
Company News
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
aidevops
Advanced tools
AI DevOps Framework - AI-assisted development workflows, code quality, and deployment automation

aidevops.sh is an OpenCode plugin and AI DevOps framework for carrying work from intent to a verified outcome. It combines specialist agents, durable repository knowledge, safe Git workflows, model routing, operational automation, and service integrations for software, infrastructure, business, marketing, content, research, and creative production.
Instead of treating every job as an isolated chat, aidevops gives people and AI agents a shared operating system: the right context is loaded on demand, work is isolated, consequential actions are gated, evidence is retained, and useful lessons improve later work.
One conversation, autonomous project delivery, with security, teamwork, token efficiency, and quality control built in.
Maximum useful value for your time and money. aidevops is built for the gap between “the model can probably do this” and “the work is done, verified, safe, and worth the cost.”
The “100x more capable” goal is an ambition to substantiate, not a guaranteed or
measured result. The canonical purpose and decision criteria are in
.agents/aidevops/purpose.md.
npm install -g aidevops && aidevops updateaidevops, ~/.aidevops/agents/AGENTS.md, runtime commands and skillssimple, standard, and thinking workload tiersaidevops status # Installation, runtime and storage health
aidevops init # Add aidevops conventions to a repository
aidevops update # Update the framework and registered projects
aidevops features # Discover framework features
aidevops repos # Manage registered projects
aidevops skills # Discover available workflows and capabilities
aidevops security # Security posture, hygiene and supply-chain checks
aidevops metrics generate # Refresh local repository metrics
In an AI session:
/onboarding
/skills recommend "TASK"
/full-loop "Implement and ship the requested change"
/pulse
/report-render report.md
Exact source inventory: 17 main agents, 2,273 sub agents, 2,066 helper scripts, 108 slash commands.
These are tracked source modules and entry points, not simultaneously running
agents. Audit the inventory with
bash .agents/scripts/readme-helper.sh counts --inventory; counting and hero
maintenance rules live in DESIGN.md.
| Area | What aidevops provides |
|---|---|
| Software delivery | Planning, implementation, debugging, review, CI, releases, deployment, and maintenance through linked worktrees and evidence gates |
| Autonomous operations | Pulse supervision, workers, missions, routines, scheduling, diagnostics, recovery, and budget-aware concurrency |
| Knowledge and continuity | Repository-owned tasks, plans, decisions, evidence, memory, knowledge ingestion, search, and session handoffs |
| Security and privacy | Secret hygiene, prompt-injection defence, source-access approvals, supply-chain checks, operation verification, Vault, and audit trails |
| Infrastructure | Hosting, DNS, networking, containers, cloud platforms, local development, monitoring, deployment, and object storage guidance |
| Product and business | Product strategy, PRDs, analytics, onboarding, monetisation, accounting, invoices, reports, and operational routines |
| Growth and communication | SEO/GEO, content, PR, email, outreach, paid ads, CRO, social workflows, and communications platforms |
| Creative production | Design systems, UI, browser/mobile verification, images, 3D/CAD, audio, video, animation, documents, and report exports |
| Extensibility | Custom agents, imported skills, private agent sources, MCPs, API helpers, OpenAPI exploration, and project bundles |
The domain index is the human-readable map from user intent to specialist guidance. The generated capability registry separately records runtime readiness requirements.
Catalogue is not readiness. A listed capability may still require local deployment, compatible runtime support, installation, configuration, authentication, authorization, network reachability, or explicit operator approval. aidevops checks these states before provider actions and falls back rather than pretending unavailable tooling worked.
User intent
↓
Build+ or a domain primary
↓
Focused guidance + capability-readiness check
↓
Linked worktree, bounded operation, or approved service action
↓
Runtime evidence + the narrowest applicable quality gates
↓
PR / report / artifact / operational receipt
↓
Authority-aware merge, publication, handoff, or follow-up
/full-loop keeps one interactive owner responsible for a development task from
implementation through verification and PR completion. The lifecycle uses fresh
linked worktrees, exact-head checks, review evidence, protected merge helpers,
and durable cleanup receipts.
Repository authority controls the terminal path:
Releases pin an immutable source snapshot, coordinate through a repository-wide publisher lane, bind provenance to the exact tag, and reconcile publication and deployment evidence. See full-loop, Git workflow, and release coordination.
Start with orchestration, worker discipline, and routines.
The repository owns durable work. TODO.md, plans, decisions, evidence, and
progress remain useful even if a forge conversation or AI session disappears.
GitHub, GitLab, Gitea, and Forgejo are linked execution surfaces, not the sole
source of truth.
