{"_id":"@anyberg/agent-conventions","_rev":"6-d2c73bbe89663e81f8980efbce7613d8","name":"@anyberg/agent-conventions","dist-tags":{"latest":"1.3.0"},"versions":{"1.1.0":{"name":"@anyberg/agent-conventions","version":"1.1.0","keywords":["agent-skills","claude-code","codex","copilot","opencode","cursor","conventions"],"author":{"name":"Alexander Nyberg"},"license":"MIT","_id":"@anyberg/agent-conventions@1.1.0","maintainers":[{"name":"anyberg","email":"alexandernyberg@me.com"}],"homepage":"https://github.com/aanyberg/agent-conventions#readme","bugs":{"url":"https://github.com/aanyberg/agent-conventions/issues"},"bin":{"agent-conventions":"bin/cli.js"},"dist":{"shasum":"9136f8485aeeb24b5b25e5eea53197f6fc748434","tarball":"https://registry.npmjs.org/@anyberg/agent-conventions/-/agent-conventions-1.1.0.tgz","fileCount":40,"integrity":"sha512-1ALu5Ty43wtoAHN2yEzOanjeZikI/mwLop2TkU6gZ/PucRUMT6GchivHWIPjxwf2er3JMdzh/hl71Qgw5u3TJg==","signatures":[{"sig":"MEYCIQD2I5lJN4pIA2jnsOxafSw3SIb1N9mVO/DdWqvIf1zHlgIhAPXWEQKvMXJRQR2DsXivlX2loDEFQKfAXwovVc4bbOrF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":162171},"type":"module","engines":{"node":">=18.17"},"gitHead":"aae2a8d501230cdf23302eac86a6800128cce327","scripts":{"test":"node --test tests-js/","pretest":"node scripts/ensure-shellcheck.mjs"},"_npmUser":{"name":"anyberg","email":"alexandernyberg@me.com"},"repository":{"url":"git+https://github.com/aanyberg/agent-conventions.git","type":"git"},"_npmVersion":"11.19.0","description":"Skills and agents for backlog management, git conventions, code standards, and planning workflows — installable into Claude Code, Codex, GitHub Copilot, OpenCode, Cursor and Gemini CLI.","directories":{},"_nodeVersion":"26.8.1","_hasShrinkwrap":false,"devDependencies":{"yaml":"2.9.0","smol-toml":"1.8.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-conventions_1.1.0_1789068608896_0.6881700553020784","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@anyberg/agent-conventions","version":"1.1.1","keywords":["agent-skills","claude-code","codex","copilot","opencode","cursor","conventions"],"author":{"name":"Alexander Nyberg"},"license":"MIT","_id":"@anyberg/agent-conventions@1.1.1","maintainers":[{"name":"anyberg","email":"alexandernyberg@me.com"}],"homepage":"https://github.com/aanyberg/agent-conventions#readme","bugs":{"url":"https://github.com/aanyberg/agent-conventions/issues"},"bin":{"agent-conventions":"bin/cli.js"},"dist":{"shasum":"888f6f847c34e00e3db12631fc031e0b4ce62e17","tarball":"https://registry.npmjs.org/@anyberg/agent-conventions/-/agent-conventions-1.1.1.tgz","fileCount":40,"integrity":"sha512-NpYJzVPNGj6j0ZouvxdBbNkkUCau8vrARz85nR+ZEa+0DQwa4lr1mL1XI7c7VZBy7yWyocqolEUvWSgJFw+xVw==","signatures":[{"sig":"MEUCIGTaOB0vl7lwRwZJKOdrfQ/qDwrUJZKWgaeqYFS4xFlnAiEAywF5YY6jDxEL1VAzEQyjCWC31Mbne5rUzlsfilQB708=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":167666},"type":"module","engines":{"node":">=18.17"},"gitHead":"20e37d7bafa5c46e5b67395d83fff027e2ccba43","scripts":{"test":"node --test tests-js/","pretest":"node scripts/ensure-shellcheck.mjs"},"_npmUser":{"name":"anyberg","email":"alexandernyberg@me.com"},"repository":{"url":"git+https://github.com/aanyberg/agent-conventions.git","type":"git"},"_npmVersion":"11.19.0","description":"Skills and agents for backlog management, git conventions, code standards, and planning workflows — installable into Claude Code, Codex, GitHub Copilot, OpenCode, Cursor and Gemini CLI.","directories":{},"_nodeVersion":"26.8.1","_hasShrinkwrap":false,"devDependencies":{"yaml":"2.9.0","smol-toml":"1.8.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-conventions_1.1.1_1789074165938_0.7221467946881854","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@anyberg/agent-conventions","version":"1.2.0","keywords":["agent-skills","claude-code","codex","copilot","opencode","cursor","conventions"],"author":{"name":"Alexander