Agent skill

Keeping Git Repos Clean

by kajisho5 in kajisho5/ffmpeg-skill

Prevents, detects, and remediates files that should never be committed — secrets (.env, API tokens, hardcoded credentials) and dev artifacts (build output, scratch databases, editor/OS files).

MITAuto-check: notesDevelopment

Install Keeping Git Repos Clean

skills CLI
$ npx skills add kajisho5/ffmpeg-skill --skill keeping-git-repos-clean -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kajisho5/ffmpeg-skill keeping-git-repos-clean --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/git-hygiene .claude/skills/keeping-git-repos-clean && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
keeping-git-repos-clean
GitHub stars
1.9k
Token cost
~2.1k tokens
SKILL.md length
783 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Prevents, detects, and remediates files that should never be committed — secrets (.env, API tokens, hardcoded credentials) and dev artifacts (build output, scratch databases, editor/OS files).

  • Works in 3 steps: Rotate the credential. Treat any secret… → Untrack going forward (git rm --cached +… → Scrub history if required (git…
  • A repo has committed secrets
  • SKILL.md covers The one rule everyone forgets, Audit what a repo actually…, Secrets need more than git rm and "Committed" means "published", plus 4 more sections
  • Calls git, make and rsync; reaches github.com; needs SECRET_KEY

What it does

Keeping Git Repos Clean is an agent skill from kajisho5/ffmpeg-skill. Prevents, detects, and remediates files that should never be committed — secrets (.env, API tokens, hardcoded credentials) and dev artifacts (build output, scratch databases, editor/OS files). Covers .gitignore (and why it does not untrack), git rm --cached, auditing tracked files, history scrubbing, and credential rotation. Use when a repo has committed secrets or junk, when setting up a new repo's ignore rules, or when reviewing what a repo actually tracks.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Git workflow. It works with Git. The licence is MIT.

When your agent uses it

  • A repo has committed secrets
  • Setting up a new repos ignore rules
  • Reviewing what a repo actually tracks

Example prompts

  • “/keeping-git-repos-clean”

Requirements

  • Python 3
  • A credential in SECRET_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Rotate the credential. Treat any secret that ever touched a remote as
  2. Untrack going forward (git rm --cached + .gitignore + .env.example
  3. Scrub history if required (git filter-repo --invert-paths --path .env,

What it can do on your machine

Read from SKILL.md and the folder at commit 1f7e7e3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • make
    • rsync
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Keeping Git Repos Clean loads about 2.1k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 783 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    hat should never be committed — secrets (.env, API tokens, hardcoded credentials) and dev artifacts (build output, scrat
  • NoteMentions a .env fileSKILL.md:17
    a `.env` is listed in `.gitignore` but was committed before the rule existed, so
  • NoteMentions a .env fileSKILL.md:44
    - **Secrets:** `.env` with a live token, hardcoded `AWS_*`/DB creds in a settings
  • NoteMentions a .env fileSKILL.md:64
    (`git filter-repo --invert-paths --path .env`,
  • NoteMentions a .env fileSKILL.md:107
    .env
  • NoteMentions a .env fileSKILL.md:108
    .env.*
  • NoteMentions a .env fileSKILL.md:183
    No live credentials in tracked source or .env
  • NoteMentions a .env fileSKILL.md:212
    are no secrets or `.env`-shaped files in this repo (no cloud/API keys by

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kajisho5/ffmpeg-skill at commit 1f7e7e3, republished under its MIT licence (© kajisho5). 783 words, ~2,122 tokens.

Download SKILL.mdSave it as .claude/skills/keeping-git-repos-clean/SKILL.md (or your agent's skills folder).
name
keeping-git-repos-clean
description
Prevents, detects, and remediates files that should never be committed — secrets (.env, API tokens, hardcoded credentials) and dev artifacts (build output, scratch databases, editor/OS files). Covers .gitignore (and why it does not untrack), git rm --cached, auditing tracked files, history scrubbing, and credential rotation. Use when a repo has committed secrets or junk, when setting up a new repo's ignore rules, or when reviewing what a repo actually tracks.

Keeping Git Repos Clean

Two classes of files keep ending up in repos: secrets and dev artifacts. Both are cheap to prevent and expensive to clean up after the fact, because git history is forever and public repos publish everything.

The one rule everyone forgets

.gitignore does NOT untrack files that are already committed. Adding a path to .gitignore only prevents future untracked files from being staged. A file git is already tracking keeps getting committed regardless. This bites repeatedly: a .env is listed in .gitignore but was committed before the rule existed, so it keeps shipping.

To actually stop tracking a file while keeping your local copy:

bash
git rm --cached path/to/file        # untrack, leave working-tree copy in place
git rm -r --cached some/dir/        # for a directory
echo "path/to/file" >> .gitignore   # then ignore it so it doesn't come back
git commit -m "Stop tracking <file>; add to .gitignore"

--cached is the important flag — plain git rm deletes the working copy too.

Audit what a repo actually tracks

Don't trust .gitignore to tell you what's clean — read the index directly:

bash
git ls-files | grep -iE '\.(env|pem|key|p12|profraw|log|bak|db|sqlite3?)$'
git ls-files | grep -iE '(^|/)(\.DS_Store|~\$|todo\.db|node_modules/|__pycache__/)'
git ls-files '*.db' '*.sqlite*'                 # scratch databases
git ls-files | xargs -I{} du -h {} | sort -rh | head   # surprisingly large tracked files

Usual suspects seen across real repos:

  • Secrets: .env with a live token, hardcoded AWS_*/DB creds in a settings module, SECRET_KEY = "CHANGEME"/"foobar" placeholders shipped to prod.
  • Build artifacts: LaTeX .aux/.toc/.log/.synctex.gz/.pdf, LLVM *.profraw, compiled binaries, htmlcov/, dist/, *.egg-info/.
  • Scratch / personal artifacts: todo.db and other tool-local SQLite scratch DBs, editor backups (*.backup, *.bak, ~$*.docx Word lock files), stray *.log.
  • OS noise: .DS_Store, Thumbs.db.

Secrets need more than git rm

Removing a secret from HEAD does not remove it from history — git log -p and the commit that introduced it still expose it. Three things must happen, in order, and the first is the only one that actually protects you:

  1. Rotate the credential. Treat any secret that ever touched a remote as compromised. Issue a new token/key/password and revoke the old one. Do this first — the leaked value is public the moment it was pushed.
  2. Untrack going forward (git rm --cached + .gitignore + .env.example documenting which vars are needed, with placeholder values only).
  3. Scrub history if required (git filter-repo --invert-paths --path .env, or BFG) and force-push. This rewrites SHAs and disrupts collaborators, so it's usually a deliberate maintainer step done after rotation — not an automated PR.

A PR that does (2) and (3) but skips (1) gives false comfort: the value is still valid and still in history clones/forks. Always call out rotation as the required human follow-up.

"Committed" means "published"

For public repos — and especially static sites deployed with path: '.' (GitHub Pages uploads the entire repo) — every tracked file is fetchable at a public URL. A scratch todo.db at the repo root of a brochure site is served at /todo.db. Before committing to any public repo, assume anyone can download it.

Prevent it: global ignore + a secret scanner

Per-developer noise (editor files, OS files, tool scratch DBs like todo.db) should be ignored globally, not in every project's .gitignore — that way it never lands anywhere:

bash
git config --global core.excludesFile ~/.gitignore_global
printf '%s\n' '.DS_Store' '*.swp' 'todo.db' '*.profraw' >> ~/.gitignore_global

Block secrets at commit time with a pre-commit hook so they never reach history:

yaml
# .pre-commit-config.yaml
repos:
  - repo: https://github.com/gitleaks/gitleaks
    rev: v8.18.0
    hooks: [{id: gitleaks}]
  - repo: https://github.com/Yelp/detect-secrets
    rev: v1.5.0
    hooks: [{id: detect-secrets, args: ["--baseline", ".secrets.baseline"]}]

