Agent skill

Repo Sentinel

by Mathews-Tom in Mathews-Tom/armory

Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

MITAuto-check passedSecurity

Install Repo Sentinel

skills CLI
$ npx skills add Mathews-Tom/armory --skill repo-sentinel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mathews-Tom/armory repo-sentinel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/repo-sentinel .claude/skills/repo-sentinel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
repo-sentinel
GitHub stars
329
Token cost
~2.2k tokens
SKILL.md length
953 words
Files
7 (incl. references)
Skills in repo
80
Repo updated
First seen
Licence
MIT

At a glance

Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

  • : push to GitHub
  • SKILL.md covers Reference files, Prerequisites, Calibration Rules and Foundational Principle, plus 4 more sections
  • Calls git and gh
  • Make repo public

What it does

Repo Sentinel is an agent skill from Mathews-Tom/armory. Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. Triggers on: "push to GitHub", "make repo public", "open source this", "is this safe to push", "release audit", "secret leaks".

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `evals/cases.yaml`, `references/attack-surfaces.md` and `references/pre-release-checklist.md`).

It sits in Security, covering Threat modeling, Git workflow and Security review. It works with GitHub and Git. The repository describes itself as: Curated, production-grade skills for AI coding agents. Battle-tested workflows for developers who use AI seriously. The licence is MIT.

When your agent uses it

  • : push to GitHub
  • Make repo public
  • Open source this
  • Is this safe to push

Example prompts

  • “push to GitHub”
  • “make repo public”
  • “open source this”
  • “/repo-sentinel”

What it can do on your machine

Read from SKILL.md and the folder at commit 4594fb7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Repo Sentinel loads about 2.2k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 69 tokens; SKILL.md has 953 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mathews-Tom/armory at commit 4594fb7, republished under its MIT licence (© Mathews-Tom). 953 words, ~2,234 tokens.

Download SKILL.mdSave it as .claude/skills/repo-sentinel/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
repo-sentinel
description
Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. Triggers on: "push to GitHub", "make repo public", "open source this", "is this safe to push", "release audit", "secret leaks".
metadata.version
1.1.1
metadata.category
review
metadata.tags
security, public-repo, secret-scanning, audit
metadata.difficulty
advanced
metadata.phase
review

Repo Sentinel

Everything in a public repo is permanent attacker surface. This skill defines what belongs in a public repo, what does not, how to detect violations across 12 attack surfaces, how to remediate when the boundary is violated, and how to enforce continuously.

Reference files

This skill uses bundled reference files for detailed patterns and templates. Read them as needed:

FileWhen to read
references/attack-surfaces.mdWhen auditing any surface — full definitions for Surfaces 0–12
references/scan-patterns.mdWhen running any audit (fast-path or full) — contains all detection commands
references/pre-release-checklist.mdWhen running the Pre-Release Audit (Stage 4) — §4.1–§4.8 readiness checklist
references/templates.mdWhen setting up enforcement, generating .gitignore, or creating CI gates
references/remediation.mdWhen fixing findings or scrubbing history — contains all fix procedures

Prerequisites

  • gh CLI installed and authenticated (gh auth status must pass) — required for GitHub-specific surface checks (Surface 10)
  • Active git repository context — the skill operates on git objects; non-git directories are out of scope
  • trufflehog or gitleaks — optional but strongly recommended for Surface 0 (git history) secret detection with entropy analysis; without them, fall back to git log -p grep patterns from references/scan-patterns.md
  • Read access to the full git object store — shallow clones (--depth N) will miss history secrets; warn the user if a shallow clone is detected

Calibration Rules

  • Public vs. private visibility: Apply stricter severity ratings for public repos — findings classified MEDIUM in a private repo (e.g., internal URL in a comment) escalate to HIGH in a public repo. Confirm repo visibility before scoring.
  • Stack-scoped surfaces: Scope the audit to attack surfaces relevant to the detected tech stack. A static HTML repo has no meaningful Surface 6 (containers) or Surface 7 (lock files) exposure — mark those surfaces N/A rather than penalizing.
  • N/A handling: Surfaces scored N/A are not penalized and do not lower the overall risk posture. Document N/A surfaces explicitly so the user understands what was skipped.
  • Tool availability: If trufflehog/gitleaks are unavailable, note this in the audit header and describe the reduced confidence in Surface 0 coverage.
  • False positive discipline: Flag a finding only when there is evidence of actual exposure, not just pattern proximity. A variable named api_key with a placeholder value is LOW, not CRITICAL.

Foundational Principle

The public/private boundary is a one-way valve. Once a byte reaches a public remote — via push, PR, issue, wiki, release asset, or GitHub Pages — assume it is indexed, cached, mirrored, and archived permanently. git push --force, PR deletion, issue edits, and release removal do NOT guarantee erasure. Scraping infrastructure (GitHub Archive, GH Torrent, Software Heritage, Google Cache, Wayback Machine, and dozens of proprietary security scanners) operates continuously with sub-hour latency.