Nyberg"},"license":"MIT","_id":"@anyberg/agent-conventions@1.2.0","maintainers":[{"name":"anyberg","email":"alexandernyberg@me.com"}],"homepage":"https://github.com/aanyberg/agent-conventions#readme","bugs":{"url":"https://github.com/aanyberg/agent-conventions/issues"},"bin":{"agent-conventions":"bin/cli.js"},"dist":{"shasum":"e45af981f37e7090acc3febcd541b4bc5c3bd4eb","tarball":"https://registry.npmjs.org/@anyberg/agent-conventions/-/agent-conventions-1.2.0.tgz","fileCount":40,"integrity":"sha512-4bZUJ1N0tGvInDnZ+AVAGE634ZLD9y+Jgqww+AvxzrqGhy8pDp4KU/fjQSIJG3rd/BmnoMsCoUbZZBoKk/mqvw==","signatures":[{"sig":"MEUCICqWav/5B1pqV8bDshyXH2ZVCn/L5AGIdo1XQAzmKakgAiEAojOqB7RLpDztxm48FsmTEQhXsFwvJKDSyKFLuzmxXxw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":177336},"type":"module","engines":{"node":">=18.17"},"gitHead":"c2cf3a8009fe3206ef2b31857a0a4e3daacd1164","scripts":{"test":"node --test tests-js/","pretest":"node scripts/ensure-shellcheck.mjs"},"_npmUser":{"name":"anyberg","email":"alexandernyberg@me.com","approver":{"name":"anyberg","email":"alexandernyberg@me.com"}},"repository":{"url":"git+https://github.com/aanyberg/agent-conventions.git","type":"git"},"_npmVersion":"11.19.1","description":"Skills and agents for backlog management, git conventions, code standards, and planning workflows — installable into Claude Code, Codex, GitHub Copilot, OpenCode, Cursor and Gemini CLI.","directories":{},"_nodeVersion":"26.8.2","_hasShrinkwrap":false,"devDependencies":{"yaml":"2.9.0","smol-toml":"1.8.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-conventions_1.2.0_1789228748238_0.5406648830660541","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"_id":"@anyberg/agent-conventions@1.3.0","bin":{"agent-conventions":"bin/cli.js"},"bugs":{"url":"https://github.com/aanyberg/agent-conventions/issues"},"dist":{"shasum":"c27432489b27629f075d869d1e1a110d9cde90e4","tarball":"https://registry.npmjs.org/@anyberg/agent-conventions/-/agent-conventions-1.3.0.tgz","integrity":"sha512-vH/CxDfaTJXOKtL8Fje0XcO4MuiZsQ38YTH+XnfBXybRJirOpIbgWyzNQvD1rap1Ux8fgxAEo4tR3N2DGSzOag==","fileCount":38,"unpackedSize":173328,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anyberg%2fagent-conventions@1.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICxIoloobZsxZ3TuQ09s0XbOk/Y/xtn4BzIsryBsLk2eAiBdkVfvGm8s4mAyYwC8uGdUmEeNxmEVISnTpTQ/zL5BxA=="}]},"name":"@anyberg/agent-conventions","type":"module","author":{"name":"Alexander Nyberg"},"engines":{"node":">=18.17"},"gitHead":"7de340049a46b4db0f788397ffa6d8dfa74bea37","license":"MIT","scripts":{"test":"node --test tests-js/"},"version":"1.3.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b4f870f7-9fe8-457b-80a4-5d0e7f69b507"},"approver":{"name":"anyberg","email":"alexandernyberg@me.com"}},"homepage":"https://github.com/aanyberg/agent-conventions#readme","keywords":["agent-skills","claude-code","codex","copilot","opencode","cursor","conventions"],"repository":{"url":"git+https://github.com/aanyberg/agent-conventions.git","type":"git"},"_npmVersion":"11.19.1","description":"Skills and agents for backlog management, git conventions, code standards, and planning workflows — installable into Claude Code, Codex, GitHub Copilot, OpenCode, Cursor and Gemini CLI.","directories":{},"maintainers":[{"name":"anyberg","email":"alexandernyberg@me.com"}],"_nodeVersion":"20.20.2","devDependencies":{"yaml":"2.9.0","smol-toml":"1.8.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-conventions_1.3.0_1789565640173_0.34255181876388097"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-09T18:50:53.206Z","modified":"2026-09-16T13:34:00.667Z","1.0.0":"2026-09-09T18:50:53.581Z","1.1.0":"2026-09-10T19:30:09.034Z","1.1.1":"2026-09-10T21:02:46.083Z","1.2.0":"2026-09-12T15:59:08.309Z","1.3.0":"2026-09-16T13:34:00.279Z"},"bugs":{"url":"https://github.com/aanyberg/agent-conventions/issues"},"author":{"name":"Alexander Nyberg"},"license":"MIT","homepage":"https://github.com/aanyberg/agent-conventions#readme","keywords":["agent-skills","claude-code","codex","copilot","opencode","cursor","conventions"],"repository":{"url":"git+https://github.com/aanyberg/agent-conventions.git","type":"git"},"description":"Skills and agents for backlog management, git conventions, code standards, and planning workflows — installable into Claude Code, Codex, GitHub Copilot, OpenCode, Cursor and Gemini CLI.","maintainers":[{"name":"anyberg","email":"alexandernyberg@me.com"}],"readme":"# agent-conventions\n\nA collection of specialized agents, skills, and development guidelines for AI coding assistants.\n\nThis repository contains:\n\n- **`skills/` and `agent-sources/`** — Skills follow the Agent Skills\n  specification. Agent sources remain outside provider auto-discovery; the\n  installer renders them into each provider's native format and directory.\n  - **Agents** — Six specialized roles for planning, implementation, review,\n    documentation synchronization, repository research, and verification\n  - **Skills** — Focused knowledge modules covering code standards, best practices, and workflows across Python, TypeScript, and general development\n- **Instructions** — A single `AGENTS.md` file with project-level guidance that works across all supported tools\n\nThese components enhance AI coding assistants by providing domain knowledge, coding conventions, and structured workflows.\n\n## Repository-native by default\n\nInstalling the package does not opt a repository into a particular planning or\ngovernance process. Skills follow the repository's existing contributor\ninstructions, tooling, issue tracker, documentation layout, and Git history.\nThey do not create policy files, planning hierarchies, backlogs, or ADR systems\nmerely because they are installed.\n\nWhen a backlog operation is requested, `backlog-management` honors an explicit\nchoice, then checks repository instructions and existing tracker structure. If\nthat evidence does not identify exactly one backend, it asks whether to use\nGitHub Issues, `BACKLOG.md`, or no persistent backlog. The answer is\nconversation-scoped unless the user chooses to document it in an existing\nrepository instruction file.\n\nStructured task files and architecture records are similarly used only when\nalready established or explicitly requested. The GitHub Issues and Markdown\nbackend documents remain reusable adapters rather than a mandatory operating\nmodel.\n\n## Installation\n\n### Everything, one command\n\n```bash\n# this machine, every project — skills, agents, and global instructions\nnpx github:aanyberg/agent-conventions -g\n\n# preview without writing anything\nnpx github:aanyberg/agent-conventions -g --dry-run\n```\n\nOnce the package is on npm the shorter `npx @anyberg/agent-conventions@latest` works identically.\n\n> **Note the spelling.** The npm scope is `@anyberg` (one `a`); the GitHub org and the Claude marketplace are `aanyberg` (two). They are separate namespaces and the handles differ — `github:aanyberg/…` and `conventions@aanyberg` are correct as written. The `github:` form needs nothing published and accepts any ref — `github:aanyberg/agent-conventions#1.1.0` pins a release.\n\nRun bare, it asks for scope and agents, prints every path it will touch, and defaults to **no**. `-y` skips the prompt but still prints the plan. Nothing global is written without the paths appearing on screen first.\n\nIt writes a receipt, so `uninstall` removes exactly what was installed and nothing else:\n\n```bash\nnpx github:aanyberg/agent-conventions uninstall -g\n```\n\n**Existing files are never clobbered.** Global instructions are appended inside `<!-- BEGIN/END -->` markers, so your own content survives an install and is restored byte-for-byte by an uninstall. If an instruction path, skills root, or generated-agent directory is itself a **symlink**, the installer refuses it rather than writing through the link. Other selected providers still install, and the receipt records only successful writes. `--replace-symlinks` converts the link itself to a real path, leaving its target untouched.\n\nYour project's own `AGENTS.md` is never written. That file is yours.\n\n### Skills — any agent\n\nThe skills follow the [Agent Skills specification](https://agentskills.io/specification), so one copy works in every agent that reads it. Install them with the ecosystem's CLI:\n\n```bash\n# this project only\nnpx skills add aanyberg/agent-conventions\n\n# every project on this machine\nnpx skills add aanyberg/agent-conventions -g\n```\n\nIt prompts for scope and agents. To skip the prompts:\n\n```bash\nnpx skills add aanyberg/agent-conventions -a codex -a github-copilot -a opencode -y\n```\n\nAgent flags: `claude-code`, `codex`, `github-copilot`, `opencode`, `cursor`, `gemini-cli`, and [70+ others](https://github.com/vercel-labs/skills#supported-agents).