Agent skill

Project Safety

by flonat in flonat/flonat-research

Install or reconcile research-project safety rules and protected folder boundaries for data, code, outputs, and paper sources.

MITAuto-check passedAI & LLM Engineering

Install Project Safety

skills CLI
$ npx skills add flonat/flonat-research --skill project-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install flonat/flonat-research project-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/flonat/flonat-research.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/project-safety .claude/skills/project-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
project-safety
GitHub stars
146
Token cost
~960 tokens
SKILL.md length
309 words
Files
1
Skills in repo
83
Repo updated
First seen
Licence
MIT

At a glance

Install or reconcile research-project safety rules and protected folder boundaries for data, code, outputs, and paper sources.

  • Works in 6 steps: Create CLAUDE.md with safety rules → Create legacy/ folder → Move all originals to legacy/ → …
  • A project lacks guardrails
  • SKILL.md covers Purpose, When to Use, Safety Rules Template and Directory Structure, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Project Safety is an agent skill from flonat/flonat-research. Install or reconcile research-project safety rules and protected folder boundaries for data, code, outputs, and paper sources. Use when a project lacks guardrails or is being migrated into the governed structure. Not for auditing the full research scaffold; use $audit-project-research.

Its SKILL.md is about 960 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering. The repository describes itself as: Shareable Claude Code + Codex infrastructure for PhD researchers — skills, agents, hooks, and rules for academic workflows. The licence is MIT.

When your agent uses it

  • A project lacks guardrails
  • Is being migrated into the governed structure

Example prompts

  • “/project-safety”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Create CLAUDE.md with safety rules
  2. Create legacy/ folder
  3. Move all originals to legacy/
  4. Copy needed files into new structure
  5. Verify legacy/ contains everything
  6. Proceed with project work

What it can do on your machine

Read from SKILL.md and the folder at commit da27600. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Project Safety loads about 960 tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~960

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from flonat/flonat-research at commit da27600, republished under its MIT licence (© flonat). 309 words, ~960 tokens.

Download SKILL.mdSave it as .claude/skills/project-safety/SKILL.md (or your agent's skills folder).
name
project-safety
description
Install or reconcile research-project safety rules and protected folder boundaries for data, code, outputs, and paper sources. Use when a project lacks guardrails or is being migrated into the governed structure. Not for auditing the full research scaffold; use $audit-project-research.
argument-hint
[project-path]

Project Safety Skill

CRITICAL RULE: Never delete data or code files. Never. Use legacy/ folder for originals. Copy, don't move.

Establish safety rules and structures before Claude makes changes to research projects.

Purpose

Based on Scott Cunningham's workflow: prevent accidental data loss by establishing rules and using legacy folders before Claude reorganizes or modifies project files.

When to Use

  • Starting a new research project folder
  • Before asking Claude to reorganize files
  • When Claude will be running code or modifying data
  • Setting up a project for collaborative work

Safety Rules Template

Add this to any project's CLAUDE.md file:

markdown
## Safety Rules

1. **Never delete data files** — No .csv, .dta, .xlsx, .parquet, or any data format
2. **Never delete code files** — No .py, .R, .do, .tex, .md or scripts
3. **Use legacy/ folder** — If reorganizing, move originals to legacy/ first
4. **Copy from legacy, don't move** — Always preserve the original

### If you need to reorganize:
1. Create a legacy/ folder if it doesn't exist
2. Move ALL original files into legacy/
3. Copy (not move) needed files into new structure
4. Never modify anything in legacy/

Directory Structure

After safety setup:

project/
├── CLAUDE.md           ← Safety rules + project context
├── README.md           ← Project documentation
├── legacy/             ← PROTECTED: original files
│   └── [all originals]
├── code/
│   ├── R/
│   ├── python/
│   └── stata/
├── data/
│   ├── raw/            ← Copied from legacy, never modified
│   └── processed/
├── output/
│   ├── figures/
│   └── tables/
├── docs/
│   └── manuscript/
└── log/                ← Progress logs

Dry Run Pattern

Before Claude executes potentially destructive operations, ask for a preview:

"Tell me what commands you would run to reorganize this folder, but don't execute them yet."

"Show me what files would be affected by this change before you make it."

"Walk me through your plan for cleaning this data before you run any code."

When to use dry runs:

  • File operations (move, delete, rename)
  • Git operations (reset, clean, force push)
  • Database operations
  • Batch processing
  • Any operation affecting multiple files

After reviewing:

  • If correct: "Go ahead"
  • If wrong: "Wait — don't do X, instead Y"

Workflow

  1. Create CLAUDE.md with safety rules
  2. Create legacy/ folder
  3. Move all originals to legacy/
  4. Copy needed files into new structure
  5. Verify legacy/ contains everything
  6. Proceed with project work

Prompt Template

I'm starting work on [PROJECT]. Before we do anything:

1. Create a CLAUDE.md with safety rules (never delete data/code, use legacy folder)
2. Create a legacy/ folder
3. Move all existing files into legacy/
4. Show me the proposed new directory structure before creating it

Do a dry run first — tell me what you would do before doing it.

Why This Matters

  • Claude operates at speed — mistakes happen fast
  • You can't always verify what Claude will do before it does it
  • Version control (git, Dropbox) helps but prevention is better
  • The legacy/ folder is your safety net
  • Dry runs give you a chance to catch mistakes

Example Use

"Set up my new Carbon Markets project with proper safety rules. Create the CLAUDE.md, legacy folder, and recommended directory structure. Show me your plan before executing."

© flonat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/project-safety of flonat/flonat-research.