Decision framework for every artifact:

QuestionIf YES →If NO →
Could this help an attacker who has no other access?EXCLUDEContinue
Does this reveal internal topology not inferable from public signals?EXCLUDEContinue
Does this contain values that grant access to anything?EXCLUDEContinue
Does this violate a license obligation or expose legal risk?EXCLUDEContinue
Would removing this reduce the repo's utility to legitimate users?INCLUDE (if above = all NO)EXCLUDE

When in doubt, exclude. False negatives (leaked secrets) are catastrophic and irreversible. False positives (over-redaction) are trivially correctable.


The 12 Attack Surfaces

Full definitions — what belongs, what doesn't, why it leaks, detection approach — for Surfaces 0 through 12 are in references/attack-surfaces.md. Read that file when scoping or scoring any audit. Scan commands per surface live in references/scan-patterns.md; remediation procedures in references/remediation.md.


Show full SKILL.md (386 more words)Show less

Severity Classification

All findings are classified by severity. The classification drives action priority:

SeverityCriteriaAction
CRITICALActive credential exposure, private key, auth tokenBlock push. Fix immediately.
HIGHInfrastructure/topology enabling targeted attackResolve before push.
MEDIUMInformation leakage aiding reconnaissanceFix in next commit.
LOWHygiene, style, redundancy issuesFix at convenience.

CRITICAL and HIGH in git history → full history scrub + credential rotation required.


Operations

Fast-Path Audit (Staged Changes Only)

Use when pushing a single file or small changeset. Scans only staged changes, not the full repo. Read references/scan-patterns.md § Fast-Path for the commands.

Full Repo Audit (20+ checks)

Run before making any repo public or before first push to a public remote. Read references/scan-patterns.md § Full Audit for the complete 20-check sequence, the Quick-Reference Scan Commands block, and the audit output format.

Pre-Release Audit Mode (4-Stage DAG)

When preparing a repo for open-source release, run this 4-stage pre-release audit instead of the surface-based audit. Each stage emits PASS / WARN / FAIL with actionable remediation. Hard blockers in stages 1–3 halt the pipeline. Stage 4 produces advisory output.

text
Stage 1: Sensitive Assets        [HARD BLOCKER] → Surfaces 0–4, 8–9
Stage 2: Legal & Compliance      [HARD BLOCKER] → Surface 11
Stage 3: Public Surface Hygiene  [HARD BLOCKER] → Surfaces 4–7, 9–10
Stage 4: Contribution & Release  [SOFT BLOCKER] → Surface 12 + Pre-Release Checklist

Run stages sequentially. Report results in a structured audit table at the end. Stage 4 checklist items (§4.1–§4.8) are in references/pre-release-checklist.md.

Continuous Enforcement Setup

Shift-left prevention is the highest-leverage action. Read references/templates.md for ready-to-use pre-commit config, GitHub Actions workflow, and .gitignore generator.

History Contamination Remediation

When secrets have already been committed. Read references/remediation.md for the full triage decision tree, git filter-repo commands, BFG fallback, post-scrub protocol, and .gitignore generation guidance.


Limitations

  • History scrubbing does not guarantee removal of exposure. Force-push is required, and external mirrors (forks, GitHub Archive, Software Heritage) retain history indefinitely regardless of local operations.
  • External mirrors, caches, and search engine indexes cannot be verified as de-indexed after content removal.
  • Single-repo scope only — not designed for monorepo audits without adaptation. Cross-package secret propagation requires separate analysis per package root.
  • GitHub-specific checks (branch protection, secret scanning alerts, security advisories) require the gh CLI with authenticated access. Without it, Surface 10 coverage is reduced.
  • Secret scanning depth depends on available tooling. trufflehog and gitleaks provide verified detection with entropy analysis; manual regex patterns used as fallback have higher false-positive rates and miss obfuscated credentials.
  • Artifact decisions for package registry publishing (npm, PyPI, crates) have ecosystem-specific norms that differ from source repo inclusion rules — apply ecosystem conventions when auditing published artifacts.

© Mathews-Tom, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/repo-sentinel of Mathews-Tom/armory.

  • SKILL.md
  • evals/cases.yaml
  • references/attack-surfaces.md
  • references/pre-release-checklist.md
  • references/remediation.md
  • references/scan-patterns.md
  • references/templates.md

Open the folder on GitHubat commit 4594fb7

Compare with similar skills

Repo Sentinel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Repo Sentinel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Repo Sentinel this skillMathews-Tom/armory329—~2.2kAutomated safety check: PassMIT
Release312362115/claude107—~874Automated safety check: PassMIT
Gpg Multi KeyProrise-cool/Claude-Code-Multi-Agent306—~3.2kAutomated safety check: WarnNone
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Qv Devops PR Reviewtetherto/qvac685—~2.5kAutomated safety check: PassApache-2.0
Security Ownership Mapdiegosouzapw/awesome-omni-skills159—~4.6kAutomated safety check: PassApache-2.0

Similar skills

  • Release

    312362115/claude

    发版自动化技能:CalVer 版本号 + 从 git log 生成 changelog + GitHub Releases。

    107 GitHub stars~874 tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Gpg Multi Key

    Prorise-cool/Claude-Code-Multi-Agent

    Advanced GPG multi-key management strategies for consultants, CI/CD automation, and enterprise teams.

    306 GitHub stars~3.2k tokensUpdated 25 days ago
    DevOps & CloudAuto-check: warnings
  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Qv Devops PR Review

    tetherto/qvac

    PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

    685 GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Security Ownership Map

    diegosouzapw/awesome-omni-skills

    Security Ownership Map workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4.6k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Worktrunk Release Workflow

    max-sixty/worktrunk

    Walks a maintainer through cutting a Worktrunk release: sync the release branch, pass two test gates, review the changes, then publish.

    9.2k GitHub stars~7.5k tokensUpdated today
    DevelopmentAuto-check passed

More from Mathews-Tom/armory

All 80 skills in this repo
  • Architecture Reviewer

    Mathews-Tom/armory

    Architecture reviews across 7 dimensions (structural, scalability, enterprise readiness, performance, security, ops, data) with scored reports.

    329 GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check passed
  • Concept To Image

    Mathews-Tom/armory

    Turn concepts into static HTML visuals exported as PNG or SVG files via HTML/CSS/SVG.

    329 GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check passed
  • Watch

    Mathews-Tom/armory

    A skill your agent uses when analyzing an existing video URL or local recording: "watch this video", "analyze youtube video", "summarize this video", "youtube transcript", "find this moment", "what…

    329 GitHub stars~2.8k tokensUpdated 5 days ago
    Auto-check passed
  • Code Refiner

    Mathews-Tom/armory

    Deep code simplification and refactoring preserving behavior across Python, Go, TypeScript, Rust.

    329 GitHub stars~3.1k tokensUpdated 5 days ago
    Auto-check passed
  • Concept To Video

    Mathews-Tom/armory

    Turn concepts into animated explainer videos using Manim (Python) with MP4/GIF output, audio overlay, multi-scene composition.

    329 GitHub stars~4.9k tokensUpdated 5 days ago
    Auto-check passed
  • Decision Map

    Mathews-Tom/armory

    Maps the unresolved architecture, policy, and scope decisions that must be answered before planning can start: one durable decision ticket per question on the issue tracker, typed and blocker-linked…

    329 GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed

Works with

Questions about Repo Sentinel

What does Repo Sentinel do?

Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. Repo Sentinel is an agent skill from Mathews-Tom/armory. Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

When should I use Repo Sentinel?

Repo Sentinel fits situations like: : push to GitHub; make repo public; open source this; is this safe to push.

How do I install Repo Sentinel in Claude Code?

Run `npx skills add Mathews-Tom/armory --skill repo-sentinel -a claude-code`. Or copy the skill folder (skills/repo-sentinel in Mathews-Tom/armory) into .claude/skills/repo-sentinel in your project. Claude Code loads it when a task matches its description.

How do I install Repo Sentinel in Codex?

Run `npx skills add Mathews-Tom/armory --skill repo-sentinel -a codex`. Or copy the skill folder (skills/repo-sentinel in Mathews-Tom/armory) into .agents/skills/repo-sentinel in your project. Codex loads it when a task matches its description.

Can I use Repo Sentinel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mathews-Tom/armory --skill repo-sentinel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/repo-sentinel, .gemini/skills/repo-sentinel, .github/skills/repo-sentinel and .opencode/skills/repo-sentinel in your project.

What does Repo Sentinel need to run?

Going by SKILL.md and its folder, Repo Sentinel needs the command-line tools its instructions call (git and gh).

Does Repo Sentinel access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Repo Sentinel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Repo Sentinel use?

Repo Sentinel is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Repo Sentinel use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Repo Sentinel?

Skills that share tags, products or a category with Repo Sentinel: Release (312362115/claude, 107 stars), Gpg Multi Key (Prorise-cool/Claude-Code-Multi-Agent, 306 stars), GitHub Actions Hardening (github/awesome-copilot, 40k stars) and Qv Devops PR Review (tetherto/qvac, 685 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Repo Sentinel?

Mathews-Tom (a GitHub user) maintains it in Mathews-Tom/armory, which has 329 GitHub stars. The repository holds 80 skills in this directory. The repository was last updated on October 6, 2026.

Source: Mathews-Tom/armory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.