Dependabot Alerts Update
livesession/xyd
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
Guide for working with Nimara's layered monorepo architecture.
$ npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mirumee/nimara-ecommerce project-guidelines --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mirumee/nimara-ecommerce.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/project-guidelines .claude/skills/project-guidelines && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "project-guidelines" agent skill from https://github.com/mirumee/nimara-ecommerce/tree/main/.claude/skills/project-guidelines into .claude/skills/project-guidelines/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-guidelines", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mirumee/nimara-ecommerce/tree/main/.claude/skills/project-guidelinesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mirumee/nimara-ecommerce project-guidelines --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mirumee/nimara-ecommerce.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/project-guidelines .agents/skills/project-guidelines && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "project-guidelines" agent skill from https://github.com/mirumee/nimara-ecommerce/tree/main/.claude/skills/project-guidelines into .agents/skills/project-guidelines/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-guidelines", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mirumee/nimara-ecommerce project-guidelines --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mirumee/nimara-ecommerce.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/project-guidelines .cursor/skills/project-guidelines && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "project-guidelines" agent skill from https://github.com/mirumee/nimara-ecommerce/tree/main/.claude/skills/project-guidelines into .cursor/skills/project-guidelines/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-guidelines", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mirumee/nimara-ecommerce.git --path .claude/skills/project-guidelines--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mirumee/nimara-ecommerce project-guidelines --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mirumee/nimara-ecommerce.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/project-guidelines .gemini/skills/project-guidelines && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "project-guidelines" agent skill from https://github.com/mirumee/nimara-ecommerce/tree/main/.claude/skills/project-guidelines into .gemini/skills/project-guidelines/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-guidelines", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mirumee/nimara-ecommerce project-guidelinesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mirumee/nimara-ecommerce.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/project-guidelines .github/skills/project-guidelines && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "project-guidelines" agent skill from https://github.com/mirumee/nimara-ecommerce/tree/main/.claude/skills/project-guidelines into .github/skills/project-guidelines/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-guidelines", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mirumee/nimara-ecommerce project-guidelines --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mirumee/nimara-ecommerce.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/project-guidelines .opencode/skills/project-guidelines && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "project-guidelines" agent skill from https://github.com/mirumee/nimara-ecommerce/tree/main/.claude/skills/project-guidelines into .opencode/skills/project-guidelines/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "project-guidelines", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
project-guidelinesGuide for working with Nimara's layered monorepo architecture.
Project Guidelines is an agent skill from mirumee/nimara-ecommerce. Guide for working with Nimara's layered monorepo architecture. Use when adding new features, choosing which package to use, understanding data flow, or making architectural decisions. Covers domain/infrastructure/foundation/features layers and their responsibilities.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/architecture-examples.md` and `references/dependency-management.md`).
It sits in Development, covering Monorepo tooling. It works with React, GraphQL, shadcn/ui and Next.js. The repository describes itself as: Headless, composable ecommerce storefront built with Next.js, Typescript, and shadcn/ui. The licence is BSD-3-Clause.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b883dec. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Project Guidelines loads about 4.8k tokens when it runs, and up to ~6k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 1,304 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mirumee/nimara-ecommerce at commit b883dec, republished under its BSD-3-Clause licence (© mirumee). 1,304 words, ~4,817 tokens.
.claude/skills/project-guidelines/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.This skill helps you navigate Nimara's layered monorepo architecture and make correct decisions about where code belongs and how layers interact.
apps/ # User-facing applications
├── storefront/ # Next.js customer-facing storefront
├── marketplace/ # Vendor dashboard, ledger, payouts
├── stripe/ # Stripe payment integration app
└── automated-tests/ # CodeceptJS E2E tests
packages/ # Shared, reusable code
├── domain/ # Pure business logic (no framework deps)
├── infrastructure/ # External integrations (APIs, GraphQL)
├── foundation/ # Utilities, hooks, helpers
├── features/ # Feature implementations (UI + logic)
├── ui/ # Shared UI components (Shadcn-style)
└── config/ # Shared configs (Tailwind, ESLint, etc.)@nimara/domain)Responsibility: Pure business logic, types, constants, entities—zero external dependencies.
What belongs here:
What does NOT belong here:
Example structure:
packages/domain/
├── objects/
│ ├── Result.ts # Result<T, E> type
│ └── Product.ts # Product entity
├── types/
│ ├── Cart.types.ts
│ └── Order.types.ts
├── constants/
│ ├── paymentStatus.ts
│ └── orderStatus.ts
└── validators/
└── emailValidator.tsKey rule: Domain is a leaf package—it imports nothing from other Nimara packages.
@nimara/foundation)Responsibility: Core utilities, React hooks, helpers—framework-aware but integration-agnostic.
