Skip to content
Back to skills

Ai Config To Project

ASecurity

Adapts a governed project's architecture rules, config, overrides, and AGENTS.md after ai-eng init. Manual only. Writes a proposal page and stops until the person says yes, then runs ai-eng adapt apply. Trigger for "/ai-config-to-project", "adapt this project", "the init rules are wrong for this repo".

  • 60 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
ai-agentsgoshellsecurity

Works with

  • claude code
  • cursor
  • cli

Security analysis

A100/100

Scanned October 7, 2026

npx -y skills add arcasilesgroup/ai-engineering --skill ai-config-to-project --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ai Config To Project?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ai Config To Project
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/arcasilesgroup-ai-config-to-project/badge)](https://www.skillsdirectory.com/skills/arcasilesgroup-ai-config-to-project)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ai-config-to-project
description: >-
  Adapts a governed project's architecture rules, config, overrides, and AGENTS.md
  after ai-eng init. Manual only. Writes a proposal page and stops until the person
  says yes, then runs ai-eng adapt apply. Trigger for "/ai-config-to-project",
  "adapt this project", "the init rules are wrong for this repo".
disable-model-invocation: true
license: Apache-2.0
---

# Adapt this project to ai-engineering

If the person did not invoke this skill by name, stop. Do not write a file. Do not run a command.

This skill is the manual door. `disable-model-invocation: true` is the Claude Code latch. The sentence above is the latch for every other host. Do not claim that Cursor, Pi, or Codex honor the frontmatter field.

## What you may change, and how

Read the tree. Propose. Stop. The person says approve, ok, or go. Then run `ai-eng adapt apply`.

Do not Edit or Write these files yourself. The session fence denies it, and that denial stays:

- `.ai-engineering/arch.rules.json`
- `.ai-engineering/config.toml`
- `.ai-engineering/overrides.toml`
- `.ai-engineering/ai-eng.lock`

`ai-eng adapt apply` is the writer. It checks the page hash, refuses an empty `user.name`, refuses an override without `until`, and commits with `Approved-by:`.

## The page

Write `.ai-engineering/config-proposal.html` in the artifact shell (the same tokens as `templates/brainstorm.html.tpl`, including the scroll-spy script). The page shows each diff in words a person can refuse.

The machine-readable payload is one JSON object inside the page. Keys, only these, sorted:

- `AGENTS.md`
- `.ai-engineering/arch.rules.json`
- `.ai-engineering/config.toml`
- `.ai-engineering/overrides.toml`

```html
<meta name="ai-eng-proposal-sha256" content="<sha256 of the script body>">
<script type="application/json" id="payload">…</script>
```

The sha256 is the hex digest of the exact script body. `<` inside that body is the six characters `\u003c`. If you change the body after stamping the hash, apply refuses.

## Survivors

Survivors that a proposal must keep: Security, Lifecycle, Anti-drift, Voice.

Security is the hook, linter, and secrets floor. Lifecycle is the spoken yes and the agent running the command. Anti-drift is the line that deletes a rule the code already states. Voice is the pointer to `ai-write`, not a copy of the standard.

KISS, YAGNI, DRY, SOLID, and Clean Code stay only when the proposal names the check that fails when they are broken. A slogan with no check leaves.

Build and test commands come from this tree. Run them. Do not copy another repo's command line.

Layer names come from directories that exist here. A second run starts from the files on disk. It does not restore the framework's `cli` / `guards` / `chain` layers.

## Overrides

Every `[[guard.off]]` block in the proposal has `name`, `reason`, and `until` (a date). Show that block on the page as the dangerous one. No `until` means you do not include the block. Apply will refuse it anyway.

## After the yes

Run `ai-eng adapt apply` from the repo root. Do not pass `--no-verify`. If it refuses, show the line and stop.

The page uses the artifact design system in [ai-brainstorm › references/artifact-design.md](../ai-brainstorm/references/artifact-design.md). Copy that document's whole CSS block and the scroll-spy script verbatim — tokens, layout rules and components, not tokens alone. Do not invent a second style.

## Lifecycle

Lane: any
Writes: .ai-engineering/config-proposal.html
Read by: the person who approves, and ai-eng adapt apply
Dies: when the next run rewrites the page
Next: none

Source: ai-engineering (own), Apache-2.0.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…