by boshu2
The operations layer for agentic engineering — portable skills and contracts connecting intent, agents, software factories, and independent judgment.
# Add to your Claude Code skills
git clone https://github.com/boshu2/agentopsLast scanned: 5/26/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-26T07:46:23.789Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}agentops is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by boshu2. The operations layer for agentic engineering — portable skills and contracts connecting intent, agents, software factories, and independent judgment. It has 429 GitHub stars.
Yes. agentops passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/boshu2/agentops" and add it to your Claude Code skills directory (see the Installation section above).
agentops is primarily written in Go. It is open-source under boshu2 on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh agentops against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
AgentOps is the operations layer for agentic engineering. It is a set of
portable skills and evidence contracts that make one coding-agent change
independently judgeable: the context that wrote the code does not get to
declare it done. Your tracker keeps the work, Git keeps the history, and your
coding agents keep running the execution; AgentOps joins them as a
federated integration graph and adds the judgment step. A fresh context reads
the exact change and returns PASS, FAIL, or NOT_PROVEN. The standard
path is one RPI traversal:
RPI -> Plan -> Implement -> fresh Validate -> report and stop
npx skills@latest add boshu2/agentops --all -g
One command installs the skill bundle into every coding agent you use. The
skills run inside your coding agent (Claude Code, Codex, Cursor, …): type
/rpi in that agent's chat, or ask for plan, implement, validate, and
learn by name. No other runtime is required.
Ran it? Tell us what it judged. Open an issue, and paste the verdict.v2 if
you asked validate to persist one:
https://github.com/boshu2/agentops/issues.
Prefer a managed bundle that updates with the release:
# Claude Code
claude plugin marketplace add boshu2/agentops
claude plugin install agentops@agentops-marketplace
# Codex
codex plugin marketplace add boshu2/agentops
codex plugin add agentops@agentops-marketplace
Three install paths:
ao skills link: source-tracked symlinks for contributors
(see Install and day-2 operations).AgentOps ships a PreToolUse policy dispatcher: deterministic guards that block a small set of known-destructive commands (staging the private bead ledger, hand-editing the hash-chained provenance ledger, overwriting installed skill copies) and route you to the correct tool instead. Silent on every clean call; every block is one line.
~/.claude/skills/cc-hooks/scripts/install-hooks.sh once.scripts/install-policy-dispatch.sh once.Disable anytime (/plugin disable agentops, or remove the two PreToolUse
matchers from settings). Policy list and design:
skills/cc-hooks/SKILL.md.
Remove with your runtime's plugin uninstall, or delete the linked skill directories.
Beads is the preferred tracker
(optional; brew install beads). Plan
writes BDD acceptance and DDD ubiquitous
language into the bead;
Implement builds against it; Validate judges a hashed snapshot under
.agents/ao/intents/sha256/. No beads? Plan shapes the caller's issue or chat
text and the runtime snapshots those bytes the same way.
validate must run in a fresh context (not the author session). It can use
the same model as the author or a different one.
The default is one agent, one writer. When you need a fleet,
swarm, agent-native,
ntm, and using-gc
orchestrate multi-agent work. They dispatch; they do not own the verdict.
AgentOps supplies skills and evidence contracts, not another software-factory
runtime or a competing Gas City pack. Install the skills in the agent runtime
used by the factory you choose; its Mayor, coordinator, and workers can then use
plan, implement, test, validate, and the rest of the catalog.
Two factory stacks are supported:
gascity build pack,
the workflow family used by Maintainer City. It owns formulas, roles,
worktrees, dispatch, draining, and run state. The
using-gc skill covers installation, launch,
observation, and recovery.using-flywheel skill covers
provisioning, skill visibility, and the evidence boundary.AgentOps does not wrap either factory or translate factory completion into
semantic PASS. When proof is required, a fresh validate context judges the
exact candidate and evidence.
ao CLIDeterministic checks, inspection, and skill linking. Skip it if you only need
the skills. Install steps (Homebrew or go install), and ao skills link for
tracking skills from a local checkout:
Install and day-2 operations.
Same session that wrote the code also declared victory. AgentOps separates
authorship from judgment: implement produces a candidate; validate must
run in a fresh context and may use a different model. It issues PASS,
FAIL, or NOT_PROVEN.
A single context can share blind spots with the author. Opt into
idea-genie or council
for sealed or multi-judge review. They return a report; an author-distinct
validate context issues the binding result.
Without a fixed behavior and write scope, "done" is whatever the agent
improvised. plan locks acceptance in the bead before anyone builds. Later
phases bind to that digest.
Chat scrolls away. When replay or automation needs durable evidence, validate
writes a content-addressed verdict.v2 under
.agents/ao/verdicts/sha256/ with checked scope, omissions, and evidence refs.
Plain JSON. No hosted service required. Interactive validation does not create
one unless requested.
| Skill | Job |
|---|---|
rpi |
run Plan, Implement, and fresh Validate at most once |
plan |
create the bead (BDD + DDD ubiquitous language) |
implement |
TDD against the bead: RED → GREEN → refactor |
validate |
fresh context (optionally different model); optionally persist verdict.v2 |
Optional later: learn. Strategies:
council, idea-genie,
premortem, postmortem.
AgentOps prefers a smaller skill set you can steer over dozens of near-duplicate skills. Modes and flags change behavior inside one contract.
| Skill | Steer with | Examples |
|---|---|---|
doc |
--mode |
readme, oss, default API/docs; README mode runs a docs-prose (de-slop) pass |
codebase-recon |
mode · view · lens · depth | baseline/delta; emphasize audit or mental model; one domain lens per pass |
idea-genie |
elicit | duel | portfolio vs sealed multi-perspective challenge |
rpi |
bead / intent ref | one full traversal against a frozen bead |
Read the skill's mode table before inventing a sibling skill. Full inventory: Skill Router.
A PASS binds unchanged acceptance, a deterministic subject manifest, complete
changed-path coverage inside write scope, distinct author and validator context
IDs, a freshness attestation, and criterion-level evidence.
Missing identity, mutation, or incomplete coverage → NOT_PROVEN. Proven
out-of-scope change or failed criterion → FAIL.
RPI traversal · CLI · Docs
Contributing: docs/CONTRIBUTING.md. License: Apache-2.0.