Agent skill

Public Repo Guard

by heptameta in heptameta/heptabase-cli-skills

This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history.

MITAuto-check: warningsDevelopment

Install Public Repo Guard

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install heptameta/heptabase-cli-skills public-repo-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/public-repo-guard .claude/skills/public-repo-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
public-repo-guard
GitHub stars
155
Token cost
~1.2k tokens
SKILL.md length
512 words
Files
3 (incl. scripts)
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history.

  • Works in 4 steps: Before every commit, scan the staged… → Judge each finding — the scanner errs… → Before a release or when auditing, scan… → …
  • Asked to review any content in this repo for public sharing
  • SKILL.md covers What counts as sensitive here, Workflow, Scanner reference and Hard enforcement: git…, plus 1 more section
  • Runs JavaScript scripts from its folder; calls git and node

What it does

Public Repo Guard is an agent skill from heptameta/heptabase-cli-skills. This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history. Use before EVERY commit, push, PR, or release here, and whenever adding or editing docs, skills, scripts, or examples in this repo. Scans staged changes for sensitive or internal data — credentials, tokens, private keys, emails, personal home paths, internal workspace URLs (Notion, Slack, Discord, Linear), real card/workspace UUIDs, IP addresses, secret-bearing filenames — and explains how to…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts.

It sits in Development, covering Git workflow. It works with Discord, Slack and Notion. The repository describes itself as: Agent skills for Heptabase CLI. The licence is MIT.

When your agent uses it

  • Asked to review any content in this repo for public sharing
  • Tasks that involve Git workflow

Example prompts

  • “/public-repo-guard”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(node *), Bash(git diff *), Bash(git status *), Bash(git ls-files *)

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Before every commit, scan the staged changes (this is also what the pre-commit hook runs)
  2. Judge each finding — the scanner errs toward flagging; a finding is a question, not a verdict
  3. Before a release or when auditing, scan every tracked + untracked file
  4. The scanner is a net, not a guarantee. It only knows patterns. Also apply judgment to things regex cannot see: screenshots, real user data…

What it can do on your machine

Read from SKILL.md and the folder at commit b5fb23f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(node *)
    • Bash(git diff *)
    • Bash(git status *)
    • Bash(git ls-files *)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Public Repo Guard loads about 1.2k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 512 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~158
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:40
    es (catches `.env`, `.envrc`, `*.pem`, `id_rsa`, etc. even when their content evades patterns).

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from heptameta/heptabase-cli-skills at commit b5fb23f, republished under its MIT licence (© heptameta). 512 words, ~1,191 tokens.

Download SKILL.mdSave it as .claude/skills/public-repo-guard/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
public-repo-guard
description
This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history. Use before EVERY commit, push, PR, or release here, and whenever adding or editing docs, skills, scripts, or examples in this repo. Scans staged changes for sensitive or internal data — credentials, tokens, private keys, emails, personal home paths, internal workspace URLs (Notion, Slack, Discord, Linear), real card/workspace UUIDs, IP addresses, secret-bearing filenames — and explains how to judge and fix findings. Also use when asked to review any content in this repo for public sharing.
allowed-tools
Bash(node *), Bash(git diff *), Bash(git status *), Bash(git ls-files *)
metadata.internal
true

Public-repo guard

Everything in this repo ships to the world twice: it is a public GitHub repo, AND the whole repo is installed onto users' machines as a plugin. A leaked secret or internal detail is permanent — git history survives force-pushes in forks, caches, and mirrors. Prevention is the only cheap moment to act.

What counts as sensitive here

  • Credentials of any kind: API keys, tokens, private keys, passwords — including "test" or "expired" ones (they reveal naming schemes and invite confusion).
  • Personal / employee data: email addresses, personal home paths like /Users/<name>/... (they leak usernames), real names of non-maintainers.
  • Internal workspace links: Notion pages, Slack archives, Discord channels, Linear issues, Google Docs, Datadog dashboards. Public GitHub links and app.heptabase.com placeholder patterns are fine.
  • Real identifiers: actual card/workspace/chat UUIDs from anyone's Heptabase data. Docs must use placeholders like <cardId>, <workspaceId>.
  • Infrastructure details: non-loopback IPs, internal hostnames, unreleased product details.