What belongs here:
What does NOT belong here:
features or infrastructure)ui)Example structure:
packages/foundation/
├── hooks/
│ ├── usePagination.ts
│ └── useLocalStorage.ts
├── utils/
│ ├── formatPrice.ts
│ ├── formatDate.ts
│ └── slugify.ts
└── types/
└── common.types.tsKey rule: Foundation is a leaf package—it depends only on domain.
@nimara/infrastructure)Responsibility: External integrations (Saleor, ButterCMS, Algolia, Stripe, etc.) and GraphQL operations.
What belongs here:
What does NOT belong here:
Example structure:
packages/infrastructure/
├── saleor/
│ ├── queries/
│ │ ├── GetProducts.graphql
│ │ └── GetProducts.generated.ts
│ ├── mutations/
│ │ └── AddToCart.graphql
│ ├── client.ts # Saleor client config
│ └── providers/
│ └── ProductProvider.ts
├── butter-cms/
│ ├── client.ts
│ └── providers/
│ └── PageProvider.ts
├── algolia/
│ ├── client.ts
│ └── search.ts
└── use-cases/
├── getProduct.ts
├── searchProducts.ts
└── addToCart.tsKey rule: Infrastructure depends on domain + foundation. Services in infrastructure should return Result<T, E> for operations that can fail.
@nimara/features)Responsibility: Feature implementations—combining UI, state, and business logic into cohesive features.
What belongs here:
What does NOT belong here:
ui)foundation)domain)Example structure:
packages/features/
├── checkout/
│ ├── Checkout.tsx
│ ├── CheckoutProvider.tsx
│ ├── useCheckout.ts
│ ├── checkoutFormSchema.ts
│ └── _actions/
│ └── completeCheckout.ts
├── product-search/
│ ├── ProductSearch.tsx
│ ├── SearchFilters.tsx
│ └── useProductSearch.ts
└── user-account/
├── AccountSettings.tsx
├── useUserProfile.ts
└── _actions/
└── updateProfile.tsKey rule: Features depends on all packages (domain, foundation, infrastructure, ui). This is the only layer that depends on everything.
@nimara/ui)Responsibility: Reusable UI components and design system—presentational, not business logic.
What belongs here:
What does NOT belong here:
Example structure:
packages/ui/
├── components/
│ ├── Button.tsx
│ ├── Input.tsx
│ ├── Modal.tsx
│ ├── Card.tsx
│ └── Form/
│ ├── FormField.tsx
│ └── FormError.tsx
├── icons/
│ ├── ChevronDown.tsx
│ └── ShoppingCart.tsx
├── layouts/
│ ├── Container.tsx
│ └── Grid.tsx
└── theme/
└── colors.tsKey rule: UI is a leaf package or minimal-dependency—imports only domain and foundation if needed.
The dependency direction is unidirectional:
domain (leaf)
↑
foundation (leaf)
↑
infrastructure ─┐
↑ │
└─ domain │
└─ foundation│
├→ features
ui (leaf) │
↑ │
ui ─────────────┘
↑
└─ domain, foundation
apps (storefront, stripe)
↑
└─ features, infrastructure, ui, foundation, domainIn practice:
features, infrastructure, ui, foundation, domaininfrastructure, ui, foundation, domain (all packages!)domain, foundationdomain onlydomain, foundation (minimal)What NEVER happens:
domainfoundationinfrastructureuifeaturesapps/storefront/ or apps/stripe/Domain: Add payment type/status constants
// packages/domain/constants/paymentStatus.ts
export const PAYMENT_METHODS = {
CREDIT_CARD: "credit_card",
DIGITAL_WALLET: "digital_wallet",
} as const;Infrastructure: Create the payment provider + GraphQL mutations
packages/infrastructure/payments/
├── mutations/CreatePayment.graphql
├── mutations/CreatePayment.generated.ts
└── providers/PaymentProvider.tsFeatures: Create the payment form component
packages/features/payment-form/
├── PaymentForm.tsx
└── usePayment.tsApp: Use in checkout page
// apps/storefront/src/app/[locale]/(checkout)/payment/page.tsx
import { PaymentForm } from '@nimara/features';
export default function PaymentPage() {
return <PaymentForm />;
}domainfoundationRULE: NEVER automatically install new dependencies. ALWAYS require explicit user approval first.
pnpm add or pnpm add -DI need to add a new dependency to [package-name]:
Package: library-name
Version: X.Y.Z
Purpose: Brief description of what it's used for
Reasons to choose this:
- Reason 1
- Reason 2
Alternatives considered:
- Alternative 1 (pros/cons)
- Alternative 2 (pros/cons)
Where it will be used:
- packages/infrastructure/...
- apps/storefront/...
