degit Project Scaffolding
Rich-Harris/degit
Downloads a repository snapshot or template with degit into an empty folder, from GitHub, GitLab, Bitbucket, Sourcehut or a Gist, optionally at a branch, tag or commit.
Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup.
$ npx skills add AlexZio00/sovereign-skills --skill project-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AlexZio00/sovereign-skills project-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/project-check .claude/skills/project-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "project-check" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/project-check into .claude/skills/project-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AlexZio00/sovereign-skills/tree/master/project-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AlexZio00/sovereign-skills --skill project-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AlexZio00/sovereign-skills project-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/project-check .agents/skills/project-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "project-check" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/project-check into .agents/skills/project-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexZio00/sovereign-skills --skill project-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AlexZio00/sovereign-skills project-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/project-check .cursor/skills/project-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "project-check" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/project-check into .cursor/skills/project-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AlexZio00/sovereign-skills.git --path project-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AlexZio00/sovereign-skills --skill project-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AlexZio00/sovereign-skills project-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/project-check .gemini/skills/project-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "project-check" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/project-check into .gemini/skills/project-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AlexZio00/sovereign-skills project-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AlexZio00/sovereign-skills --skill project-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/project-check .github/skills/project-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "project-check" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/project-check into .github/skills/project-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlexZio00/sovereign-skills --skill project-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AlexZio00/sovereign-skills project-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/project-check .opencode/skills/project-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "project-check" agent skill from https://github.com/AlexZio00/sovereign-skills/tree/master/project-check into .opencode/skills/project-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
project-checkExisting project health scan — audits Infrastructure, Security, Quality, and Harness setup.
Project Check is an agent skill from AlexZio00/sovereign-skills. Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup. Read-only. Use when: '/project-check', 'project health check', 'project audit', 'what\'s missing', 'analyze my project', 'check setup'. Ends with /project-init and /setup recommendations. NOT for new projects (use /project-init); project-check = shallow health scan.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `.claude-plugin/plugin.json` and `agents/openai.yaml`).
It sits in Development, covering Project scaffolding. It works with Git. The repository describes itself as: 20 production-grade skills for AI coding agents — setup, scope, discipline, code review, security, session management, governance, ops, and quality audits (eval-leakage… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c062683. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitgoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Project Check loads about 5k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 2,275 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
e 🔴 Security issues (hardcoded secrets, .env missing) displayed before all other gaps?| `.gitignore` | Exists? `.env` actually ignored — verified via `git check-ignore -v .env` (see Step 2), not just stringAdditional checks — `.env` protection (skip entirely if not a git repo, per Key Assumption 2):A string match for `.env` inside `.gitignore` is not proof of protection — the pattern can be malformed (wrong path, typ1. `git check-ignore -v .env` — confirms the pattern actually matches the file. No output / non-zero exit → the listed p2. `git ls-files --error-unmatch .env` (exit 0 means tracked) — if `.env` is already tracked, → 🔴 "`.env` is already tr- `.env` missing from `.gitignore` entirely (no string match) → 🔴 as before.- `.env.local`, `.env.*.local` in `.gitignore` → ⚠ if missing (TypeScript/Next.js projects). Apply the same `git check-iemove secrets at [file:line] and move to .env (manual edit required)"| "`.gitignore` contains `.env`, so it is protected" | String presence is not proof. Step 2 verifies the real match andAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from AlexZio00/sovereign-skills at commit c062683, republished under its MIT licence (© AlexZio00). 2,275 words, ~5,019 tokens.
.claude/skills/project-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Discovered gaps are sorted by severity so the user knows "what to fix first" — an unsorted gap list causes information overload. A report without priority is useless.
Scan an existing project against setup best practices across 4 dimensions: Infrastructure, Security, Quality, and Harness. Surface all gaps ordered by severity so the user knows exactly what to fix and in what order.
Dominant variable: Are 🔴 Security issues (hardcoded secrets, .env missing) displayed before all other gaps?
/project-init or /setup.Discard if: Empty directory or a freshly initialized project (git init) — nothing to scan. Use /project-init directly instead.
Empty directory or newly initialized project (git init with no code yet) — nothing to audit. Use /project-init.
This skill audits code, infrastructure, security, and quality only.
Need a persistent, weighted maturity score with cross-axis trend tracking instead of a one-time 4-dimension pass/fail scan — use /check-harness, not this skill.
/project-init./project-checkCount source files to calibrate warning thresholds:
Scan: *.py, *.ts, *.tsx, *.js, *.go, *.rs, *.java, *.kt, *.swift, *.c, *.cpp, *.h
Exclude dirs: node_modules/, .venv/, venv/, __pycache__/, vendor/, dist/, build/, .git/, .next/, target/(Without this exclusion, dependency/build directories get swept into the file/LOC count and skew the Step 0 scale classification.)
Classify:
Detect project name from directory name or name field in package.json / pyproject.toml / Cargo.toml if present.
| Item | Check | Severity if missing/incomplete |
|---|---|---|
CLAUDE.md | Exists? Has ## Hard Rules? Has ## Secrets Policy? | ✗ missing / ⚠ incomplete |
docs/DEVELOPMENT_ROADMAP.md | Exists? (skip if scale=script) | ✗ if scale=full/mini |
.gitignore | Exists? .env actually ignored — verified via git check-ignore -v .env (see Step 2), not just string presence in the file | ✗ missing / 🔴 not ignored or already tracked (see Step 2) |
.env.example | Exists? (if API key patterns found in code) | ✗ if keys detected |
docs/decisions/ | Exists? (only check if scale=full) | ⚠ if scale=full |
For CLAUDE.md: count Hard Rules entries (lines starting with - under ## Hard Rules). Report the count.
Grep these patterns across all source files (case-insensitive). Exclude: *.example, .env.example, files in tests/, __tests__/, spec/, and dependency/build directories (node_modules/, .venv/, venv/, __pycache__/, vendor/, dist/, build/, .git/, .next/, target/ — same list as Step 0):
API_KEY\s*=\s*["'][^$({] → hardcoded API key
sk-[A-Za-z0-9]{20,} → OpenAI key (sk-...)
sk-ant-[A-Za-z0-9\-]{20,} → Anthropic key (sk-ant-api03-...)
ghp_[A-Za-z0-9]{36} → GitHub PAT
password\s*=\s*["'][^$({] → hardcoded password
secret\s*=\s*["'][^$({] → hardcoded secret
token\s*=\s*["'][^$({] → hardcoded tokenEach match → 🔴 with file:line reference. Read the matched line before judging: a placeholder value (your_key_here, xxx, changeme, <...>) is ℹ info, not 🔴. Never print the found value — report file:line and the pattern name only.
Additional checks — .env protection (skip entirely if not a git repo, per Key Assumption 2):
A string match for .env inside .gitignore is not proof of protection — the pattern can be malformed (wrong path, typo, wrong glob syntax) and never actually match, or the file can already be tracked in git, in which case .gitignore has no effect on it at all. Verify both:
git check-ignore -v .env — confirms the pattern actually matches the file. No output / non-zero exit → the listed pattern doesn't cover .env → 🔴 ".env present in .gitignore text but the pattern doesn't actually match (git check-ignore reports it as not ignored)". If the command is denied or fails (e.g. the target is outside the worktree), report "⚠️ cannot verify — string presence only" instead of a red finding.git ls-files --error-unmatch .env (exit 0 means tracked) — if .env is already tracked, → 🔴 ".env is already tracked in git — .gitignore cannot retroactively untrack it. Needs git rm --cached .env (manual step; this skill does not run it)"..env missing from .gitignore entirely (no string match) → 🔴 as before..env.local, .env.*.local in .gitignore → ⚠ if missing (TypeScript/Next.js projects). Apply the same git check-ignore -v verification when a matching line is present.Apply the same exclusion list as Step 0 (node_modules/, .venv/, __pycache__/, vendor/, dist/, build/, .git/, etc.) to every file count and grep below.
Test coverage proxy:
Count test files (test_*.py, *_test.py, *.test.ts, *.spec.ts, *_test.go, *Test.java, *Spec.kt) vs source files.
| Ratio | Result |
|---|---|
| ≥ 0.4 | ✓ |
| 0.2–0.4 | ⚠ |
| < 0.2 | ✗ (skip if scale=script) |
Debug remnants (grep non-test files):
console\.log|print\(f?["']|debugger;|pprint\(→ ⚠ if > 5 matches
Open work markers (grep all files):
TODO|FIXME|HACK|XXX→ ⚠ if > 10 total count
Profile detection (run first — determines whether orchestrator/agent-team absence is a gap at all):
Check whether the project shows any sign of agent-routing adoption:
.claude/agents/*.md (project-level) — any files present?~/.claude/agents/*.md (global) — any files present?If none of the above are present, infer Minimal profile — per the setup skill's own Q2 ("Minimal: rules + memory only. No agent routing" is a first-class, intentional choice, not a defect). Under Minimal profile, orchestrator/agent-team absence is a configuration choice, not a gap — do not score it as ⚠.
If any of the above are present, the project has adopted Standard/Orchestrated routing at least partially — a missing orchestrator or key agents at that point is a real gap (routing infrastructure exists without the piece that coordinates it), and stays ⚠.
Check Claude Code infrastructure:
| Item | Check | Severity |
|---|---|---|
~/.claude/rules/project rules | Exists? | ⚠ if missing |
~/.claude/rules/agents.md | Exists? | ⚠ if missing |
.claude/settings.json or ~/.claude/settings.json | hooks section present? | ⚠ if no hooks |
| CLAUDE.md Hard Rules format | Inline text vs project rules reference link | ⚠ if both (duplication) |
~/.claude/agents/ | Any .md agent files installed? (global) | ⚠ if empty and not Minimal profile; ℹ (no score) if empty and Minimal profile |
.claude/agents/ | Any .md agent files installed? (project-level) | ℹ if present (report separately) |
~/.claude/agents/orchestrator.md | Exists? | ⚠ if missing and not Minimal profile; skip (no flag) if Minimal profile |
| Orchestrator type | Contains drift detection (MISSING, EXTRA, DIVERGED, correction loop)? | ⚠ if absent, only when orchestrator.md exists (Light-only case) — N/A if orchestrator.md itself is missing, since that's already covered by the row above |
tasks/lessons.md | Exists? (skip if scale=script) | ⚠ if scale=full/mini |
| SubagentStop hook | SubagentStop included in settings.json hooks? | ⚠ if missing and not Minimal profile (a Minimal setup has no subagents to stop) |
Count total agent files across both locations. Report global vs project-level split. Report which key agents are installed (orchestrator, code-reviewer, verification, brainstorming, security-reviewer). If Minimal profile was inferred, report "0 agents — consistent with Minimal setup profile (rules + memory only)" instead of counting it toward gaps.
If CLAUDE.md has inline Hard Rules AND ~/.claude/rules/project rules exists → ⚠ "Hard Rules duplication: directly in CLAUDE.md AND project rules file present. Recommend consolidating to project rules with reference link in CLAUDE.md."
Sort all findings by severity within each section: 🔴 → ✗ → ⚠ → ✓
Score calculation:
Start: 10
-2 per 🔴
-1 per ✗
-0.5 per ⚠ (round to nearest 0.5)
Floor: 0Output:
Project Health Check: [project-name]
Scale: [script / mini / full] ([N] source files)
Security: ← always first, even if all pass
🔴/✓/⚠ items
Infrastructure:
✓/✗/⚠ items
Quality:
✓/✗/⚠ items
Harness:
✓/✗/⚠ items
Score: [N]/10
Gaps: [N] total (🔴 [N], ✗ [N], ⚠ [N])Always end with next steps:
/project-init — if CLAUDE.md exists, choose Update mode"/setup to configure Claude Code infrastructure"/setup to install agent team (orchestrator + reviewer + implementer)"/setup Update mode if you want review agents or orchestration."/setup Update mode to enable Full orchestrator (with drift detection)"Recommended loop (new users):
/project-check → discover gaps
→ /project-init (CLAUDE.md + ROADMAP + .gitignore)
→ /setup (rules + hooks + memory)
→ /setup (orchestrator + agent team)
→ /project-check (re-scan → verify score improvement)Look for a previous check result in two places, project-root first:
.project-check-history.json in project root.~/.claude/.harness/project-check/<project-name>.json (keyed by the detected project name from Step 0). This survives the project-root file being gone after a fresh clone or a .gitignore'd local file getting wiped.If either is found, compare against it:
── Score Delta ──
Previous: [N]/10 (YYYY-MM-DD) → Current: [M]/10
Change: [+X / -X / no change]
By category — Previous → Current:
🔴 Critical: [N] → [N]
✗ Fail: [N] → [N]
⚠ Warn: [N] → [N]Honesty limit: the history file stores only the total score and per-category counts (see JSON schema below) — it does not store which items failed. Item-level claims like "X went from ✗ to ✓" or "Y is a new gap" are not supported by this data and must never be shown — showing them would be a guess dressed as a fact. Report only the aggregate score and per-category count deltas above (e.g., "2 fewer ⚠ items than last run," not which ones resolved). Per-item history tracking is out of scope for this skill by design (a persistent, item-level maturity trend is check-harness's job — see see_also), not a missing feature to add here.
If neither exists, suggest saving current result — project-root file by default, user-level cache path as the fallback option if the project doesn't want history checked into (or gitignored within) the repo:
{"date":"YYYY-MM-DD","score":N,"gaps":{"critical":N,"fail":N,"warn":N}}"Next /project-check will show score delta." — one line.
No auto-save — this skill never writes it, period. The JSON snippet above is printed to the chat as text only. Actually creating or appending to .project-check-history.json is something the user does themselves — it is outside this skill's execution scope (this skill has no Write/Edit tool; see Invariant 1).
| Excuse | Rebuttal |
|---|---|
| "It's a new project, so gaps are normal" | If gaps are normal, the score is meaningless. Gaps are action items. |
| "Security scans have too many false positives" | That judgment is on you. A scan surfaces suspicious patterns. Better to ask. |
| "ROADMAP is unnecessary for small projects" | If scale=script, warnings are auto-skipped. Don't manually skip — let calibration work. |
| "Harness checks only apply to Claude Code users" | Missing agent infrastructure = re-explaining context every session. Costs accumulate. |
| "The score is low, but we can't fix it right now" | The score is priority information. Deferring is different from ignoring. |
".gitignore contains .env, so it is protected" | String presence is not proof. Step 2 verifies the real match and tracked status with git check-ignore -v and git ls-files --error-unmatch. |
| "0 agents means a setup deduction" | Check the project profile first. Under a Minimal profile, no agents is an intended choice, not a gap. |
| "Just delete the secret" | Invariant 1 — read-only. Report the location only; never remove it directly. |
| Does | Does NOT |
|---|---|
| [READ] Scan file existence (Glob) | Modify, create, or delete any file |
| [READ] Grep code patterns (read-only) | Execute tests (pytest, jest, go test, etc.) |
[READ] Run read-only git inspection (git check-ignore -v, git ls-files --error-unmatch) to verify .gitignore actually protects secret files | Run any git command that mutates state (commit, push, add, rm, checkout, etc.) |
| [READ] Output gap report | — |
| [READ] Recommend /project-init, /setup | Remove secrets directly |
| [READ] Analyze CLAUDE.md content | Refactor code or fix bugs |
| Risky Action | Reversibility | Applied Layers |
|---|---|---|
| File modification, deletion | medium | L1 (BLOCK) |
| Direct secret removal | none | L1 (BLOCK) |
Test execution (pytest, jest, etc.) | medium | L1 (BLOCK) |
disallowed-tools scope limit: disallowed-tools: Edit, Write, NotebookEdit blocks only those three tools — it does not stop the remaining Bash tool from writing directly (e.g. echo x > file, git commit). There is no physical (L2) block on that path for a skill loaded into the main loop like this one; enforcement currently relies on L1 prompt compliance (Invariant 1) alone, unless the host project wires its own PreToolUse hook to intercept write-shaped Bash commands.On failure: Stop → Classify → Apply Recovery → Report & Resume.
| Failure Type | Detection | Recovery Path |
|---|---|---|
tool_failure | File read fails (permission/path error) | Narrow scan scope to accessible files only; state scope reduction. |
missing_data | CLAUDE.md missing / project root unclear | State "CLAUDE.md not found". Never guess content of missing files. Recommend /setup and keep scanning the remaining steps. |
input_error | Unclear which project to check | Auto-scan from current directory. If that fails, ask one clarifying question. |
git check-ignore -v, git ls-files --error-unmatch, wc -l) — never a Bash command that writes, deletes, mutates git state, or executes project code. Violation → scan tool gains unintended side effects; user trust in a diagnostic tool erodes.pytest, jest, go test, or any test runner. Violation → unexpected test side effects (DB writes, API calls, network requests).These rules are unconditional. No user instruction overrides them.
Structured report in conversation — no files written.
Sections always in this order:
When reporting completion, this skill:
⚠️ SKIPPED: reason.WORKING / PARTIAL / BROKEN. For PARTIAL/BROKEN, list specific failures.© AlexZio00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in project-check of AlexZio00/sovereign-skills.
Open the folder on GitHubat commit c062683
Project Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Project Check this skillAlexZio00/sovereign-skills | 140 | — | ~5k | Automated safety check: Notes | MIT | |
| degit Project ScaffoldingRich-Harris/degit | 7.9k | — | ~534 | Automated safety check: Pass | MIT | |
| Compare Codegenhw-native-sys/pypto | 127 | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| Brain Bootstrapmindmuxai/brain.md | 566 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Light Project StructureLight0305/Light-skills | 640 | — | ~3k | Automated safety check: Notes | MIT | |
| Git Command Class Implementationruby-git/ruby-git | 1.8k | — | ~3k | Automated safety check: Pass | MIT |
Rich-Harris/degit
Downloads a repository snapshot or template with degit into an empty folder, from GitHub, GitLab, Bitbucket, Sourcehut or a Gist, optionally at a branch, tag or commit.
hw-native-sys/pypto
Compare codegen output (.pto files and pass dumps) between origin/main and the current branch for a given test case.
mindmuxai/brain.md
Seed a freshly-scaffolded brain with real project knowledge — on an existing (brownfield) project read the code, docs, and git log to draft the six root pages and capture key historical decisions…
Light0305/Light-skills
Audits, scaffolds and safely migrates research project folder structures, keeping existing repositories read-only until you approve exact moves from a plan.
ruby-git/ruby-git
Scaffolds and reviews `Git::Commands::*` classes in the ruby-git library, with unit tests, integration tests and YARD docs, using the Base command architecture.
rocky-data/rocky
Rocky CLI JSON-output schema cascade. An agent skill from rocky-data/rocky.
AlexZio00/sovereign-skills
A skill your agent uses when the user wants a deterministic cross-project status map generated from registered projects' session handoffs.
AlexZio00/sovereign-skills
Scope definition before implementation — two modes. An agent skill from AlexZio00/sovereign-skills.
AlexZio00/sovereign-skills
Interview-based project setup — generates CLAUDE.md, ROADMAP, .gitignore, .env.example from scratch.
AlexZio00/sovereign-skills
This skill should be used when the user types /collab-audit or requests AI collaboration diagnosis.
AlexZio00/sovereign-skills
A skill your agent uses when the user wants to audit the memory and documents Claude Code loads into context — CLAUDE.md (user global + project + nested), MEMORY.md, @imports, .claude/skills…
AlexZio00/sovereign-skills
A skill your agent uses when saving session state before context compaction, switching tasks, or ending a session.
Works with
Categories
Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup. Project Check is an agent skill from AlexZio00/sovereign-skills. Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup.
Project Check fits situations like: : /project-check; project health check; analyze my project.
Run `npx skills add AlexZio00/sovereign-skills --skill project-check -a claude-code`. Or copy the skill folder (project-check in AlexZio00/sovereign-skills) into .claude/skills/project-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AlexZio00/sovereign-skills --skill project-check -a codex`. Or copy the skill folder (project-check in AlexZio00/sovereign-skills) into .agents/skills/project-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AlexZio00/sovereign-skills --skill project-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-check, .gemini/skills/project-check, .github/skills/project-check and .opencode/skills/project-check in your project.
Going by SKILL.md and its folder, Project Check needs the command-line tools its instructions call (git and go) and credentials named API_KEY. Our summary lists: A credential in API_KEY.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Project Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Project Check: degit Project Scaffolding (Rich-Harris/degit, 7.9k stars), Compare Codegen (hw-native-sys/pypto, 127 stars), Brain Bootstrap (mindmuxai/brain.md, 566 stars) and Light Project Structure (Light0305/Light-skills, 640 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AlexZio00 (a GitHub user) maintains it in AlexZio00/sovereign-skills, which has 140 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.
Source: AlexZio00/sovereign-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.