skills/oss-ready/SKILL.md
Transform a project into a professional open-source repository by adding LICENSE, README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, and GitHub issue/PR templates. Don't use for documentation overhauls, landing-page generation, or registry publishing.
npx skillsauth add luongnv89/skills oss-readyInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Transform a project into a professional open-source repository with standard community files and GitHub templates.
Before creating/updating/deleting files in an existing repository, sync the current branch with remote:
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin
git pull --rebase origin "$branch"
If the working tree is not clean, stash first, sync, then restore:
git stash push -u -m "pre-sync"
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin && git pull --rebase origin "$branch"
git stash pop
If origin is missing, pull is unavailable, or rebase/stash conflicts occur, stop and ask the user before continuing.
Before proceeding, check Edge Cases below for a non-MIT LICENSE, a monorepo, no detectable language, a private/internal repo, or a dirty/detached HEAD — handle the matching case first if it applies.
Before making any changes:
feat/, feature/, etc.)feat/oss-readyIdentify:
README.md - Enhance with:
CONTRIBUTING.md - Include:
LICENSE - Default to MIT unless specified. Copy from assets/LICENSE-MIT.
CODE_OF_CONDUCT.md - Use Contributor Covenant. Copy from assets/CODE_OF_CONDUCT.md.
SECURITY.md - Vulnerability reporting process. Copy from assets/SECURITY.md.
Copy from assets/.github/:
ISSUE_TEMPLATE/bug_report.mdISSUE_TEMPLATE/feature_request.mdPULL_REQUEST_TEMPLATE.mddocs/
├── ARCHITECTURE.md # System design, components
├── DEVELOPMENT.md # Dev setup, debugging
├── DEPLOYMENT.md # Production deployment
└── CHANGELOG.md # Version history
Update package file based on tech stack:
package.json - name, description, keywords, repository, licensepyproject.toml or setup.pyCargo.tomlgo.mod + README badgesVerify comprehensive patterns for the tech stack.
After completion, show:
After completing each major step, output a status report in this format:
◆ [Step Name] ([step N of M] — [context])
··································································
[Check 1]: √ pass
[Check 2]: √ pass (note if relevant)
[Check 3]: × fail — [reason]
[Check 4]: √ pass
[Criteria]: √ N/M met
____________________________
Result: PASS | FAIL | PARTIAL
Adapt the check names to match what the step actually validates. Use √ for pass, × for fail, and — to add brief context. The "Criteria" line summarizes how many acceptance criteria were met. The "Result" line gives the overall verdict.
◆ Analysis (step 1 of 4 — project profiling)
··································································
Language detected: √ pass — TypeScript (primary)
Project type identified: √ pass — CLI tool
Existing docs found: √ pass — README.md (partial), no LICENSE
[Criteria]: √ 3/3 met
____________________________
Result: PASS
Repeat this format for each subsequent step (Core Files, GitHub Setup, Documentation), adapting the check names to what that step actually validates.
The skill is complete when every item below can be verified with test -f, grep, or a quick visual check. Treat this as a checklist the agent must assert before reporting success.
LICENSE exists at repo root and contains a valid SPDX identifier (e.g., MIT, Apache-2.0). Verify: grep -E "MIT License|Apache License" LICENSE.README.md exists, is at least 40 lines, and includes sections for Installation, Usage, and License. Verify: grep -iE "^#+ (install|usage|license)" README.md | wc -l returns >= 3.CONTRIBUTING.md exists and references the issue tracker plus a branching/PR workflow. Verify: grep -iE "issue|pull request|branch" CONTRIBUTING.md.CODE_OF_CONDUCT.md exists and mentions the Contributor Covenant. Verify: grep -i "contributor covenant" CODE_OF_CONDUCT.md.SECURITY.md exists and lists at least one vulnerability-reporting contact (email or form URL). Verify: grep -E "@|https?://" SECURITY.md..github/ISSUE_TEMPLATE/bug_report.md and .github/ISSUE_TEMPLATE/feature_request.md both exist with YAML frontmatter (name:, about:)..github/PULL_REQUEST_TEMPLATE.md exists and contains a checklist (- [ ])..gitignore exists and excludes the language-appropriate build/temp artefacts (e.g., node_modules/, dist/, __pycache__/, target/).package.json, pyproject.toml, Cargo.toml, or go.mod) declares license, description, and repository fields where the format supports them.After a successful run on a TypeScript CLI project that started with only a partial README.md, the agent emits a final report shaped like this:
◆ OSS Ready summary (4 of 4 steps complete)
··································································
Files created:
√ LICENSE (MIT)
√ CONTRIBUTING.md (33 lines)
√ CODE_OF_CONDUCT.md (Contributor Covenant 2.1)
√ SECURITY.md (reporting via [email protected])
√ .github/ISSUE_TEMPLATE/bug_report.md
√ .github/ISSUE_TEMPLATE/feature_request.md
√ .github/PULL_REQUEST_TEMPLATE.md
√ docs/ARCHITECTURE.md, DEVELOPMENT.md, DEPLOYMENT.md, CHANGELOG.md
Files updated:
√ README.md (+ Quick Start, Usage, License badge)
√ package.json (license, repository, keywords)
√ .gitignore (added dist/, .env)
Acceptance criteria: √ 10/10 met
Manual review needed:
- Confirm SECURITY.md contact email is monitored
- Add real maintainer names to CODE_OF_CONDUCT enforcement section
____________________________
Result: PASS
The agent must list the manual-review items explicitly so the user can finish what cannot be automated. Assert that the file tree printed by the agent matches what is actually on disk before declaring PASS.
The skill should detect and handle these inputs explicitly rather than fail silently:
package.json files — update only the root metadata file unless the user names a sub-package.CODE_OF_CONDUCT.md or SECURITY.md — diff against the template; only append a missing section, never replace user content..github/ workflows or templates — preserve them; merge only the missing files.Templates in assets/:
LICENSE-MIT - MIT license templateCODE_OF_CONDUCT.md - Contributor CovenantSECURITY.md - Security policy template.github/ISSUE_TEMPLATE/bug_report.md.github/ISSUE_TEMPLATE/feature_request.md.github/PULL_REQUEST_TEMPLATE.mdtools
Run Herdr loops for one open GitHub issue (resolve→review→fix) or an existing PR (review→lazy fixer) until CLEAN. Don't use for plain resolution without review, review-only/no-fix requests, backlog automation, or merging.
tools
Manage AI agent fleets in Herdr: split root + sub-agents into one tab as a tiled grid, message/wait/read via herdr CLI, steer any pane. Use for Herdr multi-agent fleets. Don't use for tmux, screen, or non-Herdr terminals.
development
Generate or update docs to match the code, citing each claim to path:line and asking on ambiguity; runbook docs also get a check-only validation script. Don't use for API-reference autogen (JSDoc/Sphinx), landing pages, or CLAUDE.md/AGENTS.md.
testing
Generate a diagram and route to the right engine — draw.io XML (precise, editable, C4, swimlanes) or Excalidraw JSON (hand-drawn, sketch, wireframes). One entry for flowcharts, architecture, ER, sequence, mind maps. Don't use for Mermaid or slides.