Source-control safety for Git. An agent skill from asgeirtj/system_prompts_leaks.

CC0-1.0Auto-check passedDevelopment

Install Git

skills CLI
$ npx skills add asgeirtj/system_prompts_leaks --skill git -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install asgeirtj/system_prompts_leaks git --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Meta/muse-code/skills/git .claude/skills/git && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
git
GitHub stars
69k
Token cost
~1k tokens
SKILL.md length
492 words
Files
2 (incl. scripts)
Skills in repo
121
Repo updated
First seen
Licence
CC0-1.0

At a glance

Source-control safety for Git. An agent skill from asgeirtj/system_prompts_leaks.

  • Works in 3 steps: After read_skill gives the physical Git… → Keep the printed refs/tbh/recovery/...… → If the save fails or the workspace is…
  • Tasks that involve Git workflow
  • SKILL.md covers Never without an explicit ask, Before an authorized discard, Always fine and The rest, plus 2 more sections
  • Runs Shell scripts from its folder; calls bash and git

What it does

Git is an agent skill from asgeirtj/system_prompts_leaks. Source-control safety for Git. Two rules apply whether or not you read the body. First, never commit, amend, push, tag, rebase, cherry-pick, revert, or reset --hard unless the user asked for that exact write in this session. An explicit request to create a new commit counts anywhere in the user's own task text, but it is not a request to amend, push, or tag. Finishing a task without that request is not authorization, so leave your work uncommitted for review. Second, when a Git lock file or corrupt index blocks…

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/workspace-recovery.sh`).

It sits in Development, covering Git workflow. It works with Git. The repository describes itself as: Documented system prompts from Anthropic - Claude Fable 5.1, Opus 5.5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-6-Astra, Codex. Google - Gemini 3.8 Flash, 3.1 Pro… The licence is CC0-1.0.

When your agent uses it

  • Tasks that involve Git workflow

Example prompts

  • “/git”

Requirements

  • A Bash shell

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. After read_skill gives the physical Git skill package path, run
  2. Keep the printed refs/tbh/recovery/... value in your handoff, then perform
  3. If the save fails or the workspace is unsupported, stop before destruction

What it can do on your machine

Read from SKILL.md and the folder at commit dd45aa5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Git loads about 1k tokens when it runs. Until then it costs about 184 tokens; SKILL.md has 492 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~184
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from asgeirtj/system_prompts_leaks at commit dd45aa5, republished under its CC0-1.0 licence (© asgeirtj). 492 words, ~1,028 tokens.

Download SKILL.mdSave it as .claude/skills/git/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
git
description
Source-control safety for Git. Two rules apply whether or not you read the body. First, never commit, amend, push, tag, rebase, cherry-pick, revert, or reset --hard unless the user asked for that exact write in this session. An explicit request to create a new commit counts anywhere in the user's own task text, but it is not a request to amend, push, or tag. Finishing a task without that request is not authorization, so leave your work uncommitted for review. Second, when a Git lock file or corrupt index blocks you, never kill the holding process or bulldoze through with deletions - wait, retry, use the holder's own stop mechanism, or stop and report. Load the body only before writing Git history or recovering Git state.
user-invocable
false

Git source-control safety

The working tree belongs to the user. Make the change, leave it visible, and let them decide what becomes history.

Never without an explicit ask

The user must have asked for that exact write in this session, in their own words. An explicit request to create a new commit counts anywhere in the user's own task text, but it is not a request to amend, push, or tag. Finishing a task without that request does not authorize a history write.

  • commit, commit --amend, push, tag, rebase, cherry-pick, revert, merge, branch deletion, reset --hard, path restore, and clean -f all require an explicit ask.
  • Never publish merely because publication would be useful.

Before an authorized discard

Recovery is insurance, not authorization. A save never expands what the user allowed you to delete or overwrite.

When the user explicitly authorized an operation that may discard or broadly overwrite workspace changes, and the workspace is an ordinary Git checkout:

  1. After read_skill gives the physical Git skill package path, run:

    bash
    bash <git-skill-dir>/scripts/workspace-recovery.sh save before-discard
  2. Keep the printed refs/tbh/recovery/... value in your handoff, then perform only the exact authorized operation.

  3. If the save fails or the workspace is unsupported, stop before destruction and ask the user.

To recover that saved tree later, run:

bash
bash <git-skill-dir>/scripts/workspace-recovery.sh restore <recovery-ref>

Restore first saves the current workspace, leaves HEAD, branch, and the real index in place, and restores the selected snapshot into the worktree. The ref also retains distinct staged bytes when the same path had later worktree edits. Read those staged bytes with git show '<recovery-ref>^2:<path>'; the recovery commit's second parent is the saved index tree. Ignored files are not saved; restore refuses an ignored-path collision rather than overwrite data it could not save. Use only the exact printed ref, not a revision expression.

Show full SKILL.md (198 more words)Show less

Always fine

Read-only inspection such as status, log, show, diff, blame, branch -v, show-ref, rev-parse, for-each-ref, and merge-base is fine. Staging named files to inspect diff --cached, and a temporary stash around a tool that requires a clean tree, are also fine when the original state is put back afterward.

The rest

  • Do not use a broad add in a tree you did not clean; name the files you changed.
  • Do not initialize a repository inside vendored, build, data, or existing source-control trees.
  • Do not hand-edit generated files; change their source of truth.
  • Scratch repositories under a temporary directory are yours to experiment in.

Locks and corrupt state

A Git lock usually means another process is writing. Never kill the holder on your own initiative. Wait, inspect the holder read-only, use that tool's normal stop mechanism, or report the block. Never delete a lock without proving no live process owns it, and never respond to index corruption by deleting state and committing anyway.

Never commit or push while status reports changes you did not make and cannot explain.

If you already made an unwanted write

Say so plainly and stop. Do not attempt more history surgery without direction.

© asgeirtj, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in Meta/muse-code/skills/git of asgeirtj/system_prompts_leaks.

  • SKILL.md
  • scripts/workspace-recovery.sh

Open the folder on GitHubat commit dd45aa5

Compare with similar skills

Git next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Git compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Git this skillasgeirtj/system_prompts_leaks69k—~1kAutomated safety check: PassCC0-1.0
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Git Merge Conflict Resolver

    tailcallhq/forgecode

    Resolves Git merge conflicts with a plan-first workflow that keeps both sides' intent, regenerates lock files and backs up deleted-but-modified files.

    7.6k GitHub starsUsed in 1 repo~4.5k tokens
    DevelopmentAuto-check passed

More from asgeirtj/system_prompts_leaks

All 121 skills in this repo
  • Fleet Manager for Agent Sessions

    asgeirtj/system_prompts_leaks

    Shows one digest of coding-agent sessions across your connected machines and lets you open, read, steer, approve, stop and close them, over Herdr, tmux or MSP.

    69k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Muse Code Product Doctor

    asgeirtj/system_prompts_leaks

    Diagnoses a Muse Code installation's own failures from binary and session evidence, instead of treating the report as an ordinary repository bug.

    69k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Agents Project Coordinator

    asgeirtj/system_prompts_leaks

    Runs a goal as a project in which the agent coordinates separate agent threads, judging when to split the work, and interviews you first when nothing can be verified.

    69k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Muse Plugin Creator

    asgeirtj/system_prompts_leaks

    Creates and validates a new native Muse plugin package in the current workspace, limited to five capability families, and leaves installation to you.

    69k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Figma Design Inspector

    asgeirtj/system_prompts_leaks

    Inspects Figma designs through the figma CLI and Figma's MCP server to read variants, spacing, tokens and layouts and to extract assets for implementation.

    69k GitHub stars~936 tokensUpdated today
    Auto-check passed
  • Morning Brief Renderer

    asgeirtj/system_prompts_leaks

    Renders a calm, single-page HTML morning brief from your connected calendar, email and chat, or sets it up to run automatically on weekdays.

    69k GitHub stars~4.5k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Git

What does Git do?

Source-control safety for Git. An agent skill from asgeirtj/system_prompts_leaks. Git is an agent skill from asgeirtj/system_prompts_leaks. Source-control safety for Git.

When should I use Git?

Git fits situations like: tasks that involve Git workflow.

How do I install Git in Claude Code?

Run `npx skills add asgeirtj/system_prompts_leaks --skill git -a claude-code`. Or copy the skill folder (Meta/muse-code/skills/git in asgeirtj/system_prompts_leaks) into .claude/skills/git in your project. Claude Code loads it when a task matches its description.

How do I install Git in Codex?

Run `npx skills add asgeirtj/system_prompts_leaks --skill git -a codex`. Or copy the skill folder (Meta/muse-code/skills/git in asgeirtj/system_prompts_leaks) into .agents/skills/git in your project. Codex loads it when a task matches its description.

Can I use Git in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add asgeirtj/system_prompts_leaks --skill git -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/git, .gemini/skills/git, .github/skills/git and .opencode/skills/git in your project.

What does Git need to run?

Going by SKILL.md and its folder, Git needs a shell for the scripts in its folder and the command-line tools its instructions call (bash and git). Our summary lists: A Bash shell.

Does Git access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Git safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Git use?

Git is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Git use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Git?

Skills that share tags, products or a category with Git: Finishing a Development Branch (obra/superpowers, 296k stars), Code Design Rationale Investigator (cursor/plugins, 10k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Git?

asgeirtj (a GitHub user) maintains it in asgeirtj/system_prompts_leaks, which has 69,095 GitHub stars. The repository holds 121 skills in this directory. The repository was last updated on October 7, 2026.

Source: asgeirtj/system_prompts_leaks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.