Open the folder on GitHubat commit da27600

Compare with similar skills

Project Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Project Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Project Safety this skillflonat/flonat-research146—~960Automated safety check: PassMIT
Agent BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Add Uint Supportpytorch/pytorch104k2 repos~2.3kAutomated safety check: PassCustom licence
LLM Benchmarking with lm-evaluation-harnessOrchestra-Research/AI-Research-SKILLs13k8 repos~3kAutomated safety check: PassMIT
Segment Anything Model GuideOrchestra-Research/AI-Research-SKILLs13k8 repos~3.3kAutomated safety check: PassMIT
1passwordtrpc-group/trpc-agent-go1.9k14 repos~656Automated safety check: PassApache-2.0

Similar skills

  • Agent Builder

    shareAI-lab/learn-claude-code

    Design and build AI agents for any domain. An agent skill from shareAI-lab/learn-claude-code.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Add Uint Support

    pytorch/pytorch

    Add unsigned integer (uint) type support to PyTorch operators by updating ATDISPATCH macros.

    104k GitHub starsUsed in 2 repos~2.3k tokens
    AI & LLM EngineeringAuto-check passed
  • LLM Benchmarking with lm-evaluation-harness

    Orchestra-Research/AI-Research-SKILLs

    Runs lm-evaluation-harness to benchmark language models on academic suites such as MMLU, GSM8K and HumanEval, compare models and track training checkpoints.

    13k GitHub starsUsed in 8 repos~3k tokens
    AI & LLM EngineeringAuto-check passed
  • Segment Anything Model Guide

    Orchestra-Research/AI-Research-SKILLs

    Guide to using Meta's Segment Anything Model for zero-shot image segmentation with point, box or mask prompts, or automatic mask generation.

    13k GitHub starsUsed in 8 repos~3.3k tokens
    AI & LLM EngineeringAuto-check passed
  • 1password

    trpc-group/trpc-agent-go

    Set up and use 1Password CLI (op). An agent skill from trpc-group/trpc-agent-go.

    1.9k GitHub starsUsed in 14 repos~656 tokens
    AI & LLM EngineeringAuto-check passed
  • Planning With Files

    jarrodwatts/claude-code-config

    Transforms workflow to use Manus-style persistent markdown files for planning, progress tracking, and knowledge storage.

    1.1k GitHub starsUsed in 5 repos~967 tokens
    AI & LLM EngineeringAuto-check passed

More from flonat/flonat-research

All 83 skills in this repo
  • Latex Posters

    flonat/flonat-research

    Create a large-format academic poster in LaTeX using beamerposter, tikzposter, or baposter.

    146 GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check: notes
  • Skill Creator

    flonat/flonat-research

    Create, revise, and evaluate reusable AI workflow skills, including trigger-quality tests.

    146 GitHub stars~4.4k tokensUpdated 10 days ago
    Auto-check passed
  • DOCX

    flonat/flonat-research

    Create, read, edit, or convert Microsoft Word documents while preserving professional document structure.

    146 GitHub stars~1.2k tokensUpdated 10 days ago
    Auto-check passed
  • PDF

    flonat/flonat-research

    Read, create, combine, split, rotate, OCR, watermark, secure, or extract content from PDF files.

    146 GitHub stars~488 tokensUpdated 10 days ago
    Auto-check passed
  • Init Project Orchestration

    flonat/flonat-research

    Create or migrate project-level agents, repeatable project workflows, and planning state from one client-neutral contract, then render repository-scoped adapters for both Claude Code and Codex.

    146 GitHub stars~1.6k tokensUpdated 10 days ago
    Auto-check passed
  • Pre Commit Audit

    flonat/flonat-research

    Deliver a fast pre-commit safety scan: file size, anonymity (author / affiliation strings in tex/bib), hardcoded secrets, and invisible-Unicode carriers.

    146 GitHub stars~2.8k tokensUpdated 10 days ago
    Auto-check: notes

Questions about Project Safety

What does Project Safety do?

Install or reconcile research-project safety rules and protected folder boundaries for data, code, outputs, and paper sources. Project Safety is an agent skill from flonat/flonat-research. Install or reconcile research-project safety rules and protected folder boundaries for data, code, outputs, and paper sources.

When should I use Project Safety?

Project Safety fits situations like: A project lacks guardrails; is being migrated into the governed structure.

How do I install Project Safety in Claude Code?

Run `npx skills add flonat/flonat-research --skill project-safety -a claude-code`. Or copy the skill folder (skills/project-safety in flonat/flonat-research) into .claude/skills/project-safety in your project. Claude Code loads it when a task matches its description.

How do I install Project Safety in Codex?

Run `npx skills add flonat/flonat-research --skill project-safety -a codex`. Or copy the skill folder (skills/project-safety in flonat/flonat-research) into .agents/skills/project-safety in your project. Codex loads it when a task matches its description.

Can I use Project Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add flonat/flonat-research --skill project-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-safety, .gemini/skills/project-safety, .github/skills/project-safety and .opencode/skills/project-safety in your project.

What does Project Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Project Safety is instructions for the agent only.

Does Project Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Project Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Project Safety use?

Project Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Project Safety use?

About 960 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Project Safety?

Skills that share tags, products or a category with Project Safety: Agent Builder (shareAI-lab/learn-claude-code, 78k stars), Add Uint Support (pytorch/pytorch, 104k stars), LLM Benchmarking with lm-evaluation-harness (Orchestra-Research/AI-Research-SKILLs, 13k stars) and Segment Anything Model Guide (Orchestra-Research/AI-Research-SKILLs, 13k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Project Safety?

flonat (a GitHub user) maintains it in flonat/flonat-research, which has 146 GitHub stars. The repository holds 83 skills in this directory. The repository was last updated on September 29, 2026.

Source: flonat/flonat-research on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.