Should I proceed with installation?❌ WRONG: Automatically installing
pnpm add lodash-es
# Package added without asking!✅ RIGHT: Asking for approval first
I need to add `zod` to `@nimara/domain` for schema validation.
Reasons:
- Runtime validation with TypeScript integration
- Already used in the project
- Lightweight (~8kb gzipped)
Alternatives:
- io-ts (more complex, better for complex validations)
- joi (heavier, more features)
Should I add zod to packages/domain/package.json?Once the user approves, proceed:
# Navigate to the correct package
cd packages/domain
# Install the dependency
pnpm add zod
# Or dev dependency
pnpm add -D vitest
# Verify it was added to package.json
git diff package.jsonAsk for approval because:
Before adding:
Should I add shadcn-ui@next to packages/ui?
- Already used in the project
- Gives access to pre-built accessible components
- Can be customized with Tailwind
Approve? (yes/no)Ask for approval because:
Before adding:
Should I add zod to @nimara/domain?
- Runtime validation with TS types
- Lightweight and performant
- Already partially used in infrastructure
Approve? (yes/no)Ask for approval because:
Before adding:
Should I add date-fns to @nimara/foundation?
- For date formatting and manipulation
- More tree-shakeable than moment.js
- Smaller bundle than other alternatives
Approve? (yes/no)If a dependency is already installed and used elsewhere in the project, you don't need approval to use it in a new package—but you still cannot install it without asking.
✅ OK to use: "I'll use the existing zod dependency"
❌ NOT OK: "I'll add zod" (without asking)After installing, always verify:
# Check package.json was updated
cat packages/your-package/package.json | grep "dependency-name"
# Verify pnpm.lock was updated
git diff pnpm.lock | head -20
# Ensure it's in the right place (dependencies vs devDependencies)If you're editing package.json manually (not recommended), still ask first:
I need to add "zod": "^3.22.0" to packages/domain/package.json
Should I proceed? (yes/no)Root workspace:
App/package package.json:
Shared packages:
@nimara/domain (it should be minimal)// packages/infrastructure/saleor/products/getProduct.ts
import { Result } from "@nimara/domain/objects/Result";
export async function getProduct(id: string): Promise<Result<Product, Error>> {
try {
const product = await saleorClient.getProduct(id);
return { ok: true, data: product };
} catch (error) {
return { ok: false, error };
}
}// packages/features/product-detail/useProduct.ts
import { getProduct } from "@nimara/infrastructure/saleor/products";
export function useProduct(id: string) {
const [result, setResult] = useState<Result<Product, Error>>({ ok: false });
// ...
useEffect(() => {
getProduct(id).then(setResult);
}, [id]);
return result;
}// packages/features/checkout/_actions/completeCheckout.ts
"use server";
import { completeCheckoutUseCase } from "@nimara/infrastructure";
export async function completeCheckout(data: CheckoutData) {
const result = await completeCheckoutUseCase(data);
if (!result.ok) return { error: result.error };
revalidatePath("/orders");
return { success: true };
}A function/factory taking more than one argument accepts a single options object, not positional params — more readable at the call site and easy to extend without breaking callers.
// ❌ positional
export const clientEntryPoint = (context: Context, appName: string) => { … };
clientEntryPoint(context, "handler");
// ✅ options object
export const clientEntryPoint = ({
appName,
context,
}: {
appName: string;
context: Context;
}) => { … };
clientEntryPoint({ context, appName: "handler" });A single argument stays positional (getOperationName(document)).
A single-operation use-case returns the callable directly — no { execute }
wrapper (that's ceremony). Reserve method objects for genuine multi-operation
services (joseAuthService, appConfigService).
// ✅ callable use-case
export const installSaleorAppUseCase =
(deps): InstallSaleorAppUseCase =>
async (input) => { … };
container.get("installAppUseCase")(input);domain// ❌ WRONG: domain should not have external deps
// packages/domain/services/ProductService.ts
import axios from "axios";
export function getProduct(id: string) {
return axios.get(`/api/products/${id}`);
}
// ✅ RIGHT: move to infrastructure
// packages/infrastructure/saleor/products/getProduct.ts// ❌ WRONG: Creates circular dependency
// packages/infrastructure/use-cases/checkout.ts
import { CheckoutForm } from "@nimara/features";
// ✅ RIGHT: Infrastructure provides data, features consume it// ❌ WRONG: This is storefront-specific
// packages/features/StorefrontHeader.tsx
// ✅ RIGHT: Keep in app
// apps/storefront/src/components/StorefrontHeader.tsx// ❌ WRONG: Business logic in UI
// packages/ui/ProductCard.tsx
const ProductCard = ({ productId }) => {
const product = await fetchProduct(productId); // ❌
return <div>{product.name}</div>;
};
// ✅ RIGHT: UI receives data as prop
// packages/ui/ProductCard.tsx
const ProductCard = ({ product }: { product: Product }) => {
return <div>{product.name}</div>;
};Follow this checklist:
Create domain types (if new entity type)
packages/domain/types/YourEntity.types.tsAdd infrastructure integration (if external API call)
packages/infrastructure/your-provider/Create feature package
packages/features/your-feature/Use in app
@nimara/featuresAdd tests
apps/automated-testsCLAUDE.md.claude/rules/architecture.mdreferences/architecture-examples.mdreferences/dependency-management.md© mirumee, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/project-guidelines of mirumee/nimara-ecommerce.
