Agent skill

Git Profile

by sd0xdev in sd0xdev/sd0x-harness

Git identity and GPG signing profile manager. An agent skill from sd0xdev/sd0x-harness.

MITAuto-check passedDevelopment

Install Git Profile

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill git-profile -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness git-profile --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/git-profile .claude/skills/git-profile && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
git-profile
GitHub stars
192
Token cost
~1.5k tokens
SKILL.md length
450 words
Files
2 (incl. scripts)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Git identity and GPG signing profile manager. An agent skill from sd0xdev/sd0x-harness.

  • Works in 6 steps: Run: bash scripts/run-skill.sh… → Parse the JSON output → Render a health report table → …
  • : user says switch identity
  • SKILL.md covers Workflow, Subcommands, Auto-Discovery and Safety Rules, plus 1 more section
  • Runs Shell scripts from its folder; calls bash

What it does

Git Profile is an agent skill from sd0xdev/sd0x-harness. Git identity and GPG signing profile manager. Discovers profiles from GPG + git config, switches local identity, checks signing health. Use when: user says 'switch identity', 'git profile', 'check signing', 'gpg key status', 'which identity', or /git-profile

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/git-profile.sh`).

It sits in Development, covering Git workflow. It works with Git. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : user says switch identity
  • Tasks that involve Git workflow

Example prompts

  • “switch identity”
  • “git profile”
  • “check signing”
  • “/git-profile”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash(bash:*), Bash(git:*), Read, Grep, Glob, AskUserQuestion

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Run: bash scripts/run-skill.sh git-profile git-profile.sh doctor
  2. Parse the JSON output
  3. Render a health report table
  4. If status is halt: show the issue and stop
  5. If status is warn: show warnings, continue
  6. If registry is missing AND this is the first run: trigger auto-discovery (see below)

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(bash:*)
    • Bash(git:*)
    • Read
    • Grep
    • Glob
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Git Profile loads about 1.5k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 450 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 450 words, ~1,486 tokens.

Download SKILL.mdSave it as .claude/skills/git-profile/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
git-profile
description
Git identity and GPG signing profile manager. Discovers profiles from GPG + git config, switches local identity, checks signing health. Use when: user says 'switch identity', 'git profile', 'check signing', 'gpg key status', 'which identity', or /git-profile
allowed-tools
Bash(bash:*), Bash(git:*), Read, Grep, Glob, AskUserQuestion
argument-hint
[doctor|list|use <profile>|remove <profile>|verify]

Git Profile Manager

Manage git identity and GPG signing profiles per-repository.

Workflow

mermaid
sequenceDiagram
    participant U as User
    participant SK as SKILL.md
    participant SH as git-profile.sh
    participant AQ as AskUserQuestion

    U->>SK: /git-profile [subcommand]
    SK->>SK: Parse subcommand (default: doctor)

    alt doctor (default)
        SK->>SH: doctor
        SH-->>SK: Diagnostic JSON
        SK->>U: Health report table
    end

    alt list
        SK->>SH: list
        SH-->>SK: Profiles JSON
        SK->>U: Profile table with current match
    end

    alt use <profile>
        SK->>SH: resolve <profile>
        SH-->>SK: Plan JSON + plan-hash
        SK->>AQ: "Apply [hash] to local config?" / "Abort"
        AQ-->>SK: Approved
        SK->>SH: apply --plan-hash <hash>
        SH-->>SK: Result JSON
        SK->>U: Applied / Error
    end

    alt remove <profile>
        SK->>SH: remove-check <profile>
        SH-->>SK: Safety JSON (active repos list)
        alt profile is active
            SK->>AQ: "Profile active in N repos. Remove anyway?" / "Cancel"
        end
        SK->>SH: remove-exec <profile> [--force]
        SH-->>SK: Result JSON
        SK->>U: Removed / Error
    end

    alt verify
        SK->>SH: verify
        SH-->>SK: Verification JSON
        SK->>U: Verification report
    end

Subcommands

doctor (default)

Run diagnostics on current repository's git identity and GPG signing config.

Steps:

  1. Run: bash scripts/run-skill.sh git-profile git-profile.sh doctor
  2. Parse the JSON output
  3. Render a health report table:
## Git Profile Health

| Item | Value | Source | Status |
|------|-------|--------|--------|
| Name | ... | ... | ... |
| Email | ... | ... | ... |
| Signing | ... | ... | ... |
| GPG Key | ... | ... | ... |
| Env Override | ... | ... | ... |
| Worktree | ... | ... | ... |
| Profile Match | ... | ... | ... |

Status: [overall status]
  1. If status is halt: show the issue and stop
  2. If status is warn: show warnings, continue
  3. If registry is missing AND this is the first run: trigger auto-discovery (see below)
list

List all registered profiles.

Steps:

  1. Run: bash scripts/run-skill.sh git-profile git-profile.sh list
  2. Parse the JSON output
  3. Render a profile table with a marker on the currently matched profile
use <profile>

Switch the current repository to use a named profile.

