Skip to content
Back to skills

Setup Project

BSecurity

Onboards a new developer - explains the project, runs setup steps, verifies everything works

  • 10 stars
  • 0 votes
  • 0 copies
  • 9 views
  • Added May 27, 2026
data-aibashapidatabase

Works with

  • api

Security analysis

B80/100
  • mediumUses curl or wget to download content
  • criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned May 27, 2026

npx -y skills add berkcangumusisik/claude-code-practices --skill setup-project --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Setup Project?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Setup Project
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/berkcangumusisik-setup-project/badge)](https://www.skillsdirectory.com/skills/berkcangumusisik-setup-project)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: setup-project
description: Onboards a new developer - explains the project, runs setup steps, verifies everything works
user-invocable: true
allowed-tools: Bash Read Glob
effort: medium
---

## Project Setup & Onboarding

1. Read the project:
```bash
cat README.md 2>/dev/null | head -60
cat package.json | grep -E '"name"|"description"|"scripts"' -A 10
ls src/ 2>/dev/null
```

2. Run the setup sequence:
```bash
# Install dependencies
npm install 2>&1 || bun install 2>&1

# Check environment
ls .env* 2>/dev/null
```

3. Env vars check - if `.env` is missing, copy from `.env.example` and list what needs filling:
```bash
cp .env.example .env 2>/dev/null && echo "Created .env from example"
```

4. Database setup:
```bash
npx prisma migrate dev 2>/dev/null || echo "No Prisma detected"
```

5. Run the dev server:
```bash
npm run dev 2>&1 | head -20 &
sleep 3
curl -s http://localhost:3000/health 2>/dev/null || echo "Check manually"
```

6. Run tests:
```bash
npm test 2>&1 | tail -10
```

7. Produce a summary report:
```
Project: [name]
Stack: [detected tech]
Setup: ✅ complete / ❌ issues found

Next steps for new developer:
1. Fill in .env: STRIPE_SECRET_KEY, SENDGRID_API_KEY
2. Run: npm run db:seed
3. Read: docs/architecture.md
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…