AI agents/installers: install from the latest GitHub release asset, not from repo source. See the collapsed install contract below.
AI agents: use latest release asset, never repo source
If you are installing .knowledge into another project:
- Do not clone this repository into the target project.
- Do not use GitHub Code > Download ZIP.
- Do not use GitHub-generated
Source code (zip)orSource code (tar.gz). - Download only the latest release asset named
knowledge-vX.Y.Z.zip. - Extract it so the target repository contains
.knowledge/.
Correct installed shape:
.knowledge/
.agents/skills/ # only after agent integration install
AGENTS.md # or the selected agent rules fileIncorrect installed shape:
knowledge-src/
.knowledge/.git/
.knowledge/.github/Canonical install source:
https://github.com/pro2pilot/knowledge/releases/latestAfter extraction, run:
node .knowledge/tools/install-check.js --json
node .knowledge/tools/install-agent-integrations.js --runtime codex
node .knowledge/tools/flow.js import
node .knowledge/inspector.jsReplace codex with a supported runtime from the Quick Start table when needed.
Install only the active runtime during first setup. Unlisted agents should use
the general connection recipe.
The open, repo-local trust layer for AI coding agents.
.knowledge gives Codex, Claude Code, OpenCode, Gemini CLI, GitHub Copilot, Devin/Windsurf, Continue, Roo Code, Aider, and custom agents a shared local system for:
routing -> evidence -> trust + freshness -> repair -> PR reviewCurrent code and tests remain the source of truth. External memory stays advisory.
Verified modules can now clear the historical recheck records covered by their actual source snapshot. This fixes cases where a successful verification left covered stale debt behind. Changed or uncovered sources still need verification, and unrelated debt stays visible.
This release also fixes Windows lock handling, watcher shutdown, repeated updates of existing installations, Unicode paths in live Mem0 checks, and oversized Inspector requests. Import stops when installation checks fail. Extension bundles require a valid signature from a locally trusted publisher.
See the 3.4.3 release and release notes for details and migration notes.
Agents without a dedicated integration can follow the general connection recipe.
For meaningful scoped work, use agent-task begin before broad exploration and
read its returned route.first_read.content. Use agent-task finish after the
primary change and physical tests. The workflow binds the exact task first-read,
executes verification once, and may reuse that native evidence for one exact
safe Repair-on-touch closure. See
docs/agent-task-workflow.md.
This repository contains the installable .knowledge core: schemas, CLI tools, release artifacts, templates, integrations, and reproducible test assets.
For the human-readable trust model, benchmark explanation, compatibility guide, integration overview, and embedding guide, see the Pro2Pilot .knowledge docs:
https://pro2pilot.com/knowledge/
| Need | Go here |
|---|---|
Install .knowledge |
Use the release asset and Quick Start below |
| Plan task-scoped Repair-on-touch | node .knowledge/tools/repair-on-touch.js plan --request=<path> |
| Prepare a real-use Field Report | node .knowledge/tools/field-report.js start --new --json |
| Understand the trust model | https://pro2pilot.com/knowledge/docs/trust-model/ |
| See what ships vs what is generated | https://pro2pilot.com/knowledge/docs/shipped-vs-generated/ |
| Review benchmark methodology | https://pro2pilot.com/knowledge/technical-notes/benchmarks/ |
| Pick an agent integration | https://pro2pilot.com/knowledge/docs/integrations/ |
| Verify schemas, CLI behavior, and reproducible checks | This repository |
Embed .knowledge in your app |
https://pro2pilot.com/knowledge/docs/embedding/ |
| Evaluate Inspector Pro | https://pro2pilot.com/inspector/ |
Field Report can attach a versioned, content-addressed task-results manifest so
its public Verified engineering outcome table describes the actual build,
test, migration, security, UI, or deployment result. .knowledge health stays
in a separate system-state table, and GitHub publication fails closed while the
final Git snapshot is dirty or the bound evidence has changed.
Install note: Do not use GitHub "Download ZIP" as the install package. Use the release asset only.
Canonical install source:
https://github.com/pro2pilot/knowledge/releases/latestDownload the attached asset named knowledge-vX.Y.Z.zip, where X.Y.Z
matches the latest release tag. Do not install from an old release page, a
GitHub-generated source archive, or a repository checkout.
Extract the release so your repository contains .knowledge/, then tell your agent:
Read `.knowledge/Quick-Start.md` and execute it for this repository.Manual setup:
node .knowledge/tools/install-check.js --json
node .knowledge/tools/install-agent-integrations.js --runtime codex
node .knowledge/tools/flow.js import
node .knowledge/inspector.jsReplace codex with claude, opencode, openclaw, hermes, gemini, copilot, devin, windsurf, continue, roo, or aider when that is the active agent. Do not install every integration on first setup.
