agents-md
Audits and edits agent instruction files, verifies repository commands, and migrates repositories to AGENTS.md as the single shared source. Use when asked to "improve my AGENTS.md", "migrate CLAUDE.md to AGENTS.md", or make instructions work across agents.
How do I install this agent skill?
npx skills add https://github.com/mblode/agent-skills --skill agents-mdIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill audits and refactors agent instruction files like AGENTS.md. It involves reading local configuration files, executing repository-defined commands (such as test and build scripts), and potentially installing additional skills. While these actions are central to its purpose, they create opportunities for indirect prompt injection from repository content and arbitrary command execution from untrusted project scripts.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
- Runlayerwarn
6/6 files flagged
- ZeroLeakswarn
1 finding · Score: 69/100
What does this agent skill do?
AGENTS.md Setup and Audit
- IS: wiring a repo so every agent tool in use reads the same rules, then auditing, scoring, refactoring, and writing the AGENTS.md / CLAUDE.md / CLAUDE.local.md files agents load at session start.
- IS NOT: authoring SKILL.md files (use
agent-skills-creator), project docs or READMEs (useghostwriter), or mining session history (use the externalcadence-adviseskill where installed; this skill audits the file as-is).
AGENTS.md files are execution contracts, not knowledge bases. Two tests catch the two ways a line fails.
- Dead weight: "Would removing this cause the agent to make a mistake?" If no, cut it; bloat makes agents ignore the rules that matter.
- Harmful precision: "Is this wrong on any plausible task in this repo?" A prohibition that is wrong one task in ten is still obeyed on that task, and the agent cannot tell that this is the exception. State the outcome you want and let the surrounding code pick the path.
NEVER write commentsbecomesmatch the comment density of the file you are editing: shorter, no exception list to maintain, and correct in a densely commented file without being told.
Absolutes still earn their place for safety, data loss, format contracts, and rules this repo's agents have actually been observed to break.
AGENTS.md is the tool-agnostic source of truth. Claude Code's built-in agents-md mod supports it directly. Use AGENTS.md at the root and in scoped subdirectories, without CLAUDE.md wrappers or symlinks. The default claude-md-or-agents-md mode yields when project Claude instruction files exist on the root-to-working-directory path; see references/project-setup.md for migration, settings, and loader limits. Preserve unique instructions before removing old files. User-level and managed Claude files are separate from repository migration.
Choose a Mode
- Repo has no agent instructions, or targets a tool it is not wired for -> Setup:
references/project-setup.mddecides which files exist and which tool reads each one, then Writing From Scratch below fills the root file, then Audit scores it. - A file exists and the question is quality -> Audit, below.
- A file exists and is bloated, stale, or scored badly -> Refactor,
references/refactor-workflow.md.
Reference Files
| File | Read when |
|---|---|
references/project-setup.md | Setting a repo up for Claude Code, Codex, and Cursor; deciding which files exist and what each tool actually loads |
references/quick-checklist.md | Every audit; default 12-check triage |
references/quality-criteria.md | Quick audit fails, file is high-risk, or full scoring requested |
references/refactor-workflow.md | File is bloated (root over ~150 lines), stale, or below target |
references/root-content-guidance.md | Deciding what stays in root and where moved content goes so it still loads |
references/repo-evals.md | Measuring whether instruction changes make agents faster or more correct in this repo |
references/templates.md | Drafting or rebuilding a file from scratch |
Writing From Scratch
The content step of Setup, and the whole job when the repo is already wired and only the file is missing. Skip the audit. Gather real commands from the manifest (package.json, Makefile, CI config), pick a skeleton from references/templates.md, fill it with verified commands and known gotchas, then validate against references/quick-checklist.md before delivering.
Audit Workflow
Copy this checklist to track progress:
Audit Progress:
- [ ] Step 1: Discover files
- [ ] Step 2: Select audit mode (quick or full)
- [ ] Step 3: Run audit and score
- [ ] Step 4: Report findings with score table
- [ ] Step 5: Propose minimal diffs
- [ ] Step 6: Validate changes
- [ ] Step 7: Apply and report before/after scores
Step 1: Discover files
find . \( -name "AGENTS.md" -o -name "AGENTS.override.md" -o -name "CLAUDE.md" -o -name "CLAUDE.local.md" \) -not -path "*/node_modules/*" 2>/dev/null | sort
ls -la CLAUDE.md .claude/rules .cursor/rules 2>/dev/null
Also check ~/.claude/CLAUDE.md and ~/.codex/AGENTS.md; both load in every repo. ls -la CLAUDE.md tells you whether it is a symlink, an @AGENTS.md pointer, or a second copy, and a copy is a finding on its own. For monorepos, include workspace-level files. Audit each level independently: root holds universal rules, child files hold directory-specific rules (see what each tool loads in references/project-setup.md).
Step 2: Select audit mode
- Quick (default): 12 checks from
references/quick-checklist.md, target >= 10/12. - Full: 49 checks from
references/quality-criteria.md, target >= 91% of applicable points (grade A). Use when the quick audit fails, the file gates a high-risk repo, or full scoring is requested.
Step 3: Run audit and score
Score each root file independently; exclude N/A checks from the denominator.
Step 4: Report findings
Output a concise report before any edits:
## AGENTS.md Audit Report
| File | Mode | Score | Grade | Key Issues |
|------|------|-------|-------|------------|
| ./AGENTS.md | Quick | 6/10 | Fail | Missing test command, stale path, doc-heavy section |
Every issue in the table must map to a Step 5 diff; no vague findings.
Step 5: Propose minimal diffs
In priority order:
- Fix broken or stale commands; bugs, not style.
- Remove generic, duplicate, or obsolete guidance, restatements of what the harness already does, and facts auto-memory owns.
- Diff each project skill (
.claude/skills/,.agents/skills/,skills/) against the root file. Where both state the same fact or procedure, keep one copy (the skill for a procedure, root for what every task needs) and leave a one-line pointer in the other. - Rewrite blanket prohibitions as the outcome they were protecting; keep the absolute only where the harmful-precision test clears it.
- Move detail needed in fewer than ~30% of tasks to a location that loads on demand: a nested
AGENTS.mdin the directory it concerns, a path-scoped.claude/rules/*.md, or a skill (not an@import; see Gotchas). - Add emphasis ("IMPORTANT:", "YOU MUST") only on critical rules agents skip, one line at a time.
For an audit request, propose the diffs. A request to improve, refactor, or write the file already authorizes those edits; apply them and report the rationale.
Step 6: Validate changes
- Smoke-run core commands (
dev,test,build,lint/typecheck) where the environment allows; otherwise verify the script exists in the manifest and note the limitation. - Check every linked and
@imported path resolves. In a Claude Code session,/contextlists the memory files that actually loaded; a file absent from that list is not loaded, whatever the tree looks like. - Confirm no contradictory rules remain across levels (home, root, child), against installed skills (
.claude/skills/,.agents/skills/,~/.claude/skills/), or against harness defaults. Where the overlap is deliberate, the file must say who wins, so the agent is told precedence instead of arbitrating it every task. - Issues found: revise, then validate again. Never proceed on "looks right".
Step 7: Apply and report
Apply approved edits, re-score with the same checklist, report before/after scores and line counts. Per future PR, add at most one new gotcha, only if it prevented or fixed a real mistake.
Make Drift a Gate
Step 6 proves the file once; the next rename breaks it again and nothing notices. When the repo has a check script, add one that fails when an instruction file (every AGENTS.md, any review rubric, every project SKILL.md) names something the repo no longer has:
- Every
<package-manager> run <script>names a script in the root manifest, or in the workspace a--filternames. - Every relative Markdown link resolves.
- Every backtick path names a tracked or non-ignored file or directory, relative to the root or to the instruction file's own directory.
- Every backtick camelCase or PascalCase identifier appears somewhere in source.
The identifier check proves existence, not visibility: a documented middleware made private or moved behind another API still passes. Say so in the script's header so nobody reads a pass as more than it is. If the repo keeps eval tasks with setup patches (references/repo-evals.md), the same gate checks each patch still applies to HEAD. Run it in the pre-push or CI check, not as advice.
Gotchas
- A project
CLAUDE.md,.claude/CLAUDE.md, orCLAUDE.local.mdcan suppress the default AGENTS.md fallback across the project. Removing only the root wrapper may not fix loading. Check the built-in mod and/configProject instructions, then verify loaded files. @importmoves text, not cost, and reaches Claude Code only. Imported files expand into context at launch (a 400-line file split into five imports still loads 400 lines), Codex and Cursor see the line as plain text, an import inside a code span or fence never loads, chains stop at four hops, and an external import from AGENTS.md needs an approval the mod cannot raise. Each failure is silent, so a rule every tool must obey stays inline.- Nested files do not load the same way per tool. Claude Code loads a subdirectory's file when it reads files there; Codex concatenates only the files on the path from repo root to the launch directory. A rule that lives only in
packages/api/AGENTS.mdis invisible to a Codex session started at the root and to any Claude Code task that never opens that subtree. Universal rules go in root. - Codex stops adding instruction files once the concatenated total reaches
project_doc_max_bytes(32 KiB by default), root first. A bloated root file silently crowds out every nested file beneath it. - Project-specific commands in
~/.claude/CLAUDE.mdor~/.codex/AGENTS.mdload in every repo, so one project'snpm run devbecomes noise or a wrong command everywhere else. - A committed
AGENTS.override.mdreplacesAGENTS.mdin that directory for Codex, so one checked in by accident silently swaps the rule set while the AGENTS.md everyone edits looks correct. - Audit
CLAUDE.local.mdonly for broken commands and contradictions with the shared file; it's gitignored personal config, and it exists only in the worktree that created it. - Don't strip emphasis markers (IMPORTANT, YOU MUST) during a density cut; they exist because plain phrasing was already ignored once. When many lines carry them, none stands out, so the fix for a new skipped rule is emphasis on that one line, not another pass over the file.
- Content auto-memory owns (user preferences, personal feedback, evolving project status) collects in
CLAUDE.mdfrom the old#-hotkey habit. It loads every session, isn't repo knowledge, and drifts silently because nothing in the codebase contradicts it. Cut it to memory orCLAUDE.local.md. - A passing quick score doesn't prove commands run; stale commands hide behind checklist passes. Step 6 smoke-runs aren't optional.
- Don't rewrite a whole file when targeted diffs would pass; full rewrites destroy battle-tested wording and inflate review burden.
Related Skills
agent-skills-creator: authoring and improving SKILL.md files (different format and rules).- External
cadence-adviseskill where installed: proposes AGENTS.md/CLAUDE.md edits from observed session history; complements this skill's file-first audit. ghostwriter: human-facing documentation; AGENTS.md content that belongs in docs should move there.codebase-architecture(Harden mode): the rest of the repo an agent works in. A rule a linter can enforce belongs there as an exit code, not here as prose, and it owns the docs tree this file indexes.- Claude Code's
/doctorcheckup: proposes trims for a checked-inCLAUDE.md, cutting what Claude can derive from the codebase and migrating always-loaded procedures into skills and nested files. Complementary automated triage; it doesn't run the commands, so it never replaces Step 6.
Maintenance only: evals/evals.json contains regression scenarios for changes to this skill; it does not load during a user task.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/mblode/agent-skills/agents-md">View agents-md on skillZs</a>