A starter project .gitignore (commit this):

gitignore
# Secrets / local config
.env
.env.*
!.env.example
*.pem
*.key

# Python build/test artifacts
__pycache__/
*.py[cod]
build/
dist/
*.egg-info/
.coverage
htmlcov/
.pytest_cache/

# Scratch / OS / editor
*.db
*.sqlite
*.sqlite3
*.profraw
*.log
*.bak
*.backup
.DS_Store
~$*
Show full SKILL.md (311 more words)Show less

Verification can dirty the tree

Compilers, test runners, and asset pipelines often write into the checkout even when the command is only meant to verify a change. They may create unignored cache files or regenerate a tracked distributable such as a PDF or compiled CSS. A green command does not mean the working tree still contains only your change.

Bracket verification with status checks and stage only reviewed paths:

bash
git status --short
make test                         # or the project's real build command
git status --short
git diff -- path/you/changed
git add path/you/changed          # never sweep in generated files with git add -A
git diff --cached --check
git diff --cached --stat

If a tool necessarily produces noisy output, run it in a disposable copy of the checkout. This preserves a real build while keeping generated files away from the patch:

bash
scratch_dir=$(mktemp -d)
rsync -a --exclude .git ./ "$scratch_dir/"
(cd "$scratch_dir" && make build)

When verification modifies a tracked generated output that is intentionally out of scope, restore that exact path only after reviewing its diff:

bash
git diff -- docs/manual.pdf
git restore -- docs/manual.pdf

Do not use a broad restore/reset to clean up: the checkout may already contain someone else's work. Also do not rely on git stash as cleanup for untracked artifacts; ordinary stashes omit them, and even --include-untracked can collide with files regenerated before stash pop. Prevent or remove known generated paths explicitly instead.

Checklist

Audit:
- [ ] `git ls-files` reviewed for secrets, build output, scratch DBs, OS files
- [ ] No live credentials in tracked source or .env
- [ ] No surprisingly large/binary tracked files

Remediate (if dirty):
- [ ] Secret rotated/revoked FIRST (history is public the moment it was pushed)
- [ ] `git rm --cached` + .gitignore entry for each offending file
- [ ] .env.example documents required vars with placeholder values only
- [ ] History scrub flagged as a maintainer follow-up if the secret is in history

Prevent:
- [ ] Project .gitignore covers secrets, build artifacts, OS/editor noise
- [ ] Global core.excludesFile catches per-developer scratch files
- [ ] gitleaks / detect-secrets pre-commit hook installed
- [ ] Verification bracketed by `git status --short`; only reviewed paths staged

For scanning source code for vulnerabilities and hardcoded-secret patterns rather than what git tracks, use the /security-review skill already available in this session.

Note for this repository (ffmpeg-skill)

.gitignore already covers __pycache__/, and package.json's "files" list is the actual publish gate — but this session hit exactly the "verification can dirty the tree" case: running python3 scripts/proxy.py and the test suites locally created __pycache__/*.pyc files that then showed up in an npm publish --dry-run listing before they were deleted. The git status --short bracket-and-check habit above (or, cheaper here, just re-running the dry-run after deleting stray __pycache__/ directories) is the concrete fix. There are no secrets or .env-shaped files in this repo (no cloud/API keys by design), so the credential-rotation half of this skill does not currently apply — the dev-artifact half is the one worth watching.

Source: wdm0006/python-skills (MIT).

© kajisho5, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/git-hygiene of kajisho5/ffmpeg-skill.

Open the folder on GitHubat commit 1f7e7e3

Compare with similar skills

Keeping Git Repos Clean next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Keeping Git Repos Clean compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Keeping Git Repos Clean this skillkajisho5/ffmpeg-skill1.9k—~2.1kAutomated safety check: NotesMIT
Update DocsArcReel/ArcReel5.4k—~544Automated safety check: NotesAGPL-3.0
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins11k9 repos~2.6kAutomated safety check: PassNone
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost56k—~3.8kAutomated safety check: PassMIT

Similar skills

  • Update Docs

    ArcReel/ArcReel

    根据最近的 git 改动,更新面向用户的文档(README 双语、入门教程、部署、剪映导出等)。手动调用. An agent skill from ArcReel/ArcReel.

