Atlas / Skills / florianbruniaux / Scaffold

ScaffoldCAUTION

skills/florianbruniaux/scaffold

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
1 documented
License
CC-BY-SA-4.0
Stars
6,123
01

Overview

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Read from source at commit d90170da4369OBSERVED · 2026-10-07
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: scaffold
description: "Interactive coach that asks 4-5 questions to determine whether you need an agent, command, skill, hook, or rule, then generates a ready-to-use template. Usage: /scaffold (no arguments needed, starts the coaching session)"
effort: medium
disable-model-invocation: true
---

# Claude Code scaffold coach

Interactive wizard that identifies the right Claude Code component for your use case and generates a ready-to-use template.

**Usage**: `/scaffold` (no arguments needed). Start the conversation.

---

## Phase 1: Discovery

Open with this prompt, then wait for the user's answer before asking anything else:

> What do you want to automate or build? One sentence is enough to start.

Once you have a rough idea, ask the following questions in order. Skip a question if a previous answer already answers it.

### Q1: Trigger

> How is this triggered?
>
> a) I run it myself with a command (e.g. `/something`)
> b) It should fire automatically when Claude takes an action (writes a file, runs bash, finishes a session...)
> c) It should apply all the time, every session, without me doing anything

- If **b** → likely a **Hook** (jump to Q_hook)
- If **c** → likely a **Rule** (jump to Q_rule)
- If **a** → continue with Q2

### Q2: Domain expertise

> Does this require deep, project-specific expertise?
> For example: knowing your GraphQL schema, your migration conventions, your internal API patterns, your cost model...

- If **yes, deep expertise** → likely an **Agent** (jump to Q_agent)
- If **no, more of a checklist or procedure** → continue with Q3

### Q3: Complexity

> How much context and logic does this involve?
>
> a) A lot: multiple rules, domain-specific examples, nuanced judgment
> b) Straightforward: a few steps, a template, some bash

- If **a** → likely a **Skill**
- If **b** → likely a **Command**

### Q4: Reuse scope

> Who needs this?
>
> a) Just me
> b) My whole team
> c) It needs to be invokable by other agents automatically

- **c** → strengthens **Agent** (needs a `description:` field that other agents can read)
- **b** → strengthens **Command** or **Skill** (shared config)
- **a** → can stay a simple personal **Command**

### Q5: Output type

> What should happen at the end?
>
> a) A report or analysis: Claude reads and explains, no files touched
> b) Code or files generated
> c) An action taken (commit, push, API call...)
> d) Claude's behavior changes permanently (always does X, never does Y)

- **a** → read-only Agent (no `Write` or `Bash` in tools)
- **b/c** → Agent or Command/Skill with write access
- **d** → Rule, or Hook if conditional on a specific event

---

## Internal decision tree (do not display, use to reason)

```
Triggered automatically?
  ├─ On Claude action (Write, Bash, SessionEnd...) -> Hook
  └─ Always active, no trigger -> Rule

Triggered manually?
  ├─ Deep domain expertise required?
  │   ├─ Yes + invokable by other agents -> Agent
  │   └─ Yes + manual use only -> Agent or Skill
  └─ Procedure / checklist, no special expertise?
      ├─ Complex, lots of project-specific context -> Skill
      └─ Simple, a few steps -> Command

Common hybrid cases:
  - Agent + Command: specialist agent + a shortcut command to invoke it
  - Rule + Hook: permanent behavior + blocking on a specific action
  - Skill + Agent: skill that delegates analysis to an agent
```

---

## Phase 2: Recommendation

After the questions, display this structure:

```
## Diagnosis

You want to: [one-line summary of the use case]

## Recommendation: [TYPE]

**Why?**
[2-3 sentences: trigger type, complexity level, reuse scope]

**What it would NOT be, and why:**
- Not an agent because [short reason]
- Not a rule because [short reason]
[adjust based on actual candidates]

**Hybrid case?** [Yes / No]
[If yes: explain the combination and which file to create first]
```

---

## Phase 3: Scaffold

Ask: "Generate the scaffold file?"

If yes, produce the template below based on the detected type.

---

### Agent scaffold

```markdown
---
name: [kebab-case-name]
description: "[What this agent does in one sentence. When to invoke it. Example triggers for other agents.]"
model: sonnet
tools: Read, Grep, Glob[, Write, Bash (add only if this agent must modify files or run commands)]
---

# [Agent Name]

[One paragraph: what this agent is for, what it is NOT for, and when to prefer another agent.]

## Context

[Stack, conventions, or domain knowledge this agent needs to be effective.]

## When to invoke

- [Concrete trigger 1]
- [Concrete trigger 2]
- [Concrete trigger 3]

## Protocol

### Step 1: Read context

```bash
# What to read before reasoning
cat CLAUDE.md 2>/dev/null
```

### Step 2: Analyze

[What to look for. Patterns to detect. Red flags to surface.]

### Step 3: Output

[Exact output format: use a markdown code block to show the structure.]

## Red flags

| Pattern | Risk |
|---------|------|
| [pattern] | [impact] |

## What this agent does NOT do

- [Scope boundary 1]
- [Scope boundary 2: point to another agent if relevant]
```

**File**: `.claude/agents/[name].md`

---

### Command scaffold

```markdown
---
name: [name]
description: "[What this command does in one sentence]"
argument-hint: "[arg] [--flag]"
---

# [Command Name]

[Brief description. What problem it solves. When to use it vs alternatives.]

## Arguments

- `[arg]`: [description] (default: [value])
- `--flag`: [description]

## Usage

```bash
/[name]              # Basic usage
/[name] --flag       # With flag
```

---

## Phase 1: [First phase name]

[What Claude does in this phase.]

```bash
# Example commands if applicable
```

## Phase 2: [Second phase name]

[What Claude does.]

## Phase 3: Output

[Output format. Use a markdown block to show the structure.]

$ARGUMENTS
```

**File**: `.claude/commands/[name].md`

---

### Skill scaffold

```markdown
---
name: [skill-name]
description: "[What this skill does. Trigger phrases that activate it. Usage: /[name] [arg]]"
---

# [Skill Name]

[What 
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/en/_extensions
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
whitepapers/recap-cards/fr/_extensions
whitepapers/recap-cards/fr/_extensions
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d90170da4369full audit observations/trust-audit/skill/florianbruniaux__scaffold.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-07d90170da4369CAUTIONB89first audit
06

Questions

What does the Scaffold skill do?

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Is Scaffold safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Scaffold access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Scaffold work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement