Skip to content
Back to skills

Bootstrap Project

ASecurity

Plan and run the scaffolding and setup skills a repository needs, in order. Use for "bootstrap this project" or "set up everything"; not to refresh.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 2, 2026
developmentjavascripttypescriptpythonrustgojavarubyshellbashnode

Works with

  • claude code
  • cli

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 2, 2026

npx -y skills add cboone/agent-harness-plugins --skill bootstrap-project --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Bootstrap Project?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Bootstrap Project
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cboone-bootstrap-project/badge)](https://www.skillsdirectory.com/skills/cboone-bootstrap-project)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: bootstrap-project
description: >-
  Plan and run the scaffolding and setup skills a repository needs, in order.
  Use for "bootstrap this project" or "set up everything"; not to refresh.
---

# Bootstrap Project

Assess the current repository, detect what scaffolding and setup is already in place, build a plan of which tools to run, get user approval, and execute everything in the correct order.

Works for both brand-new and existing repositories.

## Skill dependencies

- **Required:** None
- **Optional:** `add-community-files`, `add-goreleaser-homebrew`, `add-scrut-cli-tests`, `pin-everything`, `scaffold-go-cli`, `scaffold-go-library`, `scaffold-lean-library`, `scaffold-new-repo`, `scaffold-rust-cli`, `set-up-ci`, `set-up-installers`, `set-up-linters`, `set-up-review-config`, `set-up-secret-scanning`

## Workflow

### 1. Detect Project Type

Scan for language and framework markers using Glob. Exclude `node_modules/`, `.yarn/`, `.lake/`, `vendor/`, and other dependency directories from all searches.

| Marker(s)                                                                                           | Project type          |
| --------------------------------------------------------------------------------------------------- | --------------------- |
| `go.mod` + (`main.go` or `cmd/`)                                                                    | Go CLI                |
| `go.mod` without `main.go` or `cmd/`                                                                | Go library            |
| `package.json` + JS/TS source files                                                                 | JavaScript/TypeScript |
| `pyproject.toml`, `setup.py`, `requirements.txt`                                                    | Python                |
| `Cargo.toml` + (`src/main.rs`, `src/bin/*.rs`, or `[[bin]]` in Cargo.toml)                          | Rust CLI              |
| `Cargo.toml` without `src/main.rs`, `src/bin/*.rs`, or `[[bin]]`                                    | Rust library          |
| `lakefile.toml` or `lakefile.lean` with `[[lean_exe]]`, `lean_exe`, `Main.lean`, or user says CLI   | Lean CLI              |
| `lean-toolchain`, `lakefile.toml`, `lakefile.lean`, or `*.lean` without Lean CLI markers            | Lean library          |
| User says Lean formalization, Mathlib-downstream library, PFR downstream project, or theorem prover | Lean library          |
| `build.zig` + (`src/main.zig` or `src/`)                                                            | Zig CLI               |
| `Gemfile`, `*.gemspec`                                                                              | Ruby                  |
| `*.sh`, `bin/*`, `scripts/*`                                                                        | Shell                 |
| `*.zsh`, `#!/usr/bin/env zsh` shebangs, `.zshrc`, `.zshenv`                                         | Zsh                   |
| No recognizable files                                                                               | New/empty repo        |

If no recognizable files are found, ask the user what type of project they intend to create.

If multiple types are detected (monorepo), note all of them.

### 2. Detect Existing Infrastructure

Check for files and directories that indicate what is already set up:

| Check                                                                                                     | Indicates                | Typically provided by                         |
| --------------------------------------------------------------------------------------------------------- | ------------------------ | --------------------------------------------- |
| `LICENSE`                                                                                                 | License exists           | `scaffold-new-repo`                           |
| `README.md`                                                                                               | README exists            | `scaffold-new-repo`                           |
| `CHANGELOG.md`                                                                                            | Changelog exists         | `scaffold-new-repo`                           |
| `AGENTS.md` or `CLAUDE.md`                                                                                | Agent config exists      | `scaffold-new-repo`                           |
| `.github/workflows/ci.yml`                                                                                | CI exists                | `set-up-ci` / `scaffold-go-*`                 |
| `.github/workflows/text-lint.yml`                                                                         | Text lint CI exists      | `scaffold-lean-library` / `set-up-linters`    |
| `.github/workflows/release.yml`                                                                           | Release workflow exists  | `scaffold-go-*` / `add-goreleaser-homebrew`   |
| `.github/workflows/gitleaks.yml`                                                                          | Gitleaks exists          | `set-up-secret-scanning`                      |
| `.github/workflows/trufflehog.yml`                                                                        | TruffleHog exists        | `set-up-secret-scanning`                      |
| `lean-toolchain`                                                                                          | Lean toolchain exists    | `scaffold-lean-library`                       |
| `lakefile.toml` or `lakefile.lean`                                                                        | Lake package exists      | `scaffold-lean-library`                       |
| `bin/bootstrap-worktree`                                                                                  | Lean bootstrap exists    | `scaffold-lean-library`                       |
| `.goreleaser.yml`                                                                                         | GoReleaser exists        | `scaffold-go-cli` / `add-goreleaser-homebrew` |
| `rustfmt.toml`                                                                                            | Rust formatter config    | `scaffold-rust-cli` / `set-up-linters`        |
| `deny.toml`                                                                                               | cargo-deny config        | `scaffold-rust-cli` / `set-up-linters`        |
| `typos.toml`                                                                                              | typos config             | `scaffold-rust-cli` / `set-up-linters`        |
| `cliff.toml`                                                                                              | git-cliff config         | `scaffold-rust-cli`                           |
| `Makefile`                                                                                                | Build targets exist      | `scaffold-go-*` / `set-up-ci`                 |
| Linter config files                                                                                       | Linters exist            | `set-up-linters` / `scaffold-go-*`            |
| `tests/scrut/`                                                                                            | Scrut tests exist        | `add-scrut-cli-tests`                         |
| `Formula/`                                                                                                | Installers exist         | `set-up-installers`                           |
| `CONTRIBUTING.md`                                                                                         | Community files exist    | `add-community-files`                         |
| `.github/skills/code-review/SKILL.md` and `REVIEW.md` both holding a `set-up-review-config` managed block | Review config exists     | `set-up-review-config`                        |
| `.github/dependabot.yml` or `.yaml`                                                                       | Dependabot config exists | `pin-everything`                              |

