# Hooks, commands, skills, and a manifest so an update does not eat your edits

> safe-agentic-workflow is a template repository rather than a tool: you copy a provider directory into your project, customise placeholders with one script, and get a three-layer harness of guardrails, slash commands and model-invoked skills. The part that suggests it has been run in production is not the SAFe framing, it is the sync manifest that protects your customisations when a new version lands.

**bybren-llc/safe-agentic-workflow** — SAW — SAFe Agentic Workflow AI Agent Harness for Multi-Agent Team Workflows Built on SAFe methodology (Scaled Agile Framework), adapted for AI agent teams (Now With AI-DLC!) Works for any team with repeatable processes: Software, Marketing, Research, Legal, Operations.

- Repository: https://github.com/bybren-llc/safe-agentic-workflow
- Website: https://jscottgraham.us
- Stars: 419 · Forks: 90
- Language: Shell
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/bybren-llc-safe-agentic-workflow

## It is a template, and the setup is a copy plus one script

The README leads with a warning-shaped instruction: this is a template repository, and you click Use this template to create your own agent harness. After cloning you run bash scripts/setup-template.sh to customise it for your project, with the details in TEMPLATE_SETUP.md.

Adoption is then a directory copy per provider. For Claude Code:

```bash
cp -r .claude/ /your-project/.claude/
bash scripts/setup-template.sh
/start-work TICKET-123
```

The script's job is placeholders: {{TICKET_PREFIX}}, {{PROJECT_NAME}} and the rest, replaced in one pass across all provider files. That single-pass detail is the reason the script exists rather than a find-and-replace in the README, since the same placeholder has to change in four provider directories at once.

The scale it claims is worth reading for what it implies about the artifact. Twenty model-invoked skills with Skills 2.0 frontmatter, twenty-four slash commands, eleven SAFe agent profiles, three layers, agent teams with SAFe quality gates marked experimental, a Dark Factory for persistent autonomous teams over tmux on remote servers, and a Knowledge Vault with a drift-detecting validator.

The origin line is 5 months of production use, 169 issues and 2,193 commits, which is what separates this from a prompt collection.

## The three layers are hooks, commands, skills

The architecture is one diagram and three rows. Layer one is hooks, described as automatic guardrails covering format checks and blockers. Layer two is commands, which the user invokes as workflows such as /start-work and /pre-pr. Layer three is skills, which the model invokes when it recognises the pattern.

The distinction between layers two and three is the part that makes the design legible. A command is something you type, so it is an explicit request with a defined start. A skill is something the agent loads because the task looks like something it has seen, which means the twenty skills are mostly invisible until they fire.

The command set is named in the README, grouped by kind. Workflow commands number eight: /start-work, /pre-pr, /release, /end-work, /check-workflow, /update-docs, /retro and /sync-linear. Local operations add three: /local-sync, /local-deploy and /quick-fix. Remote operations add five: /remote-status, /remote-deploy, /remote-health and /remote-logs, the fifth of that group not visible in the copy of the README available for this review.

The stated philosophy is process as service rather than control, and everything exists to reduce cognitive load on problems the team has already solved.

## Four providers, one set of conventions

Multi-provider support is the first claim in the What This Is section: Claude Code from Anthropic, the Gemini CLI from Google, the Codex CLI from OpenAI and the Cursor IDE from Anysphere. Each has its own directory in the template.

The setups differ more than the file names suggest. Claude Code gets a slash command, /start-work TICKET-123. Gemini needs npm install -g @google/gemini-cli, an exported GEMINI_API_KEY and its own namespaced command, /workflow:start-work. Codex needs both .codex/ and .agents/ copied, npm install -g @openai/codex, an exported OPENAI_API_KEY, and it is started with a bare codex and natural language rather than a slash command, because the README says Codex has no slash commands. Cursor gets .cursor/ copied and rules that activate automatically from file context, with @rule-name to invoke an agent role by hand.

That last difference is the informative one. In Cursor the rules load based on which files you have open, which is a different activation model from an explicitly typed command, and a harness that supports both has to encode the difference rather than pretend it is not there.

## The manifest is what stops an update from eating your work

Two update paths are documented, and the automated one exists because of a specific failure mode.

The automated path is manifest-based. You initialise sync metadata once with ./scripts/sync-claude-harness.sh init and ./scripts/sync-claude-harness.sh manifest init --yes, then preview with a dry run before applying, optionally narrowing with --scope .claude,.gemini. The script knows which domains to touch from a sync_scope in your manifest.

The guarantee is stated in one line and it is the important sentence in the section: the sync script protects your customisations via a manifest, required since v2.10.0, and it will not overwrite files you have marked as protected.

The manual path is unapologetically git. You add the harness repository as a remote, fetch it with tags, look at a git diff --stat between two versions to see what changed, then check out only the directory you want from the remote branch. That is a cherry-pick of a directory, and its virtue is that it is obviously not going to touch anything else.

A manifest file and a schema file for it are both in the root listing, .harness-manifest.yml and .harness-manifest.schema.json, along with a HARNESS_CHANGELOG.yml, so the version history is machine-readable rather than only prose.

## Dark Factory and Knowledge Vault are the two heavy features

The feature list flags two things as more than conventions.

The Dark Factory is described as persistent autonomous agent teams via tmux on remote servers, with its own README. tmux is doing real work here: a tmux session survives a dropped connection, which is the minimum requirement for an agent that keeps running while you are not looking. Running it on remote servers rather than a laptop is the second half of that decision.

