Agent skill

Git Repo Audit

by rongxinzy in rongxinzy/RongxinAI

深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。

MITAuto-check passedDevelopment

Install Git Repo Audit

skills CLI
$ npx skills add rongxinzy/RongxinAI --skill git-repo-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rongxinzy/RongxinAI git-repo-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/SKILLs/git-repo-audit .claude/skills/git-repo-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
git-repo-audit
GitHub stars
154
Token cost
~486 tokens
SKILL.md length
158 words
Files
7 (incl. scripts)
Skills in repo
94
Repo updated
First seen
Licence
MIT

At a glance

深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。

  • Works in 3 steps: 热点文件分析 (scripts/hotfiles.sh) → 代码归属分析 (scripts/ownership.sh) → 密钥泄露扫描 (scripts/secret-scan.sh)
  • Tasks that involve Git workflow
  • SKILL.md covers 功能概览, 使用场景 and 依赖
  • Runs Shell scripts from its folder; calls bash

What it does

Git Repo Audit is an agent skill from rongxinzy/RongxinAI. 深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。

Its SKILL.md is about 490 tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `scripts/hotfiles.sh`, `scripts/ownership.sh` and `scripts/secret-scan.sh`).

It sits in Development, covering Git workflow. It works with Git. The repository describes itself as: An all-in-one local AI Agent workspace with a fully self-developed stack. The licence is MIT.

When your agent uses it

  • Tasks that involve Git workflow

Example prompts

  • “/git-repo-audit”

Requirements

  • A Bash shell

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. 热点文件分析 (scripts/hotfiles.sh)
  2. 代码归属分析 (scripts/ownership.sh)
  3. 密钥泄露扫描 (scripts/secret-scan.sh)

What it can do on your machine

Read from SKILL.md and the folder at commit 9c64865. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Git Repo Audit loads about 486 tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 158 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~486

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from rongxinzy/RongxinAI at commit 9c64865, republished under its MIT licence (© rongxinzy). 158 words, ~486 tokens.

Download SKILL.mdSave it as .claude/skills/git-repo-audit/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
git-repo-audit
description
深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。
license
MIT
metadata.type
tool
metadata.tags
git, security, analysis, devops

Git Forensics — Git 历史深度分析

对 Git 仓库进行三维深度分析:热点文件识别、代码归属分析、密钥泄露扫描。

功能概览

1. 热点文件分析 (scripts/hotfiles.sh)

找出仓库中变更最频繁的文件,帮助识别:

  • 高风险代码区域(频繁修改 = 潜在不稳定)
  • 需要重点 code review 的文件
  • 可能需要拆分或重构的模块

用法:

bash
bash scripts/hotfiles.sh [选项]
选项说明默认值
--repo PATH仓库路径当前目录
--top N显示前 N 个文件20
--since DATE起始日期(如 2024-01-01)不限
--until DATE截止日期不限
--author AUTHOR按作者过滤不限
--format FORMAT输出格式:table / csv / jsontable
2. 代码归属分析 (scripts/ownership.sh)

分析代码的实际归属关系,输出每位贡献者在指定范围内的:

  • 提交次数与占比
  • 修改行数(增/删)
  • 最近活跃时间

用法:

bash
bash scripts/ownership.sh [选项]
选项说明默认值
--repo PATH仓库路径当前目录
--path SUBPATH分析指定子目录或文件整个仓库
--top N显示前 N 位贡献者10
--since DATE起始日期不限
--format FORMAT输出格式:table / csv / jsontable
3. 密钥泄露扫描 (scripts/secret-scan.sh)

扫描 Git 全量历史(包括已删除的 commit),检测常见的密钥和敏感信息泄露:

  • AWS Access Key / Secret Key
  • GitHub / GitLab / Slack Token
  • SSH 私钥
  • 通用 API Key、密码、Secret 模式

用法:

bash
bash scripts/secret-scan.sh [选项]
选项说明默认值
--repo PATH仓库路径当前目录
--branch BRANCH扫描指定分支所有分支
--since DATE起始日期不限
--format FORMAT输出格式:table / csv / jsontable
--severity LEVEL最低严重级别:low / medium / highlow

使用场景

  • 安全审计:在代码上线前扫描历史中是否有密钥泄露
  • Code Review 优化:识别热点文件,优先 review 高风险区域
  • 团队协作:了解谁最熟悉哪部分代码,合理分配 review 任务
  • 技术债务评估:高频变更文件可能是重构候选

依赖

  • git(>= 2.20)
  • bash(>= 4.0)
  • 标准 Unix 工具:awk、sort、head、grep

无需安装任何额外依赖或付费 API。

© rongxinzy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts) in SKILLs/git-repo-audit of rongxinzy/RongxinAI.

