Agent skill

Scaffold CLI

by mblode in mblode/agent-skills

Scaffolds a TypeScript CLI and npm package with the house toolchain, dual tsdown outputs, CLI contracts, changesets, and publishing templates.

MITAuto-check passedDevelopment

Install Scaffold CLI

skills CLI
$ npx skills add mblode/agent-skills --skill scaffold-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mblode/agent-skills scaffold-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mblode/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/scaffold-cli .claude/skills/scaffold-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scaffold-cli
GitHub stars
143
Token cost
~2.2k tokens
SKILL.md length
1,046 words
Files
6 (incl. references)
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Scaffolds a TypeScript CLI and npm package with the house toolchain, dual tsdown outputs, CLI contracts, changesets, and publishing templates.

  • Works in 8 steps: Gather project info → Create directory structure → Generate config files → …
  • Asked to scaffold a CLI
  • SKILL.md covers Reference Files, Scaffold Workflow, Dependencies and Gotchas, plus 1 more section
  • Calls pnpm and npm

What it does

Scaffold CLI is an agent skill from mblode/agent-skills. Scaffolds a TypeScript CLI and npm package with the house toolchain, dual tsdown outputs, CLI contracts, changesets, and publishing templates. Use when asked to "scaffold a CLI" or "start an npm package".

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `evals/evals.json`, `references/agent-friendly-cli.md` and `references/post-scaffold.md`). Compatibility notes: Requires a shell, Git, Node.js, pnpm, and npm registry access. Remote publishing requires the relevant account authentication.

It sits in Development, covering Project scaffolding. It works with npm and TypeScript. The repository describes itself as: Nobody ships AI slop on purpose. These skills make sure you don’t. The licence is MIT.

When your agent uses it

  • Asked to scaffold a CLI
  • Start an npm package

Example prompts

  • “scaffold a CLI”
  • “start an npm package”
  • “Use the scaffold-cli skill to scaffold a TypeScript CLI and npm package with the house toolchain, dual tsdown outputs, CLI contracts, changesets…”
  • “/scaffold-cli”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Requires a shell, Git, Node.js, pnpm, and npm registry access. Remote publishing requires the relevant account authentication.

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Gather project info
  2. Create directory structure
  3. Generate config files
  4. Generate source files
  5. Generate docs and skill
  6. Run post-scaffold commands
  7. Validate scaffold
  8. Bootstrap GitHub and npm

What it can do on your machine

Read from SKILL.md and the folder at commit cef4cfa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a shell, Git, Node.js, pnpm, and npm registry access. Remote publishing requires the relevant account authentication.

    From compatibility in the SKILL.md frontmatter.

Context cost

Scaffold CLI loads about 2.2k tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 54 tokens; SKILL.md has 1,046 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mblode/agent-skills at commit cef4cfa, republished under its MIT licence (© mblode). 1,046 words, ~2,197 tokens.

Download SKILL.mdSave it as .claude/skills/scaffold-cli/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
scaffold-cli
description
Scaffolds a TypeScript CLI and npm package with the house toolchain, dual tsdown outputs, CLI contracts, changesets, and publishing templates. Use when asked to "scaffold a CLI" or "start an npm package".
compatibility
Requires a shell, Git, Node.js, pnpm, and npm registry access. Remote publishing requires the relevant account authentication.

Scaffold CLI

  • IS: bootstrapping a brand-new TypeScript CLI or npm package (Node 24, TypeScript 7) from the pinned templates in references/, through to a green first CI run and a package npm can publish over OIDC.
  • IS NOT: a Next.js web app (use scaffold-nextjs), folder structure or module contracts for an existing codebase (use codebase-architecture), auditing an existing CLI's ergonomics (use dx-audit), or shipping a release of an existing package (use autoship).

The templates encode the house toolchain. Substitute project values and verify template APIs against installed package versions; repair proven incompatibilities instead of blindly reproducing them. The toolchain is the opinion: tsdown not tsup, vitest not jest, oxlint and oxfmt via ultracite not eslint or prettier, node:util styleText not chalk, @clack/prompts not ora. Swapping any of them or restructuring the layout produces a repo the templates' notes no longer describe.

Reference Files

FileRead When
references/scaffold-configs.mdStep 3: package.json, tsconfig, tsdown, gitignore, license, changeset config, GitHub Actions
references/scaffold-source.mdSteps 4-5: src/cli.ts, src/index.ts, src/types.ts, AGENTS.md, README.md, skills/SKILL.md
references/agent-friendly-cli.mdStep 4, only when a command takes an identifier, path, or URL, or mutates state: input validation, dry-run, confirmation, schema
references/post-scaffold.mdSteps 6-8: post-scaffold commands, the lefthook.yml replacement, validation checklist, GitHub and npm bootstrap, troubleshooting

Scaffold Workflow

Copy this checklist to track progress:

text
Scaffold progress:
- [ ] Step 1: Gather project info
- [ ] Step 2: Create directory structure
- [ ] Step 3: Generate config files
- [ ] Step 4: Generate source files
- [ ] Step 5: Generate docs and skill
- [ ] Step 6: Run post-scaffold commands
- [ ] Step 7: Validate scaffold
- [ ] Step 8: Bootstrap GitHub and npm (with the user's go-ahead)
Step 1: Gather project info

Ask only for what the user didn't provide:

VariableExampleDefaultUsed in
{{name}}md-toolsrequiredpackage.json name, README title, npm package
{{description}}CLI tool to convert content to markdownrequiredpackage.json, README, SKILL.md
{{bin}}mdsame as {{name}}package.json bin field, CLI examples, skills folder
{{repo}}acme/md-toolsrequiredpackage.json repository, GitHub repo, npm trusted publisher
{{author}}Your Namerequiredpackage.json, LICENSE
{{year}}2026current yearLICENSE

{{repo}} must be the exact GitHub owner/name: npm provenance rejects a publish whose repository.url differs from the repo it came from.

Step 2: Create directory structure
{{name}}/
  .changeset/
  .github/
    workflows/
  src/
  skills/{{bin}}/
Step 3: Generate config files

Load references/scaffold-configs.md. Generate every file there, replacing each {{placeholder}}:

package.json, tsconfig.json, tsdown.config.ts, .gitignore, LICENSE.md, .changeset/config.json, .changeset/README.md, .github/workflows/ci.yml, .github/workflows/npm-publish.yml

Step 4: Generate source files

Load references/scaffold-source.md. Generate:

  • src/cli.ts: Commander entry point with agent-friendly defaults (--output text|json, --no-input, stdout data / stderr log split, JSON error envelope)
  • src/index.ts: Public API exports
  • src/types.ts: Shared type definitions

When a command takes an identifier, path, or URL, or mutates state, also load references/agent-friendly-cli.md and copy the matching pinned pattern. Skip it for a CLI with no such command.

Step 5: Generate docs and skill

From the same references/scaffold-source.md, generate:

  • AGENTS.md: commands, architecture, gotchas, agent invariants
  • README.md: install, usage, API, agent skill install, license
  • skills/{{bin}}/SKILL.md: agent skill definition

Use AGENTS.md directly; do not create a CLAUDE.md wrapper or symlink.

Step 6: Run post-scaffold commands

Load references/post-scaffold.md. Run the command sequence in the order given, including the lefthook.yml overwrite between ultracite init and the first commit.

Step 7: Validate scaffold

Run the validation checklist in references/post-scaffold.md. Every item is a command whose output is the evidence; the checklist includes publint, arethetypeswrong, the hook exercised against real files, and the placeholder sweep.

Step 8: Bootstrap GitHub and npm

For a local scaffold, stop after Step 7. If the user already requested remote setup or publication, carry out that authorized scope. Otherwise present the prepared repository/package identity before asking to create or publish it. Otherwise follow "Bootstrap GitHub and npm" in references/post-scaffold.md: create and push the repo, enable Actions-created PRs, publish 0.0.1 once by hand so the package exists, then register the workflow as a trusted publisher. Terminal evidence is a green CI run on the pushed commit and npm view {{name}} version printing 0.0.1. From here every release belongs to autoship.

Dependencies

Runtime: @clack/prompts, commander

Development (in the package.json template): @changesets/cli, @types/node, tsdown, typescript, vitest

Added by ultracite init, never listed by hand: ultracite (pinned exact by init), oxlint, oxfmt, lefthook, plus the check, fix, and prepare scripts. By-hand entries produce duplicate scripts and version skew against what init installs.

Show full SKILL.md (401 more words)Show less

Gotchas

  • tsdown emits .mjs by default. With platform: node (the default) fixedExtension is on, so a config without outputOptions.entryFileNames: "[name].js" builds dist/cli.mjs, dist/index.mjs, and dist/index.d.mts, and bin and exports point at files that do not exist. The outputOptions block in the template is what keeps them .js; do not trim it as noise.
  • No shebang in src/cli.ts. tsdown's banner injects #!/usr/bin/env node; a source shebang doubles it in dist/cli.js. The two build entries stay separate: the CLI entry has the banner and dts: false, the library entry has dts: true and no banner.
  • "test": "vitest run" without --passWithNoTests exits 1 on a repo with zero test files, so the first CI run goes red.
  • @changesets/cli@3 pairs with changesets/action@v2 and the publish-script: input. @v1 cannot drive changesets v3, and @v2 given the v1 publish: input versions the package and then completes green without publishing. The templates carry the matching pair; do not downgrade one side.
  • npm cannot register a trusted publisher for a package that does not exist yet. The first release run fails E404 or ENEEDAUTH until Step 8's one-time manual pnpm publish has created the package and the workflow is registered. That publish happens before any changeset exists, so it is the one manual publish autoship's rules do not forbid.
  • Node 22 ships npm 10.9.x; OIDC publishing needs npm 11.5.1 or later. Node 24 ships npm 11.19, which is why both workflows pin node-version: 24. Lowering it to 22 breaks publishing with ENEEDAUTH. The release workflow upgrades npm even though the project uses pnpm: pnpm publish can hand the upload to the npm CLI on PATH, and an older npm there fails OIDC.
  • Agent-facing output is a format contract. Data on stdout, logs and progress on stderr; a stray console.log breaks a consumer parsing --output json. Never prompt when stdin is not a TTY: honor --no-input and take every value as a flag, or the process hangs under a pipe.
  • autoship: every release after the bootstrap publish: changeset, CI watch, Version Packages PR, publish verification, and diagnosis of a release that did not publish.
  • dx-audit: audit the CLI's flags, errors, and types once real commands exist.
  • agents-md: grow the generated AGENTS.md as the codebase gains structure.
  • ghostwriter: rewrite the README once there is a real usage story to tell.

Maintenance only: evals/evals.json contains regression scenarios for changes to this skill; it does not load during a user task.

© mblode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/scaffold-cli of mblode/agent-skills.

  • SKILL.md
  • evals/evals.json
  • references/agent-friendly-cli.md
  • references/post-scaffold.md
  • references/scaffold-configs.md
  • references/scaffold-source.md

Open the folder on GitHubat commit cef4cfa

Compare with similar skills

Scaffold CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scaffold CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scaffold CLI this skillmblode/agent-skills143—~2.2kAutomated safety check: PassMIT
Upgrade Starter Kitworkadventure/map-starter-kit156—~1.3kAutomated safety check: NotesCustom licence
Create Saleor Packagesaleor/apps162—~608Automated safety check: PassCustom licence
Deno Runtime and Package Managerdenoland/skills100—~2.7kAutomated safety check: PassMIT
Pixijs Createpixijs/pixijs-skills346—~3.1kAutomated safety check: PassMIT
Adk Readme WriterBrainDAO/adk-ts119—~2.6kAutomated safety check: NotesMIT

Similar skills

  • Upgrade Starter Kit

    workadventure/map-starter-kit

    Upgrade a WorkAdventure map repository to the latest version of the map-starter-kit (github.com/workadventure/map-starter-kit) - refreshes package.json dependencies, vite/tsconfig/build config, CI…

    156 GitHub stars~1.3k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes
  • Scaffold a new shared package in the saleor-apps monorepo under ./packages/.

    162 GitHub stars~608 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Guides writing, running and configuring Deno 2.9+ projects: installing npm and JSR dependencies, permissions, config file precedence and the built-in fmt, lint, test and compile toolchain.

    100 GitHub stars~2.7k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Pixijs Create

    pixijs/pixijs-skills

    A skill your agent uses when scaffolding a new PixiJS v8 project with the create-pixi CLI or adding PixiJS to an existing project.

