Agent skill

Project Check

by AlexZio00 in AlexZio00/sovereign-skills

Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup.

MITAuto-check: notesDevelopment

Install Project Check

skills CLI
$ npx skills add AlexZio00/sovereign-skills --skill project-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AlexZio00/sovereign-skills project-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AlexZio00/sovereign-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/project-check .claude/skills/project-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
project-check
GitHub stars
140
Token cost
~5k tokens
SKILL.md length
2,275 words
Files
3
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup.

  • Works in 8 steps: Scale Detection → Infrastructure Scan → Security Scan → …
  • : /project-check
  • SKILL.md covers Dominant Variable, Purpose, Discard If and Key Assumptions, plus 10 more sections
  • Calls git and go; needs API_KEY

What it does

Project Check is an agent skill from AlexZio00/sovereign-skills. Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup. Read-only. Use when: '/project-check', 'project health check', 'project audit', 'what\'s missing', 'analyze my project', 'check setup'. Ends with /project-init and /setup recommendations. NOT for new projects (use /project-init); project-check = shallow health scan.

Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `.claude-plugin/plugin.json` and `agents/openai.yaml`).

It sits in Development, covering Project scaffolding. It works with Git. The repository describes itself as: 20 production-grade skills for AI coding agents — setup, scope, discipline, code review, security, session management, governance, ops, and quality audits (eval-leakage… The licence is MIT.

When your agent uses it

  • : /project-check
  • Project health check
  • Analyze my project

Example prompts

  • “/project-check”
  • “project health check”
  • “project audit”
  • “/project-check”

Requirements

  • A credential in API_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Scale Detection
  2. Infrastructure Scan
  3. Security Scan
  4. Quality Scan
  5. Harness Scan
  6. Build Report
  7. Recommendations
  8. 5: Score Delta Tracking

What it can do on your machine

Read from SKILL.md and the folder at commit c062683. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Project Check loads about 5k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 2,275 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:41
    e 🔴 Security issues (hardcoded secrets, .env missing) displayed before all other gaps?
  • NoteMentions a .env fileSKILL.md:91
    | `.gitignore` | Exists? `.env` actually ignored — verified via `git check-ignore -v .env` (see Step 2), not just string
  • NoteMentions a .env fileSKILL.md:113
    Additional checks — `.env` protection (skip entirely if not a git repo, per Key Assumption 2):
  • NoteMentions a .env fileSKILL.md:115
    A string match for `.env` inside `.gitignore` is not proof of protection — the pattern can be malformed (wrong path, typ
  • NoteMentions a .env fileSKILL.md:116
    1. `git check-ignore -v .env` — confirms the pattern actually matches the file. No output / non-zero exit → the listed p
  • NoteMentions a .env fileSKILL.md:117
    2. `git ls-files --error-unmatch .env` (exit 0 means tracked) — if `.env` is already tracked, → 🔴 "`.env` is already tr
  • NoteMentions a .env fileSKILL.md:118
    - `.env` missing from `.gitignore` entirely (no string match) → 🔴 as before.
  • NoteMentions a .env fileSKILL.md:119
    - `.env.local`, `.env.*.local` in `.gitignore` → ⚠ if missing (TypeScript/Next.js projects). Apply the same `git check-i
  • NoteMentions a .env fileSKILL.md:218
    emove secrets at [file:line] and move to .env (manual edit required)"
  • NoteMentions a .env fileSKILL.md:276
    | "`.gitignore` contains `.env`, so it is protected" | String presence is not proof. Step 2 verifies the real match and

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from AlexZio00/sovereign-skills at commit c062683, republished under its MIT licence (© AlexZio00). 2,275 words, ~5,019 tokens.