### 3. Build the Plan

Determine which tools to run based on the project type, existing infrastructure, and the overlap rules in `./references/overlap-rules.md`. Read that file for the full decision table.

Key overlap rules:

- If `scaffold-go-cli` will run: skip `set-up-ci`, skip `add-goreleaser-homebrew` (both are included). Scope down `scaffold-new-repo` to only generate agent config files (AGENTS.md, CLAUDE.md, .claude/settings.json, .github/copilot-instructions.md).
- If `scaffold-go-library` will run: skip `set-up-ci` (included). Scope down `scaffold-new-repo` to only generate agent config files. `add-goreleaser-homebrew` and `set-up-installers` are not applicable for libraries.
- If `scaffold-go-library` will run: still run `set-up-linters` but only for cross-language tools (Prettier, EditorConfig, markdownlint) since `.golangci.yml` is already configured.
- If `scaffold-go-cli` will run: still run `set-up-linters` for `.golangci.yml` configuration and cross-language tools (the Makefile lint target exists but no golangci config).
- If `scaffold-rust-cli` will run: skip `set-up-ci` (included). Scope down `scaffold-new-repo` to only generate agent config files. Still run `set-up-linters` but only for cross-language tools since Rust linting is already configured.
- If `scaffold-lean-library` will run: skip `set-up-ci` (included). Scope down `scaffold-new-repo` to only generate missing agent/config extras not produced by the Lean scaffolder. Scope down `set-up-linters` to extra cross-language or Pandoc-academic refinements only, since the Lean scaffolder generates `lintDriver`, `lean-lint`, Markdown and cspell configs, and split CI workflows.
- If `scaffold-lean-library` will run: mark `add-goreleaser-homebrew`, `set-up-installers`, and `add-scrut-cli-tests` as not applicable because Lean libraries do not produce distributable binaries.
- `set-up-secret-scanning` is always independent (no overlap with other tools).
- `add-scrut-cli-tests` is applicable only if the project produces a CLI binary.
- `set-up-review-config` runs after the scaffolders, CI, linters and scrut tests, so it sees the final file types and the checks CI runs, and it adds its review rules to the `AGENTS.md` that `scaffold-new-repo` or a scaffolder wrote. It is applicable when the project has, or will have once the plan runs, a file type with a review checklist (Go, Lean, Bash, Zsh, Markdown or scrut tests). Managed blocks in both `.github/skills/code-review/SKILL.md` and `REVIEW.md` at plan time make it `Already set up`. One without the other leaves a reviewer unconfigured, so the skill runs and fills the gap. `AGENTS.md` is not part of this test, because a repository may have declined it.
- `pin-everything` runs scoped down to `--scope dependabot` when the project has, or will have once the plan runs, workflows, a composite `action.yml` or `action.yaml` with an external `uses:` step, or a manifest Dependabot supports, and has no Dependabot config at plan time. A config present at plan time is `Already set up`, and `pin-everything` does not run. The scaffolders already SHA-pin every action they emit, so what a new repository lacks is the config that keeps those pins current. The full pinning pass is a separate decision the user can make later.

