# Bootstrap · timo-jakob

> Bootstraps a project with the full quality + security toolchain. Detects repo visibility (public vs private), languages, and Docker presence, then generates GitHub Actions workflows, scanner configs, pre-commit hooks, branch protection, Dependabot, templates, and developer docs. Public repos use SonarCloud + Snyk; private repos use self-hosted SonarQube + Trivy. Enforces a Zero Tolerance standard via layered CI + pre-push + Sonar enforcement (falls back to Sonar way on SonarCloud free). Idempotent — safe to re-run on partially configured repos. Also reconciles GitHub-side state (branch protection, secrets, Sonar project) when files are already in place but Step 4 didn't complete (the State D gap-fill mode).

## Facts
- Page: https://tashan.sh/capability/skill-timo-jakob-bootstrap
- tashan id: skill:timo-jakob/bootstrap
- Source: https://github.com/timo-jakob/timos-claude-code-plugins
- Type: skill
- Category: security
- tashan score: 45.0 / 100
- Adoption: 14.0
- Upkeep: 80.0
- Freshness: 95.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: MIT
- Official: no

## Install

```sh
cp -r bootstrap ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-09-12 by tashan (https://tashan.sh) from public evidence. Scorer s5.