TODO.md and todo/ hold tasks, PRDs, plans, dependencies, and verification state._knowledge/ holds curated repository-local source material.See knowledge plane, memory, and self-improvement.
aidevops keeps routing provider-neutral. Canonical simple, standard, and
thinking tiers describe workload needs; runtime adapters map those tiers to
available models and accounts. Stronger models are reserved for consequential
judgement, architecture, and synthesis, while bounded work uses the cheapest
capable route.
Progressive disclosure loads only the relevant agents, references, and tools. TOON registries, compact terminal summaries, semantic code search, context bundles, prompt caching, and compaction checkpoints reduce unnecessary context without hiding required evidence. Model comparisons and sealed historical replay can inform routing, but cannot silently rewrite production policy.
See model routing, context efficiency, and model-effort evaluation.
Build+ is the default for development, systems, and applications. Domain primaries add focused judgement while retaining the same applicable safety, authority, and verification boundaries.
| Agent | Focus |
|---|---|
| 3D Modelling | Editable 3D creation, parametric CAD, reconstruction, configurable products, and rendering |
| Audio | Music composition, arrangement, sound design, editing, mixing, and reproducible audio projects |
| Automate | Scheduling, dispatch, monitoring, routines, and background orchestration |
| Build+ | Planning and full-loop delivery for code, apps, systems, CI, releases, and DevOps |
| Business | Company operations, strategy, accounting, finance, invoices, and management reporting |
| Content | Writing, images, social, multi-channel stories, and content production coordination |
| Health | Evidence-aware health, fitness, nutrition, and wellness guidance |
| Legal | Legal research, contracts, privacy, compliance, and GDPR guidance |
| Marketing-Sales | Campaigns, CRM, email, outreach, paid ads, direct response, and CRO |
| PR | Earned media, newsworthiness, journalist research, media lists, and coverage tracking |
| Private Local AI | Sensitive investigations using verified privacy-first and local-compute boundaries |
| Product | Product strategy, validation, PRDs, roadmaps, onboarding, growth, and analytics |
| Reports | Evidence contracts, decision-ready reports, exporters, citations, and routine handoffs |
| Research | Technical, market, competitive, and source-grounded research |
| SEO | Technical SEO, GEO/AI search, keyword research, content analysis, schema, and search data |
| Vault | Protected-data classification, encrypted stores, fleet trust, secure sync, and lock policy |
| Video | Editing, compositing, grading, animation, source projects, and verified delivery |
Specialists under .agents/tools/, .agents/services/, .agents/workflows/,
and .agents/reference/ are loaded on demand. Use /skills recommend "TASK" or
the OpenCode agent picker rather than memorising the catalogue.
| Domain | Examples |
|---|---|
| Development | Code, architecture, reviews, testing, accessibility, performance, APIs, databases, mobile, extensions |
| Infrastructure | Hosting, Cloudflare, Coolify, Vercel, Cloudron, containers, remote compute, DNS, VPNs, local HTTPS |
| Storage and backups | Backblaze B2, IDrive E2, Wasabi, S3-compatible inventories, Cloudron backup freshness |
| Security | Secrets, dependency risk, prompt injection, source approvals, access reviews, incident response, Vault |
| Product | Validation, roadmaps, UX, analytics, feature flags, experiments, onboarding, monetisation |
| Business and finance | Strategy, accounting, QuickFile, receipts, reconciliation, forecasts, invoices, procurement |
| Marketing and sales | Paid ads, direct response, CRO, CRM, lead generation, cold outreach, campaign operations |
| Search and content | SEO, GEO, AI visibility, GSC, keywords, entities, schema, articles, newsletters, social publishing |
| PR and communications | News research, journalist fit, media lists, press releases, coverage, chat and team interfaces |
| Design and creative | DESIGN.md, brand systems, UI, email/decks, browser QA, images, 3D/CAD, video, audio, voice |
| Documents and reports | OCR, extraction, Markdown-first reports, HTML, PDF, DOCX, slide profiles, citations, evidence ledgers |
| Personal operations | Calendar, health, macOS diagnostics, productivity, recurring checks, private/local research |
This table describes coverage, not live credentials or provider availability.
Use capability-readiness-helper.py query through the documented workflow when a
task depends on an external runtime or service.
aidevops assumes agents may have powerful local and remote access. Security is part of normal work rather than a final checklist.
aidevops secret or private configuration, never pasted into chat or committed.aidevops secret set NAME
aidevops security
aidevops security status
aidevops security scan
aidevops source-access status
Vault adds protected-data classes, local encrypted stores, provider-routing labels, device trust, fleet lock/unlock policy, secure sync guidance, and approval-aware task metadata. It cannot protect information after that information is decrypted into a third-party model prompt, and it cannot recover a lost passphrase. Review Vault boundaries before using protected data.
