bootstrap-project
Bootstrap a new project at a chosen graduation tier (t0 minimum, t1 decision-tracked, t2 full pattern language) following AI-Assisted Project Orchestration best practices. Use when starting a new software project, promoting an existing project to a higher tier, or converting an e
供给资产档案
编程与开发 Agent
代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。
场景
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
适配 Agent
Claude Code + CLI + Codex
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project
维护状态
新鲜
距上次推送 1 天
风险
需审查
Dependency or permission surface needs review
GitHub 质量
14
58/100 质量 · 61/100 信任
覆盖标签
审查说明
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
有潜力有用的候选项,但采用前应与替代方案比较。
信任
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
安装前需人工审查
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
14 个 GitHub Stars
仓库活跃度
14 个 Star,0 个 Fork
维护状态
距上次推送 1 天
许可证
MIT
安装
npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project
安装安全性
标准软件包或运行时安装路径
权限范围
secrets or environment access, shell or command execution
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- The provided SKILL.md excerpt is truncated; the full workflow, outputs, and limitations are not visible in the review material.
- Financial research output is not financial advice; require human review before any live investment decision.
- Low GitHub adoption signal
- Quality score needs review
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 已声明许可证
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
- Inspect repository metadata
适用 Agent
安装决策
- 命令
- npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project
- 策略
- 阻止
- 人工审查
- 是
信任与风险
- 信任
- 53/100
- 审计
- 70/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
安装命令
npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project不适用场景
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- Low GitHub adoption signal
- The provided SKILL.md excerpt is truncated; the full workflow, outputs, and limitations are not visible in the review material.
- 高风险权限提示:Shell or command execution, Secrets or environment access
Agent 安全 v2
26/100 · 避免自动安装
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
Browser automation
Skill may drive a browser or interact with web pages.
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
- 高风险权限提示:Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
安装目标
在你的 Agent 工作流中安装此 Skill
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install jrjsmrtn-bootstrap-projectAgent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20bootstrap-project%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20bootstrap-project%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/jrjsmrtn-bootstrap-project/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use bootstrap-project in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20bootstrap-project%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/jrjsmrtn-bootstrap-project/install
Install command: npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/jrjsmrtn-bootstrap-project/install
LLM 文本格式
/api/skills/jrjsmrtn-bootstrap-project/install?format=text
寻找替代方案
/api/skills/search?q=bootstrap-project&limit=3
Agent 提示词
Use bootstrap-project for this task. Review https://www.openagentskill.com/api/skills/jrjsmrtn-bootstrap-project/install, then install with: npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-projectRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Agent 决策面板
Fallback candidate for GitHub automation
先用此 Skill 做原型验证,并保留备选方案。
栈中角色
备选候选
主要匹配
GitHub automation
信任标签
先做原型验证
安装路径
命令已就绪
适用场景
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
证据
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 58/100 质量档案
- 4 个 OpenAgentSkill 交互事件
先审查
- Low GitHub adoption signal
- The provided SKILL.md excerpt is truncated; the full workflow, outputs, and limitations are not visible in the review material.
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub 采用度
修复14 个 GitHub Stars
Star/Fork 活跃度
修复14 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过距上次推送 1 天
许可证清晰度
通过MIT
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- The provided SKILL.md excerpt is truncated; the full workflow, outputs, and limitations are not visible in the review material.
- Financial research output is not financial advice; require human review before any live investment decision.
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 14 GitHub stars
- Stars/forks activity: 14 stars, 0 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
Choose a stronger alternative or inspect the source manually before any install attempt.
质量档案
有潜力 适用于 Agent 工作流的候选
有用的候选项,但采用前应与替代方案比较。
工作流匹配
在这些场景使用此 Skill
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
工作流匹配
加入完整工作流
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
MoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Cua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
概览
--- name: bootstrap-project description: Bootstrap a new project at a chosen graduation tier (t0 minimum, t1 decision-tracked, t2 full pattern language) following AI-Assisted Project Orchestration best practices. Use when starting a new software project, promoting an existing project to a higher tier, or converting an existing project for AI-assisted development. metadata: author: "Georges Martin <jrjsmrtn@gmail.com>" version: "0.1.34" license: MIT ---
# Project Bootstrap
Bootstrap a new project with foundational artifacts following AI-Assisted Project Orchestration best practices. Implements the **Tiered Bootstrap** pattern with three graduation tiers (t0/t1/t2) so that decision rationale is captured at decision-time and tier promotion is reformatting, not archaeology.
