Hold on. Think first. Code less.
waitsec is a set of plain instruction files for your AI coding agent. It is not a library you import and not a program you run in your app. It is a set of rules your agent reads so it behaves better while it works on your code.
Think of it as a checklist taped to your agent's desk. When you ask for a feature, the agent follows the checklist: ask when something is unclear, keep the change small, read the error before fixing it, and prove the work before saying it is done.
If you have ever asked for a small change and got twelve new files, or reported a one line bug and watched the agent edit five unrelated files, waitsec is for that problem.
Use the interactive installer in your project folder. It handles every editor and puts the files in the right place:
npx waitsecAll five skills are selected by default. Press Space to unselect any you do not want, then Enter.
Prefer a non-interactive install? Use the universal skills CLI:
npx skills add fastroware/waitsec -yPartial install works for any extension, not just the page builder. Extensions depend on the core skill, so always include waitsec.
npx skills add fastroware/waitsec --skill waitsec # core only
npx skills add fastroware/waitsec --skill waitsec waitsec-pagemaker # core plus page builder
npx skills add fastroware/waitsec --skill waitsec waitsec-ui # core plus UI
npx skills add fastroware/waitsec --skill waitsec waitsec-code # core plus code
npx skills add fastroware/waitsec --skill waitsec waitsec-quality # core plus quality
# several extensions at once
npx skills add fastroware/waitsec --skill waitsec waitsec-pagemaker waitsec-uiIn the interactive installer npx waitsec, you do this in the first prompt: all skills are checked, so just unselect the ones you do not want and keep the rest.
When you install waitsec, the installer asks for a scope. That is only about where the rule files are saved.
| Scope | Where the files go | Best for |
|---|---|---|
| This project only | Inside the current folder, for example .agents/skills/ or .claude/skills/, plus a rules file |
Teams. The rules travel with the repository and can be committed. |
| Everywhere (Global) | Your home directory, for example ~/.agents/skills or ~/.claude/skills |
You. Every project on this computer gets the guardrails, even brand new ones. |
You can install both. A project install wins inside that project.
Full explanation: docs/installation.md or Bahasa Indonesia.
| Skill | What it does | Use it when |
|---|---|---|
waitsec |
Core 5 guardrails: ask-first, anti-overengineering, small-diff, debug-first, verify-first | Always. This is the base every extension builds on. |
waitsec-pagemaker |
Orchestrates complete web pages: project recon, page structure, responsive UI, content flow, and conditional guidance for SEO, structured data, auth, motion, 3D, and images | You build, restructure, or audit a complete web page. |
waitsec-code |
Clean code: no comment noise, small focused functions, no unnecessary dependencies | You write or refactor source code. |
waitsec-ui |
Frontend restraint: anti-slop visuals, mobile-first layout, clean UI copy | You work on UI or design systems. |
waitsec-quality |
Security auditing, realistic tests, safe database migrations | You touch auth, payments, tests, or migrations. |
- Install it once, either for a project or globally.
- Open your project in your editor and work as usual.
- When a task matches a skill, the agent reads that skill and follows it. You do not run anything.
For example, just ask:
- "Build a landing page for my SaaS."
- "Add a login page with a forgot password flow."
- "Fix this failing test."
- "Review this endpoint for security issues."
The full guide, including per-editor setup, manual install, update, uninstall, and troubleshooting, is here:
- English: docs/installation.md
- Bahasa Indonesia: docs/installation-id.md
Read this before you use waitsec.
- waitsec is a set of instruction documents for AI agents. It is guidance, not a runtime library.
- We do not audit your application and we cannot guarantee that generated code, third party skills, or dependencies are safe, correct, or free of vulnerabilities.
- Skills run with the same permissions as your AI agent, which can read and write files and run commands on your machine. Always review what the agent changed before you run or ship it.
- Be especially careful with authentication, authorization, payments, secrets, and database migrations. Never let an agent push secrets or run destructive migrations unattended.
- The security advice inside these skills is advice only. You are responsible for testing and securing your own project.
In short: use waitsec to make your agent more careful, not as a guarantee that your code is secure.
waitsec/
├── docs/
│ ├── installation.md # Full install and usage guide (English)
│ └── installation-id.md # Panduan instalasi (Bahasa Indonesia)
├── skills/
│ ├── waitsec/ # Core workflow guardrails
│ │ ├── SKILL.md # Router for the five core guardrails
│ │ └── references/ # Focused workflow guidance
│ │ ├── ask-first.md
│ │ ├── anti-overengineering.md
│ │ ├── small-diff.md
│ │ ├── debug-first.md
│ │ ├── verify-first.md
│ │ └── write-info-analyzer.md # Compatibility pointer to UI copy guidance
│ ├── waitsec-ui/ # Responsive, accessible, restrained UI
│ │ ├── SKILL.md
│ │ └── references/
│ │ └── ui-copy.md # KEEP, REWRITE, and REMOVE copy decisions
│ ├── waitsec-pagemaker/ # Complete page orchestrator
│ │ ├── SKILL.md # Recon, workflow, UI contract, and reference routing
│ │ └── references/
│ │ ├── project-recon.md
│ │ ├── seo-and-structured-data.md
│ │ ├── landing-page.md
│ │ ├── blog-index.md
│ │ ├── article-single.md
│ │ ├── about-me.md
│ │ ├── contact-page.md
│ │ ├── auth-pages.md
│ │ ├── motion-and-3d.md
│ │ └── image-sourcing.md
│ ├── waitsec-code/ # Code readability and dependency hygiene
│ │ └── SKILL.md
│ └── waitsec-quality/ # Security, testing, and migration safety
│ ├── SKILL.md
│ └── references/
│ ├── security.md
│ ├── testing.md
│ └── migrations.md
│
├── rules/
│ ├── AGENTS.md # Universal rule pointer (Antigravity / Claude Code)
│ └── waitsec.md # All-in-one bundled rules (Kilo Code / Cline / Cursor)
├── assets/
│ ├── banner-waitsec.png
│ └── logo-waitsec.png
├── bin/
│ └── cli.mjs # Interactive terminal installer (Clack prompts)
├── skills.sh.json # skills.sh repo page grouping
├── plugin.json # Antigravity plugin manifest
├── package.json # npm / npx manifest
└── composer.json # Composer / Laravel manifest
Found a bug, want to suggest a new guardrail, or want to contribute? Everything is tracked through GitHub.
If an agent bypassed a guardrail, generated unexpected boilerplate, or an installer command failed:
- Go to GitHub Issues.
- Click New Issue.
- Include your editor, the prompt you ran, and what the agent did wrong.
- Open a ticket on GitHub Issues titled
[Feature] your idea. - Provide a before-and-after example showing the bad output and the clean solution.
- Fork this repository on GitHub.
- Create a branch:
git checkout -b feature/my-guardrail. - Keep instructions concise, actionable, and free of generic AI slop.
- Submit a Pull Request to
main.
Thanks to everyone who has contributed to this project.
MIT