project-setup
How to create new projects using blueprints from the project-blueprints repo. Follow when the user asks to create, scaffold, or initialize a new project.
How do I install this agent skill?
npx skills add https://github.com/loxosceles-dev/dev-skills --skill project-setupIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides guidelines for setting up new projects using blueprints from the author's repositories. It manages local configuration files, installs development tools via npx, and creates necessary directory structures for devcontainers. All actions are consistent with the stated purpose of project scaffolding.
- Socketwarn
1 alert: gptSecurity
- Snykwarn
Risk: MEDIUM · 2 issues
What does this agent skill do?
Project Setup
This is a strict guideline. Follow these rules exactly.
New projects are created from blueprints stored at loxosceles/project-blueprints on GitHub.
Workflow
- Pre-flight: Verify devcontainer-state: Before anything else, check that
~/.devcontainer-state/.gitexists. If it doesn't, stop immediately and instruct:
Do not proceed until this is resolved.⛔ ~/.devcontainer-state is not a git repo. Docker will auto-create mount targets as empty root-owned directories, breaking the devcontainer. Fix: git clone git@github.com:loxosceles/devcontainer-state.git ~/.devcontainer-state If ~/.devcontainer-state already exists (empty/root-owned), remove it first: sudo rm -rf ~/.devcontainer-state - Identify the blueprint: Ask which stack the user wants (e.g., "nextjs-sst", "sst-python"). Read the corresponding blueprint from
blueprints/{stack}.mdin the repo. - Read the full blueprint before starting. Understand all sections.
- Collect variables: Ask for
project_name,git_name,git_email, and any other values the blueprint requires. - Execute sections in order: Follow the blueprint step by step.
- Copy fragments verbatim: Fragment files from
fragments/are exact configs. Copy them, then replace{{template_variables}}with actual values. - Assemble stack-specific files: Common fragments (
fragments/common/) contain{{INJECTION_MARKERS}}. Read the matching injection snippets fromfragments/injections/{stack}/and insert them at the marked points. Pick the Dockerfile fromfragments/dockerfiles/{stack}/. The result is one clean file per output — no runtime includes or sourcing. Fordevcontainer.json, merge the injection's extensions and settings into the common base. - Pause on version mismatches: If a tool (create-next-app, SST, etc.) has a new major version compared to what the blueprint specifies, stop and ask: "Should I evaluate the upgrade or use the pinned version?"
- Never silently modify fragments: If a fragment doesn't work with current tool versions, report the conflict and ask.
- Run verification: Execute all verification commands at the end. All must pass.
- GitHub Copilot instructions: Copy
fragments/common/github/copilot-instructions.mdto.github/copilot-instructions.mdandfragments/common/github/copilot/review.mdto.github/copilot/review.md. These provide code quality guidelines for Copilot Chat and PR reviews. - Install skills:
- Run
npx skills add loxosceles/ai-dev --agent claude-code github-copilot codex kiro-cli -yand ask about additional third-party skills. - Pre-create all host mount targets (Docker creates missing sources as root-owned, breaking permissions):
PROJECT=<project-name> mkdir -p ~/.devcontainer-state/cache/${PROJECT}/claude mkdir -p ~/.devcontainer-state/cache/${PROJECT}/kiro/settings - The
skills/directory is always created by the installer as a symlink convenience folder. It cannot be prevented — just gitignore it. .gitignoremust include:.agents/,.claude/skills/,.kiro/skills/,skills/- Steering files (mounted ro at
~/.kiro/steering/from~/.devcontainer-state/ai/steering/) handle skill auto-discovery. No agent configs needed — skills cover all workflows.
- Run
- Verify MCP server config: Check that
~/.devcontainer-state/ai/mcp/servers.jsonexists. If not, warn the user to copy fromservers.json.template. MCP servers are distributed to all agents (Kiro, Claude, Amazon Q) bypost_start.shon every container start. - Verify devcontainer scripts: The setup uses two scripts:
post_create.sh— runs once after container creation (validation, symlinks, git identity, skills restore)post_start.sh— runs on every container start (Claude CLI install/update, Claude settings copy, MCP server distribution)
Rules
- Execute in the current directory (must be empty or an empty git repo)
- Git remotes must use SSH, never HTTPS:
git@github.com:user/repo.git - Never skip verification steps
- If a step fails, present the error with options — don't silently retry
- Template variables use
{{double_braces}}syntax - Fragment files are the source of truth for configs — don't improvise alternatives
- Consistency with
project-migration: This skill andproject-migrationmust produce identical results for shared concerns (devcontainer, skills, kiro, linting, CI/CD). If you detect a discrepancy between what this skill instructs and whatproject-migrationdoes, stop and warn the developer before proceeding.
Progressive Improvement
If the developer corrects a behavior that this skill should have prevented, suggest a specific amendment to this skill to prevent the same correction in the future.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/loxosceles-dev/dev-skills/project-setup">View project-setup on skillZs</a>