## When to Use
- Starting a new software project (pick a tier appropriate to scope) - Promoting an existing project from a lower tier to a higher one - Converting an existing project to follow best practices - Setting up a project for AI-assisted development
> **Pattern Reference**: See [TIERED-BOOTSTRAP](https://github.com/jrjsmrtn/ai-assisted-project-orchestration/blob/develop/docs/patterns/inception/tiered-bootstrap.md) for the underlying pattern, including knowledge-preservation argument and the comparison with spec-driven development tools.
## Required Inputs
Before running this skill, gather from the user:
1. **Project name** (kebab-case, e.g., `my-awesome-project`) 2. **Project description** (1-2 sentences) 3. **Tier** (graduation level — see [Tier Selection](#tier-selection) below): - **t0** — minimum viable foundation (CLAUDE.md + git + conventional-commits) - **t1** — decision-tracked project (+ foundation ADRs + pre-commit + changelog) - **t2** — full pattern language (+ Diátaxis + C4 + sprint cadence + roadmap) — **default** 4. **Project category**: - **Development**: Software (applications, libraries, services) - **Infrastructure**: Operations (homelab, deployment, monitoring) - **Hybrid**: Both development and operations components 5. **Project type** (library, web application, CLI tool, API service, infrastructure automation) 6. **Technology stack** (e.g., "Elixir/Phoenix/Ash", "Python/FastAPI", "Ansible") 7. **License** (MIT, Apache-2.0, proprietary) — required at t1+, optional at t0 8. **Git remotes** (private origin only, or multi-remote with public GitHub/GitLab) 9. **Distribution profile** (exposure — orthogonal to the tier): **Private** (default — internal/homelab/WIP) or **Public** (open-sourced on a public forge *and* properly licensed). Set the **`ships-artifacts`** marker if the maintainer will publish built packages/images to a registry (Hex/PyPI/GHCR/containers) or signed release binaries. The profile governs which compliance controls apply — see [Distribution Profile](#distribution-profile) below.
**Why project category matters:** - **Development**: ADR-0004 (Operations) is skipped - **Infrastructure**: ADR-0004 is created (backup, monitoring, change management) - **Hybrid**: ADR-0004 is created, covering both application and infrastructure operations
## Tier Selection
This skill implements the **Tiered Bootstrap** pattern. Each tier is a strict superset of the previous one. Pick the lowest tier that fits the project's current state — promotion is mechanical (reformat / reorganize), not archaeological.
| Project state | Recommended tier | |---|---| | Same-day exploration, weekend prototype | **t0** | | Multi-week solo project, expected to outlive prototype | **t1** | | Multi-contributor, professional, or upstream-OSS-bound | **t2** (default) | | Existing prototype with chat-only history | **t0** immediately, then promote |
**Promotion triggers**: - **t0 → t1**: more than one contributor, project survives two weeks, first decision deserves a numbered record - **t1 → t2**: docs need structure beyond CLAUDE.md, architecture needs visual artifacts, work needs sprint-scale planning, project nears 1.0
**Knowledge-preservation property**: at every tier, decision rationale is captured at decision-time in durable, version-controlled artifacts (CLAUDE.md, conventional commits, ADRs). No tier requires recovering rationale from non-durable sources (chat logs, agent session memory).