    346 GitHub stars~3.1k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Adk Readme Writer

    BrainDAO/adk-ts

    ADK-TS README specialist. An agent skill from BrainDAO/adk-ts.

    119 GitHub stars~2.6k tokensUpdated 3 mo ago
    DevelopmentAuto-check: notes
  • Corvus Typescript Evaluator

    corvus-dotnet/Corvus.JsonSchema

    Work on the TypeScript port of the V5 standalone schema evaluator (src-ts/corvus-json-schema, npm package @corvus-dotnet/json-schema): loader, compiler, JavaScript code generator, results collector…

    199 GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed

More from mblode/agent-skills

All 28 skills in this repo
  • Agent Ready

    mblode/agent-skills

    Implements agent-readiness on public sites and docs from Mintlify Agent Score, AFDocs, Is Agentic, Is It Agent Ready, or url-discovery-bench reports, or from server logs of agents 404ing on guessed…

    143 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agent Skills Creator

    mblode/agent-skills

    Creates and improves portable Agent Skills with a validator, routing scenarios, and evidence-based keep, cut, merge, or retire decisions.

    143 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed
  • Chat History

    mblode/agent-skills

    Recovers decisions, previous fixes, research, and what followed a prompt from past AI conversations, with source evidence.

    143 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • CI Speedup

    mblode/agent-skills

    Cuts the wait from push to green by measuring a pipeline's critical path from run timestamps, then splitting, sharding, trimming setup and sharing test module state, with a before/after ledger.

    143 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • PR Babysitter

    mblode/agent-skills

    Monitors or repairs an open GitHub PR: CI failures, conflicts, review threads, and merge readiness, reporting state changes.

    143 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • App Verification

    mblode/agent-skills

    Builds and maintains a repo's own verification harness (verify CLI, doctor, worktree isolation, feature map, seed data) and a reproduce-first bug handoff.

    143 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Works with

Categories

Questions about Scaffold CLI

What does Scaffold CLI do?

Scaffolds a TypeScript CLI and npm package with the house toolchain, dual tsdown outputs, CLI contracts, changesets, and publishing templates. Scaffold CLI is an agent skill from mblode/agent-skills. Scaffolds a TypeScript CLI and npm package with the house toolchain, dual tsdown outputs, CLI contracts, changesets, and publishing templates.

When should I use Scaffold CLI?

Scaffold CLI fits situations like: asked to scaffold a CLI; start an npm package.

How do I install Scaffold CLI in Claude Code?

Run `npx skills add mblode/agent-skills --skill scaffold-cli -a claude-code`. Or copy the skill folder (skills/scaffold-cli in mblode/agent-skills) into .claude/skills/scaffold-cli in your project. Claude Code loads it when a task matches its description.

How do I install Scaffold CLI in Codex?

Run `npx skills add mblode/agent-skills --skill scaffold-cli -a codex`. Or copy the skill folder (skills/scaffold-cli in mblode/agent-skills) into .agents/skills/scaffold-cli in your project. Codex loads it when a task matches its description.

Can I use Scaffold CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mblode/agent-skills --skill scaffold-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scaffold-cli, .gemini/skills/scaffold-cli, .github/skills/scaffold-cli and .opencode/skills/scaffold-cli in your project.

What does Scaffold CLI need to run?

Going by SKILL.md and its folder, Scaffold CLI needs the command-line tools its instructions call (pnpm and npm). Our summary lists: Node.js. Compatibility (from SKILL.md): Requires a shell, Git, Node.js, pnpm, and npm registry access. Remote publishing requires the relevant account authentication..

Does Scaffold CLI access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Scaffold CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Scaffold CLI use?

Scaffold CLI is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scaffold CLI use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.

What are the alternatives to Scaffold CLI?

Skills that share tags, products or a category with Scaffold CLI: Upgrade Starter Kit (workadventure/map-starter-kit, 156 stars), Create Saleor Package (saleor/apps, 162 stars), Deno Runtime and Package Manager (denoland/skills, 100 stars) and Pixijs Create (pixijs/pixijs-skills, 346 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scaffold CLI?

mblode (a GitHub user) maintains it in mblode/agent-skills, which has 143 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 6, 2026.

Source: mblode/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.