Download SKILL.mdSave it as .claude/skills/project-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
project-check
description
Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup. Read-only. Use when: '/project-check', 'project health check', 'project audit', 'what\'s missing', 'analyze my project', 'check setup'. Ends with /project-init and /setup recommendations. NOT for new projects (use /project-init); project-check = shallow health scan.
skill_type
analysis
triggers
/project-check, project-check, what's wrong
user-invocable
true
tools
Read, Bash, Glob, Grep
disallowed-tools
Edit, Write, NotebookEdit
depends_on.files
CLAUDE.md, ~/.claude/rules/project rules, .project-check-history.json
concurrency_profile.read_only
true
concurrency_profile.concurrency_safe
true
concurrency_profile.destructive
none
not_for
New project setup -> setup skill, Deep, scored harness-maturity audit against a fixed multi-axis checklist -> check-harness (project-check is a shallow…

Project Check — Existing Project Health Scan

Dominant Variable

Discovered gaps are sorted by severity so the user knows "what to fix first" — an unsorted gap list causes information overload. A report without priority is useless.

Purpose

Scan an existing project against setup best practices across 4 dimensions: Infrastructure, Security, Quality, and Harness. Surface all gaps ordered by severity so the user knows exactly what to fix and in what order.

Dominant variable: Are 🔴 Security issues (hardcoded secrets, .env missing) displayed before all other gaps?

  • Read-only skill: This skill does not modify project files. It generates a gap report only; fix recommendations are delegated to /project-init or /setup.

Discard if: Empty directory or a freshly initialized project (git init) — nothing to scan. Use /project-init directly instead.

Discard If

Empty directory or newly initialized project (git init with no code yet) — nothing to audit. Use /project-init. This skill audits code, infrastructure, security, and quality only. Need a persistent, weighted maturity score with cross-axis trend tracking instead of a one-time 4-dimension pass/fail scan — use /check-harness, not this skill.

Key Assumptions

  1. Project root contains CLAUDE.md or .claude/ directory — if missing: recommend /project-init.
  2. Git repository — if not a repo: skip some Infrastructure checks.

Trigger

  • /project-check
  • "project-check"
  • "what's wrong"

Workflow

Step 0: Scale Detection

Count source files to calibrate warning thresholds:

Scan: *.py, *.ts, *.tsx, *.js, *.go, *.rs, *.java, *.kt, *.swift, *.c, *.cpp, *.h
Exclude dirs: node_modules/, .venv/, venv/, __pycache__/, vendor/, dist/, build/, .git/, .next/, target/

(Without this exclusion, dependency/build directories get swept into the file/LOC count and skew the Step 0 scale classification.)

Classify:

  • script: < 10 source files or < 500 LOC → minimal structure expected, skip ROADMAP/ADR warnings
  • mini: 10–50 files or 500–5,000 LOC → CLAUDE.md + tests expected
  • full: > 50 files or > 5,000 LOC → full structure expected, ROADMAP + docs/decisions/ recommended

Detect project name from directory name or name field in package.json / pyproject.toml / Cargo.toml if present.

Step 1: Infrastructure Scan
ItemCheckSeverity if missing/incomplete
CLAUDE.mdExists? Has ## Hard Rules? Has ## Secrets Policy?✗ missing / ⚠ incomplete
docs/DEVELOPMENT_ROADMAP.mdExists? (skip if scale=script)✗ if scale=full/mini
.gitignoreExists? .env actually ignored — verified via git check-ignore -v .env (see Step 2), not just string presence in the file✗ missing / 🔴 not ignored or already tracked (see Step 2)
.env.exampleExists? (if API key patterns found in code)✗ if keys detected
docs/decisions/Exists? (only check if scale=full)⚠ if scale=full

For CLAUDE.md: count Hard Rules entries (lines starting with - under ## Hard Rules). Report the count.

Step 2: Security Scan

Grep these patterns across all source files (case-insensitive). Exclude: *.example, .env.example, files in tests/, __tests__/, spec/, and dependency/build directories (node_modules/, .venv/, venv/, __pycache__/, vendor/, dist/, build/, .git/, .next/, target/ — same list as Step 0):

API_KEY\s*=\s*["'][^$({]      → hardcoded API key
sk-[A-Za-z0-9]{20,}           → OpenAI key (sk-...)
sk-ant-[A-Za-z0-9\-]{20,}     → Anthropic key (sk-ant-api03-...)
ghp_[A-Za-z0-9]{36}           → GitHub PAT
password\s*=\s*["'][^$({]     → hardcoded password
secret\s*=\s*["'][^$({]       → hardcoded secret
token\s*=\s*["'][^$({]        → hardcoded token

Each match → 🔴 with file:line reference. Read the matched line before judging: a placeholder value (your_key_here, xxx, changeme, <...>) is ℹ info, not 🔴. Never print the found value — report file:line and the pattern name only.

Additional checks — .env protection (skip entirely if not a git repo, per Key Assumption 2):

A string match for .env inside .gitignore is not proof of protection — the pattern can be malformed (wrong path, typo, wrong glob syntax) and never actually match, or the file can already be tracked in git, in which case .gitignore has no effect on it at all. Verify both:

  1. git check-ignore -v .env — confirms the pattern actually matches the file. No output / non-zero exit → the listed pattern doesn't cover .env → 🔴 ".env present in .gitignore text but the pattern doesn't actually match (git check-ignore reports it as not ignored)". If the command is denied or fails (e.g. the target is outside the worktree), report "⚠️ cannot verify — string presence only" instead of a red finding.
  2. git ls-files --error-unmatch .env (exit 0 means tracked) — if .env is already tracked, → 🔴 ".env is already tracked in git — .gitignore cannot retroactively untrack it. Needs git rm --cached .env (manual step; this skill does not run it)".
  • .env missing from .gitignore entirely (no string match) → 🔴 as before.
  • .env.local, .env.*.local in .gitignore → ⚠ if missing (TypeScript/Next.js projects). Apply the same git check-ignore -v verification when a matching line is present.
Step 3: Quality Scan

Apply the same exclusion list as Step 0 (node_modules/, .venv/, __pycache__/, vendor/, dist/, build/, .git/, etc.) to every file count and grep below.

Test coverage proxy:

Count test files (test_*.py, *_test.py, *.test.ts, *.spec.ts, *_test.go, *Test.java, *Spec.kt) vs source files.

RatioResult
≥ 0.4✓
0.2–0.4⚠
< 0.2✗ (skip if scale=script)

Debug remnants (grep non-test files):

console\.log|print\(f?["']|debugger;|pprint\(

→ ⚠ if > 5 matches

Open work markers (grep all files):

TODO|FIXME|HACK|XXX

→ ⚠ if > 10 total count

Step 4: Harness Scan

Profile detection (run first — determines whether orchestrator/agent-team absence is a gap at all):

Check whether the project shows any sign of agent-routing adoption:

  • .claude/agents/*.md (project-level) — any files present?
  • ~/.claude/agents/*.md (global) — any files present?
  • CLAUDE.md or project rules mention agent routing (e.g., "orchestrator", "Tier 1/2/3", "subagent-dev", "brainstorming → writing-plans")?

If none of the above are present, infer Minimal profile — per the setup skill's own Q2 ("Minimal: rules + memory only. No agent routing" is a first-class, intentional choice, not a defect). Under Minimal profile, orchestrator/agent-team absence is a configuration choice, not a gap — do not score it as ⚠.

If any of the above are present, the project has adopted Standard/Orchestrated routing at least partially — a missing orchestrator or key agents at that point is a real gap (routing infrastructure exists without the piece that coordinates it), and stays ⚠.

Check Claude Code infrastructure:

ItemCheckSeverity
~/.claude/rules/project rulesExists?⚠ if missing
~/.claude/rules/agents.mdExists?⚠ if missing
.claude/settings.json or ~/.claude/settings.jsonhooks section present?⚠ if no hooks
CLAUDE.md Hard Rules formatInline text vs project rules reference link⚠ if both (duplication)
~/.claude/agents/Any .md agent files installed? (global)⚠ if empty and not Minimal profile; ℹ (no score) if empty and Minimal profile
.claude/agents/Any .md agent files installed? (project-level)ℹ if present (report separately)
~/.claude/agents/orchestrator.mdExists?⚠ if missing and not Minimal profile; skip (no flag) if Minimal profile
Orchestrator typeContains drift detection (MISSING, EXTRA, DIVERGED, correction loop)?⚠ if absent, only when orchestrator.md exists (Light-only case) — N/A if orchestrator.md itself is missing, since that's already covered by the row above
tasks/lessons.mdExists? (skip if scale=script)⚠ if scale=full/mini
SubagentStop hookSubagentStop included in settings.json hooks?⚠ if missing and not Minimal profile (a Minimal setup has no subagents to stop)

Count total agent files across both locations. Report global vs project-level split. Report which key agents are installed (orchestrator, code-reviewer, verification, brainstorming, security-reviewer). If Minimal profile was inferred, report "0 agents — consistent with Minimal setup profile (rules + memory only)" instead of counting it toward gaps.

If CLAUDE.md has inline Hard Rules AND ~/.claude/rules/project rules exists → ⚠ "Hard Rules duplication: directly in CLAUDE.md AND project rules file present. Recommend consolidating to project rules with reference link in CLAUDE.md."

Step 5: Build Report

Sort all findings by severity within each section: 🔴 → ✗ → ⚠ → ✓

Score calculation:

Start: 10
-2 per 🔴
-1 per ✗
-0.5 per ⚠ (round to nearest 0.5)
Floor: 0

Output:

Project Health Check: [project-name]
Scale: [script / mini / full] ([N] source files)

Security:           ← always first, even if all pass
  🔴/✓/⚠ items

Infrastructure:
  ✓/✗/⚠ items

Quality:
  ✓/✗/⚠ items

Harness:
  ✓/✗/⚠ items

Score: [N]/10
Gaps: [N] total (🔴 [N], ✗ [N], ⚠ [N])
Step 6: Recommendations

Always end with next steps:

  • 🔴 Security → "🔴 First: Remove secrets at [file:line] and move to .env (manual edit required)"
  • Infrastructure ✗ → "→ Use /project-init — if CLAUDE.md exists, choose Update mode"
  • Harness rules ✗/⚠ (rules, agents, hooks) → "→ Use /setup to configure Claude Code infrastructure"
  • Harness agents ✗/⚠ (no agents, no orchestrator) AND agent-routing infra already exists elsewhere (Step 4 profile detection = not Minimal) → "→ Use /setup to install agent team (orchestrator + reviewer + implementer)"
  • No agents anywhere AND no orchestrator, Minimal profile inferred (Step 4) → do not recommend an agent team as a fix; instead: "ℹ No agent-routing layer detected — consistent with a Minimal setup (rules + memory only). No action needed if intentional; run /setup Update mode if you want review agents or orchestration."
  • Orchestrator Light only (orchestrator.md exists but lacks drift detection) → "→ Use /setup Update mode to enable Full orchestrator (with drift detection)"
  • Quality only → "→ Recommend adding tests"
  • Score ≥ 8 → "✓ Already well configured. Optionally address ⚠ items."

Recommended loop (new users):

/project-check → discover gaps
  → /project-init  (CLAUDE.md + ROADMAP + .gitignore)
  → /setup  (rules + hooks + memory)
  → /setup     (orchestrator + agent team)
  → /project-check (re-scan → verify score improvement)
Show full SKILL.md (1,029 more words)Show less
Step 6.5: Score Delta Tracking

Look for a previous check result in two places, project-root first:

  1. .project-check-history.json in project root.
  2. If that's absent, fall back to the user-level persistent cache before concluding there's no prior result: ~/.claude/.harness/project-check/<project-name>.json (keyed by the detected project name from Step 0). This survives the project-root file being gone after a fresh clone or a .gitignore'd local file getting wiped.

If either is found, compare against it:

── Score Delta ──
Previous: [N]/10 (YYYY-MM-DD) → Current: [M]/10
Change: [+X / -X / no change]

By category — Previous → Current:
  🔴 Critical: [N] → [N]
  ✗ Fail:      [N] → [N]
  ⚠ Warn:      [N] → [N]

Honesty limit: the history file stores only the total score and per-category counts (see JSON schema below) — it does not store which items failed. Item-level claims like "X went from ✗ to ✓" or "Y is a new gap" are not supported by this data and must never be shown — showing them would be a guess dressed as a fact. Report only the aggregate score and per-category count deltas above (e.g., "2 fewer ⚠ items than last run," not which ones resolved). Per-item history tracking is out of scope for this skill by design (a persistent, item-level maturity trend is check-harness's job — see see_also), not a missing feature to add here.

If neither exists, suggest saving current result — project-root file by default, user-level cache path as the fallback option if the project doesn't want history checked into (or gitignored within) the repo:

json
{"date":"YYYY-MM-DD","score":N,"gaps":{"critical":N,"fail":N,"warn":N}}

"Next /project-check will show score delta." — one line.

No auto-save — this skill never writes it, period. The JSON snippet above is printed to the chat as text only. Actually creating or appending to .project-check-history.json is something the user does themselves — it is outside this skill's execution scope (this skill has no Write/Edit tool; see Invariant 1).


Rationalization Table

ExcuseRebuttal
"It's a new project, so gaps are normal"If gaps are normal, the score is meaningless. Gaps are action items.
"Security scans have too many false positives"That judgment is on you. A scan surfaces suspicious patterns. Better to ask.
"ROADMAP is unnecessary for small projects"If scale=script, warnings are auto-skipped. Don't manually skip — let calibration work.
"Harness checks only apply to Claude Code users"Missing agent infrastructure = re-explaining context every session. Costs accumulate.
"The score is low, but we can't fix it right now"The score is priority information. Deferring is different from ignoring.
".gitignore contains .env, so it is protected"String presence is not proof. Step 2 verifies the real match and tracked status with git check-ignore -v and git ls-files --error-unmatch.
"0 agents means a setup deduction"Check the project profile first. Under a Minimal profile, no agents is an intended choice, not a gap.
"Just delete the secret"Invariant 1 — read-only. Report the location only; never remove it directly.

Scope Boundary

DoesDoes NOT
[READ] Scan file existence (Glob)Modify, create, or delete any file
[READ] Grep code patterns (read-only)Execute tests (pytest, jest, go test, etc.)
[READ] Run read-only git inspection (git check-ignore -v, git ls-files --error-unmatch) to verify .gitignore actually protects secret filesRun any git command that mutates state (commit, push, add, rm, checkout, etc.)
[READ] Output gap report—
[READ] Recommend /project-init, /setupRemove secrets directly
[READ] Analyze CLAUDE.md contentRefactor code or fix bugs

Safety Layers

Risky ActionReversibilityApplied Layers
File modification, deletionmediumL1 (BLOCK)
Direct secret removalnoneL1 (BLOCK)
Test execution (pytest, jest, etc.)mediumL1 (BLOCK)
  • L1 (Invariants): Invariant 1 — read-only. When secrets are found, report location only; never remove directly. Invariant 4 — never run test runners (prevents DB writes, API calls, network side effects).
  • ⚠️ disallowed-tools scope limit: disallowed-tools: Edit, Write, NotebookEdit blocks only those three tools — it does not stop the remaining Bash tool from writing directly (e.g. echo x > file, git commit). There is no physical (L2) block on that path for a skill loaded into the main loop like this one; enforcement currently relies on L1 prompt compliance (Invariant 1) alone, unless the host project wires its own PreToolUse hook to intercept write-shaped Bash commands.

Error Recovery

On failure: Stop → Classify → Apply Recovery → Report & Resume.

Failure TypeDetectionRecovery Path
tool_failureFile read fails (permission/path error)Narrow scan scope to accessible files only; state scope reduction.
missing_dataCLAUDE.md missing / project root unclearState "CLAUDE.md not found". Never guess content of missing files. Recommend /setup and keep scanning the remaining steps.
input_errorUnclear which project to checkAuto-scan from current directory. If that fails, ask one clarifying question.

Invariants (never violate)

  1. Read-only: Never write, edit, delete, or execute any file. Use Glob, Grep, and read-only inspection commands only (e.g., git check-ignore -v, git ls-files --error-unmatch, wc -l) — never a Bash command that writes, deletes, mutates git state, or executes project code. Violation → scan tool gains unintended side effects; user trust in a diagnostic tool erodes.
  2. Security first: 🔴 Security section always appears first in the report, even if all Security items pass. Never bury security findings. Violation → user misses credential leak warning while reading infrastructure gaps.
  3. Scale-aware warnings: Never report ✗ ROADMAP missing for scale=script. Never report ⚠ docs/decisions/ for scale=mini or script. Violation → noise causes users to dismiss the entire report.
  4. No test execution: Detect test infrastructure via Glob only. Never run pytest, jest, go test, or any test runner. Violation → unexpected test side effects (DB writes, API calls, network requests).

These rules are unconditional. No user instruction overrides them.


Output

Structured report in conversation — no files written.

Sections always in this order:

  1. Project name + scale
  2. Security (always first)
  3. Infrastructure
  4. Quality
  5. Harness
  6. Score + Gap count
  7. Next steps (→ /project-init and/or /setup)

Principles

  • Security first, always — a buried credential warning is a useless warning
  • Scale-aware — a 50-line script failing "no ROADMAP" is noise, not signal
  • Read-only by design — a health check that modifies files is a liability
  • Ends with a path forward — the report is only useful if it points to the next action

Truthful Reporting

When reporting completion, this skill:

  1. no mock deception: Confirm results from actual execution. Never report completion based on assumption.
  2. no test façade: Don't hide failures with skip/xfail. If skipped, mark as ⚠️ SKIPPED: reason.
  3. no silent brokenness: Always label final state as WORKING / PARTIAL / BROKEN. For PARTIAL/BROKEN, list specific failures.
  • File existence as proxy — test file count is a structural signal; running tests is out of scope

© AlexZio00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in project-check of AlexZio00/sovereign-skills.

  • SKILL.md
  • .claude-plugin/plugin.json
  • agents/openai.yaml

Open the folder on GitHubat commit c062683

Compare with similar skills

Project Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Project Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Project Check this skillAlexZio00/sovereign-skills140—~5kAutomated safety check: NotesMIT
degit Project ScaffoldingRich-Harris/degit7.9k—~534Automated safety check: PassMIT
Compare Codegenhw-native-sys/pypto127—~1.4kAutomated safety check: PassCustom licence
Brain Bootstrapmindmuxai/brain.md566—~1.8kAutomated safety check: PassApache-2.0
Light Project StructureLight0305/Light-skills640—~3kAutomated safety check: NotesMIT
Git Command Class Implementationruby-git/ruby-git1.8k—~3kAutomated safety check: PassMIT

Similar skills

  • degit Project Scaffolding

    Rich-Harris/degit

    Downloads a repository snapshot or template with degit into an empty folder, from GitHub, GitLab, Bitbucket, Sourcehut or a Gist, optionally at a branch, tag or commit.

    7.9k GitHub stars~534 tokensUpdated 26 days ago
    DevelopmentAuto-check passed
  • Compare Codegen

    hw-native-sys/pypto

    Compare codegen output (.pto files and pass dumps) between origin/main and the current branch for a given test case.

