Skip to content

FAQ

A set of Markdown instructions: eight Skills plus a shared Core of rules, workflows, policies, profiles, and templates. It is packaged as plugins for Claude Code, Codex, and GitHub Copilot. The host agent reads and follows them. See the Overview.

No. Packages contain no scripts, MCP servers, hooks, LSP servers, or executables. The host agent runs commands, under the host’s permissions, when a Skill’s procedure calls for it and your request authorizes it.

No. Kiyo’s access contracts are advisory. The host enforces permissions, and Kiyo cannot guarantee that an agent complies. It is not a sandbox, DLP, egress filter, or policy engine. What it does provide is a consistent procedure and reports that make non-compliance visible, for example a claimed PASS without a recorded command.

Name Where it appears
Kiyo Codejadee Framework Repository name; this website
Kiyo Axiom Framework Working name inside the framework’s own files
kiyo-axiom-framework / kiyo-codejadee Installable plugin ID / catalog (marketplace) name

Earlier evidence also uses kiyo-compass, the previous working plugin ID. The final publication name is an open owner decision (DEC-001).

There is no product version yet (UNSET). A host showing “1.0.0” (Codex does this) is a host fallback. Identify a package by its source revision or archive hash.

Packages exist for Claude Code (CLI and VS Code), Codex CLI, and GitHub Copilot (CLI and VS Code). The Codex IDE extension does not support native plugins. Evidence status differs per target; see Compatibility and evidence.

No. Any Skill works after explicit selection; it reads its packaged bootstrap. Init is for when you want project Memory and configuration, and it never runs automatically for features or bug fixes.

Not implicitly. No Skill commits, pushes, opens pull requests, publishes, or deploys as part of completing a task. Production and destructive execution fall under G4 Restricted.

Only in your repository, under .kiyo/ by default, and only when you authorize it. Nothing mutable is stored in the plugin cache. Memory never contains secrets, personal data, raw logs, or private reasoning.

Kiyo itself sends nothing; it has no network component. Your host agent and its model provider handle your code under their own terms. Kiyo’s provider policy says provider, account, and retention facts must come from real evidence, and that the word “Enterprise” establishes none of them.

Can I use it in languages other than English?

Section titled “Can I use it in languages other than English?”

Yes. Intent is read from natural language, and the framework’s own walkthroughs include requests written in Thai. The project config has a reporting language field for your preference.

Kiyo maps its practices to ISO/IEC, NIST SSDF, and OWASP sources as dated, advisory context. It makes no certification or compliance claim. See Engineering standards.

How do I know the agent actually followed Kiyo?

Section titled “How do I know the agent actually followed Kiyo?”

Look at the report. Every check should have a nine-field record, and read-only Skills should leave git status clean. The Security Skill’s self-check reports what the host actually exposes. Automatic loading in every session is NOT_TESTED, so select Skills explicitly.