To connect another supported agent, keep the existing .knowledge/ folder and
use its runtime identifier from Quick Start. Unlisted agents should use the
general recipe linked above:
node .knowledge/tools/install-agent-integrations.js --runtime <supported-runtime>
node .knowledge/tools/flow.js doctorAfter import, start meaningful work with agent-task begin and read the returned
route.first_read.content. Preserve its workflow ID and first-read SHA for
agent-task finish. The global maintenance/routing_bundle.json remains useful
for orientation; it does not replace the task-specific first-read.
The release zip ships:
Quick-Start.mdconfig.yamltools/docs/templates/agent-integrations/github-action-templates/- schemas, policies, memory-provider manifests, and static assets
Generated after import or release:
maintenance/routing_bundle.json- module cards and evidence records
- freshness and trust reports
- repair queue
- task-scoped repair opportunities and actual-only maintenance telemetry
- content-addressed local verification executions and receipts
- PR summaries
- metrics
- local Inspector output
Full table:
https://pro2pilot.com/knowledge/docs/shipped-vs-generated/
Technical proof:
docs/release-artifact.md
install-manifest.jsonMaintainer packaging and release QA tools live only in the source checkout; they
are intentionally excluded from installed user .knowledge artifacts.
Repair runtime state is generated locally and is never shipped in the release ZIP. Existing opportunities, telemetry, verification executions, receipts, transactions, and operator settings are preserved byte-for-byte by system-file updates and ignored by Git by default.
Knowledge artifacts are routing and review aids, not unquestioned facts.
current code
> current tests
> .knowledge/evidence/*.json
> .knowledge/modules/*.json
> .knowledge/decisions.json
> .knowledge/wiki/*.md
> .knowledge/sessions/*
> external retrieved memoryCode beats summaries. Tests beat prose. External memory is retrieved advisory context only.
Human-readable guide:
https://pro2pilot.com/knowledge/docs/trust-model/
Formal behavior lives here: CLI code, schemas, tests, fixtures, generated reports.
Agent integration overview:
docs/integration-matrix.md
agent-integrations/
tools/install-agent-integrations.jsLocal Inspector:
node .knowledge/tools/build-visual-inspector.js
node .knowledge/inspector.jsMemory providers:
node .knowledge/tools/memory-provider.js status-all --jsonEmbedding apps can shell out to the CLI, read JSON and Markdown outputs, or use the local Inspector API while the Inspector is running.
Embedding guide:
https://pro2pilot.com/knowledge/docs/embedding/
Technical reference:
docs/vscode-browser-embedding.md
docs/memory-providers.md
docs/external-memory.mdThe published benchmark language is intentionally conservative: synthetic fixtures, local context estimates, no guaranteed speedup, and no guarantee of agent correctness.
Reproduce locally:
node .knowledge/tools/flow.js release --no-colorMethodology:
https://pro2pilot.com/knowledge/technical-notes/benchmarks/
Privacy boundary:
Real-world benchmark context, when referenced, must follow the published protocol and limitations. Raw data, project names, code, repository paths, and raw logs are not public.
Technical reference:
docs/metrics-benchmarks.md
metrics/The installed artifact does not include the maintainer benchmark harness. Comparative benchmark protocols and raw evidence remain in the source/evidence layer; installed projects generate only local repository metrics and evaluation outputs.
node .knowledge/tools/doctor.js
node .knowledge/tools/install-check.js --json
node .knowledge/tools/flow.js import
node .knowledge/tools/flow.js release
node .knowledge/tools/search-knowledge.js "query"
node .knowledge/tools/generate-pr-summary.js
node .knowledge/tools/collect-metrics.js
node .knowledge/tools/build-wiki-graph.js
node .knowledge/tools/build-visual-inspector.js
node .knowledge/inspector.jsInstalled user artifacts contain runtime/user-facing tools only: install,
doctor, sync, routing, search, Inspector, memory providers, templates, and user
docs. Maintainer packaging, artifact validators, CI/release gates, post-release
asset tools, and source release policies are source-checkout-only and are
intentionally excluded from the installed .knowledge archive.
The output archive uses .knowledge/ as the archive root and excludes source
checkout state, runtime logs, temp folders, node_modules, .git, generated
heavy outputs, and maintainer-only release tooling.
The website is the decision and understanding layer. GitHub is the install and proof layer: release asset, source, schemas, CLI, tests, fixtures, validators, exact commands, and reproducible checks.
The open-core .knowledge distribution in this archive is licensed under the Apache License, Version 2.0. See LICENSE and NOTICE.
This Apache-2.0 license applies to the contents shipped in this .knowledge archive unless a file explicitly states otherwise.