The Agent Engineering Kit

Safety

Guardrails that don’t depend on the agent remembering.

Rules tell an agent what to do. These three parts enforce some of it from outside the conversation: every edit comes out formatted, secrets stay unread, and commits that break your checks are stopped, whichever agent (or person) made them.

§01 · The parts

Format, guard, check.

format-hook

Formats every file your agent edits, using your project’s own formatter.

What it does
A small Node script plus an after-edit hook for the tools that document one (Claude Code, Cursor, Windsurf). After each edit it runs the formatter your project already has (Prettier, Biome, ruff, gofmt, rustfmt, …). It never blocks the agent and does nothing if no formatter is found.
When it’s used
Automatically, after every file edit in those tools. For other tools, use the optional pre-commit check.
Example
Nothing to trigger. Edited files simply come out formatted.
Preset
Recommended and Everything
Needs
Node.js 18+ (the hook is a small Node script); Your project's formatter (optional)

secret-guard

Stops your agent from reading .env files and secrets/.

What it does
Keeps agents out of .env files and a secrets/ folder in each tool's own way: deny rules in Claude Code's settings, and ignore files for Cursor, Gemini CLI, Windsurf, Kiro, Junie, Augment and Aider. For tools that can't be configured from the repo, the installer tells you what to set.
When it’s used
Always active once installed.
Example
If an agent tries to read .env, the read is refused.
Preset
Recommended and Everything

checks

Runs your project's checks before every commit, whichever AI tool (or person) made the change.

What it does
A small script, .agent-kit/check.sh, that runs the commands you list in .agent-kit/checks.conf (format, lint, type-check, test) and refuses commits that change files listed in .agent-kit/protected, such as acceptance tests an agent must not weaken. A git pre-commit hook runs it, so it works the same for every tool. If your repo already manages hooks (husky, lefthook, pre-commit), the installer shows the one line to add instead.
When it’s used
On every git commit, and whenever the verify skill runs.
Example
git commit → "check test: npm test … FAILED" → the commit is stopped until the tests pass.
Preset
Everything (opt-in)
Needs
git; A POSIX shell (Git for Windows includes one)

§02 · By tool

What each tool supports.

✓ means the installer sets it up. “note” means it can’t be set safely from the project, so the preview tells you exactly what to do. “—” means the tool has no way to do it; the pre-commit checks still apply. The reason behind every note.

Format on edit and secret guard by tool
ToolFormat on editSecret guard
Claude Codeyesyes
OpenAI Codexnotenote
Cursoryesyes
GitHub Copilotnotenote
Gemini CLInoteyes
Google Antigravitynotenote
Grok Buildnot supportednote
Windsurf / Devin Desktopyesyes
Kironoteyes
opencodenotenote
Kilo Codenot supportednote
JetBrains Junienot supportedyes
Augment Codenoteyes
Clinenot supportednote
Zednot supportednote
Ampnot supportednote
Warpnot supportednote
Aidernot supportedyes
Any other agent (AGENTS.md)not supportednot supported

§03 · Limits

What these can’t do.

  1. Hooks aren’t shared by clones. .git/hooks stays local, so each developer installs the pre-commit check.
  2. It can be skipped. git commit --no-verify skips the pre-commit check.
  3. The check list is code. checks.conf runs on every commit, so review changes to it like code.
  4. The format hook runs your formatter. That’s the same trust you give a project when you let an agent edit it. In a project you don’t trust, a global install would run that project’s formatter when an agent edits a file there.
  5. Existing hook managers win. With husky, lefthook, the pre-commit framework or core.hooksPath, the installer writes no hook and shows you the one line to add instead.