Skip to content
Back to skills

Folders

ASecurity

Index important directories and perform safe folder operations with proper security checks.

  • 17 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 6, 2026
businessgonodegitsecurity

Works with

  • cli

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill folders --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Folders?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Folders
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-folders/badge)](https://www.skillsdirectory.com/skills/clawic-folders)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Folders
slug: folders
version: 1.0.0
description: Index important directories and perform safe folder operations with proper security checks.
homepage: https://clawic.com/skills/folders
metadata:
  clawdbot:
    emoji: πŸ“‚
    os:
    - linux
    - darwin
    - win32
    displayName: Folders
---

## Folder Index

Maintain a lightweight index at `~/.config/folder-index.json` to know where important things are without rescanning.

```json
{
  "folders": [
    {"path": "/Users/alex/projects/webapp", "type": "project", "note": "Main client project"}
  ]
}
```

When user asks "where is X" or "find my project Y", check the index first. If not found, do targeted discovery then offer to add the result.

## Discovery

When asked to find or index folders:
- Scan likely locations: ~/projects, ~/Documents, ~/code, ~/dev, ~/work
- Detect projects by markers: .git, package.json, pubspec.yaml, Cargo.toml, go.mod, pyproject.toml, *.sln
- Stop at first marker (don't recurse into node_modules, vendor, build)
- Propose what was found, don't auto-add: "Found 8 projects in ~/code. Add to index?"

## Path Security

- Canonicalize paths (resolve `~`, `..`, symlinks) before any operation
- Reject system paths: /, /etc, /var, /usr, /System, /Library, C:\Windows, C:\Program Files
- Skip symlinks during traversal, report them separately

## Destructive Operations

- Use OS trash instead of permanent delete
- State recoverability: "node_modules: recoverable with npm install"
- Build artifacts safe to delete: node_modules, __pycache__, .gradle, build/, target/, Pods/, .next/

## Platform Quirks

- **macOS:** .DS_Store alone = effectively empty. Treat .app as single item.
- **Windows:** Paths >260 chars need `\\?\` prefix.
- **Network drives:** Warn before bulk ops β€” may be slow or offline.

Files in this skill

  • SKILL.md1.8 KB
  • _meta.json166 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…