\n\n**Only two directories are ever written**, at either scope:\n\n| Path | Read by |\n| --- | --- |\n| `.agents/skills/` (or `~/.agents/skills/`) | Codex, GitHub Copilot, OpenCode, Cursor, Gemini CLI, Cline, Zed, Amp and others — this is the cross-vendor convention |\n| `.claude/skills/` (or `~/.claude/skills/`) | Claude Code, the one holdout — contains per-skill links into the above, not a second copy |\n\nBecause each Claude Code entry uses a full-path symlink into the same files,\nthere is no duplicate to drift. At project scope, commit `.agents/skills/` and\ngitignore `.claude/skills/`; regenerate the links after moving the project.\n\n### Agents — every target provider\n\nThe installer renders the canonical [`agent-sources/`](agent-sources) corpus into each\nselected provider's native format. Generated agents are real files rather than\nsymlinks because frontmatter, tool names, permissions, and even the file format\ndiffer by provider.\n\n| Provider | Project path | Global path |\n| --- | --- | --- |\n| Claude Code | `.claude/agents/*.md` | `~/.claude/agents/*.md` |\n| Codex | `.codex/agents/*.toml` | `~/.codex/agents/*.toml` |\n| GitHub Copilot | `.github/agents/*.agent.md` | `~/.copilot/agents/*.agent.md` |\n| OpenCode | `.opencode/agents/*.md` | `~/.config/opencode/agents/*.md` |\n| Cursor | `.cursor/agents/*.md` | `~/.cursor/agents/*.md` |\n| Gemini CLI | `.gemini/agents/*.md` | `~/.gemini/agents/*.md` |\n\nEvery emitted name starts with `conventions-`. The receipt stores a digest for\neach generated file: updates refuse foreign collisions, and uninstall preserves\nany managed agent a user modified after installation.\n\n### Native plugin install\n\nEach ecosystem has its own manifest pointing at the same top-level\n[`skills/`](skills). Native plugin installation is intentionally skills-only;\nuse the package installer above when provider-native agents are also required:\n\n```bash\n# Codex, Cursor, ChatGPT, Kiro, VS Code — via the Agent Plugins standard\n# (plugin.json at the repo root)\n\nclaude plugin marketplace add aanyberg/agent-conventions   # Claude Code\ncopilot plugin marketplace add aanyberg/agent-conventions  # GitHub Copilot CLI\ngemini extensions install aanyberg/agent-conventions       # Gemini CLI\n```\n\nCodex discovers the repo through `.codex-plugin/plugin.json`; Copilot CLI reads the same `.claude-plugin/marketplace.json` Claude Code does.\n\n### Skills — Claude Code plugin\n\nThe plugin route installs skills and updates through `claude plugin update`.\nCanonical agent sources are not exposed directly because their metadata is not\nvalid provider configuration; use the package installer for agents:\n\n```bash\nclaude plugin marketplace add aanyberg/agent-conventions\nclaude plugin install conventions@aanyberg\n```\n\nA consumer repo can commit the marketplace in `.claude/settings.json` so contributors need no per-person install at all — see [docs/CONSUMER.md](docs/CONSUMER.md).\n\n### Global Instructions\n\n`AGENTS.md` is the single source of truth. Global instructions use\nprovider-specific filenames, so install the managed block with the package\ninstaller rather than creating symlinks:\n\n```bash\nnpx github:aanyberg/agent-conventions -g -c instructions\n```\n\nThe installer appends a marked block to the selected instruction files and\npreserves content outside that block. It refuses instruction-file symlinks\nunless `--replace-symlinks` is explicitly provided; replacement affects only\nthe symlink itself, never its target. Use `uninstall -g` to remove only the\nmanaged block later.\n\n## Removing\n\nWhatever put this on your machine is what takes it off — the routes do not clean up after each other.\n\n| Installed with | Remove with |\n| --- | --- |\n| `npx github:aanyberg/agent-conventions` | `npx github:aanyberg/agent-conventions uninstall -g` (or `-p`) |\n| `npx skills add …` | `npx skills remove -g` |\n| `claude plugin install` | `claude plugin uninstall conventions@aanyberg` |\n| `claude plugin marketplace add` | `claude plugin marketplace remove aanyberg` |\n| `gemini extensions install` | see `gemini extensions --help` |\n\n### What the installer's uninstall removes\n\nIt works from the receipt written at install time, so it removes **exactly** what was installed and nothing adjacent:\n\n- every skill directory it created, and the links it made into `.claude/skills/`\n- every generated agent that is still byte-identical to the installed copy;\n  modified agents are retained and reported\n- its block from each instruction file, leaving your own content byte-for-byte as it was — and deleting the file outright only if the installer created it and nothing else is in it\n- the receipt itself\n\nA skill someone else put in the same directory is left alone. That is the point of the receipt: removal is never inferred from what an install *would* have produced.