惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
C
Cybersecurity and Infrastructure Security Agency CISA
P
Palo Alto Networks Blog
N
News | PayPal Newsroom
L
Lohrmann on Cybersecurity
S
Schneier on Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
IT之家
IT之家
云风的 BLOG
云风的 BLOG
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
C
Cyber Attacks, Cyber Crime and Cyber Security
量子位
人人都是产品经理
人人都是产品经理
S
Securelist
Last Week in AI
Last Week in AI
V
V2EX
Simon Willison's Weblog
Simon Willison's Weblog
AWS News Blog
AWS News Blog
I
Intezer
T
The Exploit Database - CXSecurity.com
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
美团技术团队
Project Zero
Project Zero
博客园 - 叶小钗
Cyberwarzone
Cyberwarzone
A
Arctic Wolf
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
P
Privacy International News Feed
Blog — PlanetScale
Blog — PlanetScale
C
Cisco Blogs
G
GRAHAM CLULEY
V
Vulnerabilities – Threatpost
K
Kaspersky official blog
P
Proofpoint News Feed
NISL@THU
NISL@THU
Latest news
Latest news
Scott Helme
Scott Helme
The Hacker News
The Hacker News
Know Your Adversary
Know Your Adversary
F
Full Disclosure
The Cloudflare Blog
Spread Privacy
Spread Privacy
H
Hacker News: Front Page

