by osovv
GRACE (Graph-RAG Anchored Code Engineering): open Agent Skills for contract-driven AI code generation with semantic markup, knowledge graphs, and support for Claude Code, Codex CLI, and Kilo Code.
# Add to your Claude Code skills
git clone https://github.com/osovv/grace-marketplaceGuides for using ai agents skills like grace-marketplace.
Last scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T15:44:27.673Z",
"npmAuditRan": true,
"pipAuditRan": true
}grace-marketplace is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by osovv. GRACE (Graph-RAG Anchored Code Engineering): open Agent Skills for contract-driven AI code generation with semantic markup, knowledge graphs, and support for Claude Code, Codex CLI, and Kilo Code. It has 239 GitHub stars.
Yes. grace-marketplace passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/osovv/grace-marketplace" and add it to your Claude Code skills directory (see the Installation section above).
grace-marketplace is primarily written in TypeScript. It is open-source under osovv on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh grace-marketplace against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
GRACE means Graph-RAG Anchored Code Engineering: a contract-first AI engineering methodology built around semantic markup, .grace XML artifacts, knowledge-graph navigation, assertions, scopes, and log-driven verification.
This repository ships the GRACE skills plus the optional grace CLI. It is a packaging and distribution repository, not an end-user application.
Current packaged version: 4.0.4
skills/grace/*plugins/grace/skills/grace/*.claude-plugin/marketplace.jsonplugins/grace/.claude-plugin/plugin.jsonopenpackage.yml@osovv/grace-cliGRACE 4 uses .grace as the durable project model:
| Area | Purpose |
|---|---|
.grace/context/*.xml |
Requirements, technology, principles, deployment, and UX constraints |
.grace/graph/index.xml + routed graph docs |
Current graph projection source for GD-*, M-*, and DF-* anchors |
.grace/verification/index.xml + routed verification docs |
Current verification projection source for deterministic V-M-* entries |
.grace/changes/active/C-* |
Active GraceChangeSpec, optional design context, and GraceChangePlan bundles |
.grace/changes/archive/C-* |
Applied, rejected, cancelled, or superseded change bundles |
| Source/test files with GRACE markup | File-local contracts, links, and semantic block anchors |
GRACE 4 does not dual-validate legacy GRACE 3 project docs as current state. Existing GRACE 3 projects use $grace-migrate; the CLI validates the generated .grace result but does not convert legacy docs itself.
Verification commands run from the project root by default. A V-M-* entry may declare one contained project-relative <Cwd>packages/example</Cwd> while keeping <TestFiles><File>...</File></TestFiles> paths project-root-relative. Absolute paths, .. escapes, and symlink escapes fail closed.
TypeScript/JavaScript semantic analysis is bundled and compiler-backed. Governed Python and Dart files require their respective runtimes on PATH; Python export analysis is exact when a static __all__ is present (including Unicode identifiers) and otherwise emits heuristic confidence. A missing runtime fails closed with actionable analysis.runtime-missing; an installed adapter that fails emits analysis.adapter-failed. Neither failure state is presented as exact MODULE_MAP parity.
Install skills first. The CLI is optional but recommended once skills are installed.
opkg install gh@osovv/grace-marketplace
opkg install gh@osovv/grace-marketplace -g
opkg install gh@osovv/grace-marketplace --platforms claude-code
/plugin marketplace add osovv/grace-marketplace
/plugin install grace@grace-marketplace
git clone https://github.com/osovv/grace-marketplace
cp -r grace-marketplace/skills/grace/grace-* /path/to/your/agent/skills/
Requires bun on PATH. GRACE skills invoke the installed stable grace binary directly; they do not default to bunx, npx, or a prerelease dist-tag.
# Install the current stable release from npm `latest`
bun add -g @osovv/grace-cli
grace --version
grace lint --path /path/to/grace4-project
For a new GRACE 4 project:
$grace-init to create .grace..grace/context artifacts with your agent.$grace-spec for a change.$grace-plan after spec approval.grace lint --path /path/to/project --assertions current.grace lint --path /path/to/project --change C-ID --assertions baseline before execution; add --run-commands when the baseline declares MustPassCommand.grace status --path /path/to/project --json.$grace-execute and choose sequential or parallel-safe mode. Parallel-safe mode additionally requires grace lint --path /path/to/project --parallel-preflight.grace lint --path /path/to/project --change C-ID --assertions final; add --run-commands when the target declares MustPassCommand.Existing GRACE 3 projects should run $grace-migrate and review the migration report before writing .grace artifacts.
Migration cleanup is separately gated: successful current lint, fresh status proving GRACE 4 with no integrity errors, git/worktree inspection, exact cleanup paths, and explicit cleanup confirmation are mandatory. Dirty or non-git cleanup requires an additional acknowledgement naming that risk; any cleanup failure stops without automatic destructive retry.
| Skill | Purpose |
|---|---|
grace-init |
Bootstrap the .grace skeleton, templates, and agent guidance |
grace-spec |
Create an approved GRACE 4 change spec and optional design context |
grace-plan |
Design assertions, scopes, tasks, and verification gates from an approved spec |
grace-execute |
Execute the approved plan in sequential or parallel-safe mode |
grace-refactor |
Rename, move, split, merge, and extract modules without artifact drift |
grace-setup-subagents |
Scaffold GRACE worker and reviewer presets |
grace-fix |
Debug issues from graph, contracts, tests, traces, and semantic blocks |
grace-refresh |
Detect drift and propose reconciliation changes |
grace-status |
Report .grace health and suggest the next safe action |
grace-ask |
Answer architecture and implementation questions from .grace artifacts |
grace-cli |
Use the optional grace binary as a fast lint and artifact-query layer |
grace-explainer |
Explain the GRACE methodology itself |
grace-verification |
Build and maintain .grace/verification entries and evidence |
grace-reviewer |
Review semantic integrity, projections, scopes, and verification quality |
grace-migrate |
Agent-applied GRACE 3 to GRACE 4 migration with CLI validation |
| Command | What It Does |
|---|---|
grace lint --path <root> --assertions current |
Run the pre-implementation full-project check, including baselines of active approved changes; do not use it as post-edit target/final evidence |
grace lint --path <root> --change C-ID --assertions baseline [--run-commands] |
Validate the immutable selected baseline before implementation; command assertions run only when explicitly enabled |
grace lint --path <root> --change C-ID --assertions target --run-commands |
Validate selected target assertions and explicitly opt into MustPassCommand execution |
grace lint --path <root> --change C-ID --assertions final [--run-commands] |
Run the final full-project gate, evaluate the selected target, and keep unrelated approved baselines active without re-evaluating the selected baseline |
grace lint --path <root> --parallel-preflight |
Run the explicit approved-plan scope coexistence gate required for parallel-safe execution |
grace status --path <root> |
Report durable health, stale plans, scope conflicts, and explained/unexplained observed git drift |
grace module find <query> --path <root> |
Search graph projection modules by id, path, text, dependency, or verification id |
grace module show <id-or-path> --path <root> |
Show graph projection context and linked file-local markup |
grace module show <id> --with verification --path <root> |
Include matching deterministic V-M-* verification entries |
grace verification find <query> --path <root> |
Search verification projection entries |
grace verification show <id-or-module> --path <root> |
Show one verification entry and module context |
grace file show <path> --path <root> |
Show file-local MODULE_CONTRACT, MODULE_MAP, and CHANGE_SUMMARY |
MustPassCommand entries are leaf project evidence such as tests, typecheck, build, format, or package checks. Do not nest grace lint, grace status, or another GRACE lifecycle command inside plan assertions; selected target/final lint is the external orchestration gate.
Output modes:
grace lint: text, jsongrace status: text, jsongrace module find: table, jsongrace module show: text, jsongrace verification find: table, jsongrace verification show: text, jsongrace file show: text, jsonLint, status, and projection-backed navigation fail closed: invalid options, invalid grammar, malformed active assertions/scopes, duplicate ownership, missing routed files, or ambiguous targets produce structured results or a nonzero error envelope. JSON command failures emit one stable { "schemaVersion": "1.0.0", "ok": false, "error": { ... } } envelope on stdout; text failures emit one concise actionable line without a stack trace.
Prefer this order when narrowing scope:
.grace/graph/index.xml for graph document routing.M-* and DF-* anchors..grace/verification/index.xml for verification routing.V-M-* entries..grace/changes/active/C-* for in-flight specs and plans.LINKS:, START_MODULE_CONTRACT, START_CONTRACT:, and START_BLOCK_.Common anchors:
GD-* graph document wrappersM-* module IDsDF-* data-flow IDsVD-* verification document wrappersV-M-* verification IDsC-* change bundlesT-* implementation plan tasks| Path | Purpose |
|---|---|
skills/grace/* |
Canonical skill sources |
plugins/grace/skills/grace/* |
Packaged mirror used for marketplace distribution |
.claude-plugin/marketplace.json |
Marketplace entry and publi |