    5.4k GitHub stars~544 tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    11k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    56k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed

More from kajisho5/ffmpeg-skill

All 14 skills in this repo
  • Ffmpeg Skill

    kajisho5/ffmpeg-skill

    Edit video and audio with local FFmpeg from natural-language requests: cut, trim, join, resize/reframe (9:16, 1:1), speed change, captions and subtitles (SRT/ASS, animated, karaoke), logos and text…

    1.9k GitHub stars~7.4k tokensUpdated today
    Auto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Reviewing Ffmpeg Skill Changes

    kajisho5/ffmpeg-skill

    Review a change to the ffmpeg-skill repository for the failures its own contract makes possible — a claim in a result document that is true at one layer and false at the layer a caller reads, a new…

    1.9k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Building Python MCP Servers

    kajisho5/ffmpeg-skill

    Builds robust Python MCP (Model Context Protocol) servers with FastMCP — tool design, error contracts, event-loop-safe blocking work, subprocess/CLI wrapping, single-file vs packaged distribution…

    1.9k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Concurrent Branches

    kajisho5/ffmpeg-skill

    Resolve conflicts and merges when several branches are open against one repo at the same time — the hotspot files every change must touch (registry manifests, a single version field, shared tool…

    1.9k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Guarding Destructive Operations

    kajisho5/ffmpeg-skill

    Add and review preconditions on operations that delete, overwrite, rewrite history, or resolve a caller-supplied name to a filesystem path — refusing instead of warning, placing the guard ahead of…

    1.9k GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Keeping Git Repos Clean

What does Keeping Git Repos Clean do?

Prevents, detects, and remediates files that should never be committed — secrets (.env, API tokens, hardcoded credentials) and dev artifacts (build output, scratch databases, editor/OS files). Keeping Git Repos Clean is an agent skill from kajisho5/ffmpeg-skill.env, API tokens, hardcoded credentials) and dev artifacts (build output, scratch databases, editor/OS files).

When should I use Keeping Git Repos Clean?

Keeping Git Repos Clean fits situations like: A repo has committed secrets; setting up a new repos ignore rules; reviewing what a repo actually tracks.

How do I install Keeping Git Repos Clean in Claude Code?

Run `npx skills add kajisho5/ffmpeg-skill --skill keeping-git-repos-clean -a claude-code`. Or copy the skill folder (.claude/skills/git-hygiene in kajisho5/ffmpeg-skill) into .claude/skills/keeping-git-repos-clean in your project. Claude Code loads it when a task matches its description.

How do I install Keeping Git Repos Clean in Codex?

Run `npx skills add kajisho5/ffmpeg-skill --skill keeping-git-repos-clean -a codex`. Or copy the skill folder (.claude/skills/git-hygiene in kajisho5/ffmpeg-skill) into .agents/skills/keeping-git-repos-clean in your project. Codex loads it when a task matches its description.

Can I use Keeping Git Repos Clean in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kajisho5/ffmpeg-skill --skill keeping-git-repos-clean -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/keeping-git-repos-clean, .gemini/skills/keeping-git-repos-clean, .github/skills/keeping-git-repos-clean and .opencode/skills/keeping-git-repos-clean in your project.

What does Keeping Git Repos Clean need to run?

Going by SKILL.md and its folder, Keeping Git Repos Clean needs the command-line tools its instructions call (git, make, rsync and python3) and credentials named SECRET_KEY. Our summary lists: Python 3; A credential in SECRET_KEY.

Does Keeping Git Repos Clean access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Keeping Git Repos Clean safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Keeping Git Repos Clean use?

Keeping Git Repos Clean is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Keeping Git Repos Clean use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Keeping Git Repos Clean?

Skills that share tags, products or a category with Keeping Git Repos Clean: Update Docs (ArcReel/ArcReel, 5.4k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Code Design Rationale Investigator (cursor/plugins, 11k stars) and Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Keeping Git Repos Clean?

kajisho5 (a GitHub user) maintains it in kajisho5/ffmpeg-skill, which has 1,909 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: kajisho5/ffmpeg-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.