Execution order (dependencies flow downward):

1. `scaffold-new-repo` (foundation: LICENSE, README, .gitignore, agent config)
1. `scaffold-go-cli` OR `scaffold-go-library` OR `scaffold-lean-library` OR `scaffold-rust-cli` (language-specific scaffolding, if applicable)
1. `set-up-ci` (if not already covered by step 2)
1. `set-up-linters` (cross-language tools, or full setup if no language scaffolder already covered lint wiring)
1. `set-up-secret-scanning` (secret scanning)
1. `add-goreleaser-homebrew` (if Go CLI and not already covered by step 2)
1. `add-community-files` (community files: CONTRIBUTING, CoC, SECURITY, PR template)
1. `set-up-installers` (if CLI project)
1. `add-scrut-cli-tests` (if CLI project)
1. `set-up-review-config` (review checklists for Copilot, Codex and Claude Code Review; after the tools above, so it sees their file types and CI checks)
1. `pin-everything`, scoped down to `--scope dependabot` (Dependabot config; last, so it sees every workflow and manifest the tools above wrote)

### 4. Present the Plan

Show the user a table with each tool and its status. Use these status values:

| Status         | Meaning                                                |
| -------------- | ------------------------------------------------------ |
| Will run       | Tool is needed and will be invoked                     |
| Scoped down    | Tool will run with a reduced scope (see overlap rules) |
| Already set up | Infrastructure already exists; nothing to do           |
| Skipped        | Another tool covers this functionality                 |
| Not applicable | Tool does not apply to this project type               |

Example output:

```text
| #   | Tool                     | Status         | What it does                                |
| --- | ------------------------ | -------------- | ------------------------------------------- |
| 1   | scaffold-new-repo        | Already set up | LICENSE, README, .gitignore, agent config   |
| 2   | scaffold-go-cli          | Already set up | Go CLI project structure, CI, GoReleaser    |
| 3   | set-up-ci                | Skipped        | Covered by scaffold-go-cli                  |
| 4   | set-up-linters           | Scoped down    | Cross-language tools only (Prettier, etc.)  |
| 5   | set-up-secret-scanning   | Will run       | Gitleaks + TruffleHog secret scanning       |
| 6   | add-goreleaser-homebrew  | Skipped        | Covered by scaffold-go-cli                  |
| 7   | add-community-files      | Will run       | CONTRIBUTING, CoC, SECURITY, PR template    |
| 8   | set-up-installers        | Will run       | Homebrew formula                            |
| 9   | add-scrut-cli-tests      | Will run       | Scrut CLI integration tests                 |
| 10  | set-up-review-config     | Will run       | Review checklists for automated reviewers   |
| 11  | pin-everything           | Scoped down    | Dependabot config only                      |
```

Ask the user to confirm the plan. They may:

- Deselect items they do not want
- Add items that were marked as skipped or not applicable

Wait for explicit approval before proceeding.

### 5. Execute

The tools referenced in this plan are skills. Invoke the skill for each selected item:

- `add-community-files`
- `scaffold-new-repo`
- `scaffold-go-cli`
- `scaffold-go-library`
- `scaffold-rust-cli`
- `scaffold-lean-library`
- `set-up-ci`
- `set-up-linters`
- `set-up-secret-scanning`
- `add-goreleaser-homebrew`
- `set-up-installers`
- `add-scrut-cli-tests`
- `set-up-review-config`
- `pin-everything`

For each confirmed tool, in execution order:

1. Invoke its skill. If that skill is not installed, do not set the tool up another way: record it as "skipped: not installed" with its installation command, report it apart from the completed tools, and continue with the next one.
1. Verify the tool completed successfully.
1. If a tool fails, report the error to the user and ask whether to continue with the remaining tools or stop.

When invoking `set-up-linters` in scoped-down mode, tell it to skip language-specific linters that the Go scaffolder already configured and only set up cross-language tools.

When invoking `set-up-linters` for a Lean library in scoped-down mode, tell it to skip Lean linter wiring that `scaffold-lean-library` already generated. Only request additional cross-language tools, existing-config refinement, or Pandoc-academic preset updates that the user selected.

When invoking `pin-everything`, pass `--scope dependabot`. It is only in the plan when no Dependabot config existed at plan time.

### 6. Summary

After all tools have run, print a summary:

- List everything that was set up, grouped by tool.
- Note any issues encountered during execution.
- Suggest next steps:
  - Run `/lint-and-fix` to fix any initial linting issues.
  - Make an initial commit if the repo is new.
  - Push to the remote and verify CI passes.
  - When `set-up-review-config` ran, open the setup as a pull request: Copilot reads review skills from a pull request's head branch, so that pull request is already reviewed with the new config.
  - When the plan marked the Dependabot config as already set up, run `/review-dependabot-config` to check that the config covers everything the repository uses.

## Error Handling

- **Empty repository with no user input**: If the repo is empty and the user does not specify a project type, ask before proceeding. Do not assume a type.
- **Tool invocation failure**: Report the error, ask whether to continue with remaining tools, and note the failure in the final summary.
- **Partial infrastructure**: If some files exist but are incomplete (e.g., a CI workflow exists but is missing lint jobs), note this in the plan and let the relevant tool handle it.
- **User declines all tools**: If the user deselects everything, confirm and stop gracefully.

Files in this skill

  • SKILL.md16.9 KB
  • references/overlap-rules.md12.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…