
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
Security-vetted, cross-agent project boilerplates. Scaffold a project pre-wired with curated, SkillSpector-gated agent skills.
npx a stack starter that ships with curated, scanned agent skills — wired for
Claude, Cursor, Codex, and Copilot, with NVIDIA SkillSpector gating and a
skills.lock provenance file.
Every generated project includes the Omni-Skills
startup workflow bench: $startup-goal, $founding-engineer, $qa-lead, $cto, and
$product-manager are ready the moment you scaffold.
startup-goal):npx bwai-cli install-skill bwai-advisor --global
.md):$bwai-advisor I want to build …
$bwai-advisor Read @my-idea.md and recommend a boilerplate
bwai new nextjs-app ./my-app --agents claude,cursor
$founding-engineer / $qa-lead.Already know the boilerplate? Skip to step 3. Check setup anytime: bwai doctor.
After global install, bwai-cli and the shorter alias bwai are the same CLI.
| Install advisor | npx bwai-cli install-skill bwai-advisor --global |
| List starters | npx bwai-cli list-boilerplates |
| Check setup | npx bwai-cli doctor |
| Scaffold | npx bwai-cli new nextjs-app ./app --agents claude,cursor |
| Scan skills | bwai scan-project ./app --threshold 50 |
Seven boilerplates: nextjs-app, nextjs-ai-app, express-api,
fastify-api, python-service, node-service, react-native-app.
my-app/
src/ or app/ # runnable template for your stack
.bwai/skills/ # canonical curated skills
startup-goal/ # orchestrate a goal across role subagents
founding-engineer/ # implement, test, debug, verify
qa-lead/ # acceptance checks + release risk
cto/ # architecture + technical direction
product-manager/ # PRDs, issue slicing, roadmap
… # stack-specific skills (TDD, code-review, etc.)
.bwai/plugin/ # Agent Plugins 1.0 package (skills + typed MCP)
.claude/skills/ … # mirrored for each --agents target
skills.lock # SHA-256 + scan status per skill
.github/workflows/skill-scan.yml # SkillSpector gate on push/PR
.github/copilot/settings.json # optional Copilot enabledPlugins
workflows/bwai-delivery/ # delivery workflow bundle
Each skill is a spec-compliant SKILL.md.
Skills + MCP also ship as a portable Agent Plugins package
under .bwai/plugin/ — see docs/agent-plugins.md.
Trust (SkillSpector + skills.lock) stays bwai’s layer; the plugin format does not define provenance.
Role skills are vendored from Omni-Skills
and pinned in registry/skills-index.json. Run bwai sync-upstream to pull updates.
bwai install-skill bwai-advisor --global # also installs startup-goal
bwai list-boilerplates
bwai doctor # includes global advisor check
bwai new node-service ./my-app --agents claude,cursor
bwai export-plugin nextjs-app ./bwai.nextjs-app # portable Agent Plugins package
bwai scan-project ./my-app --threshold 50
bwai scan-catalog --threshold 30 --require-scanner
bwai search-skills "code review"
bwai promote my-skill --from ./path/to/skill --target shared --require-scanner
bwai sync-upstream # pull latest omni-skills content
bwai sync-skills
bwai scan-project runs SkillSpector over each installed skill, updates
skills.lock, writes safety-reports/ (JSON + SARIF), and exits 1 when any
skill exceeds the threshold.
uv tool install git+https://github.com/NVIDIA/skillspector.git
bwai scan-project --threshold 50 --require-scanner
Without SkillSpector locally, scans record skipped unless you pass --require-scanner.
src/ # bwai-cli (TypeScript)
shared/skills/ # catalog skills (source: "shared")
shared/workflows/ # GetSuperpower bundles (e.g. bwai-delivery)
boilerplates/<name>/ # boilerplate.json, template/, skills/, optional workflow/
registry/skills-index.json # upstream pins + scan status
docs/
tests/
See docs/ARCHITECTURE.md for boilerplates vs skills vs workflows.
Create boilerplates/<name>/ with boilerplate.json, template/ (ship .gitignore
as gitignore), optional local skills/ and workflow/. Reference shared skills
with { "name": "code-review", "source": "shared" }. Bundled skills must pass
SkillSpector in CI.
Contributors: clone, npm install, npm run build, npm test — see CONTRIBUTING.md.
Landing page: https://boilerplates-with-ai-skills.vercel.app
MIT
FAQs
Security-vetted, cross-agent project boilerplates. Scaffold a project pre-wired with curated, SkillSpector-gated agent skills.
We found that bwai-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.