Workflow

  1. Before every commit, scan the staged changes (this is also what the pre-commit hook runs):
    bash
    node .claude/skills/public-repo-guard/scripts/scan-sensitive.mjs --staged
  2. Judge each finding — the scanner errs toward flagging; a finding is a question, not a verdict:
    • Real sensitive data → remove it, replace with a placeholder (<your-token>, <cardId>), or move it to private notes. Never "temporarily" commit it.
    • False positive (e.g. a deliberate documentation example) → append a public-ok marker comment to that line and say why in the PR. The scanner skips marked lines.
  3. Before a release or when auditing, scan every tracked + untracked file:
    bash
    node .claude/skills/public-repo-guard/scripts/scan-sensitive.mjs --all
  4. The scanner is a net, not a guarantee. It only knows patterns. Also apply judgment to things regex cannot see: screenshots, real user data or support-conversation excerpts, names/handles of people who did not consent, anything you would not put in a tweet. When reviewing, read the actual diff (git diff --cached) — not just the scan output.
Show full SKILL.md (215 more words)Show less

Scanner reference

scripts/scan-sensitive.mjs [--staged | --all | <paths...>]

  • --staged (default): scans only lines being ADDED by the staged diff, plus staged filenames (catches .env, .envrc, *.pem, id_rsa, etc. even when their content evades patterns).
  • --all: scans all tracked and untracked-but-not-ignored files. Use before releases.
  • <paths...>: scans the given files fully. Use for reviewing a single doc.
  • Exit code 0 = clean, 1 = findings to judge, 2 = usage error. Credential-like matches are printed masked so secrets don't end up in terminal logs.
  • Built-in allowances: example.com / noreply@ / users.noreply.github.com emails, git@… SSH clone URLs, loopback/any IPs (127.0.0.1, 0.0.0.0, …), synthetic repeated-digit UUID placeholders (11111111-1111-4111-…), and lines carrying the public-ok marker.

Hard enforcement: git pre-commit hook

Install once per clone (hooks are local, never committed):

bash
node .claude/skills/public-repo-guard/scripts/install-git-hook.mjs

Every git commit (including via gt/Graphite) then runs the staged scan and blocks on findings. Bypassing with git commit --no-verify should be a deliberate, explained exception — if you bypass, say so in the PR description so a reviewer double-checks.

If something sensitive already got committed

  1. Treat any leaked credential as compromised the moment it is pushed: rotate/revoke it first — history cleanup is NOT mitigation.
  2. MUST tell the maintainer IMMEDIATELY.
  3. Removing it from history (BFG / git filter-repo + force-push) breaks clones and installed plugin caches — coordinate before attempting, and remember public forks/mirrors may retain the data anyway.

© heptameta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .claude/skills/public-repo-guard of heptameta/heptabase-cli-skills.

  • SKILL.md
  • scripts/install-git-hook.mjs
  • scripts/scan-sensitive.mjs

Open the folder on GitHubat commit b5fb23f

Compare with similar skills

Public Repo Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Public Repo Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Public Repo Guard this skillheptameta/heptabase-cli-skills155—~1.2kAutomated safety check: WarnMIT
Code Design Rationale Investigatorcursor/plugins11k9 repos~2.2kAutomated safety check: PassNone
External Electron App Automationcashew-labs/libretto904—~967Automated safety check: PassMIT
Ops Inboxdavepoon/buildwithclaude3.6k—~7.2kAutomated safety check: NotesMIT
Loop Rungetlago/lago-front163—~3.3kAutomated safety check: PassAGPL-3.0
Community Buildingmanojbajaj95/claude-gtm-plugin105—~4.5kAutomated safety check: PassMIT

Similar skills

  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    11k GitHub starsUsed in 9 repos~2.2k tokens
    DevelopmentAuto-check passed
  • Drives desktop Electron apps already installed on your machine, such as Slack, Discord or VS Code, by relaunching them with a debugging port and using the Libretto CLI.