Steps:

  1. Run: bash scripts/run-skill.sh git-profile git-profile.sh resolve <profile>
  2. Parse the plan JSON — contains profile data, planned commands, and plan-hash
  3. Show the user what will be written:
## Apply Profile: <profile-id>

| Config Key | Current | New |
|------------|---------|-----|
| user.name | ... | ... |
| user.email | ... | ... |
| user.signingkey | ... | ... / (unset) |
| commit.gpgsign | ... | true / (unset) |

Note: Keyless profiles unset signing-related keys instead of setting them.
  1. Use AskUserQuestion with options:
    • "Apply [<plan-hash>] to local config (Recommended)"
    • "Abort"
  2. On approval: bash scripts/run-skill.sh git-profile git-profile.sh apply --plan-hash <hash>
  3. Parse result; if error (hash mismatch, write failure) report and stop
  4. On success: report applied config
remove <profile>

Remove a profile from the registry.

Steps:

  1. Run: bash scripts/run-skill.sh git-profile git-profile.sh remove-check <profile>
  2. If profile is active in any repo, use AskUserQuestion:
    • "Profile is active in N repos. Remove with --force?"
    • "Cancel"
  3. On approval: bash scripts/run-skill.sh git-profile git-profile.sh remove-exec <profile> [--force]
  4. Report result
verify

Deep verification of current identity setup.

Steps:

  1. Run: bash scripts/run-skill.sh git-profile git-profile.sh verify
  2. Parse the verification JSON
  3. Render verification report with checks:
    • Key expiry (90-day warning threshold)
    • Email match between git config and GPG key UID
    • Registry consistency
Show full SKILL.md (169 more words)Show less

Auto-Discovery

Triggered when: registry file is missing on first doctor run.

Steps:

  1. Run: bash scripts/run-skill.sh git-profile git-profile.sh discover
  2. Parse candidates JSON
  3. Present candidates to user via AskUserQuestion:
    • "Save N discovered profiles to registry (Recommended)"
    • "Skip — I'll configure manually"
  4. If approved, the discover command already persisted them; confirm to user
  5. If skipped, create an empty registry to avoid re-prompting

Safety Rules

RuleDescription
v1 NEVER writes ~/.gitconfigOnly --local scope writes
v1 NEVER enables extensions.worktreeConfigLinked worktree: detect + warn only
NEVER auto-fix without confirmationAll writes gated by AskUserQuestion
NEVER store key materialRegistry stores fingerprints only
Plan-hash verificationRe-compute hash before apply; reject if stale
Atomic registry writestemp file + chmod 0600 + mv

Diagnostic Integration

The doctor --json output follows the Shared Diagnostic Contract (see tech spec section 3.2). Other skills (e.g., /smart-commit Step 1c) can call:

bash scripts/run-skill.sh git-profile git-profile.sh doctor --json

Degradation policy: If the script is not found or fails, the calling skill falls back to its own inline diagnostics. Infrastructure failure = warn-only; identity/signing missing = halt (unchanged).

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/git-profile of sd0xdev/sd0x-harness.

  • SKILL.md
  • scripts/git-profile.sh

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Git Profile next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Git Profile compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Git Profile this skillsd0xdev/sd0x-harness192—~1.5kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Git Merge Conflict Resolver

    tailcallhq/forgecode

    Resolves Git merge conflicts with a plan-first workflow that keeps both sides' intent, regenerates lock files and backs up deleted-but-modified files.

    7.6k GitHub starsUsed in 1 repo~4.5k tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Git Profile

What does Git Profile do?

Git identity and GPG signing profile manager. An agent skill from sd0xdev/sd0x-harness. Git Profile is an agent skill from sd0xdev/sd0x-harness. Git identity and GPG signing profile manager.

When should I use Git Profile?

Git Profile fits situations like: : user says switch identity; tasks that involve Git workflow.

How do I install Git Profile in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill git-profile -a claude-code`. Or copy the skill folder (skills/git-profile in sd0xdev/sd0x-harness) into .claude/skills/git-profile in your project. Claude Code loads it when a task matches its description.

How do I install Git Profile in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill git-profile -a codex`. Or copy the skill folder (skills/git-profile in sd0xdev/sd0x-harness) into .agents/skills/git-profile in your project. Codex loads it when a task matches its description.

Can I use Git Profile in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill git-profile -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/git-profile, .gemini/skills/git-profile, .github/skills/git-profile and .opencode/skills/git-profile in your project.

What does Git Profile need to run?

Going by SKILL.md and its folder, Git Profile needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash(bash:*), Bash(git:*), Read, Grep, Glob, AskUserQuestion.

Does Git Profile access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Git Profile safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Git Profile use?

Git Profile is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Git Profile use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Git Profile?

Skills that share tags, products or a category with Git Profile: Finishing a Development Branch (obra/superpowers, 296k stars), Code Design Rationale Investigator (cursor/plugins, 10k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Git Profile?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.