
Security News
Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.
ai-engineering-init
Advanced tools
AI 工程化配置初始化工具 — 一键为 Claude Code、OpenAI Codex 等 AI 工具初始化 Skills 和项目规范
一键初始化 AI 工程化配置,支持 Claude Code、Cursor、OpenAI Codex 等主流 AI 开发工具。
npx ai-engineering-init
交互式选择工具,或直接指定:
npx ai-engineering-init --tool claude # Claude Code
npx ai-engineering-init --tool cursor # Cursor
npx ai-engineering-init --tool codex # OpenAI Codex
npx ai-engineering-init --tool all # 全部
| 命令 | 说明 |
|---|---|
npx ai-engineering-init | 交互式初始化到当前项目 |
npx ai-engineering-init@latest update | 更新已安装的框架文件 |
npx ai-engineering-init@latest global | 全局安装到 ~/.claude 等,所有项目生效 |
npx ai-engineering-init config | 初始化数据库连接 / Loki 日志配置(支持全局/本地/追加) |
npx ai-engineering-init mcp | MCP 服务器管理(安装/卸载/状态) |
npx ai-engineering-init sync-back | 对比本地技能修改,反馈回源仓库 |
所有命令均支持
--tool <claude|cursor|codex|all>指定工具。运行--help查看全部选项。
# 第一步:安装
npx ai-engineering-init --tool claude
# 第二步:修改配置(⚠️ 必做!)
# CLAUDE.md 和 AGENTS.md 是示例模板,包含 [你的xxx] 占位符
# 把它们替换为你的项目实际信息(包名、技术栈、架构规范等)
# 第三步:验证
# 在 Claude Code 中输入 /start,AI 会扫描并介绍你的项目
核心命令(第一天用这 3 个就够了):
| 命令 | 作用 |
|---|---|
/start | AI 扫描项目,给出概览 |
/dev | 从需求到代码的完整开发流程 |
/check | 检查代码是否符合规范 |
更多命令:/crud(生成增删改查)、/progress(项目进度)、/sync(代码状态同步)
包含内容:80 个 Skills 技能 + 20 个快捷命令 + 9 个多模型分层 Agent + 自动化 Hooks。详见 参考文档。
CLAUDE.md — 将 [你的xxx] 占位符替换为项目实际信息/start 验证 AI 是否正确理解你的项目sequential-thinking、context7),无需额外设置.cursor/mcp.json 中的 MCP 服务器配置/ 查看可用 Skills,或 @技能名 手动调用AGENTS.md — 将模板内容替换为你的项目规范.codex/skills/ 下的技能辅助开发参考文档 — Skills 列表、包含内容、命令详情、其他安装方式、全部选项
更新日志 — 完整版本变更记录
贡献指南 — 如何维护和更新 Skills,团队协作工作流
MIT
FAQs
AI 工程化配置初始化工具 — 一键为 Claude Code、OpenAI Codex 等 AI 工具初始化 Skills 和项目规范
The npm package ai-engineering-init receives a total of 38 weekly downloads. As such, ai-engineering-init popularity was classified as not popular.
We found that ai-engineering-init demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
A critical vm2 sandbox escape can allow untrusted JavaScript to break isolation and execute commands on the host Node.js process.

Research
Five malicious NuGet packages impersonate Chinese .NET libraries to deploy a stealer targeting browser credentials, crypto wallets, SSH keys, and local files.

Security News
pnpm 11 turns on a 1-day Minimum Release Age and blocks exotic subdeps by default, adding safeguards against fast-moving supply chain attacks.