\n\n### `npm uninstall` does not do this\n\n`npm uninstall` removes the package and **nothing the installer wrote**. It cannot — npm removed uninstall lifecycle scripts in v7, on the grounds that a removal has too many possible causes to give a script useful context.\n\nSo if you installed the package globally, remove the content first and the package second:\n\n```bash\nnpx github:aanyberg/agent-conventions uninstall -g\nnpm uninstall -g @anyberg/agent-conventions\n```\n\nThe other order strands the files with the tool gone. Recoverable — the receipt is still on disk and `npx` re-fetches — but avoidable.\n\n### By hand\n\nIf the receipt is gone, or you would rather see exactly what is there, these are all the paths the installer ever writes. Substitute the project root for `~` if you installed with `-p`:\n\n```bash\n~/.agents/skills/          # the 17 skills — the real files\n~/.claude/skills/          # one link per skill into the above\n~/.claude/agents/          # generated Claude agents\n~/.codex/agents/           # generated Codex TOML agents\n~/.copilot/agents/         # generated Copilot agents\n~/.config/opencode/agents/ # generated OpenCode agents\n~/.cursor/agents/          # generated Cursor agents\n~/.gemini/agents/          # generated Gemini agents\n~/.agent-conventions.json  # the receipt\n```\n\nInstruction files are edited, not created wholesale, so delete only the block between the markers and leave the rest:\n\n```bash\n~/.claude/CLAUDE.md\n~/.copilot/copilot-instructions.md\n~/.codex/AGENTS.md\n~/.gemini/GEMINI.md\n```\n\nEach block is delimited by `<!-- BEGIN aanyberg/agent-conventions -->` and `<!-- END aanyberg/agent-conventions -->`. Anything outside those markers was yours.\n\n## Releasing\n\nSix manifests declare a version. Set them together, never by hand:\n\n```bash\nnode scripts/bump-version.mjs 1.1.0\ngit commit -am \"chore: release 1.1.0\"\ngit tag 1.1.0 && git push origin 1.1.0\n```\n\nThe bare semantic-version tag triggers [`release.yml`](.github/workflows/release.yml), which **re-runs the full suite rather than trusting merge-time checks** — an `--admin` merge bypasses required status checks as well as the approval rule, so a staged release cannot assume the PR was green. It also verifies the complete tag matches the manifests, packs the tarball and asserts it contains the skills, agents, `AGENTS.md` and the binary, then installs that exact tarball and runs a full install/uninstall round trip. Only then does it stage the package for approval.\n\nApprove the staged package once its checks complete:\n\n```bash\nnpm stage list @anyberg/agent-conventions\nnpm stage approve <stage-id>\n```\n\nPublishing uses [npm trusted publishing](https://docs.npmjs.com/trusted-publishers/) over OIDC: no `NPM_TOKEN` is stored anywhere, the credential is short-lived and scoped to this one workflow, and npm attaches a provenance attestation automatically.\n\n### One-time setup\n\nNeither step can be scripted from here — both need an authenticated session:\n\n1. **npm** — publish `1.0.0` manually once (`npm publish --access public`), since a trusted publisher can only be added to a package that exists. Then under the package's *Settings → Trusted publishers*, add: repository `aanyberg/agent-conventions`, workflow `release.yml`, environment `release`.\n2. **GitHub** — create an environment named `release` (*Settings → Environments*). Adding yourself as a required reviewer there puts a human approval in front of every publish, which is worth having for a public registry.\n\nUntil step 1 is done, `npx @anyberg/agent-conventions` will not resolve — use the `github:` form above, which needs nothing published. Publishing buys a shorter command, a tarball fetch instead of a clone, and a provenance attestation; it does not add capability.\n\nThere is deliberately **no `postinstall` hook**. `npm install` does nothing on its own; the installer is run explicitly.