The Knowledge Vault is an evidence-verified knowledge base with a drift-detecting validator, also with its own README. A validator that detects drift is the interesting part, because a knowledge base without one silently becomes wrong. Pairing the vault with a validator is the same instinct that produces the sync manifest elsewhere in the project.

Agent Teams is listed too, as multi-agent orchestration with SAFe quality gates, and it is the one feature marked experimental. The distinction between what ships and what is being tried is drawn explicitly, which is more than most templates do.

The remaining directories in the tree point at the same shape: patterns/, patterns_library/, project_workflow/, specs_templates/, templates/, agent_providers/ and linting_configs/, each holding the material one part of the harness is built from.

## SAFe and AI-DLC, and where to start reading

The methodology layer is the Scaled Agile Framework, adapted for AI agent teams, and the repository description adds AI-DLC to the name. The claim is that it works for any team with repeatable processes, naming software, marketing, research, legal and operations.

That is a broad claim and the documentation set is arranged to back it. There is a getting started guide, a workspace adoption guide for bringing the harness into an existing repository, the harness sync guide, a release upgrade guide at docs/releases/v2.10.0-UPGRADE.md that covers rollback options, and a SAFe x AI-DLC methodology guide for planning a multi-issue programme.

The four key commands are the practical entry point: /start-work to begin a ticket with the proper workflow, /pre-pr to validate before a pull request, /end-work to complete a session cleanly, and /check-workflow for a quick status check.

The pattern sources are named too: six Anthropic engineering papers and SAFe methodology itself. Six papers is a small, checkable claim, and it is the right kind of citation for a harness whose main asset is conventions rather than code.

## MIT, two releases on one day, and a homepage that is a person

The licence is MIT with both LICENSE and NOTICE at the root, alongside SECURITY.md, CODE_OF_CONDUCT.md, CONTRIBUTING.md, AGENTS.md and CLAUDE.md. The template ships its own agent instructions, which is consistent with a repository whose entire purpose is to install agent instructions elsewhere.

Release cadence is bursty. v2.11.0 shipped on 2026-07-20 at 11:36 with a knowledge vault, AI-DLC cadence and cross-platform sync, and v2.11.1 shipped the same day at 22:12 as a public-accuracy release, after v2.10.0 in March 2026. The last push was on 2026-07-20, matching the newest tag.

A public-accuracy release the same day as a feature release tells you someone noticed something inaccurate in public documentation and shipped a correction rather than batching it. That is a good habit in a project whose output is text other people follow.

The repository homepage is a personal site rather than a project page, and the DeepWiki link is the documentation route that matters. There are no GitHub releases listed beyond the tags, so the HARNESS_CHANGELOG.yml is the version history to read.

## Conclusion

Adopt safe-agentic-workflow if your team runs repeatable processes and wants the workflow written down once rather than retyped per agent, and start with the provider you already use instead of copying all four. Do not adopt it expecting a runtime or a library, because nothing is installed and what you take is a set of text files plus shell scripts. Verify first which files you have customised and mark them protected in the manifest before you run an update, since the sync path protects only what the manifest lists and the manual path is a raw git checkout.

## FAQ

### What is an agentic workflow?

In this repository it is a three-layer harness: hooks as automatic guardrails such as format checks and blockers, slash commands the user invokes for a defined workflow, and model-invoked skills that load when the agent recognises a pattern. Twenty-four commands and twenty skills sit on those three layers, with eleven SAFe agent profiles on top.

### How do I install safe-agentic-workflow into a project?

It is a template repository, so you use it to create your own harness, then copy the provider directory you use, such as cp -r .claude/ /your-project/.claude/, and run bash scripts/setup-template.sh to replace placeholders like {{TICKET_PREFIX}} and {{PROJECT_NAME}} across all provider files in one pass. Nothing is installed as a runtime dependency.

### Which AI tools does safe-agentic-workflow support?

Claude Code, the Gemini CLI, Codex CLI and the Cursor IDE, each with its own directory in the template. Codex needs both .codex/ and .agents/ copied and is started in natural language rather than with slash commands, while Cursor rules activate from file context and agent roles are invoked with @rule-name.

### How do I update the harness without losing my customisations?

Use the manifest-based sync script: initialise with sync-claude-harness.sh init and manifest init --yes, preview with --dry-run, then apply, narrowing with --scope if you want. The script does not overwrite files you have marked as protected, a capability required since v2.10.0. The manual alternative is to add the harness as a git remote and check out only the directory you need.

### Is agent team orchestration stable in safe-agentic-workflow?

Agent Teams, the multi-agent orchestration with SAFe quality gates, is the one feature the README marks experimental. The Dark Factory for persistent autonomous teams over tmux on remote servers and the Knowledge Vault with its drift-detecting validator are listed without that caveat.

## Sources

- [bybren-llc/safe-agentic-workflow on GitHub](https://github.com/bybren-llc/safe-agentic-workflow)
- [License: MIT](https://github.com/bybren-llc/safe-agentic-workflow/blob/main/LICENSE)
- [Project website](https://jscottgraham.us)
- [README](https://github.com/bybren-llc/safe-agentic-workflow/blob/main/README.md)
- [Releases](https://github.com/bybren-llc/safe-agentic-workflow/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bybren-llc-safe-agentic-workflow
