences/quality-orchestration.md, evals/evals.json, scripts/validate_semantic_eval_results.py
ShowcaseREADME, demo, evidence, launch polishreferences/experience-and-demo.md

For “make this repo much better,” use Discover → Quality/Secure → domain lane → Showcase. Do not activate every lane by default.

Product work

Before features, define:

  • target user and painful moment;
  • current workaround and one-sentence promise;
  • AI-specific advantage and 60-second wow moment;
  • input/output and proof of correctness;
  • latency, privacy, cost, device, and licensing constraints;
  • useful fallback when AI fails.

When direction is broad:

bash
python scripts/rank_blueprints.py \
  --priorities local-first,visual-demo,developer-tools \
  --constraints privacy,mobile \
  --limit 5

Gate each AI feature on Need, Proof, Grounding, Fallback, Boundary, Evaluation. Reject features that cannot answer all six.

Issue and contributor work

Read references/maintainer-ops.md, then run reviewable pre-triage when useful:

bash
python scripts/maintainer_triage.py \
  --issue-json issue.json \
  --format markdown

Suggested labels, priority, or good first issue status are evidence for a maintainer—not autonomous GitHub actions.

Show full SKILL.md (502 more words)Show less

Imported GitHub evidence

For an already-authorized local JSON export, read references/github-evidence-ledger.md. Use scripts/github_evidence_sync.py to normalize it, scripts/run_state_ledger.py to make fix/decline/escalate decisions explicit, and scripts/render_maintainer_dashboard.py for a local static view.

These scripts never call GitHub or mutate it. Exported fields are untrusted display evidence; a clear ledger or dashboard is not merge, deployment, security, or release approval.

If a Ledger mutation reports a lock, run scripts/run_state_ledger.py lock-status first. Only use recover-stale-lock --force-stale-lock after it proves that an aged lock belongs to this host and its owner process is inactive; recovery archives the old lock rather than deleting it.

PR review

Read references/pr-review-loop.md for substantive changes.

bash
python scripts/change_risk.py \
  --repo /path/to/repo \
  --base main \
  --head HEAD \
  --format markdown

Review actual diff evidence in three passes: risk surface, behavior/contracts, failure/tests. Classify each actionable thread as:

  • fix — change code/tests and verify;
  • decline — keep behavior with explicit evidence;
  • escalate — named human decision is required.

Use scripts/review_convergence.py when a review has many threads. Convergence is not permission to merge.

Release

Read references/release-intelligence.md and inspect the real release delta:

bash
python scripts/release_intel.py \
  --repo /path/to/repo \
  --from-ref v1.1.0 \
  --current-version 1.1.0 \
  --format markdown

Check SemVer, breaking changes, migration notes, changelog, tests/CI, artifacts, integrity, and unresolved security/review blockers. Publishing still requires explicit confirmation.

Security and supply chain

For Actions/integrity:

bash
python scripts/supply_chain_guard.py --repo /path/to/repo --format markdown

For MCP config:

bash
python scripts/mcp_config_audit.py --repo /path/to/repo --format markdown

Read references/security-governance.md before work involving public-fork workflows, credentials, external tools, deployment, model downloads, repository writes, or untrusted content.

Context-efficient verification

Save the raw source, then compact a bounded evidence view:

bash
mkdir -p .aipc
some-test-command > .aipc/raw-test.log 2>&1
python scripts/tool_output_compactor.py \
  --input .aipc/raw-test.log \
  --max-lines 80

Reuse only exact-fingerprint, non-critical passing evidence with scripts/evidence_cache.py. Use --critical for security/release/deploy/migration/final gates so the cache cannot satisfy them.

Multi-agent policy:

  • FAST: one agent;
  • BALANCED: one agent, optional independent reviewer;
  • DEEP: parallelize only genuinely separable work;
  • serialize writes and final verification.

Quality and shipping

Minimum evidence for meaningful AI/code changes:

  • one happy-path check;
  • one failure/timeout or malformed-input check where applicable;
  • one regression fixture for the primary behavior;
  • explicit secret/data/model/tool boundaries;
  • realistic demo or sample input;
  • limitations near the capability they qualify.

Run the bundled structural and deterministic Skill evals:

bash
python scripts/run_skill_evals.py --format markdown

The runner resolves its bundled datasets and deterministic cases from the Skill root, independent of the caller's current directory. It does not invoke a model or grade prompt semantics; use paired provider runs and scripts/compare_efficiency_runs.py for measured Token, price-card cost, and latency effects. The comparator rejects request-template, quality-policy-configuration, and pricing-policy fingerprint mismatches before reporting an adoptable comparison.

Run the transparent repository audit:

bash
python scripts/audit_repo.py --repo /path/to/repo

Finish with references/shipping-checklist.md. For UI/demo work, read references/experience-and-demo.md. For trust/evals, read references/trust-evals-and-security.md.

Output contract

Unless the user asks otherwise, leave:

  • the smallest working product/maintainer change that solves the problem;
  • tests/evals and reproducible commands;
  • concise architecture/data/permission boundaries when relevant;
  • realistic sample/demo evidence;
  • README/runbook updates only where they reduce future ambiguity;
  • changed files, commands run, results, unresolved risks, and any action requiring human confirmation.