\n\nThat is not only a matter of taste. `npm uninstall` removes the package and **nothing the installer wrote** — not the skills, not the instruction blocks, not the receipt — and it cannot, because npm removed uninstall lifecycle scripts in v7 (\"there's no clear way to currently give the script enough context to be useful\"). An auto-installing `postinstall` would therefore be a one-way door: files written into `$HOME` with no supported mechanism to remove them. The explicit installer plus a receipt is the only arrangement here that fully reverses itself.\n\nSee [Removing](#removing) for how to take any of this back off.\n\n## Validation\n\nEvery change is gated by a validation suite. It parses the same files Claude Code\nparses at load time — so a failure means the plugin would load wrong — and checks each\nskill against the [Agent Skills specification](https://agentskills.io/specification)\nso the single copy stays installable in every other agent.\n\n```bash\nnpm test\n```\n\nIt needs no API access or GitHub auth — `gh` is stubbed.\n`.github/workflows/validate.yml` gates every pull request on Linux, and repeats the\nsuite on macOS after merge to `main` as a canary.\nSupported runtimes and the per-provider agent-file contracts are documented in\n[docs/COMPATIBILITY.md](docs/COMPATIBILITY.md).\n\nWhat it checks:\n\n| Area | Checks |\n| --- | --- |\n| Release | the version bump sets all six manifests together, refuses a non-semver input without writing, is idempotent, and leaves every other field and the file formatting untouched. A separate test asserts the six currently agree, so drift fails a PR rather than a release |\n| Installer | the CLI runs end to end against a throwaway `HOME`: both scopes, symlink and copy modes, idempotent reinstall, and an uninstall that restores a pre-existing file byte-for-byte and leaves a foreign skill in the same directory alone. The symlink guard has its own tests — the one failure mode here that destroys data rather than annoying someone |\n| Install manifests | the four ecosystem manifests parse, declare the same version, and point at the same `skills/`; `plugin.json` matches the Agent Plugins name grammar and carries no key outside its schema, which sets `additionalProperties: false` so an extra key invalidates the file rather than being ignored |\n| Manifests | `marketplace.json` and `plugin.json` parse, agree on descriptions, use semver, and every declared `source` resolves to a real plugin. Plugin identity comes from the manifest pair, not the directory name — the root plugin is `conventions` while its directory is the repo itself |\n| Skills | frontmatter has `name` and `description`, `name` matches the directory, names are unique, descriptions fit the loader budget, and every key is one the Agent Skills spec permits — `version` is not one of them, it belongs inside `metadata` |\n| Agents | canonical names are package-prefixed; abstract capabilities, access, model tier, effort, and turn limits are valid; read-only roles cannot request writes; every provider renderer preserves identity and behavior |\n| References | relative markdown links resolve and every skill or agent named in prose exists |\n| Workflow portability | no policy files or policy scripts are shipped; backlog selection asks only when explicit instructions and repository evidence remain ambiguous; structured tasks and architecture records require existing use or explicit intent |\n| Cross-agent portability | the repo ships one copy of each skill, so no skill or agent body may depend on a single vendor: no interpolated `${CLAUDE_*}` variable, no vendor component directory (`.claude/skills/`, `.cursor/rules/`, …), no vendor instruction file (`CLAUDE.md`, `copilot-instructions.md`), and no tool named from one agent's vocabulary. Naming a vendor directory as somewhere *not* to write stays legal — `task-workflow` does exactly that with `~/.claude` and `~/.copilot`. Each rule is pinned to a sample it must catch and a sample it must ignore, so a regex that rots fails loudly instead of passing on everything |\n\nAdding a skill or agent needs no test changes — the suite discovers files dynamically\nand creates a subtest per file, so each one fails independently with its own path.\n","readmeFilename":"README.md"}