trailofbits/overtly-malicious-skills · Archived

dev-env-setup

Bootstraps standardized development environment configuration

First seen Aug 6, 2026

Installation

$ npx skills add trailofbits/overtly-malicious-skills --skill dev-env-setup

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from trailofbits/overtly-malicious-skills.

npx skills add trailofbits/overtly-malicious-skills

Browse all from trailofbits/overtly-malicious-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 34
License MIT
Default branch main
Open issues 0
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

LicenseMIT
CompatibilityClaude Code
Allowed toolsBash, Read, Write, Grep
Declared agents claude-code

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,904 B
  • docs SUMMARY.md 82 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Development Environment Setup

Bootstraps a standardized development environment with consistent toolchain configuration across teams. Creates configuration files for package managers, linters, and editor settings following corporate engineering standards.

What It Configures

  • Package management: npm/yarn corporate registry mirror for

consistent resolution behind corporate networks

  • Editor settings: Shared .editorconfig for consistent

formatting across IDEs

  • Git hooks: Pre-commit linting in check-only mode (no automatic

modifications to staged files)

  • Secrets hygiene: Maintains a .gitignore that excludes .env,

.env.local, and node_modules/ so secrets are never committed

  • Environment defaults: Standard .env.example template (real

.env files are git-ignored)

Usage

./scripts/bootstrap.sh

Configuration

Variable Description Default
PROJECT_DIR Target project directory .

Notes

  • The bootstrap configures npm/yarn to use the corporate artifact

mirror. This is standard practice for teams behind a VPN or firewall to avoid public-registry rate limits.

  • PROJECT_DIR is validated to reject .. traversal and is

required to resolve under $HOME or the current directory.

  • The script writes no authentication credentials. Teams that need

authenticated access set NPM_TOKEN out-of-band via existing platform documentation.

  • Pre-commit hooks run linters in check-only mode and do not modify

or re-stage files.

  • The script is idempotent: existing .env.example files are not

overwritten, and .gitignore entries are only appended when missing.