    904 GitHub stars~967 tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Ops Inbox

    davepoon/buildwithclaude

    Full inbox management across all channels — WhatsApp (wacli), Email (Gmail MCP), Slack (MCP), Telegram (user-auth MCP), Discord (webhook + REST read), Notion (MCP — comments, mentions, assigned…

    3.6k GitHub stars~7.2k tokensUpdated 2 days ago
    Productivity & AutomationAuto-check: notes
  • Loop Run

    getlago/lago-front

    Orchestrator of the loop pipeline for lago-front: sweep → spec → build ↔ review → ship (commit, PR, Linear, CI gate, Slack frontend).

    163 GitHub stars~3.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Community Building

    manojbajaj95/claude-gtm-plugin

    Build and grow online communities across all platforms and contexts — from developer/B2B communities (Discord, Slack, Circle, Discourse) to social communities (Twitter/X, Reddit, Farcaster) to…

    105 GitHub stars~4.5k tokensUpdated 23 days ago
    DevelopmentAuto-check passed
  • Omh Apps

    rlaope/oh-my-hermes

    [omh] Email, Slack, or Jira action to perform: external app actions - email, Slack, Discord, Notion, Linear, Jira, CRM, and similar providers, scoped with auth, payload, confirmation, and…

    3.2k GitHub stars~1.9k tokensUpdated yesterday
    Sales & SupportAuto-check passed

More from heptameta/heptabase-cli-skills

  • Maintain Skills

    heptameta/heptabase-cli-skills

    Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor.

    155 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check passed
  • Release

    heptameta/heptabase-cli-skills

    Release a new version of heptabase-cli-skills, the public Agent Skills plugin package for the Heptabase CLI.

    155 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Heptabase CLI

    heptameta/heptabase-cli-skills

    Use the local heptabase CLI whenever the user mentions Heptabase or shares an app.heptabase.com URL/deep link.

    155 GitHub stars~3.1k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Public Repo Guard

What does Public Repo Guard do?

This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history. Public Repo Guard is an agent skill from heptameta/heptabase-cli-skills. This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history.

When should I use Public Repo Guard?

Public Repo Guard fits situations like: asked to review any content in this repo for public sharing; tasks that involve Git workflow.

How do I install Public Repo Guard in Claude Code?

Run `npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a claude-code`. Or copy the skill folder (.claude/skills/public-repo-guard in heptameta/heptabase-cli-skills) into .claude/skills/public-repo-guard in your project. Claude Code loads it when a task matches its description.

How do I install Public Repo Guard in Codex?

Run `npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a codex`. Or copy the skill folder (.claude/skills/public-repo-guard in heptameta/heptabase-cli-skills) into .agents/skills/public-repo-guard in your project. Codex loads it when a task matches its description.

Can I use Public Repo Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/public-repo-guard, .gemini/skills/public-repo-guard, .github/skills/public-repo-guard and .opencode/skills/public-repo-guard in your project.

What does Public Repo Guard need to run?

Going by SKILL.md and its folder, Public Repo Guard needs JavaScript for the scripts in its folder and the command-line tools its instructions call (git and node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(node *), Bash(git diff *), Bash(git status *), Bash(git ls-files *).

Does Public Repo Guard access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Public Repo Guard safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Public Repo Guard use?

Public Repo Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Public Repo Guard use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Public Repo Guard?

Skills that share tags, products or a category with Public Repo Guard: Code Design Rationale Investigator (cursor/plugins, 11k stars), External Electron App Automation (cashew-labs/libretto, 904 stars), Ops Inbox (davepoon/buildwithclaude, 3.6k stars) and Loop Run (getlago/lago-front, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Public Repo Guard?

heptameta (a GitHub organization) maintains it in heptameta/heptabase-cli-skills, which has 155 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: heptameta/heptabase-cli-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.