    127 GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Brain Bootstrap

    mindmuxai/brain.md

    Seed a freshly-scaffolded brain with real project knowledge — on an existing (brownfield) project read the code, docs, and git log to draft the six root pages and capture key historical decisions…

    566 GitHub stars~1.8k tokensUpdated 29 days ago
    DevelopmentAuto-check passed
  • Light Project Structure

    Light0305/Light-skills

    Audits, scaffolds and safely migrates research project folder structures, keeping existing repositories read-only until you approve exact moves from a plan.

    640 GitHub stars~3k tokensUpdated 3 mo ago
    DevelopmentAuto-check: notes
  • Scaffolds and reviews `Git::Commands::*` classes in the ruby-git library, with unit tests, integration tests and YARD docs, using the Base command architecture.

    1.8k GitHub stars~3k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Rocky Codegen

    rocky-data/rocky

    Rocky CLI JSON-output schema cascade. An agent skill from rocky-data/rocky.

    304 GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed

More from AlexZio00/sovereign-skills

All 17 skills in this repo
  • Project Overview

    AlexZio00/sovereign-skills

    A skill your agent uses when the user wants a deterministic cross-project status map generated from registered projects' session handoffs.

    140 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Scope

    AlexZio00/sovereign-skills

    Scope definition before implementation — two modes. An agent skill from AlexZio00/sovereign-skills.

    140 GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • Project Init

    AlexZio00/sovereign-skills

    Interview-based project setup — generates CLAUDE.md, ROADMAP, .gitignore, .env.example from scratch.

    140 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check: notes
  • Collab Audit

    AlexZio00/sovereign-skills

    This skill should be used when the user types /collab-audit or requests AI collaboration diagnosis.

    140 GitHub stars~8k tokensUpdated yesterday
    Auto-check passed
  • Doc Drift

    AlexZio00/sovereign-skills

    A skill your agent uses when the user wants to audit the memory and documents Claude Code loads into context — CLAUDE.md (user global + project + nested), MEMORY.md, @imports, .claude/skills…

    140 GitHub stars~6.2k tokensUpdated yesterday
    Auto-check passed
  • Session Checkpoint

    AlexZio00/sovereign-skills

    A skill your agent uses when saving session state before context compaction, switching tasks, or ending a session.

    140 GitHub stars~14k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Project Check

What does Project Check do?

Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup. Project Check is an agent skill from AlexZio00/sovereign-skills. Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup.

When should I use Project Check?

Project Check fits situations like: : /project-check; project health check; analyze my project.

How do I install Project Check in Claude Code?

Run `npx skills add AlexZio00/sovereign-skills --skill project-check -a claude-code`. Or copy the skill folder (project-check in AlexZio00/sovereign-skills) into .claude/skills/project-check in your project. Claude Code loads it when a task matches its description.

How do I install Project Check in Codex?

Run `npx skills add AlexZio00/sovereign-skills --skill project-check -a codex`. Or copy the skill folder (project-check in AlexZio00/sovereign-skills) into .agents/skills/project-check in your project. Codex loads it when a task matches its description.

Can I use Project Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AlexZio00/sovereign-skills --skill project-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-check, .gemini/skills/project-check, .github/skills/project-check and .opencode/skills/project-check in your project.

What does Project Check need to run?

Going by SKILL.md and its folder, Project Check needs the command-line tools its instructions call (git and go) and credentials named API_KEY. Our summary lists: A credential in API_KEY.

Does Project Check access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Project Check safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Project Check use?

Project Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Project Check use?

About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Project Check?

Skills that share tags, products or a category with Project Check: degit Project Scaffolding (Rich-Harris/degit, 7.9k stars), Compare Codegen (hw-native-sys/pypto, 127 stars), Brain Bootstrap (mindmuxai/brain.md, 566 stars) and Light Project Structure (Light0305/Light-skills, 640 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Project Check?

AlexZio00 (a GitHub user) maintains it in AlexZio00/sovereign-skills, which has 140 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.

Source: AlexZio00/sovereign-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.