Discover, install, and author Spec Kit bundles via `specify bundle`. USE FOR: searching/showing/listing bundles, installing/updating/removing a bundle (a curated set of extensions/presets/integrations/workflows), validating a bundle manifest, building a distributable bundle artifact, initializing a project and installing a bundle, managing bundle catalog sources. DO NOT USE FOR: individual extensions/presets/integrations/workflows (use their respective skills).
Check the local environment for Spec Kit by running `specify check` (and `specify version`). USE FOR: verifying required tools are installed, diagnosing a broken spec-kit setup, reporting CLI version/feature capabilities. DO NOT USE FOR: installing or upgrading the CLI itself (use the speckit-self skill).
Detect and install the Spec Kit `specify` CLI that every other speckit skill depends on. USE FOR: checking whether `specify` is installed/on PATH, installing it when missing, fixing "command not found: specify", confirming the CLI is new enough (>= 0.11). DO NOT USE FOR: upgrading an already-installed CLI to a newer release (use speckit-self) or verifying project tools (use speckit-check).
Manage Spec Kit extensions via `specify extension`. USE FOR: listing installed extensions as text or JSON, installing/removing/updating extensions, searching the extension catalog, showing extension info, enabling/disabling extensions, setting resolution priority, or managing extension catalogs. DO NOT USE FOR: artifact composition stacks (use speckit-artifact), presets (use speckit-preset), bundles (use speckit-bundle), or workflows (use speckit-workflow).
Scaffold a Spec Kit (spec-driven development) project for GitHub Copilot by running `specify init --integration copilot --integration-options="--skills"`. USE FOR: starting a new spec-kit project, bootstrapping spec-driven development in an existing repo, installing spec-kit templates/scripts/commands for Copilot. DO NOT USE FOR: managing extensions/presets/bundles of an already-initialized project (use the speckit-extension / speckit-preset / speckit-bundle skills instead).
Manage Spec Kit presets via `specify preset`. USE FOR: listing installed presets as text or JSON, installing/removing presets, searching the preset catalog, showing preset info, resolving which template a preset name maps to, enabling/disabling presets, setting resolution priority, or managing preset catalogs. DO NOT USE FOR: full artifact composition stacks (use speckit-artifact), extensions (use speckit-extension), bundles (use speckit-bundle), or workflows (use speckit-workflow).
Check for and apply Spec Kit CLI updates via `specify self`. USE FOR: checking whether a newer specify-cli release is available, previewing an upgrade with --dry-run, upgrading the CLI in place (optionally to a pinned tag). DO NOT USE FOR: checking project tools/integrations (use speckit-check) or managing extensions/presets/integrations/workflows.
Manage and run Spec Kit automation workflows via `specify workflow`. USE FOR: running a workflow by ID or local YAML, resuming a paused/failed run, checking run status, listing/installing/removing workflows, searching the workflow catalog, showing a workflow step graph. DO NOT USE FOR: extensions (use speckit-extension), presets (use speckit-preset), or bundles (use speckit-bundle).
Manage Spec Kit workflow step types via `specify workflow step`. USE FOR: listing built-in and custom workflow step types, installing/removing a custom step type from a catalog, searching/showing step-type info, managing step-type catalog sources. DO NOT USE FOR: running or installing whole workflows (use speckit-workflow), or bundles (use speckit-bundle).
gh-aw-threat-detection is the threat detection component for GitHub Agentic Workflows (gh-aw). It is a Go CLI (threat-detect) that analyzes artifacts produced by AI agents — prompts, agent output, git patches, comment memory — and decides whether to allow or block the downstream safe-outputs job. The component runs in two main contexts: It detects three categories: prompt injection, secret leak, and malicious patch, and emits a strict JSON contract. Run these from the repo root. They are the canonical entry points…
How to fetch the latest github/gh-aw release binary — either as the gh CLI extension (gh aw ...) or as a raw platform binary downloaded from GitHub Releases — including how to resolve the latest tag, pick the right asset, and verify its checksum.
How to manually regenerate the compiled agentic workflow .lock.yml files when the gh-aw Version Check workflow reports version drift. All workflows track the newest github/gh-aw release or prerelease.
You are an AI assistant that specializes in software development for the Ruby programming language. Regarding scripts that manage the environment or start the app, follow the guidance given by GitHub in their Scripts to Rule Them All blog post. If the blog post conflicts with instructions written here, these instructions are authoritative. For example: Bootstrap the Ruby project by running: Ensure all unit tests pass by running the following: This project requires X% test coverage of code, not including:
The Empty Repos Workflow is a GitHub Actions workflow that scans organizations for empty repositories and README-only repositories, generating monthly reports as GitHub issues. Always reference these instructions first and fallback to search or bash commands only when you encounter unexpected information that does not match the info here.
gh-aw-threat-detection is the threat detection component for GitHub Agentic Workflows (gh-aw). It is a Go CLI (threat-detect) that analyzes artifacts produced by AI agents — prompts, agent output, git patches, comment memory — and decides whether to allow or block the downstream safe-outputs job. The component runs in two main contexts: It detects three categories: prompt injection, secret leak, and malicious patch, and emits a strict JSON contract. Run these from the repo root. They are the canonical entry points…
Use these instructions when working in this repository. This is a beginner course repo for the GitHub Copilot app. The canonical sample is samples/book-app-web: a frontend-only book collection used to practice review, tests, browser preview, issues, and pull requests. Do not edit chapter README files unless the user asks for chapter content changes. Keep changes small and beginner-readable. samples/book-app-web is a Vite, React, TypeScript, and Vitest app. It has no backend, database, or external API. Do not add those. The…
Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.
CLAUDE.md or AGENTS.md?
CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.
What is a skill?
A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.
Can I search my own team's files too?
Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.