Code Design Rationale Investigator
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install heptameta/heptabase-cli-skills public-repo-guard --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/public-repo-guard .claude/skills/public-repo-guard && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "public-repo-guard" agent skill from https://github.com/heptameta/heptabase-cli-skills/tree/main/.claude/skills/public-repo-guard into .claude/skills/public-repo-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "public-repo-guard", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/heptameta/heptabase-cli-skills/tree/main/.claude/skills/public-repo-guardType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install heptameta/heptabase-cli-skills public-repo-guard --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/public-repo-guard .agents/skills/public-repo-guard && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "public-repo-guard" agent skill from https://github.com/heptameta/heptabase-cli-skills/tree/main/.claude/skills/public-repo-guard into .agents/skills/public-repo-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "public-repo-guard", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install heptameta/heptabase-cli-skills public-repo-guard --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/public-repo-guard .cursor/skills/public-repo-guard && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "public-repo-guard" agent skill from https://github.com/heptameta/heptabase-cli-skills/tree/main/.claude/skills/public-repo-guard into .cursor/skills/public-repo-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "public-repo-guard", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/heptameta/heptabase-cli-skills.git --path .claude/skills/public-repo-guard--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install heptameta/heptabase-cli-skills public-repo-guard --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/public-repo-guard .gemini/skills/public-repo-guard && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "public-repo-guard" agent skill from https://github.com/heptameta/heptabase-cli-skills/tree/main/.claude/skills/public-repo-guard into .gemini/skills/public-repo-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "public-repo-guard", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install heptameta/heptabase-cli-skills public-repo-guardInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/public-repo-guard .github/skills/public-repo-guard && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "public-repo-guard" agent skill from https://github.com/heptameta/heptabase-cli-skills/tree/main/.claude/skills/public-repo-guard into .github/skills/public-repo-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "public-repo-guard", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install heptameta/heptabase-cli-skills public-repo-guard --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/heptameta/heptabase-cli-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/public-repo-guard .opencode/skills/public-repo-guard && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "public-repo-guard" agent skill from https://github.com/heptameta/heptabase-cli-skills/tree/main/.claude/skills/public-repo-guard into .opencode/skills/public-repo-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "public-repo-guard", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
public-repo-guardThis repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history.
Public Repo Guard is an agent skill from heptameta/heptabase-cli-skills. This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history. Use before EVERY commit, push, PR, or release here, and whenever adding or editing docs, skills, scripts, or examples in this repo. Scans staged changes for sensitive or internal data — credentials, tokens, private keys, emails, personal home paths, internal workspace URLs (Notion, Slack, Discord, Linear), real card/workspace UUIDs, IP addresses, secret-bearing filenames — and explains how to…
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts.
It sits in Development, covering Git workflow. It works with Discord, Slack and Notion. The repository describes itself as: Agent skills for Heptabase CLI. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b5fb23f. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(node *)Bash(git diff *)Bash(git status *)Bash(git ls-files *)From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
gitnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Public Repo Guard loads about 1.2k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 512 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
es (catches `.env`, `.envrc`, `*.pem`, `id_rsa`, etc. even when their content evades patterns).Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from heptameta/heptabase-cli-skills at commit b5fb23f, republished under its MIT licence (© heptameta). 512 words, ~1,191 tokens.
.claude/skills/public-repo-guard/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Everything in this repo ships to the world twice: it is a public GitHub repo, AND the whole repo is installed onto users' machines as a plugin. A leaked secret or internal detail is permanent — git history survives force-pushes in forks, caches, and mirrors. Prevention is the only cheap moment to act.
/Users/<name>/... (they leak usernames), real names of non-maintainers.app.heptabase.com placeholder patterns are fine.<cardId>, <workspaceId>.node .claude/skills/public-repo-guard/scripts/scan-sensitive.mjs --staged<your-token>, <cardId>), or move it to private notes. Never "temporarily" commit it.public-ok marker comment to that line and say why in the PR. The scanner skips marked lines.node .claude/skills/public-repo-guard/scripts/scan-sensitive.mjs --allgit diff --cached) — not just the scan output.scripts/scan-sensitive.mjs [--staged | --all | <paths...>]
--staged (default): scans only lines being ADDED by the staged diff, plus staged filenames (catches .env, .envrc, *.pem, id_rsa, etc. even when their content evades patterns).--all: scans all tracked and untracked-but-not-ignored files. Use before releases.<paths...>: scans the given files fully. Use for reviewing a single doc.example.com / noreply@ / users.noreply.github.com emails, git@… SSH clone URLs, loopback/any IPs (127.0.0.1, 0.0.0.0, …), synthetic repeated-digit UUID placeholders (11111111-1111-4111-…), and lines carrying the public-ok marker.Install once per clone (hooks are local, never committed):
node .claude/skills/public-repo-guard/scripts/install-git-hook.mjsEvery git commit (including via gt/Graphite) then runs the staged scan and blocks on findings. Bypassing with git commit --no-verify should be a deliberate, explained exception — if you bypass, say so in the PR description so a reviewer double-checks.
git filter-repo + force-push) breaks clones and installed plugin caches — coordinate before attempting, and remember public forks/mirrors may retain the data anyway.© heptameta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in .claude/skills/public-repo-guard of heptameta/heptabase-cli-skills.
Open the folder on GitHubat commit b5fb23f
Public Repo Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Public Repo Guard this skillheptameta/heptabase-cli-skills | 155 | — | ~1.2k | Automated safety check: Warn | MIT | |
| Code Design Rationale Investigatorcursor/plugins | 11k | 9 repos | ~2.2k | Automated safety check: Pass | None | |
| External Electron App Automationcashew-labs/libretto | 904 | — | ~967 | Automated safety check: Pass | MIT | |
| Ops Inboxdavepoon/buildwithclaude | 3.6k | — | ~7.2k | Automated safety check: Notes | MIT | |
| Loop Rungetlago/lago-front | 163 | — | ~3.3k | Automated safety check: Pass | AGPL-3.0 | |
| Community Buildingmanojbajaj95/claude-gtm-plugin | 105 | — | ~4.5k | Automated safety check: Pass | MIT |
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
cashew-labs/libretto
Drives desktop Electron apps already installed on your machine, such as Slack, Discord or VS Code, by relaunching them with a debugging port and using the Libretto CLI.
davepoon/buildwithclaude
Full inbox management across all channels — WhatsApp (wacli), Email (Gmail MCP), Slack (MCP), Telegram (user-auth MCP), Discord (webhook + REST read), Notion (MCP — comments, mentions, assigned…
getlago/lago-front
Orchestrator of the loop pipeline for lago-front: sweep → spec → build ↔ review → ship (commit, PR, Linear, CI gate, Slack frontend).
manojbajaj95/claude-gtm-plugin
Build and grow online communities across all platforms and contexts — from developer/B2B communities (Discord, Slack, Circle, Discourse) to social communities (Twitter/X, Reddit, Farcaster) to…
rlaope/oh-my-hermes
[omh] Email, Slack, or Jira action to perform: external app actions - email, Slack, Discord, Notion, Linear, Jira, CRM, and similar providers, scoped with auth, payload, confirmation, and…
heptameta/heptabase-cli-skills
Maintain Agent Skills in a Heptabase repository across Claude Code, Codex, and Cursor.
heptameta/heptabase-cli-skills
Release a new version of heptabase-cli-skills, the public Agent Skills plugin package for the Heptabase CLI.
heptameta/heptabase-cli-skills
Use the local heptabase CLI whenever the user mentions Heptabase or shares an app.heptabase.com URL/deep link.
Categories
This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history. Public Repo Guard is an agent skill from heptameta/heptabase-cli-skills. This repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history.
Public Repo Guard fits situations like: asked to review any content in this repo for public sharing; tasks that involve Git workflow.
Run `npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a claude-code`. Or copy the skill folder (.claude/skills/public-repo-guard in heptameta/heptabase-cli-skills) into .claude/skills/public-repo-guard in your project. Claude Code loads it when a task matches its description.
Run `npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a codex`. Or copy the skill folder (.claude/skills/public-repo-guard in heptameta/heptabase-cli-skills) into .agents/skills/public-repo-guard in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add heptameta/heptabase-cli-skills --skill public-repo-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/public-repo-guard, .gemini/skills/public-repo-guard, .github/skills/public-repo-guard and .opencode/skills/public-repo-guard in your project.
Going by SKILL.md and its folder, Public Repo Guard needs JavaScript for the scripts in its folder and the command-line tools its instructions call (git and node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(node *), Bash(git diff *), Bash(git status *), Bash(git ls-files *).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Public Repo Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Public Repo Guard: Code Design Rationale Investigator (cursor/plugins, 11k stars), External Electron App Automation (cashew-labs/libretto, 904 stars), Ops Inbox (davepoon/buildwithclaude, 3.6k stars) and Loop Run (getlago/lago-front, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
heptameta (a GitHub organization) maintains it in heptameta/heptabase-cli-skills, which has 155 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.
Source: heptameta/heptabase-cli-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.