Agent skill

Insecure Source Code Management

by langbyyi in langbyyi/CyberStrikeAI-SRC

Source control and artifact exposure (.git, .svn, .hg, backups, .env).

Apache-2.0Auto-check: notesDevOps & Cloud

Install Insecure Source Code Management

skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbyyi/CyberStrikeAI-SRC insecure-source-code-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/insecure-source-code-management .claude/skills/insecure-source-code-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
insecure-source-code-management
GitHub stars
134
Used in
1 other repo
Token cost
~1.3k tokens
SKILL.md length
472 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Source control and artifact exposure (.git, .svn, .hg, backups, .env).

  • Works in 7 steps: QUICK START → GIT EXPOSURE → SVN EXPOSURE → …
  • Recon finds VCS paths
  • SKILL.md covers 0. QUICK START, 1. GIT EXPOSURE, 2. SVN EXPOSURE and 3. MERCURIAL EXPOSURE, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Insecure Source Code Management is an agent skill from langbyyi/CyberStrikeAI-SRC. Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Backup and disaster recovery and Git workflow. It works with Git. The licence is Apache-2.0.

When your agent uses it

  • Recon finds VCS paths
  • 403 on hidden dirs
  • Backup/config leaks during authorized testing

Example prompts

  • “/insecure-source-code-management”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. QUICK START
  2. GIT EXPOSURE
  3. SVN EXPOSURE
  4. MERCURIAL EXPOSURE
  5. OTHER LEAKS
  6. DECISION TREE
  7. RELATED ROUTING

What it can do on your machine

Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Insecure Source Code Management loads about 1.3k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 472 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:4
    fact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config lea
  • NoteMentions a .env fileSKILL.md:23
    /.env
  • NoteMentions a .env fileSKILL.md:129
    /.env
  • NoteMentions a .env fileSKILL.md:151
    *Parallel**: fetch **`/.DS_Store`**, **`/.env`**, common **backup extensions** on app root and parent paths.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 472 words, ~1,273 tokens.

Download SKILL.mdSave it as .claude/skills/insecure-source-code-management/SKILL.md (or your agent's skills folder).
name
insecure-source-code-management
description
Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.

SKILL: Insecure Source Code Management

AI LOAD INSTRUCTION: This skill covers detection and recovery of exposed version-control metadata, common backup artifacts, and related misconfigurations. Use only in authorized assessments. Treat recovered credentials and URLs as sensitive; do not exfiltrate real data beyond scope. For broad discovery workflow, cross-load recon-for-sec and recon-and-methodology when those skills exist in the workspace.

0. QUICK START

High-value paths to probe first (GET or HEAD, respect rate limits):

http
/.git/HEAD
/.git/config
/.svn/entries
/.svn/wc.db
/.hg/requires
/.bzr/README
/.DS_Store
/.env

中文路由提示:快速扫这些路径;若需完整侦察流程,从 recon-for-sec、recon-and-methodology 技能载入方法论后再深入。


1. GIT EXPOSURE

Detection
  • /.git/HEAD — valid repo often returns plain text like:
text
ref: refs/heads/main
  • /.git/config — may expose remote.origin.url, user identity, or embedded credentials.
  • /.git/index, /.git/objects/ — partial object store access enables reconstruction with the right tools.
403 vs 404
  • 404 — path likely absent or fully blocked at the edge.
  • 403 on /.git/ — directory may exist but listing is denied; still try direct file URLs:
http
/.git/HEAD
/.git/config
/.git/logs/HEAD
/.git/refs/heads/main

A 403 on the directory plus 200 on HEAD strongly indicates exposure.

Recovery tools (open source)
  • arthaud/git-dumper — dumps reachable .git tree when individual files are fetchable.
  • internetwache/GitTools — Dumper, Extractor, Finder modules for partial/corrupt dumps.
  • WangYihang/GitHacker — alternative recovery when standard dumpers miss edge cases.
Key files to prioritize
PathWhy it matters
.git/configRemotes, credentials, hooks paths
.git/logs/HEADCommit history, reflog-style leakage
.git/refs/heads/*Branch tips, commit SHAs
.git/packed-refsPacked branch/tag refs
.git/objects/**Object blobs for reconstruction

2. SVN EXPOSURE

Detection
  • SVN before 1.7: /.svn/entries — XML or text metadata listing paths and revisions.
  • SVN ≥ 1.7: /.svn/wc.db — SQLite working copy database (PRAGMA table_info after download).

Example probe:

http
GET /.svn/entries HTTP/1.1
GET /.svn/wc.db HTTP/1.1
Recovery
  • anantshri/svn-extractor — automated extraction from exposed .svn.
  • Manual: download wc.db, query with sqlite3 for file paths and checksums, then request /.svn/pristine/ blobs if exposed.

3. MERCURIAL EXPOSURE

Detection
  • /.hg/requires — small text file listing repository features; confirms Mercurial metadata.
http
GET /.hg/requires HTTP/1.1
GET /.hg/store/ HTTP/1.1
Recovery
  • sahildhar/mercurial_source_code_dumper — dumps repository when store paths are reachable.

Show full SKILL.md (185 more words)Show less

4. OTHER LEAKS

Bazaar (Bzr)
  • Probe /.bzr/README and /.bzr/branch-format for Bazaar metadata.
macOS .DS_Store
  • /.DS_Store can encode directory and filename listings.
  • Tools: gehaxelt/ds-store, lijiejie/ds_store_exp — parse .DS_Store offline.
Backup and config artifacts

Probe (adjust for app root and naming conventions):

text
/.env
/backup.zip
/backup.tar.gz
/wwwroot.rar
/backup.sql
/config.php.bak
/.config.php.swp
Web server misconfiguration signal (example: NGINX)
  • location /.git { deny all; } — may return 403 for /.git/ while still allowing or denying specific subpaths depending on rules.
  • 403 on a protected location can confirm the route exists; always distinguish from 404 on non-existent paths.

5. DECISION TREE

  1. Probe /.git/HEAD → ref: refs/heads/ pattern? → run git-dumper / GitTools / GitHacker; review config and logs/HEAD for secrets.
  2. Else probe /.svn/wc.db or entries → success? → svn-extractor or manual wc.db + pristine recovery.
  3. Else probe /.hg/requires → success? → mercurial dumper.
  4. Else probe /.bzr/README → Bazaar tooling or manual path walk.
  5. Parallel: fetch /.DS_Store, /.env, common backup extensions on app root and parent paths.
  6. Interpret status codes: 403 on directory + 200 on specific files → treat as high priority for file-by-file extraction.

  • From recon-for-sec — scope-safe discovery, crawling, and fingerprinting before deep VCS tests.
  • From recon-and-methodology — structured methodology and evidence handling.

中文:与侦察类技能联动——先定范围与速率,再针对 VCS/备份做定向验证。

© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/insecure-source-code-management of langbyyi/CyberStrikeAI-SRC.

Open the folder on GitHubat commit 166ee1c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Insecure Source Code Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Insecure Source Code Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Insecure Source Code Management this skilllangbyyi/CyberStrikeAI-SRC1341 repos~1.3kAutomated safety check: NotesApache-2.0
Clawdbot Backupsundial-org/awesome-openclaw-skills6631 repos~4.5kAutomated safety check: PassNone
Git Crypt Backupsundial-org/awesome-openclaw-skills663—~727Automated safety check: NotesNone
CI Automationjeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: NotesMIT
Ssh Skillbadseal/ssh-skill536—~2.4kAutomated safety check: NotesNone
GreptimeDB Release RunbookGreptimeTeam/greptimedb6.7k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Clawdbot Backup

    sundial-org/awesome-openclaw-skills

    Backup and restore ClawdBot configuration, skills, commands, and settings.

    663 GitHub starsUsed in 1 repo~4.5k tokens
    DevOps & CloudAuto-check passed
  • Git Crypt Backup

    sundial-org/awesome-openclaw-skills

    Backup Clawdbot workspace and config to GitHub with git-crypt encryption.

    663 GitHub stars~727 tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • CI Automation

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses when running GitHub Actions locally, creating task runner recipes, generating changelogs from git history, managing GitHub PRs/issues/releases programmatically, or creating…

    2.8k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check: notes
  • Ssh Skill

    badseal/ssh-skill

    A skill your agent uses when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download…

    536 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Release Runbook

    GreptimeTeam/greptimedb

    Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.

    6.7k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Rtk Skill

    sopaco/deepwiki-rs

    A skill your agent uses when running shell commands that produce verbose output (git, test, build, lint, package managers, docker).

    3.1k GitHub stars~1.4k tokensUpdated 24 days ago
    DevOps & CloudAuto-check passed

More from langbyyi/CyberStrikeAI-SRC

All 13 skills in this repo
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    134 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Authbypass Authentication Flaws

    langbyyi/CyberStrikeAI-SRC

    Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

    134 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • HTTP Parameter Pollution

    langbyyi/CyberStrikeAI-SRC

    HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

    134 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Type Juggling

    langbyyi/CyberStrikeAI-SRC

    PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

    134 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Websocket Security

    langbyyi/CyberStrikeAI-SRC

    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

    134 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Xslt Injection

    langbyyi/CyberStrikeAI-SRC

    XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

    134 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed

Works with

Categories

Questions about Insecure Source Code Management

What does Insecure Source Code Management do?

Source control and artifact exposure (.git, .svn, .hg, backups, .env). Insecure Source Code Management is an agent skill from langbyyi/CyberStrikeAI-SRC.env).

When should I use Insecure Source Code Management?

Insecure Source Code Management fits situations like: recon finds VCS paths; 403 on hidden dirs; backup/config leaks during authorized testing.

How do I install Insecure Source Code Management in Claude Code?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a claude-code`. Or copy the skill folder (skills/insecure-source-code-management in langbyyi/CyberStrikeAI-SRC) into .claude/skills/insecure-source-code-management in your project. Claude Code loads it when a task matches its description.

How do I install Insecure Source Code Management in Codex?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a codex`. Or copy the skill folder (skills/insecure-source-code-management in langbyyi/CyberStrikeAI-SRC) into .agents/skills/insecure-source-code-management in your project. Codex loads it when a task matches its description.

Can I use Insecure Source Code Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/insecure-source-code-management, .gemini/skills/insecure-source-code-management, .github/skills/insecure-source-code-management and .opencode/skills/insecure-source-code-management in your project.

What does Insecure Source Code Management need to run?

SKILL.md names no scripts, command-line tools or credentials: Insecure Source Code Management is instructions for the agent only.

Does Insecure Source Code Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Insecure Source Code Management safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Insecure Source Code Management use?

Insecure Source Code Management is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Insecure Source Code Management use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Insecure Source Code Management?

Skills that share tags, products or a category with Insecure Source Code Management: Clawdbot Backup (sundial-org/awesome-openclaw-skills, 663 stars), Git Crypt Backup (sundial-org/awesome-openclaw-skills, 663 stars), CI Automation (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Ssh Skill (badseal/ssh-skill, 536 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Insecure Source Code Management?

langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 134 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.