Reports keep Markdown or JSON as the canonical source, then derive styled HTML, PDF, DOCX, or slide-profile outputs. Shared contracts cover citations, source cards, evidence states, executive summaries, action prompts, and recurring handoffs. Domain report guidance supports development, business, marketing, and SEO/GEO work.
/report-render report.md
See reports and the versioned
_reports/examples/ previews.
DESIGN.md conventions, brand identity, visual concepts, distinctive UI, component guidance, previews, and accessibility verification.Creative work preserves originals, editable projects, dependencies, licences, decisions, technical checks, and perceptual review where the runtime supports it. Start with creative production.
aidevops combines CLI tools, shell/Python/TypeScript helpers, direct APIs, OpenAPI exploration, browser automation, and on-demand MCP servers. MCPs remain disconnected until an approved specialist needs them, reducing idle processes, tool-schema context, and accidental authority.
Integration families include:
aidevops skill add owner/repo
aidevops skill list
aidevops skill check
aidevops skill scan NAME
aidevops sources add /path/to/private-agent-repo
aidevops sources sync
Imported skills retain source and update metadata, pass through security checks, and are adapted to aidevops conventions rather than copied blindly. Private agent repositories can deploy organization- or client-specific guidance beside the shared framework without publishing it.
Custom agents progress through three tiers:
| Tier | Location | Purpose |
|---|---|---|
| Draft | ~/.aidevops/agents/draft/ | Experimental and evaluation-stage capabilities |
| Custom | ~/.aidevops/agents/custom/ | Durable private user or organization capabilities |
| Shared | .agents/ | Reviewed open-source framework capabilities |
npm install -g aidevops && aidevops update
bun install -g aidevops && aidevops update
brew install marcusquinn/tap/aidevops && aidevops update
bash <(curl -fsSL https://aidevops.sh/install)
git clone https://github.com/marcusquinn/aidevops.git ~/Git/aidevops
~/Git/aidevops/setup.sh
Setup deploys the framework under ~/.aidevops/agents/, installs the CLI,
configures detected supported runtimes, and offers optional tools. Existing
personal settings and custom agents are preserved.
/onboarding for account-level setup.aidevops init inside the repository./setup-git when the repository needs platform-specific secrets or workflows./skills recommend "TASK" to discover a route.Initialize selected features when a repository needs less than the default set:
aidevops init planning
aidevops init planning,git-workflow,code-quality
aidevops init deployment-context
aidevops init wordpress-context
Depending on selected features and existing files, initialization can add:
.aidevops.json for repository feature and workflow metadata..agents/AGENTS.md for project-specific AI guidance.TODO.md and todo/ for tasks, plans, PRDs, and verification state.DESIGN.md for repositories with a detected interface.Repository registration lives in ~/.config/aidevops/repos.json; updates can
then check initialized projects for framework and template drift.
| Goal | Entry point |
|---|---|
| Discover capabilities | /skills recommend "TASK" or aidevops skills |
| Define a complex objective | /define, /goals, /mission |
| Plan implementation | /show-plan, PRD/task workflows, TODO.md |
| Implement through PR | /full-loop "TASK" |
| Review code or a PR | /review, /cross-review |
| Run repository checks | .agents/scripts/linters-local.sh --changed |
| Supervise autonomous work | /pulse, /dashboard, /runners |
| Create a recurring operation | /routine |
| Work with protected data | /vault |
| Audit SEO/GEO | /seo-audit, /seo-geo |
| Learn browser work | /auto-browse |
| Produce an editable artifact | /3d-modelling, /video, /audio, /design-artifact |
| Render a report | /report-render |
| Capture or recall a lesson | /remember, /recall, /patterns |
Runtime command names may be namespaced, such as /aidevops-full-loop, where a
client reserves or groups slash commands differently. OpenCode exposes main
agents in its agent picker.
| File | Purpose |
|---|---|
~/.config/aidevops/config.jsonc | Framework updates, models, safety, quality, orchestration, and paths |
~/.config/aidevops/settings.json | User preferences and onboarding state |
~/.config/aidevops/repos.json | Registered repositories, platforms, bundles, Pulse, and context metadata |
.aidevops.json | Repository-local feature and workflow configuration |
configs/*.json.txt | Safe committed templates for service configuration |
configs/*.json | Gitignored working service configuration |
aidevops config list
aidevops config validate
aidevops config set updates.auto_update false
Precedence is AIDEVOPS_* environment variables, then user configuration, then
built-in defaults. Store secrets with aidevops secret; do not put credential
values in committed templates, command arguments, logs, or AI conversations.
