TopRank Skills

Home / Claw Skills / Git / GitHub / git-repo-auditor
Official OpenClaw rules 72%

git-repo-auditor

Audit Git repositories for security issues, large files, sensitive data, and repository health metrics.

Stars

0

Installs

0

Status

ACTIVE

Visibility

PUBLIC

安装方式

直接复制以下提示词,发送给你的 AI 助手即可完成安装。

请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 git-repo-auditor 技能。 若已安装,则直接安装 git-repo-auditor 技能。

Overview

Skill Key
derick001/git-repo-auditor
Author
skill-factory
Source Repo
openclaw/skills
Version
1.0.0
Source Path
skills/derick001/git-repo-auditor
Latest Commit SHA
4c5b16274562d59e523849b50ccabcd4bfdbbc29

Extracted Content

SKILL.md excerpt

# Git Repository Auditor

## What This Does

A CLI tool to audit Git repositories for security issues, code quality problems, and repository health. Scan repositories for secrets, large files, sensitive data, and common security anti-patterns.

Key features:
- **Secrets detection**: Scan Git history for API keys, passwords, tokens, and other sensitive data using regex patterns
- **Large file detection**: Identify large files (>10MB) in repository history that may impact performance
- **Security anti-patterns**: Detect hardcoded credentials, insecure configuration files, and dangerous permissions
- **Repository health**: Check for merge conflicts, stale branches, and other repository hygiene issues
- **Compliance reporting**: Generate security compliance reports for audits and team reviews
- **Multiple output formats**: Human-readable, JSON, and CSV output for integration with other tools
- **Custom scanning**: Configure custom regex patterns and file extensions to scan
- **Historical analysis**: Scan entire Git history or specific time ranges
- **Remediation guidance**: Suggest fixes for identified security issues

## When To Use

- You need to audit a Git repository for security compliance
- You want to detect accidental commits of secrets or sensitive data
- You're preparing a repository for open-source release
- You need to identify performance issues (large files in history)
- You're onboarding new developers and want to ensure repository hygiene
- You need to generate security audit reports for compliance requirements
- You want to automate security scanning in CI/CD pipelines
- You're cleaning up old repositories and need to identify issues

## Usage

Basic commands:

```bash
# Scan current directory repository
python3 scripts/main.py scan .

# Scan specific repository path
python3 scripts/main.py scan /path/to/repo

# Scan with custom secrets patterns file
python3 scripts/main.py scan . --patterns custom-patterns.json

# Generate JSON report for automation
py...

README excerpt

# Git Repository Auditor

Audit Git repositories for security issues, large files, sensitive data, and repository health metrics.

## Features

- Scan Git history for secrets (API keys, passwords, tokens)
- Detect large files impacting repository performance
- Check repository health (stale branches, binary files, .gitignore)
- Multiple output formats (human-readable, JSON)
- No external dependencies (Git + Python 3 only)

## Quick Start

```bash
# Scan a repository for security issues
python3 scripts/main.py scan /path/to/repo

# Get repository health report
python3 scripts/main.py health /path/to/repo

# List all branches with commit info
python3 scripts/main.py branches /path/to/repo

# Output JSON for automation
python3 scripts/main.py scan /path/to/repo --json
```

## Installation

This skill requires:
- Git 2.20+ installed and in PATH
- Python 3.x

No additional Python packages required.

## Usage Examples

### Basic security scan
```bash
python3 scripts/main.py scan ~/projects/my-app
```

### Scan with custom large file threshold
```bash
python3 scripts/main.py scan . --threshold 50
```

### Generate JSON report for CI/CD
```bash
python3 scripts/main.py scan . --json > security-report.json
```

### Check repository health
```bash
python3 scripts/main.py health .
```

## Output

The tool provides color-coded output:
- 🔍 Scanning progress
- ⚠️  Security issues found
- 💾 Large files detected
- ✅ No issues found
- 📊 Health metrics

## Limitations

- Scanning large repositories may be slow
- Secrets detection uses regex patterns (may have false positives)
- Does not automatically remove secrets from history
- Requires local Git repository (cannot scan remote directly)

## License

This skill is part of the OpenClaw Skill Factory portfolio.

Related Claw Skills

heyixuan2

bambu-studio-ai

★ 41

Bambu Lab 3D printer control and automation. Activate when user mentions: printer status, 3D printing, slice, analyze model, generate 3D, AMS filament, print monitor, Bambu Lab, or any 3D printing task. Full pipeline: search → generate → analyze → colorize → preview → open BS → user slice → print → monitor. Supports all 9 Bambu Lab printers (A1 Mini, A1, P1S, P2S, X1C, X1E, H2C, H2S, H2D).

capt-marbles

geo-optimization

★ 1

Generative Engine Optimization (GEO) for AI search visibility. Optimize content to appear in ChatGPT, Perplexity, Claude, and Google AI Overviews. Use when optimizing websites, pages, or content for LLM discoverability and citation.

carlulsoe

parakeet-stt

★ 0

Local speech-to-text with NVIDIA Parakeet TDT 0.6B v3 (ONNX on CPU). 30x faster than Whisper, 25 languages, auto-detection, OpenAI-compatible API. Use when transcribing audio files, converting speech to text, or processing voice recordings locally without cloud APIs.

carlzhao007

feishu-process-feedback

★ 0

飞书消息自动处理与进度反馈技能。安装后后台运行,监听飞书任务消息并自动创建独立进程处理。 在处理前后发送实时进度反馈(任务确认、进度百分比、完成通知)。 支持任务类型识别、智能解析、错误重试、并发控制、状态持久化。 使用场景:飞书自动化工作流、任务进度追踪、批量任务处理、需要实时反馈的场景。

cartoonitunes

bottyfans

★ 0

BottyFans agent skill for autonomous creator monetization. Lets AI agents register, build a profile, publish posts (public, subscriber-only, or pay-to-unlock), upload media, accept USDC subscriptions and tips on Base, send and receive DMs, track earnings, and appear on the creator leaderboard. Use this skill when an agent needs to monetize content, interact with fans, manage a creator profile, handle payments in USDC, or operate as an autonomous creator on the BottyFans platform.

camopel

arxivkb

★ 0

Local arXiv paper manager with semantic search. Crawls arXiv categories, downloads PDFs, chunks content, and indexes with FAISS + Ollama embeddings. No cloud API keys required — everything runs locally.