Claude Code Tresor
A set of Claude Code utilities: background skills, expert agents, slash commands and prompt templates for development
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Background skills and commands read the project code and run security and deploy checks
- The install script copies files into the user's Claude Code directories
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/claude-code-tresorDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .claude/skills
cp -R "$tmp/skills/development/code-reviewer" .claude/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .claude/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .claude/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .claude/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .claude/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .claude/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .claude/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .claude/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .agents/skills
cp -R "$tmp/skills/development/code-reviewer" .agents/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .agents/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .agents/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .agents/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .agents/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .agents/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .agents/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .agents/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .github/skills
cp -R "$tmp/skills/development/code-reviewer" .github/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .github/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .github/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .github/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .github/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .github/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .github/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .github/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .agents/skills
cp -R "$tmp/skills/development/code-reviewer" .agents/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .agents/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .agents/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .agents/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .agents/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .agents/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .agents/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .agents/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .agents/skills
cp -R "$tmp/skills/development/code-reviewer" .agents/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .agents/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .agents/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .agents/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .agents/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .agents/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .agents/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .agents/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .devin/skills
cp -R "$tmp/skills/development/code-reviewer" .devin/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .devin/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .devin/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .devin/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .devin/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .devin/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .devin/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .devin/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Formerly Windsurf.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .cline/skills
cp -R "$tmp/skills/development/code-reviewer" .cline/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .cline/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .cline/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .cline/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .cline/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .cline/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .cline/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .cline/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .roo/skills
cp -R "$tmp/skills/development/code-reviewer" .roo/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .roo/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .roo/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .roo/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .roo/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .roo/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .roo/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .roo/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add alirezarezvani/claude-code-tresor --skill code-reviewer git-commit-helper test-generator api-documenter readme-updater dependency-auditor secret-scanner security-auditor -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 4b68050
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .agents/skills
cp -R "$tmp/skills/development/code-reviewer" .agents/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .agents/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .agents/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .agents/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .agents/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .agents/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .agents/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .agents/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .agents/skills
cp -R "$tmp/skills/development/code-reviewer" .agents/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .agents/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .agents/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .agents/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .agents/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .agents/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .agents/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .agents/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/alirezarezvani/claude-code-tresor.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/development/code-reviewer/ /skills/development/git-commit-helper/ /skills/development/test-generator/ /skills/documentation/api-documenter/ /skills/documentation/readme-updater/ /skills/security/dependency-auditor/ /skills/security/secret-scanner/ /skills/security/security-auditor/
git -C "$tmp" checkout 4b680504d29a205380436e9970eccf8faa28d21d
mkdir -p .agents/skills
cp -R "$tmp/skills/development/code-reviewer" .agents/skills/code-reviewer
cp -R "$tmp/skills/development/git-commit-helper" .agents/skills/git-commit-helper
cp -R "$tmp/skills/development/test-generator" .agents/skills/test-generator
cp -R "$tmp/skills/documentation/api-documenter" .agents/skills/api-documenter
cp -R "$tmp/skills/documentation/readme-updater" .agents/skills/readme-updater
cp -R "$tmp/skills/security/dependency-auditor" .agents/skills/dependency-auditor
cp -R "$tmp/skills/security/secret-scanner" .agents/skills/secret-scanner
cp -R "$tmp/skills/security/security-auditor" .agents/skills/security-auditorCommands for macOS and Linux, on Windows run them in Git Bash.
Clone the repository and run the installer: git clone https://github.com/alirezarezvani/claude-code-tresor.git, then cd claude-code-tresor and ./scripts/install.sh. The flags --skills-only, --commands-only, --agents-only install only a part.
Other ways from the author
git clone https://github.com/alirezarezvani/claude-code-tresor.git
cd claude-code-tresor
chmod +x scripts/install.sh
./scripts/install.shInstalls skills, agents and commands. The flags --skills-only, --commands-only, --agents-only, --resources-only install only a part.
This is third-party code. Review the repository files before installing.
What it does
The set installs four kinds of add-ons into Claude Code. Background skills fire as you work: they check code quality, suggest missing tests, generate commit messages, scan for vulnerabilities and secrets, and watch dependencies and documentation. Expert agents are invoked manually for deep analysis: architecture, config review, root cause analysis, security, performance and refactoring. Slash commands handle common tasks: scaffold, review, test and documentation generation, plus orchestration commands for audit, profiling, deploy validation and incident response. It also ships prompt templates, code standards and workflow examples. Installation runs via an install.sh script or by copying folders manually, and you can install only the skills, only the commands or only the agents.
Who it is for. For developers and teams on Claude Code who want a ready set of skills, agents and commands for their daily workflow.
Good fit when
- You want background checks of code, tests and secrets while you work
- You need an expert agent for a specific task: review, security, performance
- You want slash commands for scaffolding, review and test and documentation generation
Not a fit when
- You do not work in Claude Code: the set targets its skills, agents and commands directories
- You need one narrow tool rather than a large set of skills, agents and commands
Example request
Review the staged changes for security and performance and suggest fixesLimitations
The set targets Claude Code and its directory layout, installed via an install.sh script or manual copy. Orchestration commands such as audit and incident response are agent methodologies, not separate external services. The quality ratings and testimonials in the README are not independently verified and do not affect catalog matching. MIT licensed.
How to disable. Remove the copied skill, agent and command folders from ~/.claude/skills, ~/.claude/agents and ~/.claude/commands.
Security check
- Background skills and commands read the project code and run security and deploy checks
- The install script copies files into the user's Claude Code directories
README in short
The README describes Claude Code Tresor as a collection of Claude Code utilities: background skills, expert agents, slash commands and prompt templates. Skills provide automatic checks of code, tests, secrets and dependencies, agents handle deep analysis, and commands cover scaffolding, review, test and documentation generation and orchestration of security, performance and operations tasks. The repository also includes code standards, workflow examples and an extended library of additional agents and commands. Installation runs through the install.sh script with flags for selective install, or by copying folders manually. MIT licensed.
SKILL.md
--- name: code-reviewer description: Automatic code quality and best practices analysis. Use proactively when files are modified, saved, or committed. Analyzes code style, patterns, potential bugs, and security basics. Triggers on file changes, git diff, code edits, quality mentions. allowed-tools: Read, Grep, Glob --- # Code Reviewer Skill Lightweight automatic code quality checks while you code. ## When I Activate - Files modified or saved - Git diff run - Code mentioned in conversation - User asks about code quality - Before commits
FAQ
How do skills differ from agents?
Skills run automatically in the background and give fast checks as you work. Agents are invoked manually with @ and do deep analysis with examples and strategy.
Can I install only part of it?
Yes. The install.sh script accepts --skills-only, --commands-only, --agents-only and --resources-only flags, or you can copy the folders you need manually.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything