Moved. This plugin now lives in
ibraheem4/claude-marketplace→plugins/agent-skills, history included. This repo is archived; install with/plugin install agent-skills@ibraheem4.
Behavioral guardrails and engineering workflows for AI coding agents. Each skill combats a specific agent failure mode — scope creep, blind retries, missing tests, hallucinated fixes — with step-by-step processes grounded in industry practices.
Draws from Microsoft's Engineering Playbook, Google's SWE Book, Stripe's API design, and Netflix's resilience engineering.
| Tool | Config File | Status |
|---|---|---|
| Claude Code | CLAUDE.md, or AGENTS.md where there is none |
Supported |
| Codex | AGENTS.md |
Supported |
| Gemini CLI | GEMINI.md |
Supported |
| Goose | AGENTS.md / .goosehints |
Supported |
| OpenCode | — | Planned |
AI agents fail differently than humans:
| Agent Failure Mode | Human Equivalent | Skill That Fixes It |
|---|---|---|
| Writes 500 lines without testing | Cowboy coding | incremental-implementation |
| Retries the same failing approach | Stubbornness | superpowers:systematic-debugging |
| Adds features nobody asked for | Scope creep | scope-discipline |
| Generates code with subtle security holes | Inexperience | security-and-hardening |
| Leaves debug logs and TODOs in code | Carelessness | shipping-and-launch |
| Doesn't read existing code before editing | Arrogance | code-review-and-quality |
| Over-engineers with premature abstractions | Resume-driven dev | code-health-and-maintainability |
| Ignores error messages, guesses at fixes | Panic | superpowers:systematic-debugging |
| Deletes a repo that had unpushed work | Carelessness | safe-repo-removal |
| Kills a process that immediately respawns | Whack-a-mole | find-hidden-services |
| Reads the biggest log first | Chasing noise | triage-failing-fleet |
| Deletes committed files as "build output" | Overreach | disk-reclaim |
| Hardcodes one company into a reusable skill | Short-termism | work-summary |
| Calls unread mail a to-do list | Mistaking volume for signal | work-queue |
- incremental-implementation — Never write more than 50 lines without running tests. Commit after every working change. [Google: small CLs; Microsoft: atomic commits]
- scope-discipline — Surface assumptions, then do exactly what was asked. No extra features, no unsolicited improvements. [Google: one logical change per CL]
- api-and-interface-design — Design the interface before the implementation. Consistent naming, minimal surface area, hard to misuse. [Stripe: resource-oriented design, consistent error structure]
- context-engineering — Read before writing, load deliberately, verify don't assume. Manage what enters the context window. [Agent-specific]
- agent-instruction-files — One instruction file per repo and per user, reached from each CLI's documented path by symlink or import. Never
~/AGENTS.md. [Agent-specific]
- verify-before-cite — A document is a claim, not evidence. Check the path, role or resource lives before following or repeating it. [Agent-specific]
- false-verification-signals — A cached run is a replay, a sandboxed probe is about the sandbox, and zero rows can mean no scope. Confirm the check ran. [Agent-specific]
- performance-optimization — Measure first, optimize the bottleneck, verify the improvement. Never optimize without profiling data. [Google: measure-first; Stripe: latency budgets]
- code-review-and-quality — Two-pass review: design pass, then code quality pass. Label findings by severity. [Microsoft: two-pass model; Google: readability reviews]
- security-and-hardening — DevSecOps shift-left checks: input validation, auth, secrets, dependencies. [Microsoft: SDL; OWASP Top 10]
- threat-modeling — STRIDE threat analysis on data flow diagrams. Identify threats at design time, not after deployment. [Microsoft: SDL]
- code-health-and-maintainability — Remove dead code. Improve names. Reduce nesting. Three similar lines are better than one wrong abstraction. [Google: readability; Microsoft: code health]
- shipping-and-launch — Pre-flight checklist: tests pass, no secrets, no debug logs, no TODOs without tickets. [Microsoft: Engineering Fundamentals Checklist]
- git-workflow-and-versioning — Conventional commits, branch naming, semantic versioning. Every commit compiles and passes tests. [Google: trunk-based development]
- review-response — Address every review comment: fix, acknowledge, or explain. Batch fixes, reply individually, resolve threads. [Google: review turnaround]
- pr-lifecycle — Shepherd a PR to merge-readiness: monitor CI, fix failures, handle feedback, loop until green. Never merge automatically. [Microsoft/Google: CI gates]
- graceful-degradation — Every external call needs a timeout. Classify dependencies as critical or optional. Degrade, don't crash. [Netflix: Hystrix, circuit breakers]
- observability-and-monitoring — Structured logs, RED metrics, correlation IDs. Ship monitoring with the feature. [Google: SRE]
- session-handoff — Write a continuation prompt a cold session can act on: absolute paths, real shas, verified vs assumed, one next step. Closing a session also updates tickets, the system of record and internal and external docs, then lints. [Agent-specific]
- work-summary — Summarize one workspace's activity for any period across ten sources and post it. Profile-driven. [Agent-specific]
- work-queue — The inverse: what is owed, not what is done. Nine sources into six ranked bands. Read-only, profile-driven. [Agent-specific]
- agent-operating-principles — Core behaviors: surface assumptions, stop when confused, don't be sycophantic, admit uncertainty. [Agent-specific]
- skill-authoring — Create and revise reusable skills: the contract, the invariants, and a validator. [Agent-specific]
- engineering-fundamentals-checklist — Sprint 0 setup: CI, tests, branch protection, security scanning, monitoring. [Microsoft: Engineering Fundamentals Playbook]
Three groups left this repo when it reached 49 skills, which is more descriptions than any one selection context should carry. Each is a plugin of its own:
| Plugin | Covers |
|---|---|
| frontend-skills | UI engineering, accessibility, Tailwind v4, component reference, scroll motion |
| infra-skills | AWS, GCP, DNS, mail auth, SSO, OAuth providers, preview environments, and workstation operations |
| delivery-skills | Deploy, QA, release — and the governance chains: trust review and the shape → orient → implement → review → release pipeline |
What stays here is the part that applies whatever you are building: how to work, what to check, and what to refuse.
Another plugin already does it better. Adopting beats duplicating: two skills matching the same trigger means unpredictable selection, and the weaker one wins half the time.
| Not here | Use instead | Why |
|---|---|---|
| test-driven-development | superpowers:test-driven-development |
320 lines to our 128, with an explicit verify-RED / verify-GREEN step ours lacked. Our Google test-size classification survives in engineering-fundamentals-checklist |
| debugging-and-error-recovery | superpowers:systematic-debugging |
Four phases with root-cause investigation and pattern analysis, against our six linear steps |
Checked and kept rather than deferred, because the overlap was apparent and not real:
review-response—superpowers:receiving-code-reviewcovers judgment (when to push back, forbidden responses); ours covers thread hygiene (reply to every comment, resolve threads)frontend-ui-engineering—frontend-designis 71 lines of aesthetic direction; ours is engineering plus accessibility, components, responsive and data-viz referencesfalse-verification-signals—superpowers:verification-before-completionis the first-order rule (run it, read it, then claim). Ours is the second-order one: six cases where you did run it, did read it, and were still deceived
- Agent failure modes, not human advice — Each skill targets a specific way agents break
- Process over prose — Step-by-step workflows, not knowledge dumps
- Anti-rationalization — Common excuses for skipping steps with factual rebuttals
- Industry-grounded — Every practice is cited to a public engineering playbook or book
- Tool-agnostic core — Skills work across Claude Code, Codex, and Gemini CLI
cp -r skills/ your-project/.claude/skills/cp -r skills/ your-project/.codex/skills/cp -r skills/ your-project/.gemini/skills/See CONTRIBUTING.md for guidelines. See docs/skill-anatomy.md for the skill template.
MIT