
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
Profile a shop's engineering culture from public sources and install develop-like-<target> agent skills. /dev-like Every
Steal the workflow, not the code.
/dev-like Everyand your agent develops like the shops you admire — with receipts.
dev-like profiles a tech company or developer's engineering culture from public sources
only (their shipped agent configs, linter configs, CI files, engineering blogs, talks) and
distills it into an installable, spec-compliant Agent Skill:
develop-like-every, develop-like-theo, develop-like-<your-heroes>.
Every claim in a generated skill links to the public source it came from. No source, no claim.
# Universal — symlinks into every detected harness (Claude Code, Codex, Cursor, Copilot, ...)
npx skills add marcusrbrown/dev-like
# Claude Code plugin (bare /dev-like command)
/plugin marketplace add marcusrbrown/dev-like
/plugin install dev-like
# CLI — install a cached profile's skill directly, no LLM needed
npx dev-like oxide
/dev-like Every # cached: installs develop-like-every from the registry
/dev-like Theo # aliases work: theo.gg, t3.gg, t3
/dev-like SomeNewShop # uncached: live OSINT profile -> skill -> offers to PR it back
What changes? Same prompt, before and after — see the dry-run transcript: a generic senior-engineer review becomes one that runs on the shop's actual operating model, every point traceable to a cited source.
| Slug | Kind | Consent tier | Skill |
|---|---|---|---|
every | org | self-published | develop-like-every |
oxide | org | self-published | develop-like-oxide |
theo | person | stated | generated on demand |
Want a shop profiled? Request it
— or run /dev-like <target> and PR the result back.
profile.md becomes a develop-like-<slug> skill in your
project (.agents/skills/ + .claude/skills/).Public professional sources only, official APIs over scraping, consent tiers on every profile
(self-published > stated > observed > social), a stated-tier floor for individuals,
opt-out honored within 48h, and provenance links on every claim. We
extract principles and workflow shapes — never reproduce prose.
bun install
bun run validate # frontmatter + registry schema + index sync
bun run test # generator, CLI install, link-collection suites
Plain node works too (node scripts/validate.mjs, node --test tests/) — the package has
zero runtime dependencies. Provenance links are re-checked weekly in CI; trigger evals and the
paired workflow eval live in evals/.
See CONTRIBUTING.md for adding registry profiles.
MIT
FAQs
Profile a shop's engineering culture from public sources and install develop-like-<target> agent skills. /dev-like Every
The npm package dev-like receives a total of 14 weekly downloads. As such, dev-like popularity was classified as not popular.
We found that dev-like demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.