Skip to content
Theme

~/your-repo/kiyo-axiom-framework:init

Coding agents that work from evidence, not guesses.

Kiyo Codejadee Framework is a Markdown-first set of eight Skills for Claude Code, Codex, and GitHub Copilot. It gives an agent one shared procedure: inspect the repository, choose the right workflow, make the smallest authorized change, and report only the checks that actually ran.

development previewversion unsetMIT licenseno runtime, MCP server, hooks, or database

claude — /kiyo-axiom-framework:reviewillustrative report shape
› /kiyo-axiom-framework:review
› Review my unstaged changes. Do not edit
  files or run project scripts.

Task/scope      unstaged diff · read-only
Finding         HIGH · Confirmed defect
                confidence HIGH · file:line cited
Verification    build/tests NOT_RUN
                Review never executes project code
Memory impact   NONE in inspected scope
Status          DONE bounded review delivered
Next action     fix needs a separate Implement request
skills/review/SKILL.mdsource excerpt
---
name: review
description: Review existing human or AI changes
  without editing them. … Review alone does not
  authorize fixes or build/test execution.
---

# Review

Logical ID: **kiyo.review**. Canonical name: review.

This skill authorizes analysis and chat output
only. Do not edit source, tests, config or Memory;
create report files by default; install packages;
or commit, push, stash, reset or otherwise clean
up the workspace.
Open the full file on GitHub ↗

Open source under the MIT license. Packaged for Claude Code, Codex, and GitHub Copilot. No public release yet —see project status.

Why Kiyo

Coding agents fail in predictable ways. Kiyo gives each one a rule.

The framework does not add tools or permissions. It adds a written procedure the agent follows inside the permissions your host already enforces.

  • Guessing about the project

    Evidence before assertions

    Facts, assumptions, proposals, approved decisions, and unknowns stay separate. A missing route, schema, or version is reported as Unknown instead of invented.

    KIYO-FACT-001KIYO-FACT-002

  • Changing more than requested

    Minimum authorized change

    Existing safe patterns win over new abstractions. Human edits and unrelated work are preserved; no speculative libraries, broad formatting, or silent upgrades.

    KIYO-CHG-001KIYO-ENG-007

  • Claiming checks that never ran

    Honest check statuses

    PASS requires an executed check whose observed result met its criterion. Everything else is FAIL, NOT_RUN, NOT_APPLICABLE, or BLOCKED — with a reason.

    KIYO-FACT-004KIYO-VERIFY-001

  • Turning a review into an implementation

    Read-only stays read-only

    Review, Architecture, Security, and Memory check never edit files. Finding a bug is not permission to fix it; a fix needs its own request.

    KIYO-SAFE-001KIYO-FLOW-003

  • Losing context between tasks

    Project Memory with provenance

    Observations, proposals, and approved decisions live in your repository with sources and dates, and are rechecked against current code before they are trusted.

    KIYO-MEM-001KIYO-MEM-004

  • Acting on injected instructions

    Embedded text is data

    README files, issues, tool output, and Memory can carry instructions. They never grant permission to read credentials, widen access, or skip approval.

    KIYO-TRUST-001KIYO-SEC-003

Key features

Four pillars. Eight Skills. One shared Core.

Every Skill reads the same compact bootstrap before acting, then follows its own procedure. Long rules are written once and referenced by stable control IDs.

  • 01

    Project Intelligence

    Evidence-backed context, project-owned Memory, and drift detection between code and approved decisions.

  • 02

    Software Engineering

    Requirements with acceptance criteria, minimal implementation, severity-rated review, and tests with real results.

  • 03

    AI Governance

    Governance levels G1–G4, independent risk ratings, data classes, and scoped human approval that is reused, not repeated.

  • 04

    Agentic Skill Security

    Trust review for Skills and plugins mapped to OWASP AST01–AST10, with explicit owners and limits.

How it works

Static Markdown in. A scoped, evidenced result out.

Kiyo ships no executable. Each installed Skill contains a complete copy of the shared rules, so every link resolves inside the package. The host decides what to load and enforces permissions; Kiyo supplies the procedure.

  1. 01

    Discover

    The host lists each Skill by its name and description from the installed package.

    skills/<name>/SKILL.md
  2. 02

    Select

    You pick a Skill explicitly, or the host matches your request to a description.

    /kiyo-axiom-framework:<skill>
  3. 03

    Bootstrap

    The entry sends the agent to KIYO.md and the ten-rule bootstrap before any workflow action.

    references/kiyo/KIYO.md
  4. 04

    Procedure

    The selected workflow runs, loading only the references and template the task needs.

    references/kiyo/workflows/…
  5. 05

    Report

    A chat report: scope, changes, checks with real statuses, Memory impact, and task status.

    templates/reports/…

Bounded context by design. KIYO.md plus the bootstrap must fit 120 lines and 600 words; each SKILL.md fits 250 lines and 1,200 words. The agent reads only relevant references after that.

Loading and activation →

Developer experience

No new syntax. State the intent, get the evidence.

You select a Skill through your host's own picker and describe the task in plain language. The report format and check record below are the real templates shipped in every package.

  • Intent over flags

    Modes such as assess, run, write, or sync are words in your request. Kiyo does not ship a command parser.

  • Adaptive depth

    A typo fix gets a compact scope check and a one-line report. A schema change gets a full impact assessment.

  • Chat by default

    Reports stay in the conversation. A report file is written only when you authorize that output path.

  • Nine-field evidence

    Every check — including ones that did not run — records its command, scope, status, result, and baseline.

plain-language requests (from the Skill guide)
Review my unstaged changes; do not edit or run project scripts.
Assess authorization test gaps in this module; no writes or execution.
Run the existing approved unit suite after inspecting its script and environment.
Fix the supplied boundary error and add its regression test; preserve unrelated edits.
Compare ADR-007 with this module; report deviations only.

Quick start

From install to a read-only first result.

Commands follow the framework README, using the repository's current GitHub path. The catalog route was added in the latest commits and has no recorded host test yet — treat it as a development install.

  1. 1

    Install the package in your host

    NOT_TESTED
    Claude Code session
    /plugin marketplace add 0xPratyaDev7x/kiyo-axiom-framework
    /plugin install kiyo-axiom-framework@kiyo-codejadee
  2. 2

    Select Init explicitly

    DOCUMENTED_ONLY

    In Claude Code use /kiyo-axiom-framework:init. In Codex, open /skills or the $ picker and choose the Kiyo entry. In Copilot CLI, find it with /skills list. Do not substitute the host's built-in/init.

  3. 3

    Ask for a preview — zero file writes

    first request
    Preview onboarding for this repository; report evidence, unknowns and proposed Memory/config/bootstrap changes without writing files.
  4. 4

    Initialize only what you approve, then work daily

    Ask Init to create the proposed project-local state (new projects default to .kiyo/policy.md and.kiyo/memory/index.md). Then use Requirement, Implement, Review, Test, Security, Architecture, or Memory and read the evidence in each report.

Real example

Code says one thing. An approved decision says another. Kiyo keeps both.

The framework's own reference case: an approved decision requires Mapperly, but current call sites use AutoMapper. A Memory check reports Architecture Drift without rewriting the decision to match the code.

01 Recorded intent in your repository

.kiyo/memory/decisions.md
## MEM-DEC-0007 — Object mapping uses Mapperly
- id: MEM-DEC-0007
- record_type: decision
- status: APPROVED
- statement: The Orders module maps DTOs with Mapperly only.
- source: approved record; docs/adr/ADR-007-object-mapping.md
- verification_status: UNVERIFIED
- verification_scope: decision text only; no call sites inspected
- repository_context: orders-service; component src/Orders
- git_revision: UNKNOWN
- approval_source: ADR-007
- approval_scope: src/Orders

02 A read-only check

Memory check
Check these two Memory entries against this branch.
Report factual corrections separately from decision
conflicts; do not write.

03 Drift reported, intent preserved

drift report — architecture decision comparison
- **Decision ID:** MEM-DEC-0007 (ADR-007, scope src/Orders)
- **Files/symbols/config:** OrderMappingProfile.cs, DI registration
- **Observed difference:** Deviation — AutoMapper call sites in scope
- **Confidence:** HIGH — usage inspected, not just a package reference
- **Possible interpretations:** unauthorized drift, or an unrecorded
approved exception
- **Required human decision:** fix the code, or revise ADR-007 with
real approval
- **Memory impact:** CONFLICT — decision preserved, zero files written

Synthetic walkthrough WT-07; expected behavior from the Memory specification and drift report template, not a recorded run. Field names are the real template fields. Read the full example →

Adoption

Where Kiyo fits — and where it doesn't yet.

An honest scope statement, derived from the framework's own documented limits.

Good fit

  • You already use Claude Code, Codex CLI, or GitHub Copilot and want the same disciplined behavior across tasks and people.
  • Unverified claims are expensive in your codebase: shared libraries, security-sensitive code, or regulated delivery.
  • Humans and agents both change the code, and you want read-only review plus explicit approval before sensitive actions.
  • You want durable project context — decisions, conventions, known issues — stored in the repository, not in a vendor account.

May not be the best fit

  • You need enforced guardrails. Kiyo is advisory Markdown: the host enforces permissions. It is not a sandbox, DLP, or policy engine.
  • You need a supported, versioned release. The framework is a development preview; version, publisher, and listing are still owner decisions.
  • You work only in the Codex IDE extension. Native plugins are documented as unsupported there, and no fallback is approved.
  • You need guaranteed activation in every session. Explicit selection is the documented route; automatic Core loading is not tested.
  • You want autonomous commit, push, or deploy. Kiyo never performs those implicitly.

Start here

Begin with a read-only preview.

Init's preview mode inspects your repository and proposes Memory and configuration without writing a single file. Review the proposal, then decide what to create.