AI coding agents are fast, but left alone they drift between sessions, leave no audit trail and give a reviewer nothing to check. Each tool also brings its own instruction file, so the rules get split across Claude Code, GitHub Copilot and Cursor.
My role
I designed and built ARK OS as ARK360's own delivery framework, and I maintain it in public.
What I built
A single AGENTS.md that tells every agent to stop and check for an approved spec and a feature branch before it changes a file, with thin adapters for Claude Code, Copilot and Cursor.
A project constitution, EARS-based spec template, decision records, threat model, runbook and contract templates.
Five gates (Research, Plan, Build, Ship and Run) with machine-readable criteria, and a GitHub Actions workflow that runs the automated checks on pull requests and on main.
A Proof Sheet that collects evidence against OWASP ASVS Level 1, Essential Eight ML1, APP 1, 5 and 11, and WCAG 2.2 AA. It records evidence; it does not certify.
Version 0.2 adds an optional Claude Code layer with slash commands and an opt-in hook.
Outcomes
BTR OS is the applied example. It is built under ARK OS, with its work tracked as specs and decision records in the repository.