initialize-project

initialize-project is a command for coding agents from alinaqi/maggy. It costs 0 tokens per session (14,177 once invoked), scanned D, original, MIT.

A command that prepares a new or existing software project with Claude coding instructions, skills, commands, hooks, and project structure.

In plain words
What is it for?
Use it to validate the installation, inspect project and cross-tool configuration, and set up or refresh the files that guide Claude while coding.
Why use it?
It checks the existing setup first, so initialization can add missing pieces or update configuration without assuming the project is empty.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/alinaqi/maggy/initialize-project
Clone the repo
git clone --depth 1 https://github.com/alinaqi/maggy

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for initialize-project

README.md
[![agentmods](https://agentmods.dev/badge/commands/alinaqi/maggy/initialize-project.svg)](https://agentmods.dev/commands/alinaqi/maggy/initialize-project)
Your own site
<a href="https://agentmods.dev/commands/alinaqi/maggy/initialize-project"><img src="https://agentmods.dev/badge/commands/alinaqi/maggy/initialize-project.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 14,177 The whole file, excluding the scripts and references it only reads on demand.
Security scan D 4 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.14177
Opus 5 $0.00000 $0.07089
Sonnet 5 $0.00000 $0.02835
Haiku 4.5 $0.00000 $0.01418

Measured 4d ago against content hash 3c7106ff54ae, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade D, and why

initialize-project scanned grade D with 4 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

BOOTSTRAP_DIR=$(cat ~/.claude/.bootstrap-dir 2>/dev/null)

Enumerates other installed skillsmediumAgent snooping

Other skills' SKILL.md files reveal prompts, capabilities and secrets that should be invisible to peers.

ls -la .claude/skills/ 2>/dev/null

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

rm -rf "$TEMP_DIR"

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

if curl -fsSL "$DOWNLOAD_URL" -o "$TEMP_DIR/codebase-memory-mcp.tar.gz"; then
commands/initialize-project.md · 1,849 lines

How it starts

The opening of the file, as written. The whole thing — 1,849 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Initialize Project

Full project setup with Claude coding guardrails. Works for both new and existing projects.

This command is idempotent - run it anytime to update skills, add missing structure, or reconfigure.


Phase 0: Validate Bootstrap Installation

FIRST, verify Maggy is properly installed:

# Read bootstrap directory (saved during install)
BOOTSTRAP_DIR=$(cat ~/.claude/.bootstrap-dir 2>/dev/null)
# Run quick validation
"$BOOTSTRAP_DIR/tests/validate-structure.sh" --quick

This checks:

  • Skills are installed with correct structure (folder/SKILL.md)
  • Commands are installed (~/.claude/commands/)
  • Hooks are installed (~/.claude/hooks/)

If validation fails:

  • Show the error to user
  • Suggest running: cd "$BOOTSTRAP_DIR" && git pull && ./install.sh
  • Offer to continue anyway or abort

If validation passes:

  • Continue to Phase 1

Phase 1: Detect Project State

First, check what already exists:

# Check for existing Claude setup
ls -la .claude/skills/ 2>/dev/null
ls -la CLAUDE.md 2>/dev/null
ls -la _project_specs/ 2>/dev/null

# Check for cross-tool setup (Kimi CLI, Codex CLI)
ls -la .kimi/skills/ 2>/dev/null
ls -la .codex/skills/ 2>/dev/null
ls -la .agents/skills/ 2>/dev/null
ls -la AGENTS.md 2>/dev/null

# Detect installed AI CLI tools
BOOTSTRAP_DIR=$(cat ~/.claude/.bootstrap-dir 2>/dev/null)
DETECTED_AGENTS=$("$BOOTSTRAP_DIR/scripts/detect-agents.sh" 2>/dev/null || echo "claude")
echo "Detected AI CLI tools: $DETECTED_AGENTS"

# Check for existing git repo
git remote -v 2>/dev/null

# Check for existing package files
ls package.json pyproject.toml 2>/dev/null

# Check for Flutter project
ls pubspec.yaml 2>/dev/null

# Check for Android project
ls android/build.gradle android/app/build.gradle 2>/dev/null

# Check for native language in Android projects
find android -name "*.java" -type f 2>/dev/null | head -1
find android -name "*.kt" -type f 2>/dev/null | head -1

Based on findings, determine:

  • New project: No CLAUDE.md, no .claude/skills/, no code files
  • Existing project with skills: Has .claude/skills/ - offer to UPDATE
  • Existing codebase without skills: Has code but no Claude setup - AUTO-RUN ANALYSIS

Read the full file on GitHub · 1,849 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 1,849 lines · 0 tokens per session scan D 3c7106ff54ae

Subscribe to this mod's changes

initialize-project is a command published in the GitHub repository alinaqi/maggy (705 stars, last pushed 16d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 14,177 tokens. A static security scan graded it D with 4 findings (reads agent configuration directories, enumerates other installed skills, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.