Agent skill

Memstack Security Git Guard

by cwinvestments in cwinvestments/memstack

A skill your agent uses when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo…

MITAuto-check: notesDevelopment

Install Memstack Security Git Guard

skills CLI
$ npx skills add cwinvestments/memstack --skill memstack-security-git-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cwinvestments/memstack memstack-security-git-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cwinvestments/memstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/git-guard .claude/skills/memstack-security-git-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
memstack-security-git-guard
GitHub stars
423
Token cost
~3.1k tokens
SKILL.md length
1,480 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo…

  • Works in 5 steps: Verify the global pre-commit hook is… → Verify .gitignore covers the standard… → Verify .gitleaks.toml actually detects… → …
  • The user says git-guard
  • SKILL.md covers Activation, What This Skill Is (and Is Not), Context Guard and Protocol, plus 4 more sections
  • Calls gitleaks, git and winget

What it does

Memstack Security Git Guard is an agent skill from cwinvestments/memstack. Use when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo blocks secrets and internal files before commit. This is an installer and verifier, NOT a scanner (gitleaks does the actual scanning). Do NOT use for deep secret audits or RLS work.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Git workflow and Secrets management. It works with Git. The repository describes itself as: Structured skill framework for Claude Code. 130 skills, persistent memory, TokenStack compression, localhost dashboard with 3-agent runner, real-time streaming, MCP tools. The licence is MIT.

When your agent uses it

  • The user says git-guard
  • Check git protection
  • Is this repo protected
  • Verify gitleaks

Example prompts

  • “git-guard”
  • “check git protection”
  • “is this repo protected”
  • “/memstack-security-git-guard”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Verify the global pre-commit hook is installed (Check 1)
  2. Verify .gitignore covers the standard offenders (Check 2)
  3. Verify .gitleaks.toml actually detects something (Check 3) [CRITICAL]
  4. Verify gitleaks is installed and reachable (Check 4)
  5. Report status

What it can do on your machine

Read from SKILL.md and the folder at commit 00370ce. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gitleaks
    • git
    • winget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Memstack Security Git Guard loads about 3.1k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,480 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:114
    a proper .gitignore will happily stage `.env`, `node_modules/`,
  • NoteMentions a .env fileSKILL.md:121
    type .gitignore | findstr /C:".env" /C:"node_modules" /C:"memory/" /C:".serena" /C:"dist/"
  • NoteMentions a .env fileSKILL.md:132
    itignore exists and covers, at minimum: `.env` / `.env.*`,
  • NoteMentions a .env fileSKILL.md:290
    | `.gitignore` | Stops obvious files (.env, memory/) being staged | Sensitive files get staged and reach the scanner |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cwinvestments/memstack at commit 00370ce, republished under its MIT licence (© cwinvestments). 1,480 words, ~3,108 tokens.

Download SKILL.mdSave it as .claude/skills/memstack-security-git-guard/SKILL.md (or your agent's skills folder).
name
memstack-security-git-guard
description
Use when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo blocks secrets and internal files before commit. This is an installer and verifier, NOT a scanner (gitleaks does the actual scanning). Do NOT use for deep secret audits or RLS work.
version
1.0.0

🛡️ Git-Guard: Verifying Repo Protection...

Install and verify the machine-wide secret-blocking setup on a repo. Confirms the global pre-commit hook, .gitignore coverage, a non-neutered gitleaks config, and a reachable gitleaks binary.

Activation

When this skill activates, output:

🛡️ Git-Guard: Verifying Repo Protection...

Then execute the protocol below.

What This Skill Is (and Is Not)

Git-Guard is an installer and verifier, not a scanner. It does not grep for secret patterns itself. Its job is to confirm that the protection layers are present, wired up, and actually armed, so that when a secret IS introduced, gitleaks (run by the pre-commit hook) catches it.

The single most dangerous failure this skill exists to catch is a gitleaks config that LOOKS protective but detects nothing (see Check 3). A scanner that silently scans zero rules is worse than no scanner, because it produces a green checkmark while leaving the door open.

Context Guard

ContextStatus
User asks "is this repo protected?"ACTIVE: run all 4 checks
User says "set up / install git-guard"ACTIVE: run checks, offer fixes
User says "verify gitleaks" / "check git hooks"ACTIVE: run all 4 checks
New repo, before first commitACTIVE: install gitignore + verify config
User wants a deep secret/history auditDORMANT: defer to secrets-scanner
User is mid-commit and just wants it to passDORMANT: do not loosen protection to unblock

Protocol

Run all four checks (Steps 1 to 4), then produce the status report in Step 5. Step 5 is the report itself, not a fifth check. Never silently run a setup or fix command: show the exact command and let the user run it (or confirm first). The one exception is the additive .gitignore append in Check 2, which is safe and reversible and may be applied after showing the diff.

Locating the files shipped with this plugin

Two checks reference files that ship INSIDE this plugin: the pre-commit hook and gitignore-template.txt, both under the plugin's scripts/ directory. After install, those files live in the Claude Code plugin cache, NOT in any fixed location, and NOT in the customer's own project. Resolve <plugin-root> as the plugin folder this SKILL.md was loaded from, walking up out of skills/security/git-guard/ to the folder that contains scripts/.

On a typical install, <plugin-root> looks like this (ILLUSTRATIVE ONLY: the exact path differs per machine and per marketplace):

text
%USERPROFILE%\.claude\plugins\<marketplace>\cwinvestments-memstack\

To find the real path on the current machine, search the plugin cache:

cmd
dir /s /b "%USERPROFILE%\.claude\plugins\gitignore-template.txt"

Substitute the actual resolved <plugin-root> wherever it appears in the commands below. Everything that refers to .gitignore, .gitleaks.toml, or the current repo is relative to the customer's own repo (the current directory), not the plugin.

Step 1: Verify the global pre-commit hook is installed (Check 1)

The pre-commit hook is installed machine-wide via core.hooksPath, so one hook covers every repo on the machine. Confirm it is set AND points at a real directory that contains a pre-commit file.

cmd
git config --global core.hooksPath

Then confirm the directory and hook file exist (using the resolved <plugin-root> from the locating note above):

cmd
dir "<plugin-root>\scripts\hooks\pre-commit"

Evaluate:

  • OK if core.hooksPath is set AND the directory exists AND it contains a pre-commit file.
  • GAP if core.hooksPath is empty, points at a missing directory, or the directory has no pre-commit file.

If there is a GAP, show the one-time setup command, pointing at this plugin's hooks directory. Do NOT run it silently:

cmd
git config --global core.hooksPath "<plugin-root>\scripts\hooks"

This is a global setting. Confirm the user wants machine-wide coverage before they run it. If they already use a different hooks manager (Husky, lefthook, pre-commit framework), note the conflict instead of overwriting it.

Step 2: Verify .gitignore covers the standard offenders (Check 2)

A repo without a proper .gitignore will happily stage .env, node_modules/, build output, and MemStack session/memory files. Compare the repo's .gitignore against the shipped template.

Check the file exists, then look for the high-value offender patterns:

cmd
type .gitignore | findstr /C:".env" /C:"node_modules" /C:"memory/" /C:".serena" /C:"dist/"

The canonical offender list lives in the template shipped with this plugin:

cmd
type "<plugin-root>\scripts\gitignore-template.txt"

Evaluate:

  • OK if .gitignore exists and covers, at minimum: .env / .env.*, node_modules/, build output (dist/, build/, .next/), and the MemStack internal dirs (memory/, .claude/sessions/, .serena/, .agent-bridge/).
  • GAP if .gitignore is missing entirely, or any of those categories is not covered.

If there is a GAP, offer to append the missing lines from the template. This MUST be additive and de-duplicated: never overwrite the existing .gitignore, and never add a pattern that is already present (exact-line match).

Procedure for the additive append:

  1. Read both the repo .gitignore and <plugin-root>\scripts\gitignore-template.txt.
  2. Compute the set of template lines (ignoring blank lines and comments) that are not already present as exact lines in the repo file.
  3. Show the user the exact lines that will be added.
  4. Append only those lines, under a clearly labeled section header such as # --- Added by git-guard ---, preserving the existing content untouched.

For a brand-new repo with no .gitignore at all, offer to copy the template verbatim as the starting point:

cmd
copy "<plugin-root>\scripts\gitignore-template.txt" .gitignore
Show full SKILL.md (679 more words)Show less
Step 3: Verify .gitleaks.toml actually detects something (Check 3) [CRITICAL]

This is the most important check. A .gitleaks.toml can be present and syntactically valid yet detect zero secrets. This exact silent hole has shipped live and undetected in real production repos: the config looks deliberate and protective, so nobody re-checks it.

The neutering pattern: gitleaks builds its active ruleset from (a) any [[rules]] blocks defined in the config, plus (b) its built-in default rules, but ONLY when [extend] useDefault = true is set. A config that has an [allowlist] section but NO [[rules]] blocks and NO [extend] useDefault = true loads zero rules. The allowlist then filters an already-empty result. Gitleaks runs, exits 0, reports nothing, and detects NOTHING. It looks protective. It is not.

Inspect the config:

cmd
type .gitleaks.toml

Then check for the three signals:

cmd
findstr /C:"useDefault" /C:"[extend]" /C:"[[rules]]" .gitleaks.toml

Evaluate:

  • OK (no config): No .gitleaks.toml exists at all. Gitleaks falls back to its built-in default ruleset, which detects secrets. This is safe. Note it, do not flag it.
  • OK (armed config): .gitleaks.toml exists AND has at least one of: [extend] with useDefault = true, OR one or more [[rules]] blocks. Detection is active.
  • CRITICAL GAP (NEUTERED): .gitleaks.toml exists, has content such as an [allowlist], but has NO [[rules]] block AND NO useDefault = true. Detection is silently disabled.

If NEUTERED, flag it loudly in the report and give the one-line fix. Add this block near the top of .gitleaks.toml:

toml
[extend]
useDefault = true

State plainly: until this line is added, every commit passes the secret scan because the scan has no rules to apply. This is a silent hole, not a warning.

Step 4: Verify gitleaks is installed and reachable (Check 4)

The hook scans with gitleaks when present and degrades to a weaker regex fallback when it is not. Confirm the real binary is reachable.

cmd
where gitleaks
gitleaks version

Evaluate:

  • OK if where gitleaks resolves a path AND gitleaks version prints a version.
  • GAP if gitleaks is not found. The pre-commit hook still runs and falls back to its built-in regex scan, but coverage is far weaker (a handful of patterns vs. gitleaks' full ruleset). Recommend installing it.

If there is a GAP, show install options without running them:

cmd
winget install gitleaks

or, if Scoop is in use:

cmd
scoop install gitleaks
Step 5: Report status

Produce a single status table covering all four checks, then list specific fixes for each gap. Lead with the overall verdict.

🛡️ Git-Guard Report
Repo: <repo-name>
Branch: <current-branch>

Overall: <PROTECTED / GAPS FOUND / CRITICAL GAP>

| # | Check                         | Status        | Detail                                  |
|---|-------------------------------|---------------|-----------------------------------------|
| 1 | Global pre-commit hook        | ✅ OK          | core.hooksPath set, pre-commit present  |
| 2 | .gitignore coverage           | ⚠️ GAP         | Missing: memory/, .serena/              |
| 3 | gitleaks config armed         | 🔴 CRITICAL    | NEUTERED: no rules, no useDefault       |
| 4 | gitleaks installed            | ✅ OK          | gitleaks 8.x at C:\...\gitleaks.exe     |

## Fixes
1. (Check 2) Append missing patterns to .gitignore:
   <show exact lines>
2. (Check 3) [CRITICAL] Arm gitleaks. Add to top of .gitleaks.toml:
       [extend]
       useDefault = true
   Until then, the secret scan applies zero rules and detects nothing.

## Verdict
<one or two sentences: is this repo safe to commit to right now, and what is the
single most important thing to fix>

Verdict rules:

  • CRITICAL GAP overrides everything else: if Check 3 is NEUTERED, the repo is NOT protected even if the hook is installed and gitleaks is present, and the report must say so. A neutered config is the worst case because it hides behind a passing scan.
  • GAPS FOUND if any non-critical check is a GAP.
  • PROTECTED only when all four checks are OK.

Status Levels

LevelMeaningAction
🔴 CRITICALgitleaks config is neutered: scanning is silently offAdd [extend] useDefault = true immediately
⚠️ GAPA protection layer is missing or weakenedApply the shown fix before relying on protection
✅ OKLayer present and armedNo action needed

How the Layers Fit Together

LayerRoleWhat happens if it is missing
core.hooksPath + pre-commitRuns the scan on every commit, every repoNo commit is scanned at all
.gitignoreStops obvious files (.env, memory/) being stagedSensitive files get staged and reach the scanner
.gitleaks.tomlConfigures WHAT gitleaks detectsIf neutered, the scanner detects nothing
gitleaks binaryDoes the actual deep detectionHook degrades to a weak regex fallback

Git-Guard verifies all four. gitleaks does the scanning. They are different jobs: never reach for git-guard to find secrets, and never assume an installed hook means detection is on. Check 3 is why.

  • secrets-scanner (Pro): deep secret audit, git history analysis, client-side exposure, remediation planning
  • rls-checker / rls-guardian: Supabase Row Level Security auditing and enforcement
  • api-audit: API route auth/authz review

Level History

  • Lv.1: Base installer/verifier. Four-check protocol plus a status report: global pre-commit hook (core.hooksPath), .gitignore coverage with additive append from the shipped template, gitleaks config neutering detection (the silent allowlist-only hole that has shipped live in real production repos), and gitleaks binary reachability, followed by a consolidated report with a CRITICAL-overrides verdict. (Origin: MemStack, Jun 2026)

© cwinvestments, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security/git-guard of cwinvestments/memstack.

Open the folder on GitHubat commit 00370ce

Compare with similar skills

Memstack Security Git Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Memstack Security Git Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Memstack Security Git Guard this skillcwinvestments/memstack423—~3.1kAutomated safety check: NotesMIT
Git Gh Pat AuthNEventStore/NEventStore1.6k—~828Automated safety check: PassMIT
Repo Auditzebbern/claude-code-guide4.7k—~831Automated safety check: PassMIT
Yao Workspace Git ConfigYaoApp/yao8.1k—~712Automated safety check: PassCustom licence
Leaked Secretsthedaviddias/Front-End-Checklist74k—~596Automated safety check: NotesMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone

Similar skills

  • Git Gh Pat Auth

    NEventStore/NEventStore

    A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…

    1.6k GitHub stars~828 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Repo Audit

    zebbern/claude-code-guide

    Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.

    4.7k GitHub stars~831 tokensUpdated today
    DevelopmentAuto-check passed
  • Manages Git identity, HTTPS access tokens and SSH keys at the workspace level through three `tai tool` commands, each with a get, set, list, import or delete action.

    8.1k GitHub stars~712 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Leaked Secrets

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

    74k GitHub stars~596 tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Creates backports of a merged Ansible devel pull request onto the right stable branches by cherry-picking its merge commit onto new backport branches.

    71k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed

More from cwinvestments/memstack

All 87 skills in this repo
  • Memstack SEO Site Audit

    cwinvestments/memstack

    A skill your agent uses when the user says 'SEO audit', 'site audit', 'check SEO', 'audit my site', 'SEO check', 'technical SEO', or is evaluating a website's search engine optimization health, meta…

    423 GitHub stars~3.5k tokensUpdated 11 days ago
    Auto-check passed
  • Memstack SEO Schema Markup

    cwinvestments/memstack

    A skill your agent uses when the user says 'add schema', 'schema markup', 'JSON-LD', 'structured data', 'rich results', 'rich snippets', or is adding or fixing schema.org structured data for better…

    423 GitHub stars~2.7k tokensUpdated 11 days ago
    Auto-check passed
  • Compress

    cwinvestments/memstack

    A skill your agent uses when the user says 'tokenstack', 'compression', 'token savings', 'proxy status', or asks about context window usage.

    423 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Diary

    cwinvestments/memstack

    A skill your agent uses when the user says 'save diary', 'log session', 'wrapping up', or at end of a productive session.

    423 GitHub stars~5k tokensUpdated 11 days ago
    Auto-check passed
  • Echo

    cwinvestments/memstack

    A skill your agent uses when the user references past sessions, asks 'what did we do', 'do you remember', 'last session', 'recall', or 'continue from'.

    423 GitHub stars~1.7k tokensUpdated 11 days ago
    Auto-check passed
  • Familiar

    cwinvestments/memstack

    A skill your agent uses when the user says 'dispatch', 'send familiar', 'split task', or needs work split across parallel CC sessions.

    423 GitHub stars~556 tokensUpdated 11 days ago
    Auto-check passed

Works with

Questions about Memstack Security Git Guard

What does Memstack Security Git Guard do?

A skill your agent uses when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo…. Memstack Security Git Guard is an agent skill from cwinvestments/memstack. Use when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo blocks secrets and internal files before commit.

When should I use Memstack Security Git Guard?

Memstack Security Git Guard fits situations like: the user says git-guard; check git protection; is this repo protected; verify gitleaks.

How do I install Memstack Security Git Guard in Claude Code?

Run `npx skills add cwinvestments/memstack --skill memstack-security-git-guard -a claude-code`. Or copy the skill folder (skills/security/git-guard in cwinvestments/memstack) into .claude/skills/memstack-security-git-guard in your project. Claude Code loads it when a task matches its description.

How do I install Memstack Security Git Guard in Codex?

Run `npx skills add cwinvestments/memstack --skill memstack-security-git-guard -a codex`. Or copy the skill folder (skills/security/git-guard in cwinvestments/memstack) into .agents/skills/memstack-security-git-guard in your project. Codex loads it when a task matches its description.

Can I use Memstack Security Git Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cwinvestments/memstack --skill memstack-security-git-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/memstack-security-git-guard, .gemini/skills/memstack-security-git-guard, .github/skills/memstack-security-git-guard and .opencode/skills/memstack-security-git-guard in your project.

What does Memstack Security Git Guard need to run?

Going by SKILL.md and its folder, Memstack Security Git Guard needs the command-line tools its instructions call (gitleaks, git and winget).

Does Memstack Security Git Guard access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Memstack Security Git Guard safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Memstack Security Git Guard use?

Memstack Security Git Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Memstack Security Git Guard use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Memstack Security Git Guard?

Skills that share tags, products or a category with Memstack Security Git Guard: Git Gh Pat Auth (NEventStore/NEventStore, 1.6k stars), Repo Audit (zebbern/claude-code-guide, 4.7k stars), Yao Workspace Git Config (YaoApp/yao, 8.1k stars) and Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Memstack Security Git Guard?

cwinvestments (a GitHub user) maintains it in cwinvestments/memstack, which has 423 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: cwinvestments/memstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.