~/your-repo/kiyo-axiom-framework:init
Coding agents that work from evidence, not guesses.
Kiyo Codejadee Framework is a Markdown-first set of eight Skills for Claude Code, Codex, and GitHub Copilot. It gives an agent one shared procedure: inspect the repository, choose the right workflow, make the smallest authorized change, and report only the checks that actually ran.
development previewversion unsetMIT licenseno runtime, MCP server, hooks, or database
› /kiyo-axiom-framework:review › Review my unstaged changes. Do not edit files or run project scripts. Task/scope unstaged diff · read-only Finding HIGH · Confirmed defect confidence HIGH · file:line cited Verification build/tests NOT_RUN Review never executes project code Memory impact NONE in inspected scope Status DONE bounded review delivered Next action fix needs a separate Implement request
--- name: review description: Review existing human or AI changes without editing them. … Review alone does not authorize fixes or build/test execution. --- # Review Logical ID: **kiyo.review**. Canonical name: review. This skill authorizes analysis and chat output only. Do not edit source, tests, config or Memory; create report files by default; install packages; or commit, push, stash, reset or otherwise clean up the workspace.Open the full file on GitHub ↗
- 8public Skills
- 68stable control IDs
- 105canonical Markdown files
- 3host ecosystems packaged
- 0runtime components shipped
- 37/37static contract checks pass at 897516e
Open source under the MIT license. Packaged for Claude Code, Codex, and GitHub Copilot. No public release yet —see project status.
Why Kiyo
Coding agents fail in predictable ways. Kiyo gives each one a rule.
The framework does not add tools or permissions. It adds a written procedure the agent follows inside the permissions your host already enforces.
Guessing about the project
Evidence before assertions
Facts, assumptions, proposals, approved decisions, and unknowns stay separate. A missing route, schema, or version is reported as Unknown instead of invented.
KIYO-FACT-001KIYO-FACT-002Changing more than requested
Minimum authorized change
Existing safe patterns win over new abstractions. Human edits and unrelated work are preserved; no speculative libraries, broad formatting, or silent upgrades.
KIYO-CHG-001KIYO-ENG-007Claiming checks that never ran
Honest check statuses
PASS requires an executed check whose observed result met its criterion. Everything else is FAIL, NOT_RUN, NOT_APPLICABLE, or BLOCKED — with a reason.
KIYO-FACT-004KIYO-VERIFY-001Turning a review into an implementation
Read-only stays read-only
Review, Architecture, Security, and Memory check never edit files. Finding a bug is not permission to fix it; a fix needs its own request.
KIYO-SAFE-001KIYO-FLOW-003Losing context between tasks
Project Memory with provenance
Observations, proposals, and approved decisions live in your repository with sources and dates, and are rechecked against current code before they are trusted.
KIYO-MEM-001KIYO-MEM-004Acting on injected instructions
Embedded text is data
README files, issues, tool output, and Memory can carry instructions. They never grant permission to read credentials, widen access, or skip approval.
KIYO-TRUST-001KIYO-SEC-003
Key features
Four pillars. Eight Skills. One shared Core.
Every Skill reads the same compact bootstrap before acting, then follows its own procedure. Long rules are written once and referenced by stable control IDs.
- 01
Project Intelligence
Evidence-backed context, project-owned Memory, and drift detection between code and approved decisions.
- 02
Software Engineering
Requirements with acceptance criteria, minimal implementation, severity-rated review, and tests with real results.
- 03
AI Governance
Governance levels G1–G4, independent risk ratings, data classes, and scoped human approval that is reused, not repeated.
- 04
Agentic Skill Security
Trust review for Skills and plugins mapped to OWASP AST01–AST10, with explicit owners and limits.
- kiyo.initInitOnboard a repository and create or update Project Memory.preview read-only · initialize writes .kiyo/ state
- kiyo.requirementRequirementTurn a request into an evidence-backed requirement with a readiness verdict.chat by default · optional spec file
- kiyo.implementImplementFeature, bug fix, or scoped refactor with actual verification and bounded repair.writes code, tests, docs in scope
- kiyo.reviewReviewFindings on human or AI changes with severity, confidence, and file:line evidence.read-only · never runs builds
- kiyo.testTestAssess gaps, run authorized checks, or write tests — three separate effects.assess · run · write
- kiyo.securitySecurityBounded assessment of application code, a Skill, governance config, or Kiyo itself.read-only · no scans or payload runs
- kiyo.architectureArchitectureObserved structure versus approved intent, change impact, and drift.read-only
- kiyo.memoryMemoryShow, check, sync, or repair Project Memory without rewriting decisions.show/check read-only · sync/repair scoped
How it works
Static Markdown in. A scoped, evidenced result out.
Kiyo ships no executable. Each installed Skill contains a complete copy of the shared rules, so every link resolves inside the package. The host decides what to load and enforces permissions; Kiyo supplies the procedure.
- 01
Discover
The host lists each Skill by its name and description from the installed package.
skills/<name>/SKILL.md - 02
Select
You pick a Skill explicitly, or the host matches your request to a description.
/kiyo-axiom-framework:<skill> - 03
Bootstrap
The entry sends the agent to KIYO.md and the ten-rule bootstrap before any workflow action.
references/kiyo/KIYO.md - 04
Procedure
The selected workflow runs, loading only the references and template the task needs.
references/kiyo/workflows/… - 05
Report
A chat report: scope, changes, checks with real statuses, Memory impact, and task status.
templates/reports/…
Bounded context by design. KIYO.md plus the bootstrap must fit 120 lines and 600 words; each SKILL.md fits 250 lines and 1,200 words. The agent reads only relevant references after that.
Loading and activation →Developer experience
No new syntax. State the intent, get the evidence.
You select a Skill through your host's own picker and describe the task in plain language. The report format and check record below are the real templates shipped in every package.
Intent over flags
Modes such as
assess,run,write, orsyncare words in your request. Kiyo does not ship a command parser.Adaptive depth
A typo fix gets a compact scope check and a one-line report. A schema change gets a full impact assessment.
Chat by default
Reports stay in the conversation. A report file is written only when you authorize that output path.
Nine-field evidence
Every check — including ones that did not run — records its command, scope, status, result, and baseline.
Review my unstaged changes; do not edit or run project scripts.
Assess authorization test gaps in this module; no writes or execution.
Run the existing approved unit suite after inspecting its script and environment.
Fix the supplied boundary error and add its regression test; preserve unrelated edits.
Compare ADR-007 with this module; report deviations only.- **Task/scope:** <requested result, mode, boundary and exclusions>- **Actions/files changed:** <actual changes/inspection; proposed work distinguished>- **Governance/risk rationale:** <brief scope/effect rationale, authority and uncertainties>- **Verification/evidence:** <repeat the nine-field check record below as needed>- **Residual issues:** <failures, untested scope, unknowns or none identified within scope>- **Memory impact:** <one value; reason and actual applied/pending delta>- **Status:** <one task status and its scope; readiness separately if relevant>- **Next required action:** <concrete next step/precondition or none for completed scope>Name <check/criterion>Applicability <required / optional / not applicable, reason and source>Command/method <actual command, or clearly labeled planned method>Inspected scope <actual files, state, environment>Execution status PASS | FAIL | NOT_RUN | NOT_APPLICABLE | BLOCKEDObserved result <actual observation, or "no execution" and why>Evidence location <actual safe reference or chat observation>Limitations <bounds and gaps>Baseline relation <supported comparison, or Unknown>Quick start
From install to a read-only first result.
Commands follow the framework README, using the repository's current GitHub path. The catalog route was added in the latest commits and has no recorded host test yet — treat it as a development install.
- 1
Install the package in your host
NOT_TESTEDClaude Code session /plugin marketplace add 0xPratyaDev7x/kiyo-axiom-framework/plugin install kiyo-axiom-framework@kiyo-codejadeePowerShell codex plugin marketplace add 0xPratyaDev7x/kiyo-axiom-frameworkcodex plugin add kiyo-axiom-framework@kiyo-codejadeePowerShell copilot plugin marketplace add 0xPratyaDev7x/kiyo-axiom-frameworkcopilot plugin install kiyo-axiom-framework@kiyo-codejadee - 2
Select Init explicitly
DOCUMENTED_ONLYIn Claude Code use
/kiyo-axiom-framework:init. In Codex, open/skillsor the$picker and choose the Kiyo entry. In Copilot CLI, find it with/skills list. Do not substitute the host's built-in/init. - 3
Ask for a preview — zero file writes
first request Preview onboarding for this repository; report evidence, unknowns and proposed Memory/config/bootstrap changes without writing files. - 4
Initialize only what you approve, then work daily
Ask Init to create the proposed project-local state (new projects default to
.kiyo/policy.mdand.kiyo/memory/index.md). Then use Requirement, Implement, Review, Test, Security, Architecture, or Memory and read the evidence in each report.
Real example
Code says one thing. An approved decision says another. Kiyo keeps both.
The framework's own reference case: an approved decision requires Mapperly, but current call sites use AutoMapper. A Memory check reports Architecture Drift without rewriting the decision to match the code.
01 Recorded intent in your repository
## MEM-DEC-0007 — Object mapping uses Mapperly
- id: MEM-DEC-0007- record_type: decision- status: APPROVED- statement: The Orders module maps DTOs with Mapperly only.- source: approved record; docs/adr/ADR-007-object-mapping.md- verification_status: UNVERIFIED- verification_scope: decision text only; no call sites inspected- repository_context: orders-service; component src/Orders- git_revision: UNKNOWN- approval_source: ADR-007- approval_scope: src/Orders02 A read-only check
Check these two Memory entries against this branch.Report factual corrections separately from decisionconflicts; do not write.03 Drift reported, intent preserved
- **Decision ID:** MEM-DEC-0007 (ADR-007, scope src/Orders)- **Files/symbols/config:** OrderMappingProfile.cs, DI registration- **Observed difference:** Deviation — AutoMapper call sites in scope- **Confidence:** HIGH — usage inspected, not just a package reference- **Possible interpretations:** unauthorized drift, or an unrecorded approved exception- **Required human decision:** fix the code, or revise ADR-007 with real approval- **Memory impact:** CONFLICT — decision preserved, zero files writtenSynthetic walkthrough WT-07; expected behavior from the Memory specification and drift report template, not a recorded run. Field names are the real template fields. Read the full example →
Adoption
Where Kiyo fits — and where it doesn't yet.
An honest scope statement, derived from the framework's own documented limits.
Good fit
- You already use Claude Code, Codex CLI, or GitHub Copilot and want the same disciplined behavior across tasks and people.
- Unverified claims are expensive in your codebase: shared libraries, security-sensitive code, or regulated delivery.
- Humans and agents both change the code, and you want read-only review plus explicit approval before sensitive actions.
- You want durable project context — decisions, conventions, known issues — stored in the repository, not in a vendor account.
May not be the best fit
- You need enforced guardrails. Kiyo is advisory Markdown: the host enforces permissions. It is not a sandbox, DLP, or policy engine.
- You need a supported, versioned release. The framework is a development preview; version, publisher, and listing are still owner decisions.
- You work only in the Codex IDE extension. Native plugins are documented as unsupported there, and no fallback is approved.
- You need guaranteed activation in every session. Explicit selection is the documented route; automatic Core loading is not tested.
- You want autonomous commit, push, or deploy. Kiyo never performs those implicitly.
Start here
Begin with a read-only preview.
Init's preview mode inspects your repository and proposes Memory and configuration without writing a single file. Review the proposal, then decide what to create.