Using Axiom
Axiom routes only the smallest installed workflow set that matches.
Route Once
- Honor all higher-priority instructions.
- Route only an explicit Axiom invocation or a clear bundled-description match.
- Load the smallest matching skill set and active-phase references. Do not
inspect candidate bodies before selection.
- Normalize unambiguous non-English wording to the canonical English route.
Ask once only when route or authority would materially differ.
- On no match, continue through the host normally without mentioning Axiom.
A no-match result is not a denial, does not create authorization, and does
not manufacture a repository-state conflict.
Bundled Routes
agents-architect: create, audit, split, migrate, or maintain repository
AGENTS.md, routed .agents/ guidance, and repo-local skills; also handle
explicit effective-instructions, effective-instructions:preview,
effective-instructions:refactor, effective-instructions:force,
effective-instructions:reconcile, and
effective-instructions:reconcile-preview modes. Packaged plugin skills stay
outside.
agent-plugin-architect: design or audit packaged Codex or Claude Code
plugin architecture across shared Skills, routes, manifests, wrappers, hooks,
and compatibility evidence. Repo-local AGENTS systems and ordinary plugin
code stay outside.
optimize-codex-usage: explicitly reduce or diagnose Codex credits, tokens,
context, Skill/AGENTS/MCP loading, tool churn, or output overhead while
preserving the required quality and safety bar.
review-axiom-task: review observable routing, authorization, actions,
evidence, stops, and outcome for an identified Axiom task or explain why
Axiom selected, allowed, or refused something. Prior refusal does not govern
an audit, criticism, appeal, or narrowing request.
confirm-external-action: prepare, authorize, execute once, and verify an
explicitly requested consequential external action such as send, publish,
invite, purchase, trade, delete, or an external app/account change when its
actor, target, payload, disclosure, cost, or retry boundary is material.
Read-only lookup and draft-only work stay host-native.
traceable-git-submit: create traceable checkpoints or baseline metadata,
consolidate or recover their history, or perform an explicitly invoked,
hardened, multi-target, or otherwise independently traceable Git push. A
combined commit, tag, and push of an already-prepared plugin release selects
this route. Ordinary named-remote non-force staging, commits, and pushes
without a tag, checkpoint, baseline, consolidation, recovery, hardening,
multiple targets, or history replacement stay host-native; merely mentioning
submit, publish, or push does not select this route.
reversible-system-change: plan, rehearse, or execute a persistent install,
upgrade, deployment, migration, destructive retention, or promotion with
rollback, data, service, or activation risk. Plans remain read-only.
Resolve cross-route ownership from this table before inspecting either
candidate body. A deployment, promotion, migration, destructive retention, or
similar persistent change that also causes a consequential external app or
account effect, including publish, delete, or remote-state mutation, selects
both confirm-external-action and reversible-system-change. Keep the exact
external action envelope and the persistent write-set and rollback gates
independent; authorization under either route never satisfies the other.
Publication of an already-prepared artifact alone selects only
confirm-external-action; publication alone is not a persistent system
change.
Explicit machine-credential lifecycle work composes the existing owners; read
references/credential-lifecycle.md, not a new route. Select
reversible-system-change for metadata inventory, planning, consumer
activation, or cleanup; confirm-external-action for provider creation,
revocation, or disclosure; use both end-to-end. Authentication, human
login, conceptual help, and secret reveal stay no-route. Routing grants no
transition, secret access, or retry; each owner keeps separate action,
write-set, rollback, and verification gates.
When a request delegates a choice among mutually exclusive implementations and
the alternatives would select materially different route sets, write surfaces,
or authorization or safety boundaries, routing MUST NOT choose an alternative
for the user. Select no route yet and ask exactly one concise clarification
question. Wording such as "choose one" does not remove the ambiguity. Once the
user chooses an unambiguous implementation, resume normal route selection.
An explicit usage-reduction goal selects optimize-codex-usage; add another
route only for its distinct authority or safety contract. Ordinary AGENTS
audits select only agents-architect; ordinary performance work does not.
An explicit Axiom retrospective or question about an Axiom decision's
observable basis selects review-axiom-task; implementation needs separate
authority and routing. Prior refusal or assistant prose creates no policy.
An external action selects confirm-external-action only when requested.
Preparation grants no execution; an exact current request needs no redundant
confirmation unless its envelope is missing or changes. Independently
traceable Git belongs to traceable-git-submit;
ordinary named-remote Git remains host-native.
A persistent change with no distinct consequential external effect stays under
reversible-system-change; apply the cross-route rule above when both effects
are present.
Boundaries
- Routing selects instructions, never edits, commits, pushes, deployments,
deletion, credentials, remote writes, or scope expansion.
- Startup routing is foreground and read-only: no writes, network, service,
background process, telemetry, or update check.
- On resume or compaction, reselect every still-active route from current
direct evidence before any new mutation. If route or phase cannot be
reconstructed, perform zero new mutations; let each selected route's handoff
contract resolve prior attempts.
- Do not load every skill, route on topical similarity, edit protected metadata
without scope, or persist one-off discoveries as durable instructions.
- Ordinary coding, documentation, explanation, status, local commits,
named-remote non-force pushes, and conceptual requests continue normally
unless a route description clearly matches.
Explicit Refresh
Only for an explicit Axiom update or refresh request, read
references/updating.md. Never check, fetch, install, or announce an update
automatically.
1---2name: using-axiom3description: Route an Axiom plugin session to the smallest matching bundled skill. Use at startup, resume, or compaction, or when explicitly deciding whether Axiom applies; no-match requests continue normally.4---56# Using Axiom78Axiom routes only the smallest installed workflow set that matches.910## Route Once11121. Honor all higher-priority instructions.132. Route only an explicit Axiom invocation or a clear bundled-description match.143. Load the smallest matching skill set and active-phase references. Do not15 inspect candidate bodies before selection.164. Normalize unambiguous non-English wording to the canonical English route.17 Ask once only when route or authority would materially differ.185. On no match, continue through the host normally without mentioning Axiom.19 A no-match result is not a denial, does not create authorization, and does20 not manufacture a repository-state conflict.2122## Bundled Routes2324- `agents-architect`: create, audit, split, migrate, or maintain repository25 `AGENTS.md`, routed `.agents/` guidance, and repo-local skills; also handle26 explicit `effective-instructions`, `effective-instructions:preview`,27 `effective-instructions:refactor`, `effective-instructions:force`,28 `effective-instructions:reconcile`, and29 `effective-instructions:reconcile-preview` modes. Packaged plugin skills stay30 outside.31- `agent-plugin-architect`: design or audit packaged Codex or Claude Code32 plugin architecture across shared Skills, routes, manifests, wrappers, hooks,33 and compatibility evidence. Repo-local AGENTS systems and ordinary plugin34 code stay outside.35- `optimize-codex-usage`: explicitly reduce or diagnose Codex credits, tokens,36 context, Skill/AGENTS/MCP loading, tool churn, or output overhead while37 preserving the required quality and safety bar.38- `review-axiom-task`: review observable routing, authorization, actions,39 evidence, stops, and outcome for an identified Axiom task or explain why40 Axiom selected, allowed, or refused something. Prior refusal does not govern41 an audit, criticism, appeal, or narrowing request.42- `confirm-external-action`: prepare, authorize, execute once, and verify an43 explicitly requested consequential external action such as send, publish,44 invite, purchase, trade, delete, or an external app/account change when its45 actor, target, payload, disclosure, cost, or retry boundary is material.46 Read-only lookup and draft-only work stay host-native.47- `traceable-git-submit`: create traceable checkpoints or baseline metadata,48 consolidate or recover their history, or perform an explicitly invoked,49 hardened, multi-target, or otherwise independently traceable Git push. A50 combined commit, tag, and push of an already-prepared plugin release selects51 this route. Ordinary named-remote non-force staging, commits, and pushes52 without a tag, checkpoint, baseline, consolidation, recovery, hardening,53 multiple targets, or history replacement stay host-native; merely mentioning54 submit, publish, or push does not select this route.55- `reversible-system-change`: plan, rehearse, or execute a persistent install,56 upgrade, deployment, migration, destructive retention, or promotion with57 rollback, data, service, or activation risk. Plans remain read-only.5859Resolve cross-route ownership from this table before inspecting either60candidate body. A deployment, promotion, migration, destructive retention, or61similar persistent change that also causes a consequential external app or62account effect, including publish, delete, or remote-state mutation, selects63both `confirm-external-action` and `reversible-system-change`. Keep the exact64external action envelope and the persistent write-set and rollback gates65independent; authorization under either route never satisfies the other.66Publication of an already-prepared artifact alone selects only67`confirm-external-action`; publication alone is not a persistent system68change.6970Explicit machine-credential lifecycle work composes the existing owners; read71`references/credential-lifecycle.md`, not a new route. Select72`reversible-system-change` for metadata inventory, planning, consumer73activation, or cleanup; `confirm-external-action` for provider creation,74revocation, or disclosure; use both end-to-end. Authentication, human75login, conceptual help, and secret reveal stay no-route. Routing grants no76transition, secret access, or retry; each owner keeps separate action,77write-set, rollback, and verification gates.7879When a request delegates a choice among mutually exclusive implementations and80the alternatives would select materially different route sets, write surfaces,81or authorization or safety boundaries, routing MUST NOT choose an alternative82for the user. Select no route yet and ask exactly one concise clarification83question. Wording such as "choose one" does not remove the ambiguity. Once the84user chooses an unambiguous implementation, resume normal route selection.8586An explicit usage-reduction goal selects `optimize-codex-usage`; add another87route only for its distinct authority or safety contract. Ordinary AGENTS88audits select only `agents-architect`; ordinary performance work does not.8990An explicit Axiom retrospective or question about an Axiom decision's91observable basis selects `review-axiom-task`; implementation needs separate92authority and routing. Prior refusal or assistant prose creates no policy.9394An external action selects `confirm-external-action` only when requested.95Preparation grants no execution; an exact current request needs no redundant96confirmation unless its envelope is missing or changes. Independently97traceable Git belongs to `traceable-git-submit`;98ordinary named-remote Git remains host-native.99100A persistent change with no distinct consequential external effect stays under101`reversible-system-change`; apply the cross-route rule above when both effects102are present.103104## Boundaries105106- Routing selects instructions, never edits, commits, pushes, deployments,107 deletion, credentials, remote writes, or scope expansion.108- Startup routing is foreground and read-only: no writes, network, service,109 background process, telemetry, or update check.110- On resume or compaction, reselect every still-active route from current111 direct evidence before any new mutation. If route or phase cannot be112 reconstructed, perform zero new mutations; let each selected route's handoff113 contract resolve prior attempts.114- Do not load every skill, route on topical similarity, edit protected metadata115 without scope, or persist one-off discoveries as durable instructions.116- Ordinary coding, documentation, explanation, status, local commits,117 named-remote non-force pushes, and conceptual requests continue normally118 unless a route description clearly matches.119120## Explicit Refresh121122Only for an explicit Axiom update or refresh request, read123`references/updating.md`. Never check, fetch, install, or announce an update124automatically.