light0305/light-project-structure
>- Audit, plan, scaffold, and safely migrate research project structures across greenfield, existing Git/non-Git repositories, and monorepo subroots. Use for project folders, repository cleanup, source inventory, move maps, naming and storage policy, Python/R/mixed/LaTeX profiles, template provenance, conflict review, applied-move evidence, or rollback. Existing projects are read-only until the user authorizes exact action IDs bound to a plan digest. Preserve uncommitted and untracked work, symlinks, submodules, and memory-pm's .light STAGE_GATES/ROUTES connection.
npx skills add https://github.com/Light0305/Light-skills --skill light-project-structure
Own the visible project tree and its migration evidence. Do not mistake a
tidy directory for reproducible research.
Read
references/project-lifecycle-resource-map.md
before an existing-repository migration. It defines artifacts, policy, access
levels, provenance, and cross-skill ownership. Use
references/structure-profiles.json for
small profile minima and
templates/project-policy.template.json
for explicit project/file policy.
Use scripts/structure_governance_gate.py before delivery to validate profile
choice, existing-project read-only safety, template residuals, secret scan,
environment doctor, authorization binding, applied-manifest binding, and
rollback evidence.
git rm --cached, initialize DVC, rewriteconfiguration, or move a symlink automatically.
--force as consent. The lifecycle has no force bypass..light/ content. memory-pm alone creates or edits passport,project card, decision log, version history, terminology, and handoff files.
UNKNOWN. A path such as data/raw does not prove size,sensitivity, immutability, recomputability, or Git policy.
light.findings.v1; add noSTAGE_GATES, ROUTES, stage number, or back-edge.
reproducibility, statistical validity, or paper quality.
unhandled secret-scan hits, or missing required Python/R/environment checks.
| Situation | Mode |
|---|---|
| Empty target and the user wants a starting tree | scaffold with one explicit profile |
| Existing repository, monorepo package, or non-Git directory | intake, then stop at the decision |
| User approved exact moves after seeing the plan | create authorization, then apply |
| Applied moves need reversal | rollback from the applied manifest |
Do not scaffold a non-empty directory. Do not retrofit a fixed 23-directory
tree onto R, paper-only, mixed-language, custom, or monorepo projects.
Collect or preserve as UNKNOWN:
non-Git directory;
collaborators, CI, license, and retention;
submodules, symlinks, large files, and sensitive path signals.
Choose the smallest profile after inspecting observed technology signatures and
the user's declared deliverables:
python-researchr-researchmixed-researchpaper-onlyexisting-customProfiles are extensible minima, not compliance verdicts.
The selected profile is not evidence about the project. intake records
observed file/config signals separately from policy-declared artifact types,
recommends a profile, and fails the governance gate when a different profile
has no concrete profile_selection_reason.
Copy the policy template outside the source root, fill known project facts, and
add file rules only where there is evidence. Legitimate tracked artifacts
include small public fixtures, reviewed golden files, DVC pointers, final paper
figures, release artifacts, or audit evidence when project policy requires
them. Large/sensitive source data, models, and results usually need DVC/object
storage, but require a decision rather than a directory-name verdict.
Run:
python scripts/scaffold.py intake <root> --out <evidence-dir> \
--profile mixed-research --policy <project-policy.json>
The command writes evidence to --out and verifies that the source snapshot
and Git status did not change.
intake also emits technology signatures, the environment doctor, template
residual scan, secret scan, and governance report named in the resource map.
Tool checks derive from observed or explicitly declared artifact types, not
from the chosen profile alone. If the project requires Python, R, Quarto, DVC,
LaTeX, or other local tools, record those requirements in the policy. Use the
standalone doctor command only when you need an extra ad-hoc check:
python scripts/structure_governance_gate.py --doctor python r
Read the intake artifacts named in the resource map. Check:
UNKNOWN owner, producer, recomputability, sensitivity, classification,
target, and policy basis;
evidence from policy.project.artifact_types; the selected profile matches
the recommendation or has a concrete user override reason;
../, absolute, drive-letter, UNC, or otherwise root-escaping action pathsare blocked in the dry-run plan and governance gate, not deferred to apply;
whole Git root as its project;
.light/ is preserved and has no move action;raw;doctor are present when relevant; .env ignore is not a secret-scan result.
Present:
git rm --cached, configuration rewrite, and DVC initialization;
Then stop. Ask which action IDs the user authorizes. Do not prewrite their
answer.
Run the governance gate on the delivery bundle before presenting a structure as
ready:
python scripts/structure_governance_gate.py \
--input templates/project-structure-governance.example.json
The bundled example is intentionally fail-closed: it attempts scaffold on an
existing R project, leaves template placeholders, reports secret values, misses
R, uses force, moves .light/, duplicates action IDs, applies delete, moves a
symlink, and risks overwrite.
After the user chooses, create an authorization document:
{
"schema": "light.project-structure.v2.authorization",
"authorization_id": "<user-created stable authorization id>",
"plan_sha256": "<exact migration-plan plan_sha256>",
"approved_action_ids": ["move-0001"],
"authorized_by": "<user-supplied identifier>",
"authorized_at": "<YYYY-MM-DD>"
}
Do not include blocked or unknown actions. authorization_id and
authorized_by must be concrete user-supplied values, not template text;
authorized_at cannot be in the future. A changed plan requires fresh
authorization. The authorization cannot resolve an overwrite or bypass a
symlink block.
python scripts/scaffold.py apply \
--plan <migration-plan.json> \
--authorization <authorization.json> \
--manifest-out <applied-manifest.json> \
--as-of <YYYY-MM-DD>
python scripts/scaffold.py rollback \
--manifest <applied-manifest.json> \
--rollback-out <rollback-manifest.json>
apply re-verifies source hashes and absolute containment, creates missing
target parents, refuses existing targets, moves only ordinary files, records
before/after SHA-256, and writes an applied manifest that binds the exact plan
file and authorization file by locator plus file SHA-256. A path that escaped
the selected root should already have been marked blocked during planning; if
one reaches apply anyway, apply still fails closed. rollback verifies target
hashes and refuses to overwrite a reappeared source; it uses the applied
manifest for safe restoration and does not require the original plan/auth files
to still be present.
After rollback:
.light/ content remain byte-identical;Use only on an empty target:
python scripts/scaffold.py scaffold <target> --profile r-research --name <name>
The command records profile and generator hashes in
.project-structure-provenance.json. It is one-time generation, not safe
template updating. For managed template evolution, evaluate Copier or Cruft and
review local modifications and conflicts; do not claim drift detection is a
merge guarantee.
memory-pm to run pm.py init when .light/ memory is needed; do not doits work here.
data-engineering.experiment-coding.file-reading understand supplied repositories/materials; this skillalone owns moves.
orchestrator consume a delivery if useful; do not create a gate.Run the script self-test:
python scripts/scaffold.py --selftest
python scripts/structure_governance_gate.py --selftest
It exercises source-read-only intake, a tracked fixture policy, generated
environment/template/secret/governance reports, an untracked draft, .light/
preservation, authorization binding, applied-manifest plan/auth file binding,
real move/hash evidence, rollback, reapply, non-Git mode, monorepo subroot
handling, profile scaffold idempotence, and a best-effort Windows symlink
branch.
Before delivery, verify:
file by locator and file SHA-256.
.light/ content survived move and rollback.reason are present; observed/declared signatures support the profile, and
R/Python requirements are checked when claimed.
structure_governance_gate.py passes for the actual delivery bundle.Take light0305/light-project-structure from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.