## Distribution Profile
**Orthogonal to the tier.** The tier measures process *maturity*; the distribution profile measures *exposure* — how far the software travels — which is what actually gates compliance controls. A mature internal tool has no external obligations; an early public library incurs them the moment it ships. Set the profile at inception (default **Private**), and graduate it like the tier.
| Profile / marker | Trigger | Controls it adds | |---|---|---| | **Private** (default) | internal / homelab / WIP | baseline hygiene (secret scanning — already universal) | | **Public** | open-sourced on a public forge **and** licensed | LICENSE/REUSE, `SECURITY.md` + coordinated disclosure (Phase 9), OpenSSF Scorecard aspirational | | **`ships-artifacts`** (marker) | publishes built packages/images to a registry, or signed release binaries | + SLSA provenance, SBOM, signing, trusted publishing (via `harden-github-actions`, `wrapup-sprint`) |
Going Public *is* making the source redistributable (licensing is part of the gate), so there is no separate "distributed" level. **`ships-artifacts` is a boolean, not a rung** — set it when going public, later, or never. Controls attach to the profile, not the tier, so a project pays only for its actual exposure. Record the profile in CLAUDE.md `## Project Context`; promotion to Public is the `public-release` graduation gate (`project-maintenance-skills`).
This axis maps to recognized frameworks: **Public** → EU CRA "open-source steward" duties + OpenSSF Best Practices; **`ships-artifacts`** → SLSA / EEF Ægis trusted publishing. Treat these as guidance, not legal advice. The `commercial` case (placing on the EU market for pay), which triggers full CRA manufacturer obligations, is out of scope here.
## Phases by Tier
| Phase | t0 | t1 | t2 | |---|---|---|---| | 1. Directory structure (Diátaxis) | — | — | yes | | 2. Git initialization | yes (minimal) | yes | yes | | 3. CLAUDE.md | yes | yes | yes | | 4. CHANGELOG.md | — | yes | yes | | 5. Roadmap | — | — | yes | | 6. README.md | optional | yes | yes | | 7. Audience-traced artifacts | — | — | yes (if registry) | | 8. Invoke related skills | — | `setup-adrs`, `setup-git-hooks` | all |
At **t0**, only Phases 2 (minimal `.gitignore`) and 3 (CLAUDE.md) are required. README is optional. No `docs/` tree, no ADR scaffolding, no changelog — those come with promotion to t1.
At **t1**, add Phase 4 (CHANGELOG) and invoke `setup-adrs` (creates ADR-0001/0002/0003) and `setup-git-hooks`. Still no Diátaxis tree or C4 model.
At **t2**, run all phases. This is the existing default behavior.
**Public profile (any tier)**: additionally run **Phase 9** (`SECURITY.md` + coordinated disclosure). This is gated on the distribution profile, not the tier — a t0 project that is Public still needs it, and a t2 Private project does not.
## Workflow
### Phase 1: Directory Structure
Create the Diátaxis documentation structure:
``` docs/ ├── tutorials/ # Learning-oriented │ └── .gitkeep ├── howto/ # Problem-oriented │ └── .gitkeep ├── reference/ # Information-oriented │ └── .gitkeep ├── explanation/ # Understanding-oriented │ └── .gitkeep ├── adr/ # Architecture Decision Records │ └── .gitkeep ├── architecture/ # Structurizr-specific docs (h2-first, for !docs directive) │ └── .gitkeep ├── sprints/ # Sprint planning and tracking │ └── .gitkeep └── roadmap/ # Project roadmap and phase planning └── .gitkeep ```
For BDD projects, also create: ``` features/ # or test/features/ depending on ecosystem └── step_definitions/ ```
### Phase 2: Git Initialization
1. Initialize git if not already: `git init` 2. Create appropriate .gitignore using gitignore.io for the technology stack 3. Add common security patterns to .gitignore: ``` # Secrets and credentials .env .env.* !.env.example .envrc .envrc.local *.pem *.key credentials.json secrets.yaml
# Claude Code local files CLAUDE.local.md ``` 4. Set up gitflow branches: - Create initial commit on `main` - Create `develop` branch from `main` - Set `develop` as default working branch
> **Interacts with OpenSSF Scorecard** (if you add `harden-github-actions`' Scorecard workflow). > Scorecard's content analysis runs against the **default branch**, so making `develop` the default > means the published score describes the **integration** branch, not the `main` releases are cut > from. (The `Branch-Protection` check is the exception — it also inspects release branches — but > `Pinned-Dependencies`, `Dangerous-Workflow`, `Token-Permissions`, etc. read the default branch.) > Two honest resolutions: keep `develop` default and protect/harden it as the graded branch, or make > `main` the default and treat `develop` as a long-lived branch. Decide deliberately — see > `harden-github-actions` Step 6.