Open the folder on GitHubat commit b883dec
Project Guidelines next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Project Guidelines this skillmirumee/nimara-ecommerce | 129 | — | ~4.8k | Automated safety check: Pass | BSD-3-Clause | |
| Dependabot Alerts Updatelivesession/xyd | 114 | — | ~2k | Automated safety check: Pass | MIT | |
| Databuddydatabuddy-analytics/Databuddy | 1.2k | — | ~2k | Automated safety check: Pass | AGPL-3.0 | |
| Finish Extensions Featuresenchabot-opensource/monorepo | 114 | — | ~554 | Automated safety check: Pass | GPL-3.0 | |
| Senior Fullstackdavila7/claude-code-templates | 32k | 7 repos | ~1.1k | Automated safety check: Notes | MIT | |
| LobeHub Project Maplobehub/lobehub | 83k | — | ~1.8k | Automated safety check: Pass | Custom licence |
livesession/xyd
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
databuddy-analytics/Databuddy
Help external users integrate Databuddy into their own apps.
senchabot-opensource/monorepo
A skill your agent uses when completing a new feature or making a user-facing change in the apps/extensions workspace to ensure no required files or configurations are forgotten.
davila7/claude-code-templates
Comprehensive fullstack development skill for building complete web applications with React, Next.js, Node.js, GraphQL, and PostgreSQL.
lobehub/lobehub
A map of the LobeHub open-source repository: tech stack, monorepo layout, where each code layer lives and who owns apps, packages and src.
Marve10s/Better-Fullstack
Scaffold a new app, API, backend, fullstack project, mobile app, polyglot service, monorepo, or starter with Better Fullstack.
mirumee/nimara-ecommerce
A skill your agent uses when creating, rewriting, refining, or stress-testing a Product Requirements Document (PRD), including turning an initiative or feature brief into product requirements.
mirumee/nimara-ecommerce
A skill your agent uses when designing, drafting, refining, or stress-testing an RFC for an approved PRD, including requests for a design doc, solution design, or how to build it.
mirumee/nimara-ecommerce
Operate Nimara's UCP REST commerce API. An agent skill from mirumee/nimara-ecommerce.
mirumee/nimara-ecommerce
Help the user understand the current topic visually with concise diagrams, code-shape sketches, and focused HTML artifacts.
mirumee/nimara-ecommerce
Retest a reported defect on the live Nimara board (Jira project MS, board 74) and give it an evidence-backed verdict — still reproduces → Open, fixed → Done, blocked → leave In testing and ask.
mirumee/nimara-ecommerce
Ways to explore llm-wiki and answer from it. An agent skill from mirumee/nimara-ecommerce.
Categories
Guide for working with Nimara's layered monorepo architecture. Project Guidelines is an agent skill from mirumee/nimara-ecommerce. Guide for working with Nimara's layered monorepo architecture.
Project Guidelines fits situations like: adding new features; choosing which package to use; understanding data flow; making architectural decisions.
Run `npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a claude-code`. Or copy the skill folder (.claude/skills/project-guidelines in mirumee/nimara-ecommerce) into .claude/skills/project-guidelines in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a codex`. Or copy the skill folder (.claude/skills/project-guidelines in mirumee/nimara-ecommerce) into .agents/skills/project-guidelines in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mirumee/nimara-ecommerce --skill project-guidelines -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-guidelines, .gemini/skills/project-guidelines, .github/skills/project-guidelines and .opencode/skills/project-guidelines in your project.
Going by SKILL.md and its folder, Project Guidelines needs the command-line tools its instructions call (pnpm and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Project Guidelines is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Project Guidelines: Dependabot Alerts Update (livesession/xyd, 114 stars), Databuddy (databuddy-analytics/Databuddy, 1.2k stars), Finish Extensions Feature (senchabot-opensource/monorepo, 114 stars) and Senior Fullstack (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mirumee (a GitHub organization) maintains it in mirumee/nimara-ecommerce, which has 129 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 6, 2026.
Source: mirumee/nimara-ecommerce on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.