A CLI that installs a durable AI engineering contract into real applications and audits whether production responsibilities remain explicit.
Status: pre-1.0.
aruo initis implemented on the development branch after the v0.1.0 prerelease; expect breaking changes before 1.0. Existingcreatetemplates remain available but are no longer the product's architectural center.
git clone https://github.com/Aruodore/aruo-cli.git aruo && cd aruo
go build -o "$HOME/.local/bin/aruo" ./cmd/aruo
cd your-existing-application
aruo init --dry-run
aruo init --yes && aruo doctorAI can produce working software quickly, but it cannot infer every application's architecture, threat model, operating environment, or definition of done. Aruo installs explicit rules that make those expectations available to AI agents and humans inside the repository. The installer owns and can eventually update the rules; the developer owns the application and its production intent. Doctor makes drift and unresolved responsibilities visible without pretending the application is certified production-ready.
aruo init: detects an existing repository's ecosystem, framework, and package manager; plans or installsAGENTS.md, a versioned contract and rules under.aruo/, managed-file hashes, and application-ownedaruo.yaml. It adds no runtime dependency and refuses every existing target rather than overwriting it.aruo doctor: verifies the installed contract's integrity, audits application intent, and independently scores repository health againstaruo.repository-health/v1.aruo create: the existing project-template catalog remains available during the pivot. New production guidance belongs in the installable contract, not increasingly large templates.- Accessible and scriptable by design: a line-oriented fallback adapter,
NO_COLOR/--color/--motionsupport, and clean non-interactive behavior forinit,create, anddoctor.
Everything else referenced elsewhere in this repository's docs (inspect, check, adopt, plan, apply, plugins, migrations, aruo config) is designed but not implemented. See Roadmap.
Aruo isn't on any package manager yet, but a tagged release with prebuilt binaries is available.
Grab the archive for your platform from the v0.1.0 release (Linux/macOS/Windows × amd64/arm64), verify it against checksums.txt, then extract and put aruo on your PATH. Each archive ships alongside an SBOM and a GitHub build provenance attestation.
curl -sSfL -o aruo.tar.gz https://github.com/Aruodore/aruo-cli/releases/download/v0.1.0/aruo_0.1.0_linux_amd64.tar.gz
tar xzf aruo.tar.gz
install aruo "$HOME/.local/bin/aruo"aruo version on this binary prints the real tagged version, aruo version 0.1.0. GoReleaser stamps that in at build time; go install and local builds below don't, so they report dev instead.
go install github.com/aruodore/aruo-cli/cmd/aruo@latestWorks now that the module is public and tagged. Reports aruo version dev, like any source build.
Prerequisites: Go 1.26 or newer (the repository pins 1.26.5 via go.mod's toolchain directive; a modern go command fetches it automatically). No CGO, no other system dependencies.
git clone https://github.com/Aruodore/aruo-cli.git aruo
cd aruo
go build -o "$HOME/.local/bin/aruo" ./cmd/aruo- Installed to: wherever you point
-o; the example above uses$HOME/.local/bin/aruo. Make sure that directory is onPATH. - Supported platforms: Linux, macOS, and Windows all build and pass the full test suite in CI (
ubuntu-latest,macos-latest,windows-latest);amd64andarm64both build via the pinned GoReleaser config, though only Linux/amd64has been run interactively during development. - Verify:
aruo versionprintsaruo version dev, matching every source build. - Upgrade:
git pull && go build -o "$HOME/.local/bin/aruo" ./cmd/aruo. There's no update mechanism beyond rebuilding. - Uninstall: delete the binary you built (e.g.
rm "$HOME/.local/bin/aruo"). Nothing else is installed on your system.
None of these exist today. They're listed so you don't go looking for something that isn't there yet, not as a promise of when they'll land.
| Method | Status |
|---|---|
| Homebrew | Not configured. No brews: block in the release config. |
| Scoop / Winget | Not configured. |
| AUR / Nix | Not configured. |
Install script (curl | sh) |
Not implemented. |
aruo version
cd your-existing-application
aruo init --dry-run
aruo init --yes
aruo doctorThat is inspect → install the contract → audit the repository, using only commands that exist. Run aruo init without --yes for confirmation, or use --no-input --yes in automation.
A real, unedited run of the commands above:
$ aruo create my-library --template go-library
✓ Created go-library with 35 files at ./my-library
Next steps:
cd my-library
go test ./...
git init && git add .
$ cd my-library && go test ./...
ok my-library 0.002s
$ aruo doctor
Repository health: 99/100 (A)
/path/to/my-library
Category Score
completeness 20/20
documentation 20/20
ci 15/15
tests 15/15
license 10/10
security 10/10
github 9/10
Recommendations:
- Missing CODEOWNERS
Declare real maintainers for review routing; do not add placeholders.
The one missing point is expected: a freshly generated project has no named maintainer yet, and Aruo won't invent one.
Run aruo <command> --help for the authoritative, always-current flag list; this section is a summary, not a substitute.
Installs Aruo's AI engineering contract into an existing repository. It detects local stack evidence but does not execute project code, install dependencies, or modify application source.
aruo init --dry-run # inspect the exact file plan
aruo init --yes # initialize the current repository
aruo init ./application --format json --yesManaged files are AGENTS.md and .aruo/**. aruo.yaml and generated AGENTS.local.md guidance are application-owned. Initialization refuses collisions, uses exclusive commit operations, and rolls back files it created when a commit cannot complete. Updating an existing installation is intentionally deferred to aruo update; rerunning init does not overwrite it.
Creates a new project from a catalog template. Refuses a destination with real content in it; an existing but empty directory (most commonly .) is fine.
Key flags:
--template <id>: skip the picker--language/--kind: filter the catalog--module: Go module path, npm package name, or PyPI name, depending on the template. Defaults to the project's own name; pass a real import path likegithub.com/you/nameto override it--description,--author,--license: metadata for the generated project--set key=value: template variables-y/--yes: accept the confirmation--no-input: fail instead of prompting, for CI
aruo create # fully interactive, guided
aruo create my-library --template go-library # --module defaults to my-library
aruo create my-tool --template python-library --no-input --yes # --module defaults to my-tool
aruo create . --name my-tool --template go-library --module github.com/you/my-tool --no-input --yesCancellation: Ctrl+C once cancels cleanly. Writes are staged and only committed at the end, so no partial project is left behind. A second Ctrl+C forces immediate exit.
Scores a repository's engineering health and, when aruo.yaml declares production intent, audits its capability claims and unresolved responsibilities. Intent findings are separate and do not alter the versioned 100-point score. Defaults to the current directory when no path is given.
Doctor statically verifies supported evidence conventions such as complete npm quality scripts, framework build/type-check scripts, test files, dependency-audit CI steps, committed migrations, and health-route pairs. It does not run repository code. Runtime and provider-dependent evidence remains visibly DECLARED, never overstated as verified.
Key flags: --format human|json, --minimum-score <0-100> (default 80). Doctor exits 3 when the score is below the threshold or the intent manifest has blocking findings, making it useful as a CI gate.
aruo doctor # score the current directory
aruo doctor ./some-project --format json
aruo doctor . --minimum-score 90Prints the running build's version: the real tagged version on a release binary, dev on anything built locally. See Installation.
Generates a shell completion script (Cobra's standard mechanism), including dynamic completion for --template/--language/--kind.
Only what's actually implemented: 0 success, 1 operational failure, 3 doctor findings (score below --minimum-score or blocking production intent), 130/143 interrupted by Ctrl+C/SIGTERM.
aruo create my-library --template go-library produces:
my-library/
├── .aruo/
│ ├── rules/{api,architecture,data,delivery,observability,security,testing}.md
│ ├── contract.yaml
│ ├── managed.json
│ └── stack.yaml
├── .github/
│ ├── ISSUE_TEMPLATE/{bug.yml,feature.yml}
│ ├── workflows/{ci.yml,pr-title.yml,release.yml}
│ ├── dependabot.yml
│ └── pull_request_template.md
├── docs/README.md
├── AGENTS.md # AI entry point and managed engineering contract
├── aruo.yaml # template provenance and explicit production intent
├── CHANGELOG.md
├── CODE_OF_CONDUCT.md
├── CONTRIBUTING.md
├── go.mod
├── LICENSE
├── Makefile
├── my_library.go
├── my_library_test.go
├── README.md
├── release-please-config.json
├── .release-please-manifest.json
├── ROADMAP.md
└── SECURITY.md
Every template's exact application file set differs by ecosystem (an npm-based template gets package.json and CI steps for npm test, for example). Every created project also receives the same managed AI engineering contract atomically: AGENTS.md, .aruo/contract.yaml, stack detection, managed hashes, and the rules under .aruo/rules/. When a template provides stack-specific guidance it is retained in application-owned AGENTS.local.md; production intent remains application-owned in aruo.yaml.
There's no aruo config command or resolved project configuration today. Doctor reads only the versioned provenance and intent.capabilities contract from aruo.yaml; it does not treat the file as runtime configuration. The active configuration surface remains CLI flags and four environment variables:
| Variable | Effect |
|---|---|
NO_COLOR |
Disable color output (any value, including empty) |
ARUO_ACCESSIBLE |
Force the line-oriented accessible adapter |
ARUO_MOTION=never |
Disable animation |
ARUO_NO_INPUT |
Disable prompting; fail instead of asking |
The aruo.yaml written into every generated project records template provenance and explicit production intent. aruo doctor reads and audits those fields only. docs/configuration/README.md describes a considerably larger planned configuration system (aruo.yaml as live config, aruo config explain, org policy, profiles); that configuration system does not exist yet.
docs/README.md— documentation indexdocs/architecture/README.md— system architecturedocs/architecture/create-command.md— howcreateactually worksdocs/cli/README.md— command surface and terminal UX contractdocs/cli/copy-style-guide.md— prompt/error/status wording rulesdocs/templates/README.md— the template catalog
See CONTRIBUTING.md, the RFC process, and the Code of Conduct. Security reports go through SECURITY.md, not public issues.
init, create, and doctor are real. Managed contract updates, organization policy, plugins, and resolved application configuration are not built. See ROADMAP.md for what's next.
Aruo is licensed under Apache-2.0. Report vulnerabilities privately as described in SECURITY.md.