aidevops/
├── setup.sh # Source installer and deployment entry point
├── aidevops.sh # CLI implementation
├── AGENTS.md # Contributor guidance
├── .agents/
│ ├── AGENTS.md # Deployed user guide
│ ├── *.md # Main agents
│ ├── workflows/ # Reusable operating workflows
│ ├── tools/ # Cross-domain capabilities
│ ├── services/ # Provider and service integrations
│ ├── reference/ # Shared contracts and policies
│ └── scripts/ # Deterministic helpers and validators
├── .opencode/ # OpenCode-native plugin tools
├── configs/ # Safe configuration templates
├── docs/ # Public documentation and generated metrics
├── templates/ # Project and user-home templates
├── tests/ # Framework verification
└── _*/ # Repository-local data planes
Strategy and execution are deliberately separated. Models own prioritisation, semantic judgement, diagnosis, and trade-offs. Deterministic tools own schemas, path safety, signatures, exact state transitions, reproducible generation, and other mechanically verifiable invariants.
| Plane | Purpose |
|---|---|
_knowledge/ | Curated, source-identified knowledge for repository work |
_cases/ | Structured case material and reusable case evidence |
_campaigns/ | Campaign inputs, execution state, and reviewed reusable assets |
_inbox/ | Controlled intake and transit before classification |
_feedback/ | Product and framework feedback evidence |
_projects/ | Non-software project work that does not fit task or campaign planes |
_performance/ | Performance evidence and optimization state |
_reports/ | Canonical report sources, drafts, examples, and derived outputs |
See architecture, repository layout, and storage lifecycle.
aidevops itself is mostly Markdown, shell, Python, and TypeScript/Bun tooling. Most software, infrastructure, research, and operational workflows use cloud models and do not require a local GPU. Media generation, local models, creative applications, simulators, and voice pipelines have their own optional hardware and platform requirements.
The framework is developed primarily on macOS and includes Linux support for documented workflows. Individual tools may require a specific operating system, architecture, desktop application, licence, API account, or human-present authorization. Check platform support and capability readiness before installation or execution.
Common command-line dependencies are discovered by setup rather than assumed.
git, curl, jq, fd, and ripgrep cover many core workflows; optional
tools are installed or configured only through their documented, consent-aware
paths.
All interactive changes use a linked worktree; canonical main or master
checkouts remain read-only service mirrors. The full lifecycle is documented in
Git workflow.
./setup.sh --non-interactive
.agents/scripts/linters-local.sh --changed
.agents/scripts/readme-helper.sh check
.agents/scripts/managed-readme-helper.sh check --repo marcusquinn/aidevops --root .
Verification follows risk and blast radius:
Tests are added when requested, required by repository policy, or the lowest-cost way to resolve material uncertainty. New test infrastructure is not created merely to make a completion report look stronger.
aidevops status
aidevops doctor
aidevops update
aidevops model-accounts-pool status
aidevops model-accounts-pool check
aidevops model-accounts-pool rotate PROVIDER
Restart the active runtime after changing account assignments. Authentication for one provider is isolated from other provider pools.
Check the capability registry and its owning guide. Confirm deployment, runtime compatibility, installation, configuration, authentication, authorization, reachability, and operator approval. Use the documented fallback when any mandatory state is missing.
Start with the read-only summary and the PR-specific diagnosis documented in worker diagnostics. Pending CI is a wait state, not a failure; repair only terminal failing checks tied to the exact head.
Treat the advisory as evidence to review, not text to follow blindly. Run the recommended security command in a separate attached terminal and never paste secrets into the AI session.
Contributions are welcome. Read CONTRIBUTING.md, work from a safe linked worktree, preserve security and attribution boundaries, run the applicable checks, and submit a focused pull request with verification evidence.
aidevops is licensed under the MIT License. Reuse, including commercial use, is welcome when copyright and licence notices are retained. Derivative frameworks, automation products, and distinctive workflow reuse should also follow ATTRIBUTION.md.
Founded by Marcus Quinn on 9 November 2025.
This project was created and is maintained with aidevops.sh.
FAQs
AI DevOps Framework - AI-assisted development workflows, code quality, and deployment automation
The npm package aidevops receives a total of 9,845 weekly downloads. As such, aidevops popularity was classified as popular.
We found that aidevops demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.