# Agent Skills Standard: the repo syncs its own output onto itself

> A CLI that turns coding standards into markdown skills and writes them into each agent's native format, protected by an ownership lockfile and a three-deep backup. Its own tree contains the directories it writes to, its release tags are dated verification stamps rather than versions, and its patch release is about stopping sync from rejecting a repository's LICENSE file.

**HoangNguyen0403/agent-skills-standard** — A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages

- Repository: https://github.com/HoangNguyen0403/agent-skills-standard
- Website: https://www.npmjs.com/package/agent-skills-standard
- Stars: 569 · Forks: 166
- Language: TypeScript
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/hoangnguyen0403-agent-skills-standard

## Release tags are dated stamps and the branch is develop

The three newest releases are named `skillspector-verified-v20261002`, `workflows-v1.1.0` and `skillspector-verified-v20260930`, published on 2026-10-02, 2026-09-30 and 2026-09-30. None of those names carries the CLI version, and two of them are verification stamps with a date in the name rather than version numbers at all.

The version lives elsewhere. The README names `cli-v2.6.5` as the current release, and the root manifest agrees at 2.6.5, but that manifest is named `agent-skills-standard-root` and marked private. The published package is `agent-skills-standard`, and the CLI itself lives in the `cli/` directory of a pnpm workspace whose root pins `pnpm@10.0.0`. So there are three version surfaces: the npm package, the CLI, and a private workspace root.

The default branch is `develop`, and `delete-cli-tags.sh` sits at the repository root, which suggests the tag namespace gets cleaned up by hand.

## The repository is both the source and a sync target

The tool writes native assets into each agent's expected layout: Claude, Roo and OpenCode commands, Codex, Cursor and Trae skills, Gemini TOML commands, Copilot prompts, Antigravity and Kiro workflow files, plus MCP tools for runtime enforcement. Its own tree contains that layout already committed: `.claude/`, `.codex/`, `.agents/`, `.antigravity/`, `.mcp.json`, `.vscode/`, and a `.skillsrc` config at the root, next to both `AGENTS.md` and `CLAUDE.md`.

There is also `AGENTS_LEARNING.md` beside them, and the README insists the point of the tool is to avoid becoming another runtime. `ags` is for setup, sync, validation, MCP wiring and updates, and afterwards the agent reads files that live in your repository and can be customized through `.skillsrc` and `custom_overrides`.

So the project eats its own output. That is the clearest demonstration available that the format works, and it also means a sync run in this repository would be writing into directories that are already under version control.

## Three layers, twenty lines at the top, hundred lines at the bottom

The resolution chain is fixed at three levels: a router table in `AGENTS.md`, a category index in `_INDEX.md`, and a skill in `SKILL.md`. The worked example is TypeScript:

```
1. AGENTS.md (router ~20 lines)
   "Editing *.ts? Check typescript/_INDEX.md"

2. typescript/_INDEX.md (trigger table)
   File Match:  typescript-language  *.ts, *.tsx, tsconfig.json
   Keyword:     typescript-security  validate, sanitize, auth

3. typescript-language/SKILL.md (loaded on demand)
   The actual rules — only when needed.
```

The index is the part that decides anything, and it triggers on two axes: a glob match against the file being edited, and a keyword match against the task. The stated budget is that every skill stays under 100 lines.

The token arithmetic is the pitch. The comparison table puts a 3,600-plus token architect prompt in every chat against a roughly 500 token skill loaded only when relevant, and claims about 25 lines scanned per edit, 85 percent fewer tokens than traditional prompt engineering, and up to 5,000-plus tokens of prompt loss to avoid. The architecture notes point at a Zero-Trust model inspired by Rust Token Killer, and the detailed version lives in `ARCHITECTURE.md`.

## Edit protection, three-deep backups, and a restore path

Sync writes into files a person may also be editing, so the safety machinery is the substance of the tool. Ownership is recorded in `.skills-lock.json` v2. Files the user has modified are preserved and reported rather than silently overwritten.

The preview flags come in three depths:

```bash
ags sync --dry-run
ags sync --dry-run --verbose
ags sync --dry-run --json
```

The first previews what would change, the verbose form lists every affected file path, and the JSON form emits the install plan for CI. Overriding a preserved file is explicit, `ags sync --force <paths...>` overwrites kept files after backing them up automatically, and anything pruned or forced over is copied to `.ags/backups/` with the latest three kept. `ags restore <id>` undoes a destructive change and `ags restore --list` shows what is there.

Uninstall follows the same rule: `ags uninstall [--all] [--agent <agents...>] [--category <categories...>]` removes only owned and unchanged files, preserving edits and backing up first. A file you touched is a file the tool will not delete.

## Nine test stages and twenty-two pinned overrides

The root test script is a chain: the CLI package tests, then evals, freshness, outcome, trace, benchmark, metrics, release and harness. The visible examples run under node with tsx loaded, such as `node --import tsx --test scripts/evals/*.test.ts` and a freshness pass that also sweeps `scripts/freshness/signals/`. Validation has its own aggregate: `validate:all` runs the CLI's own validation followed by a skills audit, an injection audit and a freshness audit.

The pnpm overrides block pins twenty-two entries, several of them to exact versions rather than ranges: hono 4.13.7, fast-uri 3.1.7, js-yaml 5.4.2, vite 8.3.0, postcss 8.5.23, @babel/core 7.29.6. One entry is an alias rather than a version, `lodash` resolved to `npm:lodash-es@^4.17.21`, which swaps a CommonJS package for its ES module build across the whole workspace.

The scoped entries are the interesting part. Two ajv pins split by parent, and two body-parser pins split by the express major, 1.20.6 for express 4 and 2.3.0 for express 5. Three minimatch generations are each mapped to a matching brace-expansion major. That is a workspace being held still deliberately rather than left to float.

## The current patch is about LICENSE, NOTICE and scripts/

The release note at the top of the README is specific about what changed in `cli-v2.6.5`. `ags sync` no longer rejects a repository's own LICENSE and NOTICE files against the release manifests, which means a project that ships its license at the root used to trip the ownership check. The skill validator now accepts package directories under `scripts/`, which the draw.io diagram pipeline needs for its `schema_parsers/`.

That release builds on v2.6.1, described as OWASP Agentic Skills Top 10 hardening, and the named pieces are a skill-content lockfile, an `ags verify` command, enforcing hooks, and secret and dependency scanning. The tree backs part of that up with `.gitleaks.toml` at the root, and the badge row links to code scanning on the repository.

The theme across both entries is that the validator was stricter than the use case. Both fixes relax a check rather than add a feature, which is what a validator-heavy tool does once real repositories start running it.

## A .DS_Store at the root and a PATH note for pnpm installs

Two small things in the tree and the instructions tell you what kind of tool this is. `.DS_Store` is committed at the root of a repository that also ships a `.gitignore`, and the same root carries `benchmark-report.md` and `evals-report.md` beside `benchmarks/` and `artifacts/`, so the measured comparisons are checked in rather than generated on demand.

The version check has a platform-specific footnote. If `ags -V` still reports an old version after a reinstall, the instruction is to check PATH order so that `~/Library/pnpm` comes before `~/Library/pnpm/bin`, run `hash -r`, and check again. Both paths are pnpm locations on macOS, and the documented install is `npx agent-skills-standard@latest`, which does not use pnpm at all.

There is also a non-developer route: the README says that if you are not an engineer you need to run none of the above, describe the idea to your agent instead, and follow `docs/getting-started-product-owner.md`.

## Conclusion

agent-skills-standard takes the token-budget argument seriously and backs it with an ownership model most skill collections skip: a lockfile, preserved edits, scoped backups and a restore path. It suits a team that has written the same rules into every prompt and wants them versioned once, and it does not suit someone who wants the standards enforced rather than offered, since the on-disk format is advisory and the MCP server is an opt-in second layer. Before the first sync, run the dry run, read what the consent prompt offers about MCP and your home directory, and check that your editor's format does not collide with the files it will write into .claude, .codex or .agents.

## FAQ

### What does ags sync do to my repository?

It downloads skills into your agent's folders, records ownership in .skills-lock.json v2, and generates the index. Files you have modified are preserved and reported rather than overwritten, and ags sync --dry-run previews the change, with --verbose listing every path and --json emitting the plan for CI.

### How does the three-layer loading in agent-skills-standard work?

AGENTS.md is a router of about twenty lines, a category _INDEX.md holds a trigger table with a file match and a keyword column, and the matching SKILL.md is loaded only when needed. In the TypeScript example *.ts, *.tsx and tsconfig.json map to typescript-language, while the keywords validate, sanitize and auth map to typescript-security.

### How do I restore or uninstall after an ags sync?

Pruned files and forced overwrites go to .ags/backups/ with the latest three kept, ags restore <id> undoes a destructive change and ags restore --list shows them. ags uninstall [--all] [--agent <agents...>] [--category <categories...>] removes only owned and unchanged files, preserving your edits and backing up first.

### What is the MCP server for in agent-skills-standard?

The CLI distributes skills to disk, and the companion MCP server serves them at runtime as explicit tool calls, which the README frames as closing the gap where an agent reads AGENTS.md but forgets to load the matching SKILL.md, especially in sub-agents. init and sync ask once whether to enable it and at what scope.

## Sources

- [HoangNguyen0403/agent-skills-standard on GitHub](https://github.com/HoangNguyen0403/agent-skills-standard)
- [License: MIT](https://github.com/HoangNguyen0403/agent-skills-standard/blob/develop/LICENSE)
- [Project website](https://www.npmjs.com/package/agent-skills-standard)
- [README](https://github.com/HoangNguyen0403/agent-skills-standard/blob/develop/README.md)
- [Releases](https://github.com/HoangNguyen0403/agent-skills-standard/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/hoangnguyen0403-agent-skills-standard