#### Commit message content
[Conventional Commits](https://www.conventionalcommits.org/en/v1.0.0/) specifies the **grammar** — `type(scope)!: description`, uppercase `BREAKING CHANGE`, a blank line before the body, footers as git trailers. Its Rule 7 makes the body *"free-form"*, and that is a vacuum rather than an endorsement. These rules fill it.
**Scale them by tier.** Loading a solo t0 project with a five-rule commit policy is how conventions get ignored wholesale.
| Tier | Applies | |---|---| | **t0** | Rule 1 — subject discipline | | **t1** | + Rules 2 and 3 | | **t2** | + Rule 2 wired as a hook (`setup-git-hooks`), + trailer grammar stated |
**1. The subject says what changed. The body says why — or there is no body.** The diff already shows what. A body restating the subject in longer words is worse than none, because it looks like rationale and is not. *Test: delete the body. If nothing is lost, it should not have been there.*
**2. A commit message MUST NOT claim more than the commit contains.** The sharpest rule, because a wrong message is worse than a thin one: a thin message is merely unhelpful, a wrong one is a false record that outlives everyone who could correct it, and `git log` is where people go precisely when the code no longer explains itself.
This failure is easy to commit and hard to notice. An edit silently does nothing — a pattern that did not match, a file already in the target state — while the message, written beforehand, describes it confidently. **The risk is highest when the message is generated**, since fluent prose about an intended change reads identically whether or not the change landed.
> Before committing, re-read the message against `git diff --cached` and not against your intent.
`setup-git-hooks` can enforce the mechanical half — see *Commit message honesty* there.
**3. Record what would otherwise be lost.** Why this approach rather than the one you rejected; what you tried that failed; what constraint forced the shape. Not the diff in prose — the reasoning that cannot be recovered from the tree. This is the highest-value content in any commit and the first thing omitted under time pressure.
**Two supporting rules**
- **Corrections belong in the message of the commit that fixes them**, naming *what the old state would have misled someone into believing*. A CHANGELOG entry reaches readers; a commit message reaches whoever runs `git blame` in two years, which is a different and usually more desperate person. - **Trailers are structured metadata, not decoration.** Git standardises the *shape* of a trailer block and nothing about which tokens mean what, so any project using `Assisted-by:`, `Co-authored-by:` or similar must state its own gr
技术详情
- 版本
- 1.0.0
- 许可证
- MIT
- 最近更新
- 2026年8月21日
- 发布时间
- 2026年8月21日
决策摘要
备选候选
仓库近期活跃
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 bootstrap-project 准备的场景化草稿,可手动发布到 X。
A practical pick for a repeatable workflow: bootstrap-project: Bootstrap a new project at a chosen graduation tier (t0 minimum, t1 decision-tracked, t2 full pattern language) following A... 14 stars https://www.openagentskill.com/skills/jrjsmrtn-bootstrap-project?ref=x
可选:带安装命令的回复
Listing + install path for bootstrap-project: https://www.openagentskill.com/skills/jrjsmrtn-bootstrap-project?ref=x Install: npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- jrjsmrtn
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 jrjsmrtn,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/jrjsmrtn-bootstrap-project)
[](https://www.openagentskill.com/skills/jrjsmrtn-bootstrap-project)
[](https://www.openagentskill.com/skills/jrjsmrtn-bootstrap-project/audit)
[](https://www.openagentskill.com/skills/jrjsmrtn-bootstrap-project)作者
jrjsmrtn
@jrjsmrtn
平台适配
健康信号
- GitHub Stars
- 14
- 质量评分
- 31/100
- 最近 GitHub 推送
- 2026年8月21日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 4
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
Do not auto-install
- GitHub 采用度14 个 GitHub Stars修复
- Star/Fork 活跃度14 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息修复
- 近期维护距上次推送 1 天通过
- 许可证清晰度MIT通过
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险command execution surface, credential or environment access检查
相关 Skill
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsCua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
21.4K Stars