SkillAgentSearch skills...

repo-audit

Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.

Install / Use

npx skills add zebbern/claude-code-guide --skill repo-audit

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

87/100

Category

Security

Supported Platforms

Universal

Our assessment of repo-audit

repo-audit scores 87/100 on our quality scale, 486th of 775 Security skills we index.

Its SKILL.md is 3.2 KB long, split into 7 sections with 3 code examples: a solid amount of guidance for an agent.

With 4,638 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
16/20
Description
15/15
Adoption
16/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 2 days ago, so repo-audit is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

repo-audit compared with similar skills

All 4 of these similar skills score higher than repo-audit; compare them before choosing.

SkillScoreStarsUpdatedFormat
repo-audit (this skill)by zebbern874.6k2d agoSKILL.md
Agent-Reachby Panniantong10085.9k13d agoCLAUDE.md
algorithmic-artby anthropics100177.9k5d agoSKILL.md
pptxby anthropics100177.9k5d agoSKILL.md
designby nextlevelbuilder100130.2k7d agoSKILL.md

Frequently asked questions

How do I install repo-audit?
Run npx skills add zebbern/claude-code-guide --skill repo-audit. The install tabs above show the steps for each supported agent.
Which AI agents does repo-audit work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is repo-audit safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is repo-audit still maintained?
The repository was last updated 2 days ago, so repo-audit is actively maintained.

name: repo-audit description: "Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning, security audits of commit history, or optimizing code review assignments." type: tool license: MIT tags:

  • git
  • security
  • analysis
  • devops

Repo Audit — Deep Analysis of Git History

Perform three-dimensional analysis on a Git repository: hotspot file detection, code ownership analysis, and secret leak scanning.

Feature Overview

1. Hotspot File Analysis (scripts/hotfiles.sh)

Identify the most frequently changed files in a repository to help spot:

  • High-risk code areas (frequent changes = potential instability)
  • Files that deserve extra attention during code review
  • Modules that may need splitting or refactoring

Usage:

bash scripts/hotfiles.sh [options]

| Option | Description | Default | |--------|-------------|---------| | --repo PATH | Repository path | Current directory | | --top N | Show top N files | 20 | | --since DATE | Start date (e.g. 2024-01-01) | None | | --until DATE | End date | None | | --author AUTHOR | Filter by author | None | | --format FORMAT | Output format: table / csv / json | table |

2. Code Ownership Analysis (scripts/ownership.sh)

Analyze actual code ownership, reporting for each contributor within the specified scope:

  • Commit count and percentage
  • Lines changed (additions/deletions)
  • Last active date

Usage:

bash scripts/ownership.sh [options]

| Option | Description | Default | |--------|-------------|---------| | --repo PATH | Repository path | Current directory | | --path SUBPATH | Analyze a specific subdirectory or file | Entire repo | | --top N | Show top N contributors | 10 | | --since DATE | Start date | None | | --format FORMAT | Output format: table / csv / json | table |

3. Secret Leak Scanning (scripts/secret-scan.sh)

Scan the full Git history (including deleted commits) for common secrets and sensitive information:

  • AWS Access Key / Secret Key
  • GitHub / GitLab / Slack Tokens
  • SSH Private Keys
  • Generic API Keys, passwords, and secret patterns

Usage:

bash scripts/secret-scan.sh [options]

| Option | Description | Default | |--------|-------------|---------| | --repo PATH | Repository path | Current directory | | --branch BRANCH | Scan a specific branch | All branches | | --since DATE | Start date | None | | --format FORMAT | Output format: table / csv / json | table | | --severity LEVEL | Minimum severity level: low / medium / high | low |

Use Cases

  • Security audits: Scan history for leaked secrets before deploying to production
  • Code review optimization: Identify hotspot files and prioritize reviewing high-risk areas
  • Team collaboration: Understand who knows which parts of the code best, and assign reviews accordingly
  • Tech debt assessment: Frequently changed files are strong candidates for refactoring

Dependencies

  • git (>= 2.20)
  • bash (>= 4.0)
  • Standard Unix utilities: awk, sort, head, grep

No additional dependencies or paid APIs required.

Related Skills

View on GitHub
GitHub Stars4.6k
CategorySecurity
Updated2d ago
Forks469

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions