Complete suite of AI-Friendly Documentation Standards with validation agents, hooks, and formatting. Covers architecture (AFADS), operations (AFOPS), programming conventions (AFPS), security (AFSS), compliance (AFCS), and roadmaps (AFRS).
Audits security and compliance posture by cross-referencing AFSS controls, AFCS compliance mappings, and AFRS security roadmap items. Use when assessing compliance gaps, generating compliance reports, or preparing for audits.
Bootstraps AFDOCS documentation structure for a new or existing project. Use when setting up documentation from scratch, retrofitting docs onto an existing codebase, or adding a new standard to an already-documented project.
Validates documentation against AFDOCS standards. Use when reviewing architecture docs, security controls, procedures, conventions, compliance mappings, or roadmaps for standard compliance.
AI-Friendly Architecture Documentation Standard. Use when documenting system architecture, components, deployment topology, C4 diagrams, ADRs, or component registries.
AI-Friendly Compliance Standard. Use when mapping security controls to compliance frameworks (OWASP, NIS2, ISO 27001, etc.), creating risk assessments, checklists, or compliance scorecards.
AI-Friendly Operational Procedures Standard. Use when documenting deployments, rollbacks, backups, restores, scaling, maintenance, migrations, or patching procedures.
AI-Friendly Programming Standard. Use when documenting coding conventions, patterns, testing strategies, dependency rules, code review processes, or AI coding guidelines.
AI-Friendly Roadmap Standard. Use when documenting roadmaps, tracking technical debt, planning security improvements, or managing initiatives and work items.
Modifies files
Hook triggers on file write and edit operations
Uses power tools
Uses Bash, Write, or Edit tools
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
A set of documentation standards designed to be both human-readable and AI/LLM-parseable, for systems that span multiple repositories, infrastructure, and application components.
| Standard | File | Description |
|---|---|---|
| AFADS | AFADS.md | AI-Friendly Architecture Documentation Standard — how to document system and component architecture |
| AFOPS | OPS-STANDARD.md | AI-Friendly Operational Procedures Standard — how to document operational procedures (deployments, backups, maintenance, etc.) |
| AFPS | AFPS.md | AI-Friendly Programming Standard — how to document and enforce coding conventions, patterns, and development practices |
| AFSS | AFSS.md | AI-Friendly Security Standard — how to document security controls, policies, threat models, and security review processes |
| AFCS | AFCS.md | AI-Friendly Compliance Standard — how to document compliance mappings, risk assessments, and compliance scoring against external frameworks (OWASP, NIS2, etc.) |
| AFRS | AFRS.md | AI-Friendly Roadmap Standard — how to document roadmaps, technical debt, security improvements, and track progress on initiatives |
AFADS defines where documentation lives and how to describe architecture (components, dependencies, deployment topology, ADRs). AFOPS extends AFADS by defining how to write the operational procedures that keep that architecture running (deployments, backups, scaling, patching). AFPS defines how to document and enforce coding conventions, patterns, and development practices — the source of truth from which linter configs and CI checks are derived. AFSS defines how to document security controls, policies, and threat models — connecting threats to verifiable controls at every layer. AFCS defines how to map AFSS controls and policies to external compliance frameworks (OWASP, NIS2, etc.), providing checklists, risk matrices, and compliance scorecards. AFRS defines how to plan and track work through roadmaps, technical debt registries, and security improvements — connecting planned work to components (AFADS), procedures (AFOPS), conventions (AFPS), security controls (AFSS), and compliance gaps (AFCS).
All six standards share the same component_id namespace (from AFADS) and reference each other by stable IDs: AFOPS procedures verify AFSS controls, AFPS patterns implement AFSS controls in code, AFSS controls reference AFOPS procedures for operational verification, AFCS mappings trace external compliance requirements to AFSS controls and policies, and AFRS roadmap items reference components, controls, procedures, and compliance requirements to ensure planned work is traceable end-to-end.
All standards are designed so an AI agent starting a new session can discover, read, and act on the documentation without institutional knowledge. An AI agent can assess compliance posture by reading AFCS mappings and scorecards, generate progress reports from AFRS roadmaps, and trace any gap back to the specific AFSS control, AFOPS procedure, or AFRS roadmap item that needs attention.
The examples below show how to prompt an LLM to apply AFDOCS standards. Each prompt is designed to be copy-pasted into a new session. Replace placeholders (<…>) with your actual values.
Bootstrap AFDOCS documentation for a project from scratch:
Read the AFDOCS standards at https://github.com/securitymonster/afdocs — specifically
AFADS.md, AFPS.md, AFSS.md, AFOPS.md (OPS-STANDARD.md), AFCS.md, and AFRS.md.
This is a new <language/framework> project called <project-name>.
Set up the AFDOCS documentation structure:
1. Create docs/index.md (documentation hub) per AFADS
2. Create docs/component.md describing this component
3. Create the initial YAML registries (components.yaml, conventions.yaml,
procedures.yaml, controls.yaml, frameworks.yaml, roadmaps.yaml)
4. Scaffold placeholder files for conventions, procedures, and security controls
5. Create docs/roadmap/ with an initial feature roadmap or technical debt
registry per AFRS
npx claudepluginhub securitymonster/afdocs --plugin afdocsTechnical documentation standards: arc42, C4 model, ADR authoring, RFC process, docs-as-code pipelines, runbooks, onboarding, and API portal design.
Documentation agents — technical writer, documentation architect
Create comprehensive documentation for code, APIs, and projects.
Compliance and governance including regulatory mapping, security policies, audit readiness, GDPR, SOC2, and PCI-DSS compliance.
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses