All skills
michtio avatar

/craft-project-setup

@64a3c26

Scaffold Claude Code configuration specifically for Craft CMS projects. Generates CLAUDE.md and .claude/rules/ files tailored to the project type (plugin, site, module, hybrid, or monorepo). Only for Craft CMS projects — not for Next.js, Laravel, or other frameworks. Triggers on: 'set up Claude for this Craft project', 'initialize CLAUDE.md', 'scaffold project config', 'configure Claude Code for Craft', 'create CLAUDE.md', 'missing CLAUDE.md', 'does this project have a CLAUDE.md', 'bootstrap Claude config', 'new Craft project setup', 'onboard a developer to this Craft project', 'generate .claude/rules', 'set up coding standards config', 'upgrade Claude config', 'update CLAUDE.md', 'compare my setup', 'is my config up to date', 'audit my Claude setup', 'redo project setup'. Also triggers when starting work in a new Craft CMS project that lacks a CLAUDE.md file, or when the user wants to check or upgrade an existing configuration. Detects project type from composer.json (craft-plugin, craft-module, project), .ddev/config.yaml, templates/, config/project/, and modules/. NOT for installing Craft CMS itself, creating DDEV environments, writing PHP code, building templates, or content modeling. NOT for non-Craft projects — if the project is React, Next.js, Laravel, or any non-Craft framework, this skill does not apply.

Use this Skill: https://skilld.dev/gh/michtio/craftcms-claude-skills/craft-project-setup

This session only. Nothing lands on disk.

templatessite.clauderulessecurity.md

≈101 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security

  • Sensitive data (API keys, tracking IDs) via craft.app.config.custom backed by env vars, never hardcoded in templates.
  • No secrets in CLAUDE.md, committed files, or template output.
  • CSRF tokens on all forms: {{ csrfInput() }}.
  • Escape user-generated content: {{ entry.userContent|e }} or rely on Twig's auto-escaping.
  • Content Security Policy headers configured for production.

Source: SKILL.md on GitHub

1 warning16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill automates Craft CMS project setup by scaffolding configuration and pre-approving developer commands to improve agent efficiency. While functional, the broad permission grants and the audit workflow for external repositories introduce surfaces for unauthorized command execution and indirect prompt injection.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

Signed by skilld at 64a3c26. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 weeks ago

README badge

README badge for michtio/craftcms-claude-skills/craft-project-setup