Overview
Kiyo Codejadee Framework is an engineering and governance framework for AI coding agents. It is written entirely in Markdown: eight Skills plus a shared Core of rules, workflows, policies, stack profiles, and report templates. When you select a Skill in Claude Code, Codex, or GitHub Copilot, the host agent reads that Skill and follows its procedure.
The framework does not give an agent new tools or permissions. It gives the agent a consistent way to work inside the permissions your host already enforces: investigate before asserting, choose the workflow that matches your intent, make the smallest authorized change, and report evidence honestly.
The problems it addresses
Section titled “The problems it addresses”The framework README names the failure modes it targets. Each one maps to a stable rule in the Core bootstrap:
| Failure mode | Kiyo rule | Control ID |
|---|---|---|
| Guessing about the project | Discover evidence before asking; ask before inventing routes, schemas, versions, or results | KIYO-FACT-002 |
| Changing more than requested | Make the minimum necessary authorized change; preserve human edits and unrelated work | KIYO-CHG-001 |
| Claiming checks that never ran | Never claim a check passed unless it actually ran and its observed result supports the claim | KIYO-FACT-004 |
| Turning a review into an implementation | Read-only intent stays read-only; finding a bug does not authorize repairing it | KIYO-SAFE-001 |
| Losing context between tasks | Project Memory supplies context with provenance, rechecked against current evidence | KIYO-MEM-001 |
How it works in one diagram
Section titled “How it works in one diagram”flowchart LR accTitle: Kiyo in context accDescr: A developer selects a Skill in a host agent. The host loads the static Kiyo package, and the agent reads and writes the repository only within host permissions. dev([Developer]) -->|selects a Skill and states intent| host[Host agent<br/>Claude Code · Codex · Copilot] host -->|loads on selection| pkg[Kiyo package<br/>8 Skills + shared Core<br/>static Markdown] host -->|reads and edits within host permissions| repo[(Your repository<br/>source · tests · .kiyo/ state)] host -->|chat report with evidence| dev
The host owns tool execution and permissions. The Kiyo package is read-only guidance inside the installed plugin. Mutable project state, such as Memory and policy, lives in your repository under .kiyo/ and belongs to you, not to the plugin.
What a package contains
Section titled “What a package contains”Each generated package has the same shape for every host. The layout below is taken from the packaging contract and the committed dist/ trees.
| Part | Contents | Why |
|---|---|---|
| Native manifest | plugin.json with name and description (Codex also gets .codex-plugin/plugin.json) |
Lets the host discover the plugin |
| Eight Skill entries | skills/<name>/SKILL.md for init, requirement, implement, review, test, security, architecture, memory |
What the host lists and you select |
| Shared Core snapshot | skills/<name>/references/kiyo/: KIYO.md, framework, governance, agent-security, workflows, profiles, templates |
Every link resolves inside the Skill, with no cross-Skill or network lookup |
| Host adapter | skills/<name>/references/<host>/activation.md |
Host-specific selection and project-instruction guidance |
| License | LICENSE (MIT) |
Legal terms travel with the package |
There are no MCP servers, hooks, LSP servers, scripts, or executables in any package. See Packaging and distribution for the build transform.
What it is not
Section titled “What it is not”- Not a runtime or CLI. There is no Kiyo command to run. You interact through your host’s own Skill picker.
- Not a permission system. Kiyo’s access contracts are advisory. The host enforces tools, files, and network access (
KIYO-AUTH-001). - Not a sandbox, DLP, or egress filter. It cannot stop an agent from ignoring instructions, and it cannot prevent all prompt injection.
- Not a certification. References to ISO/IEC, NIST SSDF, and OWASP are dated mappings, not compliance claims. See Engineering standards.
- Not always on. Installing a package exposes Skill metadata. Automatic loading of the Core in every session is
NOT_TESTED.
Who it is for
Section titled “Who it is for”- Developers and teams who use Claude Code, Codex CLI, or GitHub Copilot and want reviewable, consistent agent behavior across tasks.
- Tech leads who need an agent to separate verified facts from assumptions, and to stop before sensitive actions.
- Maintainers of repositories where durable context (decisions, conventions, known issues) should live next to the code.
If you need enforced guardrails or a versioned release, read Is Kiyo a fit? first.
Current status
Section titled “Current status”The framework is a development preview. As of the documented revision:
- Product version:
UNSET. No public release or marketplace listing exists. - Content: 105 canonical Markdown files, 68 control IDs, 34 templates, 8 Skills — all authored.
- Packages: development ZIPs for Claude Code, Codex, and Copilot are committed under
dist/archives/. - Host evidence: a small set of native checks was recorded (Claude Code discovery of eight Skills; Codex local install and uninstall). They predate the rename to
kiyo-axiom-framework. Skill behavior on every host remainsNOT_TESTED.
Details, evidence, and open owner decisions are on Status and releases and Compatibility and evidence.