# Project Setup Contract (All Cookbooks)

> Set up a safe default project layout that prevents accidental secret leaks and keeps setup instructions consistent across all cookbooks.

- Skill: `tools-only/project-setup-contract-all-cookbooks` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add tools-only/project-setup-contract-all-cookbooks`
- Raw SKILL.md: https://api.skillmd.com/api/skills/tools-only/project-setup-contract-all-cookbooks/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: tools-only (https://skillmd.com/u/tools-only)
- Updated: 2026-09-29
- Page: https://skillmd.com/skills/tools-only/project-setup-contract-all-cookbooks

---

# Project Setup Contract (All Cookbooks)

Use this reference before generating any cookbook app.

## Goal

Set up a safe default project layout that prevents accidental secret leaks and keeps setup instructions consistent across all cookbooks.

## Required Order

1. Create project directory.
2. Initialize git immediately.
3. Create `.gitignore` before any local `.env` file.
4. Create `.env` from [environment_requirements.md](environment_requirements.md).
5. Ask user to fill required values (`WEAVIATE_URL`, `WEAVIATE_API_KEY`) and only the optional keys they need.

## Required Files

### `.gitignore`

```gitignore
# Python
__pycache__/
*.py[cod]
.venv/

# Node
node_modules/
.next/
out/
dist/

# Local env files (never commit secrets)
.env
.env.*
secrets/

# Common local artifacts
.DS_Store
```

### `.env`

- Use the canonical template as provided in [environment_requirements.md](environment_requirements.md).
- Keep real `.env` values local only.

## Git Baseline

Run these commands in every new cookbook app:

```bash
git init
git add .gitignore
git commit -m "initialize project baseline"
```

## Claude Safety Baseline (Recommended)

For projects developed with Claude Code, add deny rules for local secret files:

```json
{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./**/.env)",
      "Read(./**/.env.*)",
      "Read(./secrets/**)"
    ]
  }
}
```

Save this to `.claude/settings.json` at project root.