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店 GitHub - EdoardoBambini/Agent-Armor-Iaga: AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens. HN Vibes — Week 15, Apr 7–13 2026 GitHub - chojs23/ec: Easy terminal-native 3-way git mergetool vim-like workflow GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - JakOb-dotcom/cloud-sandbox-security-analysis: Technical analysis and Proof of Concept (PoC) regarding environment variable exfiltration in containerized cloud sandboxes via side-channel data leaks. Springboards - Flint Alpha Show HN: A simpler coding agent harness GitHub - audiodude/sudomake-friends GitHub - 256thFission/mini-mythos: OSS clone of Anthropic’s Mythos harness to locate C/C++ memory vulnerabilities Show HN: OpenParallax: OS-level privilege separation for AI agent execution Hacker News Sorted - Chrome 应用商店 Show HN: How to Install Docker on Ubuntu 24.04 LTS: Complete 2026 Guide GitHub - himanshudongre/smriti GitHub - sverrirsig/claude-control: macOS desktop dashboard for monitoring and managing multiple Claude Code sessions GitHub - ory/dockertest: Write better integration tests! Dockertest helps you boot up ephermal docker images for your Go tests with minimal work. Chiral - Chrome 应用商店 Show HN: Two Claudes collaborating through shared memory on a $100 mini-PC GitHub - pmichaillat/latex-cv: Minimalist LaTeX template for academic CVs GitHub - oguzbilgic/posse: A web UI for Anthropic Managed Agents. GitHub - sshiraz/depsly: Dependency risk analysis tool for npm packages ABI Add safari/agent-harness — Safari browser automation via safari-mcp by achiya-automation · Pull Request #212 · HKUDS/CLI-Anything GitHub - Halfblood-Prince/trustcheck: Verify PyPI package attestations and improve Python supply-chain security GitHub - oguzbilgic/kern-ai: Agents that do the work and show it. GitHub - bruits/satteri: High-performance Markdown and MDX processing for the JavaScript ecosystem GitHub - tylergibbs1/feedstock: High-performance web crawler and scraper for TypeScript, powered by Bun and Playwright GitHub - Grimm67123/grimmbot: The self-improving sandboxed and open-source AI agent. With persistent memory and scheduling. GitHub - whitevanillaskies/whitebloom: Local whiteboard that blooms. GitHub - hwdsl2/docker-whisper: Docker image for a self-hosted Whisper speech-to-text server with speaker diarization and OpenAI-compatible transcription and translation APIs. Powered by faster-whisper. Supports all Whisper models, NVIDIA GPU (CUDA) acceleration, JSON/SRT/VTT output, SSE streaming, offline mode, and multi-arch (amd64, arm64). GitHub - yisding/reviewwiggum GitHub - MarwanAlsoltany/serrors: Structured errors for Go: sentinel hierarchies, typed data, custom formatting, and slog integration. GitHub - soatok/age-php GitHub - Luthiraa/markitme GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits GitHub - tombedor/excalicharts GitHub - wh1le/excalidraw-edit: Open and edit .excalidraw files from the terminal. Offline, auto-saves to disk. MalExt Sentry - Malicious Extension Scanner - Chrome 应用商店 GitHub - syi0808/asciianimesvg: Generate animated ASCII art SVGs from text. CLI, Rust library, WASM, and web editor. GitHub - zaina-ml/ml_forge: A visual-based graph node editor for training computer vision models. GitHub - anakin87/llm-rl-environments-lil-course: 🌱 A little course on Reinforcement Learning Environments for evaluating and training Language Models GitHub - takaakit/superpowers-uml: Superpowers-UML modifies Superpowers to ensure a software development workflow in which AI agents design through UML modeling. AdriByte Studio - Sviluppo Web e Soluzioni Digitali GitHub - chouligi/angel-copilot: Your personalized Angel Investment Advisor Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 GitHub - agenteractai/lodmem: Level Of Detail Context Management for Agents GitHub - ostefani/subnetlens: A fast, concurrent network scanner with a TUI and plain-text CLI, built in Go. It discovers live hosts on your network, scans their open ports, resolves hostnames, and fingerprints operating systems—delivered. Cyber Pulse: Agentic Intel - Apps on Google Play Whisper API: Self-Hostable Speech to Text Transcription The Agent-Web Protocol Stack: A Research Thesis GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Show HN: Provepy – A Python decorator that proves your code using Lean and LLMs Show HN: Pardonned.com – A searchable database of US Pardons GitHub - patrickdappollonio/dux: Dux is a terminal UI that lets you run multiple AI coding agents side by side, each in its own git worktree, with full companion terminals, macros, commit generation, and a command palette that knows more tricks than you do. kMC Crystal Simulator Show HN: HyperFlow – A self-improving agent framework built on LangGraph GitHub - stef41/vibescore: 🎵 Grade your vibe-coded project. One command, instant letter grade across security, quality, dependencies, and testing. GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. imgur.com GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. GitHub - nowork-studio/toprank: Open-source Claude Code skills for SEO, SEM, Google Ads GitHub - tacomanator/sash: Lightweight macOS menu bar app for reliably cycling through windows of the current application. Appents | Social Media Management for Product-First Teams GitHub - pnhoang/youtube-spam-blocker: Automatically detects and hides spam messages in YouTube Live chat. Set rate limits, keyword filters, and block repeat offenders. GitHub - decisionnode/DecisionNode: CLI + Local MCP - A shared structured memory store across Claude Code, Cursor, Windsurf, Antigravity, and every MCP client. Semantically queryable. GitHub - AvaCodeSolutions/django-email-learning: An open source Django app for creating email-based learning platforms with IMAP integration and React frontend components. The $100K Gap in Kubernetes Security Tooling Function Calling Harness: From 6.75% to 100%
GitHub - kernalix7/ai-project-setup: AI Agent configuration for my workspace
kernalix7 · 2026-05-15 · via Hacker News: Show HN

Drop one file. Tell your AI to read it. Done.

A single 7,000-line markdown bootstrap that turns Claude Code, ChatGPT Codex CLI, Cursor, and GitHub Copilot into a disciplined teammate — 13-section rules, 5 safety hooks, session-resume, dual-write memory, and bilingual GitHub files. Zero install. One source of truth.

# Fetch the bootstrap file
curl -fsSL https://raw.githubusercontent.com/kernalix7/ai-project-setup/main/AI_PROJECT_SETUP.md > AI_PROJECT_SETUP.md

# Open your AI tool, then say:
#   "Read AI_PROJECT_SETUP.md and execute it."
#   "AI_PROJECT_SETUP.md 읽고 실행해줘"

# 1–3 minutes later, verify:
./tmp-igbkp/verify-setup.sh   # → Pass: 83  Fail: 0  Warn: 0

Stable Latest

license markdown checks scripts stars PRs

Works with

Claude Code Codex CLI Cursor GitHub Copilot MCP Linux macOS Windows

English  ·  한국어  ·  Setup file  ·  Contributing  ·  Security  ·  Changelog


📌 Status: v5.2 stable

ai-project-setup ships a single-file bootstrap (AI_PROJECT_SETUP.md, ~7,600 lines) that any AI coding assistant reads and executes to produce a complete, multi-tool, gitignored AI tooling layout. v5.2 is the first polished GitHub repository release: expanded README, bilingual standard docs, issue/PR templates, and stricter no-footprint .gitignore. v5.1 moved the self-update source from a gist to this repository, so projects on v5.0 or earlier fetch v5.1 once from the legacy gist (frozen as a migration bridge), then all subsequent updates come from here. The artifact is idempotent and self-healing — re-running setup on an existing project repairs drift, force-overwrites stale shipped scripts with .bak backups, and preserves user content (CLAUDE.md sections 1–7 and 11, memory files, project agents).

One file, every AI tool. Drop AI_PROJECT_SETUP.md at your project root, tell the AI to read it, and in 1–3 minutes you have rules, hooks, session-resume, slash commands, default agents, a backup toolkit, and bilingual GitHub standard files — all gitignored so your project git history stays clean. Absolute Rule #19: AI tooling leaves zero footprint in your project's git history.


📑 Table of contents


🎯 Why this exists

Every new project, you re-do the same AI setup. This file does it once, deterministically, across multiple AI tools:

What you used to do every time What this file does automatically
Write CLAUDE.md / AGENTS.md / .cursorrules by hand ✅ 13 sections generated + 3-tool symlink sync
Block dangerous commands (rm -rf /, force push, secret leaks) ✅ Kernel-level PreToolUse hook
Set up session resume for /clear · crash · rate-limit ✅ 3-tier auto-save (current/handoff/recovery)
Configure memory · slash commands · default agents ✅ 10+ commands + 4 agents installed
Create README / SECURITY / CONTRIBUTING / CHANGELOG ✅ Bilingual EN/KO generation
Stop AI tool files from leaking into git history ✅ 22 .gitignore entries auto-applied

⚡ Quick start

One-liner (any git repository):

curl -fsSL https://raw.githubusercontent.com/kernalix7/ai-project-setup/main/AI_PROJECT_SETUP.md \
  > AI_PROJECT_SETUP.md

Then open your AI tool and tell it to execute the file:

claude       # or: codex, cursor ., or VS Code with Copilot

Tell the AI (English or Korean both work):

Read AI_PROJECT_SETUP.md and execute it.

AI_PROJECT_SETUP.md 읽고 실행해줘

Wait 1–3 minutes, then verify:

./tmp-igbkp/verify-setup.sh
# → Pass: 83  Fail: 0  Warn: 0 — All required checks passed

That's it. Everything created is gitignored — your project's git history stays clean.


📦 What gets created

your-project/
|-- CLAUDE.md              -> symlink to .priv-storage/CLAUDE.md
|-- AGENTS.md              -> symlink to .priv-storage/CLAUDE.md   # Codex / Copilot
|-- .cursorrules           -> symlink to .priv-storage/CLAUDE.md   # Cursor
|-- WORK_STATUS.md         -> current work state (project content)
|
|-- .priv-storage/         [gitignored] all AI tooling lives here
|   |-- CLAUDE.md                   # 13-section project rules (~10kB cap)
|   |-- CLAUDE.local.md             # per-developer overrides
|   |-- POST_SETUP_INDEX.md         # 50-line pointer (saves ~25k tokens/session)
|   |-- AI_PROJECT_SETUP.md         # archived, never re-read
|   |-- memory/                     # dual-written to ~/.claude/projects/ (cross-machine sync)
|   |-- sessions/                   # current.md, handoff-{date}.md, recovery.md, read-log.tsv
|   `-- .claude/
|       |-- settings.json           # statusLine + 5 hooks + outputStyle
|       |-- hooks/                  # PreToolUse / PostToolUse / SessionStart / PreCompact / Stop
|       |-- agents/                 # tech-lead, explorer, code-reviewer, log-analyzer
|       |-- commands/               # 10+ slash commands
|       |-- skills/ and rules/      # on-demand knowledge
|       |-- output-styles/terse.md
|       `-- statusline              # context percent / rate-limit ETA
|
|-- tmp-igbkp/             [gitignored] backup and verification toolkit (9 scripts)
|   |-- verify-setup.sh             # one-command health check (83+ assertions)
|   |-- smoke-test-hooks.sh         # mock-payload hook validation
|   |-- secret-guard.sh             # 14-pattern pre-commit scanner
|   |-- archive.sh / restore.sh     # AES-256-CBC + PBKDF2 600k iterations
|   |-- purge-history.sh            # git-filter-repo wrapper
|   |-- setup-worktree.sh           # bridges worktrees to main .priv-storage/
|   |-- codex-relay-{check,run}.sh  # Claude <-> Codex parallel lanes
|   `-- uninstall.sh                # safe rollback with backup
|
|-- .mcp.json              [gitignored] MCP server registry (env-var refs only)
|
|-- README.md, SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, CHANGELOG.md
|-- docs/{README,SECURITY,CONTRIBUTING,CODE_OF_CONDUCT,CHANGELOG}.ko.md
`-- .github/{ISSUE_TEMPLATE/,PULL_REQUEST_TEMPLATE.md}

Only WORK_STATUS.md, GitHub standard files, the docs/ Korean mirrors, and .github/ get committed. Everything inside .priv-storage/ and tmp-igbkp/ is gitignored by design.


🔄 Lifecycle

[1. INITIAL SETUP]
  Prompt: "Read AI_PROJECT_SETUP.md and execute it."
  - Auto-detects Scenario A/B/C
  - Creates everything above, then runs STEP 6
  - Archives AI_PROJECT_SETUP.md into .priv-storage/
  - Prints "Setup Complete" only if automode-validate.sh passes

        |
        v

[2. NORMAL SESSIONS]
  - SessionStart hook injects last handoff + current.md tail
  - AI reads CLAUDE.md (~200 lines) + POST_SETUP_INDEX.md (~50)
  - Does not re-read the 7000-line setup file, saving ~25k tokens/session
  - PreToolUse blocks dangerous commands + oversized Reads
  - PostToolUse appends to current.md + dual-writes memory
  - Stop hook writes handoff-{date}.md
  - PreCompact hook writes recovery.md (best-effort)

        |
        v

[3. CRASH / RATE-LIMIT / /clear]
  - Next session: SessionStart auto-loads handoff + recovery
  - AI resumes without "where were we?" questions

        |
        v

[4. SELF-UPDATE]
  Trigger: "update setup" or Korean "AI_PROJECT_SETUP 업데이트해"
  - Fetches latest from GitHub raw URL
  - Replaces archived setup file
  - Force-overwrites all 30+ shipped scripts with .bak backup
  - Re-runs automode-validate gate
  - Reports: "Updated: vOLD -> vNEW. Recommend /clear."

Three setup scenarios

Scenario When What the AI does
A — existing .priv-storage/ exists or real CLAUDE.md at root Update/repair in place. Force-overwrite shipped scripts (with .bak), preserve user content.
B — empty/new No .priv-storage/, no CLAUDE.md at root Full setup from scratch — STEP 0 detection → STEPs 1–12 → archive.
C — broken Files at root that look like CLAUDE.md but aren't, or partial leftover state Detect, classify, convert to canonical layout, then bridge into A's STEPs 4–12.

✨ Key features

🛡️ Safety hooks (Claude Code)

  • PreToolUse blocks rm -rf /, force push, git add of gitignored AI files, eval, base64 | sh, curl http://, ~/.ssh reads, fork bombs
  • Blocks oversized Read (>1000 lines without offset/limit)
  • Blocks commit messages mentioning AI tooling
  • PostToolUse appends to sessions/current.md + dual-writes memory
  • SessionStart auto-loads last handoff + current.md tail + recovery
  • PreCompact writes recovery.md snapshot (best-effort)
  • Stop writes handoff-{date}.md + archives old handoffs

🔄 Resilience

  • 3-tier session log: current.md (every call) → handoff-{date}.md (session end) → recovery.md (pre-compact)
  • Memory dual-write: every memory file mirrors to ~/.claude/projects/{path-encoded}/memory/ → new laptop restores instantly
  • Idempotent setup: SHA256 markers in .priv-storage/.setup-step-{N}.done
  • Force-overwrite of shipped scripts on every update (with .bak) — stale bugs auto-resolve
  • 83+ assertion verify-setup.sh — single-command health check
  • smoke-test-hooks.sh fires each hook with mock payload

🤖 Default agents (token-efficient)

  • tech-lead — auto-evaluates complexity, forms teams (modules ≥ 2 OR files ≥ 5 OR cross-module work)
  • explorer — read-only codebase search, returns summaries, preserves main context window
  • code-reviewer — security/correctness/style review
  • log-analyzer — parses crash logs / hook-error logs
  • Subagent delegation MANDATORY above thresholds (>3 files, >500 lines, codebase-wide search)

⚡ Slash commands

  • /status — current task + recent activity summary
  • /health — runs verify-setup.sh + smoke-test-hooks.sh
  • /recover — load latest handoff + recovery into context
  • /ship — pre-commit secret-guard + clean check
  • /save — manual snapshot to current.md
  • /clean — rotate old handoffs, prune sessions
  • /codex-{brief,review,fix,relay-status} — Claude ↔ Codex parallel lanes

💰 Token discipline (Absolute Rule #20)

  • CLAUDE.md hard-capped at 16k chars (WARN) / 32k (FAIL)
  • PreToolUse BLOCKS Read of >1000-line files without offset/limit
  • Subagent delegation MANDATORY above thresholds
  • read-log.tsv flags duplicate Reads within a session
  • Auto-extends from terse → verbose only when reasoning is requested
  • Expected: 30–60% token reduction vs naive AI-pair-programming

🔐 Secret guard

  • 14 regex patterns: AKIA…, ASIA…, sk-…, sk-proj-…, ghp_…, ghs_…, gho_…, glpat-…, xox[abprs]-…, sk_live_…, rk_live_…, AIza…, JWTs, -----BEGIN PRIVATE KEY-----
  • Special .mcp.json rule — env-var references only
  • Per-line # secret-guard:ignore allow-list for false positives
  • --install-hook mode wires into git pre-commit
  • AES-256-CBC + PBKDF2 600k for archived backups

🌏 Multi-tool parity

  • Same CLAUDE.md drives Claude Code, Codex CLI, Cursor, Copilot via symlinks
  • All three rule files (CLAUDE.md / AGENTS.md / .cursorrules) point to the same target — atomic updates
  • MCP servers registered via gitignored .mcp.json (env-var refs only)
  • VS Code settings symlinked for Copilot integration
  • Hooks are Claude Code-specific; other tools get policy-only enforcement

🔀 Cross-AI Codex relay (v4.9+, Claude Code only)

  • When codex CLI is on PATH, Claude offloads implementation to Codex while keeping planning/review authority
  • Flow: Claude (plan)/codex-brief → Codex (implement) → Claude (/codex-review) → Codex (/codex-fix)
  • v5.0+ parallel per-agent relay lanes for TeamCreate work
  • Conflict prevention: disjoint allowed-paths per lane via paths_overlap check
  • Lockfiles in .priv-storage/sessions/codex-relay/locks/ + active.tsv ledger

🤝 Supported AI tools

Tool Min version Reads Hook support
Claude Code 2.0+ CLAUDE.md ✅ Full (5 hook events)
ChatGPT Codex CLI 0.10+ AGENTS.mdCLAUDE.md ❌ Policy-only
Cursor 0.40+ .cursorrulesCLAUDE.md ❌ Policy-only
GitHub Copilot 1.150+ AGENTS.md ❌ Policy-only
claude.ai (web) current upload CLAUDE.md ❌ Policy-only
Any MCP-aware tool depends ❌ Policy-only

Policy-only = rules enforced via prompt content. No kernel-level block, but the AI follows them because they're in the rules file it reads.


⚖️ Comparison

This file .cursorrules only Custom CLAUDE.md Per-tool CLI tool
Single source of truth across tools ❌ Cursor only ❌ Claude only
Zero install
Safety hooks (kernel-level) manual maybe
Session resume on crash manual maybe
Token discipline enforcement manual
Self-update from upstream
Bilingual GitHub files
AI-tooling leak prevention manual
Cross-AI relay (Claude ↔ Codex)
Works on Linux / macOS / Windows depends

📚 Documentation

Document What's inside
AI_PROJECT_SETUP.md The artifact — 7,600-line bootstrap that creates everything
docs/README.ko.md This README in Korean
CONTRIBUTING.md · 한국어 Development setup, version-bump checklist, PR conventions
SECURITY.md · 한국어 Security disclosure process, secret-guard patterns
CODE_OF_CONDUCT.md · 한국어 Contributor Covenant v2.1
CHANGELOG.md · 한국어 Full version history

🔁 Self-update

Trigger via natural language: "AI_PROJECT_SETUP 업데이트해" / "update AI_PROJECT_SETUP" / "fetch latest setup".

