{"id":4197,"date":"2026-09-03T17:30:14","date_gmt":"2026-09-03T09:30:14","guid":{"rendered":"https:\/\/ai.jxgzhc.cn\/?p=4197"},"modified":"2026-09-03T17:30:17","modified_gmt":"2026-09-03T09:30:17","slug":"%e6%a8%aa%e6%9c%a8%ef%bc%9a%e5%9f%ba%e4%ba%8e%e8%af%81%e6%8d%ae%e7%9a%84%e6%9e%b6%e6%9e%84%e8%af%84%e5%ae%a1%e4%b8%8e%e8%ae%be%e8%ae%a1%e6%8a%80%e8%83%bd%e9%9b%86%e5%90%88","status":"publish","type":"post","link":"https:\/\/ai.jxgzhc.cn\/?p=4197","title":{"rendered":"\u6a2a\u6728\uff1a\u57fa\u4e8e\u8bc1\u636e\u7684\u67b6\u6784\u8bc4\u5ba1\u4e0e\u8bbe\u8ba1\u6280\u80fd\u96c6\u5408"},"content":{"rendered":"<p><img decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/ai.jxgzhc.cn\/wp-content\/uploads\/2026\/09\/hengmu.jpg\" alt=\"\u6a2a\u6728\uff1a\u57fa\u4e8e\u8bc1\u636e\u7684\u67b6\u6784\u8bc4\u5ba1\u4e0e\u8bbe\u8ba1\u6280\u80fd\u96c6\u5408\" \/><\/p>\n<p><strong>\u83b7\u5f97\u57fa\u4e8e\u9879\u76ee\u5b9e\u636e\u7684\u67b6\u6784\u98ce\u9669\u6e05\u5355\u3001\u53ef\u843d\u5730\u4fee\u590d\u65b9\u6848\u3001\u5408\u89c4\u76ee\u6807\u67b6\u6784\u8bbe\u8ba1\u4e0e\u786e\u5b9a\u6027\u8d28\u91cf\u68c0\u67e5\u7ed3\u8bba\u3002<\/strong><\/p>\n<h2>\u8be6\u7ec6\u4ecb\u7ecd<\/h2>\n<p>Website \u00b7<br \/>English \u00b7 \u7b80\u4f53\u4e2d\u6587<\/p>\n<p>Why Hengmu \u00b7<br \/>Install \u00b7<br \/>Quick start \u00b7<br \/>How it works \u00b7<br \/>Workflows \u00b7<br \/>Trust model \u00b7<br \/>Compatibility \u00b7<br \/>Feedback \u00b7<br \/>Documentation<\/p>\n<p>Hengmu is a local-first, evidence-bound architecture review and target-design<br \/>tool for Codex and compatible Agent Plugins. It turns repository facts,<br \/>approved design intent, and explicit constraints into evidence-bound<br \/>current-state assessments, open or constrained target architectures, traceable<br \/>decisions, executable plans, and deterministic policy results.<\/p>\n<p>Current-state assessment and target design are equal entry paths. Existing<br \/>systems can move from candidate findings through independent verification to a<br \/>remediation decision. New systems and major redesigns can start from an approved<br \/>Design Brief and produce a complete target architecture without inventing a<br \/>Review or Findings. Required, preferred, and prohibited constraints are<br \/>challenged inputs, never proof of feasibility or fitness.<\/p>\n<p>The architecture view includes performance efficiency, reliability, security<br \/>and privacy boundaries, data and API contracts, observability, testing,<br \/>deployment, technical debt, proportionality, technology selection, and<br \/>operating reality. Dedicated lenses cover AI-agent context and economics,<br \/>Memory, tool authority, privacy, behavior evidence, technology evolution,<br \/>mobile systems, and multi-project portfolios.<\/p>\n<p>If you are looking for a repository-local architecture review, AI-agent<br \/>architecture audit, target architecture design, architecture decision<br \/>governance, remediation planning, or a deterministic quality gate, Hengmu is<br \/>built for that workflow. It is not a hosted architecture service or a generic<br \/>code linter.<\/p>\n<p>It works at two levels:<\/p>\n<p>one repository, using a project-specific Profile, constraints, critical<br \/>flows, rules, and review history;<\/p>\n<p>a portfolio of repositories, looking for duplication, stack sprawl, shared<br \/>capability, ownership conflicts, data flows, and hidden coupling.<\/p>\n<p>Capability<br \/>What Hengmu does<\/p>\n<p>Current-state assessment<br \/>Reviews boundaries and engineering qualities, then keeps findings candidate-only until independent verification resolves their evidence.<\/p>\n<p>Target architecture design<br \/>Designs open or constrained targets across runtime and deployment units, data ownership, interfaces, trust boundaries, critical flows, operations, and technology choices.<\/p>\n<p>Decisions and plans<br \/>Compares viable options, records why alternatives lose, and turns an authorized decision into ordered remediation or Greenfield implementation slices.<\/p>\n<p>Evidence governance<br \/>Binds facts, Knowledge, provenance, authority, acceptance, and deterministic policy into one auditable chain.<\/p>\n<p>Packages and IDE compatibility<\/p>\n<p>Hengmu publishes two packages from the same source. The package choice changes<br \/>the discovery manifest and active host UI projection; it does not fork the<br \/>underlying Skills or local architecture runtime.<\/p>\n<p>Package<br \/>Manifest and contents<br \/>Intended host<br \/>What this repository verifies<\/p>\n<p>Codex package<br \/>.codex-plugin\/plugin.json plus Codex agents\/openai.yaml metadata<br \/>Codex<br \/>Native manifest, Skill contracts, deterministic archive, and CI\/release packaging<\/p>\n<p>Agent Plugins package<br \/>Host-neutral root plugin.json , standard skills\/ and resources\/ , plus an inert Codex manifest retained for selector provenance<br \/>Cursor, VS Code\/GitHub Copilot, and other Agent Plugins 1.0 clients<br \/>Standard manifest\/layout projection, deterministic archive, and exclusion of Codex-only agents\/openai.yaml files<\/p>\n<p>The portable package contains Agent Skills and does not include mcp.json or a<br \/>Cursor-specific .cursor-plugin extension. Cursor&#x27;s plugin documentation<br \/>states that spec-conformant Agent Plugins load without changes; this repository<br \/>has not yet recorded a Hengmu-specific installed smoke test in Cursor or another<br \/>external IDE. For that reason, format compatibility is not presented as a<br \/>guarantee of identical commands, permissions, UI, or marketplace behavior.<\/p>\n<p>Use the compatibility matrix for the current evidence<br \/>boundary. Kiro currently consumes the same Skills through its Agent Skills<br \/>locations rather than the root Agent Plugins manifest. Host-specific Hooks,<br \/>permissions, rules, steering, and automatic lifecycle behavior are not installed<br \/>by either Hengmu package.<\/p>\n<p>Install in your IDE<\/p>\n<p>Download the two ZIP files and their .sha256 files from the same<br \/>GitHub release . Use<br \/>hengmu-&lt;version&gt;.zip for Codex and<br \/>hengmu-&lt;version&gt;-agent-plugins.zip for the other hosts below. Verify the<br \/>download before extracting it:<\/p>\n<p>From the download directory, use shasum on macOS or sha256sum on Linux:<\/p>\n<p>shasum -a 256 -c hengmu-&lt;version&gt;.zip.sha256<br \/>shasum -a 256 -c hengmu-&lt;version&gt;-agent-plugins.zip.sha256<\/p>\n<p>Keep the extracted directory at a stable absolute path and call it<br \/>HENGMU_ROOT . Each host needs the complete directory, not only<br \/>skills\/hengmu , because the router, focused Skills, schemas, Knowledge, and<br \/>deterministic CLI use relative paths across skills\/ and resources\/ .<\/p>\n<p>Codex and ChatGPT desktop<\/p>\n<p>Extract the Codex ZIP into a personal plugin directory, for example<br \/>~\/.codex\/plugins\/hengmu . Then add this entry to the plugins array in<br \/>~\/.agents\/plugins\/marketplace.json (merge it with any existing marketplace<br \/>instead of replacing the file):<\/p>\n<p>{<br \/>&quot;name&quot;: &quot;hengmu-local&quot;,<br \/>&quot;interface&quot;: { &quot;displayName&quot;: &quot;Hengmu Local&quot; },<br \/>&quot;plugins&quot;: [<br \/>{<br \/>&quot;name&quot;: &quot;hengmu&quot;,<br \/>&quot;source&quot;: {<br \/>&quot;source&quot;: &quot;local&quot;,<br \/>&quot;path&quot;: &quot;.\/.codex\/plugins\/hengmu&quot;<br \/>},<br \/>&quot;policy&quot;: {<br \/>&quot;installation&quot;: &quot;AVAILABLE&quot;,<br \/>&quot;authentication&quot;: &quot;ON_INSTALL&quot;<br \/>},<br \/>&quot;category&quot;: &quot;Developer Tools&quot;<br \/>}<br \/>]<br \/>}<\/p>\n<p>Restart ChatGPT desktop, open Plugins , select Hengmu Local , and install<br \/>Hengmu. In Codex CLI, run \/plugins , install Hengmu from the same marketplace,<br \/>and start a new session. Invoke the router with $hengmu audit this repository<br \/>or describe the outcome naturally. In ChatGPT Work mode, select it with<br \/>@hengmu . The Codex IDE extension can use standalone Skills but does not<br \/>currently provide the plugin browser; install the full Hengmu plugin through<br \/>ChatGPT desktop or Codex CLI. See the<br \/>official OpenAI plugin installation documentation .<\/p>\n<p>Cursor<\/p>\n<p>Extract the Agent Plugins ZIP into ~\/.cursor\/plugins\/local\/hengmu , then<br \/>restart Cursor or run Developer: Reload Window . Open Customize and<br \/>confirm that the Hengmu Skills are enabled. You can also symlink a checked-out<br \/>Hengmu repository while developing:<\/p>\n<p>mkdir -p ~\/.cursor\/plugins\/local<br \/>ln -s \/absolute\/path\/to\/hengmu ~\/.cursor\/plugins\/local\/hengmu<\/p>\n<p>Invoke \/hengmu audit this repository , or ask for the same outcome in natural<br \/>language. Cursor loads the portable Skills, but this package does not install<br \/>Cursor-specific rules, agents, commands, Hooks, or variables. See<br \/>Cursor&#x27;s Agent Plugins installation guide .<\/p>\n<p>VS Code and GitHub Copilot<\/p>\n<p>Enable chat.plugins.enabled , run Chat: Install Plugin From Source , and<br \/>enter https:\/\/github.com\/qingye-lab\/hengmu . For a pinned local build, extract<br \/>the Agent Plugins ZIP and register its absolute directory in VS Code settings:<\/p>\n<p>{<br \/>&quot;chat.pluginLocations&quot;: {<br \/>&quot;\/absolute\/path\/to\/hengmu&quot;: true<br \/>}<br \/>}<\/p>\n<p>Open Chat: Open Customizations \u2192 Plugins to confirm installation. VS Code<br \/>namespaces plugin-provided Skills with the plugin name, so invoke<br \/>\/hengmu:hengmu audit this repository in Copilot Chat or use natural language.<br \/>The same package can be installed directly in GitHub Copilot CLI:<\/p>\n<p>copilot plugin install qingye-lab\/hengmu<br \/>copilot plugin list<br \/>copilot<\/p>\n<p>Start a new Copilot CLI session after installation and invoke \/hengmu &#8230; .<br \/>See the official VS Code Agent Plugins<br \/>and GitHub Copilot CLI plugin<br \/>documentation.<\/p>\n<p>Kiro<\/p>\n<p>Kiro discovers workspace Skills under .kiro\/skills\/ ; it does not use Hengmu&#x27;s<br \/>root plugin.json for this installation path. Extract the Agent Plugins ZIP to<br \/>a stable HENGMU_ROOT , then project both the Skills and their shared resources<br \/>into the repository. Run these commands only when .kiro\/resources is unused,<br \/>or merge the directories deliberately:<\/p>\n<p>mkdir -p .kiro\/skills .kiro\/resources<br \/>cp -R &quot;$HENGMU_ROOT\/skills\/.&quot; .kiro\/skills\/<br \/>cp -R &quot;$HENGMU_ROOT\/resources\/.&quot; .kiro\/resources\/<\/p>\n<p>Open Agent Steering &amp; Skills in Kiro and confirm all nine Hengmu Skills are<br \/>visible. Invoke \/hengmu audit this repository or use natural language. Do not<br \/>import only skills\/hengmu : the router delegates to eight sibling Skills and<br \/>those Skills require the shared runtime. See the official<br \/>Kiro Agent Skills guide .<\/p>\n<p>Prepare the shared Python runtime<\/p>\n<p>Hengmu&#x27;s Skills are portable, while its deterministic helpers require Python<br \/>3.11\u20133.13, PyYAML, and jsonschema. Install the locked dependencies into the<br \/>python3 environment exposed to the IDE agent, or launch the IDE from this<br \/>activated environment:<\/p>\n<p>cd &quot;$HENGMU_ROOT&quot;<br \/>python3 -m venv .venv<br \/>source .venv\/bin\/activate<br \/>python3 -m pip install &#8211;require-hashes -r requirements-runtime.lock<br \/>python3 resources\/scripts\/architecture_tool.py &#8211;version<\/p>\n<p>The last command should print architecture_tool.py 1.0.4 . On Windows<br \/>PowerShell, activate with .venv\\Scripts\\Activate.ps1 . Installation does not<br \/>grant permissions or enable Hooks; review each host&#x27;s agent permissions before<br \/>allowing repository writes or shell execution.<\/p>\n<p>Why Hengmu<\/p>\n<p>Most code and architecture reviews stop too early: they produce observations.<br \/>Hengmu is designed around a longer, evidence-bound engineering decision chain.<\/p>\n<p>Typical review failure<br \/>Hengmu&#x27;s response<\/p>\n<p>A model sees a large file or a singleton and declares an architecture problem.<br \/>Candidate findings must survive independent verification and evidence resolution before they become trusted.<\/p>\n<p>A team names a required stack but has no target architecture or explicit trade-offs.<br \/>Hengmu challenges required, preferred, and prohibited constraints, compares compliant variants, and records a complete target architecture instead of treating technology names as proof.<\/p>\n<p>A missing capability is mentioned as criticism but never designed.<br \/>Confirmed gaps flow into solution comparison, remediation slices, rollback, tests, and acceptance criteria.<\/p>\n<p>Every project copies the same architecture prompt and slowly diverges.<br \/>One global method reads a repository-local Profile and real constraints.<\/p>\n<p>Each repository looks reasonable in isolation while the portfolio duplicates infrastructure.<br \/>Portfolio review models shared capabilities, dependencies, data flow, ownership, and coupling.<\/p>\n<p>A prose policy says \u201cmust\u201d but automation cannot prove it.<br \/>JSON Schemas, hashes, Git evidence, role policy, fingerprints, signatures, and stable exit codes make enforcement reproducible.<\/p>\n<p>Hengmu is intentionally not a generic \u201cbest practices\u201d checklist. A rule is<br \/>useful only when it protects a declared quality or critical flow, and a<br \/>recommendation is useful only when the project can understand its cost,<br \/>dependencies, migration order, and stopping conditions.<\/p>\n<p>Quick start<\/p>\n<p>1. Prepare the runtime<\/p>\n<p>Hengmu supports Python 3.11\u20133.13. The runtime is local: it requires no hosted<br \/>service, telemetry, credentials, network access, or MCP server.<\/p>\n<p>git clone https:\/\/github.com\/qingye-lab\/hengmu.git<br \/>cd hengmu<\/p>\n<p>python3 -m venv .venv<br \/>source .venv\/bin\/activate<br \/>python3 -m pip install &#8211;require-hashes -r requirements-runtime.lock<br \/>python3 scripts\/validate_repository.py<\/p>\n<p>On Windows PowerShell, activate the environment with:<\/p>\n<p>.venv\\Scripts\\Activate.ps1<\/p>\n<p>2. Prepare the repository<\/p>\n<p>HENGMU_ROOT=\/path\/to\/hengmu<\/p>\n<p>python3 &quot;$HENGMU_ROOT\/resources\/scripts\/architecture_tool.py&quot; \\<br \/>prepare-project-audit &#8211;repo \/path\/to\/your-project<\/p>\n<p>The command creates a facts-derived repository-local control plane when it is<br \/>missing, or validates and reuses the existing one without overwriting it:<\/p>\n<p>.architecture\/<br \/>\u251c\u2500\u2500 profile.yaml<br \/>\u251c\u2500\u2500 repository-facts.yaml<br \/>\u251c\u2500\u2500 constraints.md<br \/>\u251c\u2500\u2500 critical-flows.md<br \/>\u251c\u2500\u2500 gate-policy.yaml<br \/>\u251c\u2500\u2500 baseline.yaml<br \/>\u251c\u2500\u2500 risk-acceptances.yaml<br \/>\u251c\u2500\u2500 evidence-providers.yaml<br \/>\u251c\u2500\u2500 evidence\/<br \/>\u251c\u2500\u2500 rules\/<br \/>\u251c\u2500\u2500 runs\/<br \/>\u2514\u2500\u2500 reviews\/<\/p>\n<p>3. Choose the outcome in Codex<\/p>\n<p>The examples below use Codex&#x27;s $hengmu invocation syntax. In another Agent<br \/>Plugins host, install the portable archive and invoke the same Skill through<br \/>that host&#x27;s documented UI or command syntax; $hengmu is not a portable<br \/>invocation contract.<\/p>\n<p>For an existing system, start with current-state assessment:<\/p>\n<p>Use $hengmu to audit this repository.<br \/>Treat missing capabilities as findings, but verify evidence before<br \/>recommending a structural change.<\/p>\n<p>$hengmu is the only Skill name you need to remember. Invoke it by itself to<br \/>see the complete capability menu, or describe the outcome in natural language:<\/p>\n<p>$hengmu<br \/>$hengmu verify the latest candidate findings<br \/>$hengmu compare the queue and durable-workflow options<\/p>\n<p>For a new system or major redesign, add and approve a Design Brief, then ask for<br \/>an open or constrained target:<\/p>\n<p>if [ ! -e \/path\/to\/your-project\/.architecture\/architecture-design-brief.yaml ]; then<br \/>cp &quot;$HENGMU_ROOT\/resources\/templates\/architecture-design-brief.yaml&quot; \\<br \/>\/path\/to\/your-project\/.architecture\/architecture-design-brief.yaml<br \/>fi<\/p>\n<p>python3 &quot;$HENGMU_ROOT\/resources\/scripts\/architecture_tool.py&quot; \\<br \/>validate-design-brief \\<br \/>\/path\/to\/your-project\/.architecture\/architecture-design-brief.yaml \\<br \/>&#8211;project \/path\/to\/your-project<\/p>\n<p>The copied template is deliberately draft . Before changing it to approved ,<br \/>add brief.approval with an authorized decision-maker identity and at least one<br \/>repository-relative approval-evidence path and SHA-256, plus one detached SSH<br \/>signature per approver. The signatures must verify against the project&#x27;s<br \/>artifact_signatures policy. Validation never treats the template authors or<br \/>a status string as approval.<\/p>\n<p>$hengmu design an open target architecture from the approved Design Brief<br \/>$hengmu constrain the target to FastAPI, PostgreSQL, and one production deployment; challenge each constraint and record rejected alternatives<\/p>\n<p>The current Brief 1.1 path produces a proposed Decision 1.4 with the complete<br \/>target architecture. Hengmu does not approve the Brief or Decision and does not<br \/>implement application code. After an authorized decision maker accepts the<br \/>Decision, $hengmu plan \u2026 can produce a Greenfield Plan 1.3.<\/p>\n<p>The audit path can be run directly: the Skill invokes the preparation command<br \/>and initializes .architecture\/ automatically. Use an explicitly read-only<br \/>request only when you want a one-off Advisory assessment with no repository<br \/>artifacts.<\/p>\n<p>The project Profile decides which qualities and specialist reviews matter.<br \/>The global Skill provides the method; the repository provides the truth.<\/p>\n<p>project:<br \/>name: example-service<br \/>type:<br \/>&#8211; ai-agent-platform<br \/>critical_qualities:<br \/>&#8211; traceability<br \/>&#8211; recoverability<br \/>&#8211; privacy<br \/>required_reviews:<br \/>&#8211; project-architecture<br \/>&#8211; ai-agent-architecture<\/p>\n<p>4. Validate the result<\/p>\n<p>python3 &quot;$HENGMU_ROOT\/resources\/scripts\/architecture_tool.py&quot; \\<br \/>validate-project \/path\/to\/your-project<\/p>\n<p>python3 &quot;$HENGMU_ROOT\/resources\/scripts\/architecture_tool.py&quot; \\<br \/>gate &#8211;project \/path\/to\/your-project &#8211;stage change<\/p>\n<p>python3 &quot;$HENGMU_ROOT\/resources\/scripts\/architecture_tool.py&quot; \\<br \/>gate &#8211;project \/path\/to\/your-project \\<br \/>&#8211;decision .architecture\/reviews\/&lt;greenfield-decision.yaml&gt; &#8211;stage change<\/p>\n<p>The gate returns 0 for pass, 1 for policy failure, and 2 for invalid<br \/>input or configuration.<\/p>\n<p>How it works<\/p>\n<p>Hengmu separates model judgment from deterministic trust. It accepts two source<br \/>paths, and neither a candidate audit nor a constraint assertion is policy or<br \/>proof.<\/p>\n<p>The diagram is maintained as<br \/>Mermaid source and an<br \/>editable Excalidraw scene .<\/p>\n<p>Establish facts and intent. Inspect the repository and bind the Profile;<br \/>for target design, add an approved Brief with measurable scenarios and<br \/>boundaries.<\/p>\n<p>Load context. Bind constraints, critical flows, selected Rule Packs, and<br \/>task-scoped Knowledge without turning detected technology or owner assertions<br \/>into proof.<\/p>\n<p>Assess or design. Existing systems produce candidate findings for<br \/>independent verification. Greenfield work uses the approved Brief to compare<br \/>open or constraint-compliant targets without manufacturing Findings.<\/p>\n<p>Decide. Record the selected target, rejected alternatives, trade-offs,<br \/>complete architecture model, source bindings, and proposed status.<\/p>\n<p>Authorize. A named decision maker accepts, rejects, or supersedes the<br \/>Decision; Hengmu&#x27;s router and Advisor cannot perform this transition.<\/p>\n<p>Plan. Turn an accepted remediation or Greenfield target into ordered<br \/>implementation slices, protections, rollback, stop conditions, and<br \/>acceptance evidence.<\/p>\n<p>Gate. Apply deterministic contract, finding, change, or release policy<br \/>to provenance-bound artifacts.<\/p>\n<p>One method, many projects<\/p>\n<p>A repository should not carry a private copy of the architecture method.<br \/>Instead, it carries only the context that makes its decisions different:<\/p>\n<p>profile.yaml \u2014 project type, critical qualities, and required reviews;<\/p>\n<p>constraints.md \u2014 real technical, product, regulatory, and team limits;<\/p>\n<p>critical-flows.md \u2014 business and runtime paths that must not regress;<\/p>\n<p>architecture-design-brief.yaml \u2014 target intent, quality scenarios,<br \/>boundaries, and typed constraints;<\/p>\n<p>reviews\/ \u2014 candidate and verified Reviews, Decisions, Plans, and evidence<br \/>history.<\/p>\n<p>Portfolio review adds the missing system-of-systems view: which capabilities<br \/>should be shared, which boundaries must remain independent, where data moves,<br \/>and where one repository can unexpectedly affect another.<\/p>\n<p>Workflows<\/p>\n<p>The installable plugin exposes one stable entry point and eight focused<br \/>workflow Skills. Use $hengmu for normal work; direct focused invocation<br \/>remains available for automation and compatibility.<\/p>\n<p>What you type<br \/>Required input<br \/>Output<\/p>\n<p>$hengmu<br \/>Declared repository context, when present<br \/>Menu and read-only next-step guidance<\/p>\n<p>$hengmu audit\/ai\/mobile\/portfolio \u2026<br \/>Repository or portfolio facts and Profile<br \/>Candidate Review in the selected scope<\/p>\n<p>$hengmu verify \u2026<br \/>Candidate Review and resolvable evidence<br \/>Provenance-bound verified Review<\/p>\n<p>$hengmu decide \u2026<br \/>Verified Review or approved Design Brief<br \/>Proposed Architecture Decision<\/p>\n<p>$hengmu design\/specify\/constrain \u2026<br \/>Approved Brief 1.1, facts, constraints, and selected Knowledge<br \/>Proposed Decision 1.4 with an open or constrained target architecture<\/p>\n<p>$hengmu plan \u2026<br \/>Accepted remediation or Greenfield Decision<br \/>Ordered remediation Plan 1.2 or Greenfield Plan 1.3<\/p>\n<p>$hengmu gate \u2026<br \/>Schema-valid, provenance-bound artifacts<br \/>Deterministic policy result and stable exit code<\/p>\n<p>Commands are optional. Natural language such as<br \/>$hengmu help me compare these two technical approaches routes to the same<br \/>focused workflow.<\/p>\n<p>Focused workflow contracts<\/p>\n<p>Phase<br \/>Skill<br \/>Responsibility<\/p>\n<p>Audit<br \/>project-architecture-audit<br \/>Boundaries, data ownership, contracts, reliability, security, operations, tests, deployment, debt, and proportionality in one repository.<\/p>\n<p>Audit<br \/>ai-agent-architecture-audit<br \/>Models, context necessity\/assembly\/compression\/cache ordering, Memory, retrieval, tools, injection, privacy, approval, recovery, version-bound behavior evidence, cost, latency, and evolution boundaries.<\/p>\n<p>Audit<br \/>mobile-architecture-audit<br \/>Local state, sync, migrations, background work, notifications, privacy, caching, and lifecycle behavior.<\/p>\n<p>Audit<br \/>portfolio-architecture-audit<br \/>Duplication, stack sprawl, shared capabilities, dependencies, data flow, ownership, and hidden coupling across projects.<\/p>\n<p>Verify<br \/>architecture-finding-verifier<br \/>Challenge candidates, resolve evidence, assign V0\u2013V5 verification, and produce a provenance-bound trusted Review.<\/p>\n<p>Decide<br \/>architecture-solution-advisor<br \/>Compare or specify open\/constrained targets; assess required conflicts, preferred trade-offs, prohibited eliminations, and target units, flows, boundaries, operations, and Knowledge.<\/p>\n<p>Plan<br \/>architecture-remediation-planner<br \/>Convert an accepted remediation or Greenfield target into ordered implementation slices, migration controls where applicable, protections, stop conditions, rollback, and acceptance criteria without inventing Findings.<\/p>\n<p>Enforce<br \/>architecture-quality-gate<br \/>Apply deterministic contract, finding, change, and release policy to trusted artifacts.<\/p>\n<p>$hengmu may also explain the read-only lifecycle state and the next valid<br \/>focused workflow from existing artifacts. It does not verify findings, accept a<br \/>decision, mutate policy, or run a Gate on the user&#x27;s behalf.<\/p>\n<p>Project-owned quality evidence<\/p>\n<p>Hengmu treats language linters and quality analyzers as optional Evidence<br \/>Providers, not as architecture truth. The bundled catalog includes representative<br \/>providers for Python, JavaScript\/TypeScript, Rust, Go, Swift, and Kotlin\/JVM in<br \/>addition to architecture, contract, test, runtime, security, and supply-chain<br \/>providers.<\/p>\n<p>Provider discovery distinguishes an applicable marker, project configuration,<br \/>enablement, executable availability, and readiness. A missing executable remains<br \/>an explicit unassessed evidence surface. Hengmu never downloads, installs, enables,<br \/>or adds a dependency implicitly. If installation would materially improve the<br \/>review, it first names the exact tool, scope, version strategy, command, affected<br \/>files, and consequence, then asks for user authorization.<\/p>\n<p>A Provider pass proves only the captured command, executable, declared project<br \/>dependency closure, isolated cache mode, configuration,<br \/>commit, and output bytes. It becomes architecture evidence only after it is bound<br \/>to an applicable invariant and independently reviewed.<\/p>\n<p>Knowledge curation is deliberately maintainer-only. Its source workflow lives<br \/>under maintainer\/skills\/architecture-knowledge-curator\/ and does not expand<br \/>the public end-user Skill surface.<\/p>\n<p>Trust model<\/p>\n<p>Hengmu&#x27;s trust boundary is simple:<\/p>\n<p>A model may propose. Evidence, authority, provenance, and policy decide what<br \/>can become trusted or blocking.<\/p>\n<p>A trusted Review binds the reviewed repository identity and Git state, exact<br \/>scope, Profile, repository facts, selected Knowledge, Rule Packs, candidate<br \/>review, verifier authority, semantic Finding fingerprints, critical-flow<br \/>coverage, and resolvable evidence.<\/p>\n<p>The deterministic runtime provides:<\/p>\n<p>JSON Schemas for project, review, decision, plan, policy, baseline, risk<br \/>acceptance, Knowledge, provider, benchmark, and governance artifacts;<\/p>\n<p>machine-readable core and domain Rule Packs with complete-coverage checks;<\/p>\n<p>sourced Knowledge Packs selected under explicit context budgets;<\/p>\n<p>opt-in Evidence Providers with no-shell execution, safe environment<br \/>allowlists, timeouts, structured-output validation, and tamper-evident run<br \/>records;<\/p>\n<p>Git evidence resolution, exact hashes, signature verification, SARIF, review<br \/>diffing, artifact migration, benchmark scoring, and layered gates.<\/p>\n<p>Gate stages are cumulative:<\/p>\n<p>Stage<br \/>Proves<\/p>\n<p>contract<br \/>Schemas, provenance, identity, hashes, roles, and coverage are valid.<\/p>\n<p>finding<br \/>Severity, confidence, verification, status, baseline, waiver, and risk acceptance satisfy policy.<\/p>\n<p>change<br \/>Review freshness, changed contracts, required decisions, migration compatibility, signatures, and evidence resolution are acceptable.<\/p>\n<p>release<br \/>Required evidence, decision authority, and complete remediation acceptance are present.<\/p>\n<p>Read the assurance model for threats, controls, and<br \/>residual risk. A passing gate proves policy evaluation of supplied artifacts;<br \/>it does not prove that the audited product is correct, secure, compliant, or<br \/>well designed.<\/p>\n<p>Trusted review and evidence commands<br \/>python3 resources\/scripts\/architecture_tool.py review-bindings \\<br \/>&#8211;project \/path\/to\/project \\<br \/>&#8211;candidate .architecture\/reviews\/example-candidates.yaml<\/p>\n<p>python3 resources\/scripts\/architecture_tool.py validate-review \\<br \/>\/path\/to\/verified.yaml &#8211;project \/path\/to\/project<\/p>\n<p>python3 resources\/scripts\/architecture_tool.py verify-evidence \\<br \/>&#8211;repo \/path\/to\/project &#8211;review \/path\/to\/verified.yaml<\/p>\n<p>python3 resources\/scripts\/architecture_tool.py verify-review-signature \\<br \/>&#8211;project \/path\/to\/project &#8211;review \/path\/to\/verified.yaml<\/p>\n<p>Task-scoped Knowledge selection<br \/>python3 resources\/scripts\/architecture_tool.py inspect-repository \\<br \/>&#8211;repo \/path\/to\/project \\<br \/>&#8211;output \/path\/to\/project\/.architecture\/repository-facts.yaml<\/p>\n<p>python3 resources\/scripts\/architecture_tool.py select-knowledge \\<br \/>&#8211;facts \/path\/to\/project\/.architecture\/repository-facts.yaml \\<br \/>&#8211;profile \/path\/to\/project\/.architecture\/profile.yaml \\<br \/>&#8211;task &quot;Current architecture audit&quot; \\<br \/>&#8211;skill project-architecture-audit \\<br \/>&#8211;output \/path\/to\/project\/.architecture\/knowledge-selection.yaml \\<br \/>&#8211;context-output \/path\/to\/project\/.architecture\/knowledge-context.yaml<\/p>\n<p>python3 resources\/scripts\/architecture_tool.py validate-knowledge-context \\<br \/>\/path\/to\/project\/.architecture\/knowledge-context.yaml \\<br \/>&#8211;selection \/path\/to\/project\/.architecture\/knowledge-selection.yaml \\<br \/>&#8211;facts \/path\/to\/project\/.architecture\/repository-facts.yaml \\<br \/>&#8211;profile \/path\/to\/project\/.architecture\/profile.yaml<\/p>\n<p>Governance modes<\/p>\n<p>Not every project needs the same ceremony.<\/p>\n<p>Mode<br \/>Use when<br \/>Behavior<\/p>\n<p>Advisory<br \/>The project needs structured architecture help without a blocking gate.<br \/>Skills produce evidence-backed artifacts; maintainers retain full judgment.<\/p>\n<p>Governed<br \/>Important changes need trusted review, explicit decisions, and change policy.<br \/>Provenance, authority, freshness, and Finding policy are enforced.<\/p>\n<p>Enforced<br \/>Releases require deterministic architecture evidence and completed remediation.<br \/>Change and release gates become required delivery controls.<\/p>\n<p>See governance modes for adoption guidance.<br \/>product_mode is a declared operating tier, not a bypass: an explicitly<br \/>invoked gate always evaluates its policy.<\/p>\n<p>Documentation<\/p>\n<p>Read this<br \/>When you need<\/p>\n<p>Target architecture<br \/>Facts, Knowledge, workflow, trust boundaries, and runtime components.<\/p>\n<p>Assurance model<br \/>Threats, guarantees, non-guarantees, and residual risk.<\/p>\n<p>Governance modes<br \/>Advisory, Governed, and Enforced adoption.<\/p>\n<p>Evaluation guide<br \/>Behavior benchmarks, ablation, scoring, and interpretation limits.<\/p>\n<p>Knowledge authoring<br \/>Source quality, freshness, frontmatter, and curation rules.<\/p>\n<p>Compatibility<br \/>Supported Python, schemas, artifacts, and version boundaries.<\/p>\n<p>Host compatibility<br \/>Cross-IDE outcome equivalence, package paths, and host-specific boundaries.<\/p>\n<p>Support and feedback<br \/>Reproducible defects, documentation gaps, and host compatibility reports.<\/p>\n<p>1.0 migration<br \/>Open\/constrained Brief\/Decision\/Plan artifacts, coexistence, and rollback.<\/p>\n<p>Release verification<br \/>Deterministic ZIPs, checksums, SBOMs, and attestations.<\/p>\n<p>Roadmap<br \/>Canonical forward plan, evidence milestones, and conditional triggers.<\/p>\n<p>Implementation matrix<br \/>How review recommendations map to executable capability and evidence.<\/p>\n<p>Dogfood review history<br \/>How Hengmu governs its own repository.<\/p>\n<p>Visual assets<br \/>Bilingual icon, banner, editorial character, and diagram source conventions.<\/p>\n<p>Accepted architecture decisions live in docs\/decisions .<br \/>The repository&#x27;s implemented target state is tracked in the<br \/>target architecture implementation matrix .<\/p>\n<p>Development<\/p>\n<p>python3 -m venv .venv<br \/>source .venv\/bin\/activate<br \/>python3 -m pip install &#8211;require-hashes -r requirements-dev.lock<\/p>\n<p>python3 scripts\/validate_repository.py<br \/>python3 resources\/scripts\/architecture_tool.py validate-project .<br \/>python3 resources\/scripts\/architecture_tool.py validate-history-anchors .<br \/>python3 resources\/scripts\/validate_knowledge.py<br \/>python3 -m pytest<br \/>python3 resources\/scripts\/architecture_tool.py gate &#8211;project . &#8211;stage change<br \/>python3 -m ruff check .<br \/>python3 -m ruff format &#8211;check .<br \/>python3 scripts\/audit_licenses.py<\/p>\n<p>Build and verify both deterministic plugin archives:<\/p>\n<p>python3 scripts\/package_plugin.py &#8211;format codex &#8211;output-dir dist<br \/>python3 scripts\/package_plugin.py &#8211;format agent-plugins &#8211;output-dir dist<br \/>python3 scripts\/smoke_test_package.py \\<br \/>&#8211;format codex \\<br \/>&#8211;archive dist\/hengmu-&lt;version&gt;.zip<br \/>python3 scripts\/smoke_test_package.py \\<br \/>&#8211;format agent-plugins \\<br \/>&#8211;archive dist\/hengmu-&lt;version&gt;-agent-plugins.zip<br \/>python3 scripts\/verify_checksum.py dist\/*.zip.sha256<br \/>python3 scripts\/generate_sbom.py \\<br \/>&#8211;archive dist\/*.zip \\<br \/>&#8211;output-dir dist<\/p>\n<p>The Codex archive is hengmu-&lt;version&gt;.zip . The portable Agent Plugins<br \/>archive is hengmu-&lt;version&gt;-agent-plugins.zip and uses the host-neutral root<br \/>plugin.json . It also retains the complete .codex-plugin\/plugin.json ,<br \/>including its Codex-only interface fields, as inert provenance data required<br \/>by the shared Knowledge selector. Codex-specific skills\/*\/agents\/openai.yaml<br \/>files are excluded from the portable archive.<\/p>\n<p>CI runs the supported Python boundary on Linux, macOS, and Windows. Tagged<br \/>releases publish both deterministic ZIPs, their SHA-256 checksums and SPDX<br \/>SBOMs, and GitHub provenance\/SBOM attestations.<\/p>\n<p>Feedback and compatibility reports<\/p>\n<p>Real user feedback is welcome, including reports that a Skill works differently<br \/>across Codex, Cursor, or another Agent Plugins host. Open a<br \/>bug report<br \/>for reproducible behavior or a<br \/>feature request<br \/>for a focused improvement. Read SUPPORT.md first.<\/p>\n<p>For an IDE or host report, include the package format, Hengmu version or commit,<br \/>client name and version, operating system, installation path, Skill or prompt,<br \/>expected result, observed result, and sanitized logs. Do not include credentials,<br \/>private repository content, or personal data. We treat client support as<br \/>evidence-backed and time-bound: a report can improve the compatibility record,<br \/>but an untested client is not presented as verified support.<\/p>\n<p>Non-goals<\/p>\n<p>Hengmu does not:<\/p>\n<p>autonomously approve architecture decisions, risk, or releases;<\/p>\n<p>turn every detected technology, pattern, or large file into a Finding;<\/p>\n<p>discover unrelated repositories without an explicit portfolio registry;<\/p>\n<p>implement the audited product&#x27;s remediation by itself;<\/p>\n<p>replace dedicated security, privacy, performance, legal, or compliance<br \/>assessment;<\/p>\n<p>prove that a system is secure or correct.<\/p>\n<p>Contributing<\/p>\n<p>Focused issues and pull requests are welcome. Start with<br \/>CONTRIBUTING.md , then read<br \/>GOVERNANCE.md , SECURITY.md , and<br \/>SUPPORT.md .<\/p>\n<p>Changes to public schemas, CLI behavior, policy, trust boundaries, or persisted<br \/>artifacts require compatibility analysis, tests, migration notes, and an<br \/>updated architecture decision when authority changes.<\/p>\n<p>When a Review or Selector Runtime binds source commits, preserve those commits<br \/>with a Merge Commit. Squash or rebase merging can invalidate source ancestry<br \/>and is rejected by validate-history-anchors .<\/p>\n<p>Credits and license<\/p>\n<p>Hengmu is a \u9752\u91ce open-source project:<br \/>\u7406\u6027\u7ed3\u6784\u4e2d\u7684\u6301\u7eed\u8fdb\u5316\uff0c\u5728\u4e0d\u786e\u5b9a\u4e2d\uff0c\u6301\u7eed\u6784\u5efa\u3002<\/p>\n<p>The README&#x27;s editorial illustration system was created with<br \/>Ian Xiaohei Illustrations<br \/>and recast with an original \u9752\u91ce builder character derived from the public<br \/>\u9752\u91ce avatar and brand palette. The technical flow is<br \/>available as Mermaid, Excalidraw, SVG, and PNG so documentation remains<br \/>editable.<\/p>\n<p>PAAD-derived concepts retain attribution in NOTICE and<br \/>third_party\/PAAD-MIT.txt .<\/p>\n<p>The software is licensed under the MIT License . The \u9752\u91ce wordmark<br \/>identifies the originating project and is not a grant to imply endorsement.<\/p>\n<h2>\u8bd5\u8bd5\u8fd9\u6837\u505a<\/h2>\n<ul>\n<li>\u5e2e\u6211\u5ba1\u8ba1\u5f53\u524d\u9879\u76ee\u4ed3\u5e93\u7684\u67b6\u6784\uff0c\u8bc6\u522b\u5b89\u5168\u8fb9\u754c\u95ee\u9898\u5e76\u7ed9\u51fa\u53ef\u843d\u5730\u7684\u4fee\u590d\u65b9\u6848\u3002<\/li>\n<li>\u5e2e\u6211\u5ba1\u8ba1\u5f53\u524d\u9879\u76ee\u4ed3\u5e93\u7684\u6574\u4f53\u67b6\u6784\uff0c\u8f93\u51fa\u7ecf\u8fc7\u9a8c\u8bc1\u7684\u98ce\u9669\u53d1\u73b0\u6e05\u5355<\/li>\n<li>\u4e3a\u6211\u65b0\u5f00\u53d1\u7684\u79fb\u52a8\u5e94\u7528\u8bbe\u8ba1\u7b26\u5408\u6027\u80fd\u548c\u9690\u79c1\u7ea6\u675f\u7684\u76ee\u6807\u67b6\u6784<\/li>\n<\/ul>\n<hr \/>\n<p>\u4f5c\u8005\uff1aqingye-lab \u5f00\u53d1\u8005 \/ \u804c\u573a\u4eba \uff5c GitHub Stars 1 \uff5c \u6807\u7b7e\uff1a\u7f16\u7a0b\u5f00\u53d1 \u9879\u76ee\u7ba1\u7406 \u5df2\u8ba4\u8bc1 \u5f00\u6e90\u8bb8\u53ef: MIT<\/p>\n<p>\u6765\u6e90\uff1a<a href=\"https:\/\/colaos.ai\/skills\/zh\/hengmu\/\">colaos.ai<\/a> \uff5c Skill ID\uff1ahengmu<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u83b7\u5f97\u57fa\u4e8e\u9879\u76ee\u5b9e\u636e\u7684\u67b6\u6784\u98ce\u9669\u6e05\u5355\u3001\u53ef\u843d\u5730\u4fee\u590d\u65b9\u6848\u3001\u5408&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4196,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[72],"tags":[],"class_list":["post-4197","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-skill"],"_links":{"self":[{"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=\/wp\/v2\/posts\/4197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4197"}],"version-history":[{"count":1,"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=\/wp\/v2\/posts\/4197\/revisions"}],"predecessor-version":[{"id":4198,"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=\/wp\/v2\/posts\/4197\/revisions\/4198"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=\/wp\/v2\/media\/4196"}],"wp:attachment":[{"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ai.jxgzhc.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}