  • SKILL.md
  • LICENSE
  • scripts/hotfiles.sh
  • scripts/ownership.sh
  • scripts/secret-scan.sh
  • zhiyuan/icon.png
  • zhiyuan/metadata.yaml

Open the folder on GitHubat commit 9c64865

Compare with similar skills

Git Repo Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Git Repo Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Git Repo Audit this skillrongxinzy/RongxinAI154—~486Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost56k—~3.8kAutomated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Git Merge Conflict Resolvertailcallhq/forgecode7.6k1 repos~4.5kAutomated safety check: PassApache-2.0

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    56k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Git Merge Conflict Resolver

    tailcallhq/forgecode

    Resolves Git merge conflicts with a plan-first workflow that keeps both sides' intent, regenerates lock files and backs up deleted-but-modified files.

    7.6k GitHub starsUsed in 1 repo~4.5k tokens
    DevelopmentAuto-check passed
  • Git Branch Naming

    makeplane/plane

    Names a new Git branch with a type prefix, the lowercased work item ID and a short kebab-case description, so the ID can be extracted later from the branch name.

    61k GitHub stars~594 tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from rongxinzy/RongxinAI

All 94 skills in this repo
  • SaaS Metrics Coach

    rongxinzy/RongxinAI

    SaaS financial health advisor. An agent skill from rongxinzy/RongxinAI.

    154 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Churn Prevention

    rongxinzy/RongxinAI

    Reduce voluntary and involuntary churn through cancel flow design, save offers, exit surveys, and dunning sequences.

    154 GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check passed
  • Presentation Studio

    rongxinzy/RongxinAI

    The only skill for creating a new PowerPoint deck. An agent skill from rongxinzy/RongxinAI.

    154 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Zhiyuan Expert Manager

    rongxinzy/RongxinAI

    ZhiYuan Agent expert package lifecycle manager for the pi engine.

    154 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Ziwei Doushu

    rongxinzy/RongxinAI

    Professional Ziwei Doushu consultation skill with an offline calculation engine.

    154 GitHub stars~746 tokensUpdated today
    Auto-check passed
  • Lark Mail

    rongxinzy/RongxinAI

    飞书邮箱:Use when user mentions 起草邮件、写邮件、草稿、发送/回复/转发邮件、查阅邮件、看邮件、搜索邮件、邮件文件夹、邮件标签、邮件联系人、监听新邮件、邮件收信规则等;use for mail/email intent only.

    154 GitHub starsUsed in 3 repos~4.1k tokens
    Auto-check: warnings

Works with

Categories

Questions about Git Repo Audit

What does Git Repo Audit do?

深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。. Git Repo Audit is an agent skill from rongxinzy/RongxinAI.

When should I use Git Repo Audit?

Git Repo Audit fits situations like: tasks that involve Git workflow.

How do I install Git Repo Audit in Claude Code?

Run `npx skills add rongxinzy/RongxinAI --skill git-repo-audit -a claude-code`. Or copy the skill folder (SKILLs/git-repo-audit in rongxinzy/RongxinAI) into .claude/skills/git-repo-audit in your project. Claude Code loads it when a task matches its description.

How do I install Git Repo Audit in Codex?

Run `npx skills add rongxinzy/RongxinAI --skill git-repo-audit -a codex`. Or copy the skill folder (SKILLs/git-repo-audit in rongxinzy/RongxinAI) into .agents/skills/git-repo-audit in your project. Codex loads it when a task matches its description.

Can I use Git Repo Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rongxinzy/RongxinAI --skill git-repo-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/git-repo-audit, .gemini/skills/git-repo-audit, .github/skills/git-repo-audit and .opencode/skills/git-repo-audit in your project.

What does Git Repo Audit need to run?

Going by SKILL.md and its folder, Git Repo Audit needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell.

Does Git Repo Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Git Repo Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Git Repo Audit use?

Git Repo Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Git Repo Audit use?

About 486 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Git Repo Audit?

Skills that share tags, products or a category with Git Repo Audit: Finishing a Development Branch (obra/superpowers, 297k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 56k stars) and Create Pull Request (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Git Repo Audit?

rongxinzy (a GitHub organization) maintains it in rongxinzy/RongxinAI, which has 154 GitHub stars. The repository holds 94 skills in this directory. The repository was last updated on October 10, 2026.

Source: rongxinzy/RongxinAI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.