The AI:

  1. Fetches https://raw.githubusercontent.com/kernalix7/ai-project-setup/main/AI_PROJECT_SETUP.md
  2. Compares Last Updated line and version against local copy
  3. If newer: replaces .priv-storage/AI_PROJECT_SETUP.md, force-overwrites all 30+ shipped scripts with .bak backup
  4. Merges template sections of CLAUDE.md (§8/9/10/12/13) while preserving project content (§1–7, §11)
  5. Re-runs the validator gate
  6. Reports Updated: vOLD → vNEW. Force-patched N shipped scripts. Recommend /clear.

Single command, no re-run prompt (since v4.6+).

v5.0 → v5.1 migration: v5.1 moved the update source from a gist to this repository. Projects on v5.0 or earlier fetch v5.1 once from the legacy gist (frozen at v5.1 as a migration bridge), then all subsequent updates come from this repository.


🍴 Forking

To point forks at your own repo for self-update:

  1. Edit AI_PROJECT_SETUP.md — replace both occurrences of kernalix7/ai-project-setup with {your-user}/{your-repo}:
    • The repo URL in the Source of Truth block
    • The raw URL in the same block and in the self-update protocol Step 2
  2. Optionally remove the legacy gist URL block (only needed when migrating users from pre-v5.1).
  3. Commit and push to your fork's main branch.

For downstream project customization, edit the generated .priv-storage/CLAUDE.md directly — sections 1–7 and 11 are preserved across self-updates.


❓ FAQ

Why a single 7,000-line markdown file instead of a CLI tool?

AI coding assistants natively read markdown. A CLI tool needs installation, version management, and platform support. A markdown file works everywhere any AI works — Linux, macOS, Windows, containers, browser-based agents — with zero install.

Doesn't 7,000 lines blow up my context window?

Only on initial setup (~25k tokens, one time). After setup, the file is archived and a 50-line POST_SETUP_INDEX.md becomes the entry point. Normal sessions consume ~200 lines of CLAUDE.md + the index — about 4k tokens.

Is it safe that nothing gets committed? My CI/CD doesn't see hooks/agents.

Correct, and intentional. AI tooling is per-developer ergonomics; CI/CD runs against your code, not your AI config. Teammates who don't use AI see no change. Those who do run setup themselves and get the same config from this same source.

Will this work with [some new AI tool that doesn't exist yet]?

If the tool reads markdown rules files (CLAUDE.md / AGENTS.md / .cursorrules / similar), yes — point it at any of the three symlinks. If it supports MCP, it'll find .mcp.json automatically. Hooks are Claude Code-specific.

How do I uninstall?
./tmp-igbkp/uninstall.sh

Backs up everything to tmp-igbkp/uninstall-backup-{ts}/ before removing. Add --clean-gitignore to also remove the AI-tooling block from .gitignore.

What about Windows?

Works on Git Bash, WSL, and MSYS2. Native PowerShell is not supported for hooks (they're bash scripts), but the rules file itself is plain markdown and works with any AI tool on Windows.

Can I use this with multiple AI tools simultaneously in the same project?

Yes — that's the design. Claude Code reads CLAUDE.md, Codex/Copilot read AGENTS.md, Cursor reads .cursorrules. All three are symlinks to the same .priv-storage/CLAUDE.md so updates are atomic.

I found a bug / want a feature.

Open an issue or PR at https://github.com/kernalix7/ai-project-setup. See CONTRIBUTING.md.


🗺️ Roadmap

  • v5.3.devcontainer/ template, GitHub Actions workflow for setup verification
  • v5.4 — Native Windows PowerShell hooks (experimental)
  • v6.0 — Pluggable rule modules (.priv-storage/.claude/rules/<lang>/)

See CHANGELOG.md for version history.


⭐ Star history

Star History Chart

💛 Support

If ai-project-setup saved you setup time:

Ko-fi Fairy

Ko-fi handles international cards and PayPal; fairy.hada.io is a Korean tipping platform. Bug reports, PRs, and ⭐ stars on the repo are equally appreciated and free.


📄 License

MIT — Kim DaeHyun (kernalix7@kodenet.io)