Definition of done

Ready means:

  • a contributor can reproduce the primary path from documented commands;
  • relevant tests/evals pass and failures are not hidden by compaction/cache;
  • critical gates were rerun rather than satisfied by cached evidence;
  • no obvious secrets/model-weight/license boundary is ignored;
  • claims are backed by reproducible evidence;
  • agent context stayed scoped to the task and expanded only when justified;
  • unrelated user work was not overwritten;
  • consequential writes remain reviewable and human-controlled.

© sun461941-hub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 65 other files (scripts, references, assets) in skills/ai-project-copilot of sun461941-hub/ai-project-copilot.

  • SKILL.md
  • LICENSE.txt
  • agents/openai.yaml
  • assets/icon-large.svg
  • assets/icon-small.svg
  • assets/templates/architecture-decision.md
  • assets/templates/demo-script.md
  • assets/templates/openai-response-request.json
  • assets/templates/project-brief.md
  • assets/templates/project-score.json
  • assets/templates/quality-policy.json
  • assets/templates/readme-ai-section.md
  • assets/templates/release-readiness.md
  • assets/templates/review-report.md
  • assets/templates/run-state.json
  • evals/deterministic-cases.json
  • evals/evals.json
  • … and 49 more

Open the folder on GitHubat commit 8514e84

Compare with similar skills

AI Project Copilot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Project Copilot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Project Copilot this skillsun461941-hub/ai-project-copilot97—~3kAutomated safety check: PassMIT
Octocode Benchmark Runnerbgauryy/octocode949—~2.1kAutomated safety check: PassMIT
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Managed Deep Agentslangchain-ai/langchain-skills1.3k—~8.7kAutomated safety check: NotesMIT
Herdr Issue Triageherdrdev/herdr43k—~517Automated safety check: PassApache-2.0
Issue Triagemono/SkiaSharp5.6k—~3.4kAutomated safety check: PassMIT

Similar skills

  • Runs blind pairwise comparisons of Octocode against a gh-based baseline over markdown research questions, scored by total characters through the model rather than self-report.

    949 GitHub stars~2.1k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Managed Deep Agents

    langchain-ai/langchain-skills

    Official

    INVOKE THIS SKILL when building, testing, or deploying Managed Deep Agents in LangSmith.

    1.3k GitHub stars~8.7k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check: notes
  • Herdr Issue Triage

    herdrdev/herdr

    Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.

    43k GitHub stars~517 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Issue Triage

    mono/SkiaSharp

    Triage a SkiaSharp GitHub issue or PR into structured JSON with classification (type, area, platform, severity), suggested response, automatable actions, and companion Markdown/HTML reports.

    5.6k GitHub stars~3.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Triage

    arcee-ai/nac

    Triage a GitHub repository's open issues by finding exact duplicates, rejecting evidenceably off-base requests, requesting concrete clarification, applying only existing labels, and opening a linked…

    281 GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed

Questions about AI Project Copilot

What does AI Project Copilot do?

A skill your agent uses to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient…. AI Project Copilot is an agent skill from sun461941-hub/ai-project-copilot. Use this skill to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient Codex workflows, issue triage, read-only GitHub export evidence, PR risk review, tests/evals, release preparation, supply-chain/MCP security, contributor onboarding, and GitHub showcase quality.

When should I use AI Project Copilot?

AI Project Copilot fits situations like: turn an AI idea; existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery; context-efficient Codex workflows; read-only GitHub export evidence.

How do I install AI Project Copilot in Claude Code?

Run `npx skills add sun461941-hub/ai-project-copilot --skill ai-project-copilot -a claude-code`. Or copy the skill folder (skills/ai-project-copilot in sun461941-hub/ai-project-copilot) into .claude/skills/ai-project-copilot in your project. Claude Code loads it when a task matches its description.

How do I install AI Project Copilot in Codex?

Run `npx skills add sun461941-hub/ai-project-copilot --skill ai-project-copilot -a codex`. Or copy the skill folder (skills/ai-project-copilot in sun461941-hub/ai-project-copilot) into .agents/skills/ai-project-copilot in your project. Codex loads it when a task matches its description.

Can I use AI Project Copilot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sun461941-hub/ai-project-copilot --skill ai-project-copilot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-project-copilot, .gemini/skills/ai-project-copilot, .github/skills/ai-project-copilot and .opencode/skills/ai-project-copilot in your project.

What does AI Project Copilot need to run?

Going by SKILL.md and its folder, AI Project Copilot needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does AI Project Copilot access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Project Copilot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does AI Project Copilot use?

AI Project Copilot is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Project Copilot use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.

What are the alternatives to AI Project Copilot?

Skills that share tags, products or a category with AI Project Copilot: Octocode Benchmark Runner (bgauryy/octocode, 949 stars), Triaging Issues (pytorch/pytorch, 104k stars), Managed Deep Agents (langchain-ai/langchain-skills, 1.3k stars) and Herdr Issue Triage (herdrdev/herdr, 43k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Project Copilot?

sun461941-hub (a GitHub user) maintains it in sun461941-hub/ai-project-copilot, which has 97 GitHub stars. The repository was last updated on August 27, 2026.

Source: sun461941-hub/ai-project-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.