本文へ移動
cccskills
無料GitHub で公開

repo-audit

Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning, security audits of commit history, or optimizing code review assignments.

インストール方法を見る

含まれるファイル(5)

  • SKILL.md3.2 KB
  • LICENSE1.1 KB
  • scripts/hotfiles.sh3.6 KB
  • scripts/ownership.sh5.0 KB
  • scripts/secret-scan.sh9.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Repo Audit — Deep Analysis of Git History

Perform three-dimensional analysis on a Git repository: hotspot file detection, code ownership analysis, and secret leak scanning.

Feature Overview

1. Hotspot File Analysis (scripts/hotfiles.sh)

Identify the most frequently changed files in a repository to help spot:

  • High-risk code areas (frequent changes = potential instability)
  • Files that deserve extra attention during code review
  • Modules that may need splitting or refactoring

Usage:

bash scripts/hotfiles.sh [options]
OptionDescriptionDefault
--repo PATHRepository pathCurrent directory
--top NShow top N files20
--since DATEStart date (e.g. 2024-01-01)None
--until DATEEnd dateNone
--author AUTHORFilter by authorNone
--format FORMATOutput format: table / csv / jsontable

2. Code Ownership Analysis (scripts/ownership.sh)

Analyze actual code ownership, reporting for each contributor within the specified scope:

  • Commit count and percentage
  • Lines changed (additions/deletions)
  • Last active date

Usage:

bash scripts/ownership.sh [options]
OptionDescriptionDefault
--repo PATHRepository pathCurrent directory
--path SUBPATHAnalyze a specific subdirectory or fileEntire repo
--top NShow top N contributors10
--since DATEStart dateNone
--format FORMATOutput format: table / csv / jsontable

3. Secret Leak Scanning (scripts/secret-scan.sh)

Scan the full Git history (including deleted commits) for common secrets and sensitive information:

  • AWS Access Key / Secret Key
  • GitHub / GitLab / Slack Tokens
  • SSH Private Keys
  • Generic API Keys, passwords, and secret patterns

Usage:

bash scripts/secret-scan.sh [options]
OptionDescriptionDefault
--repo PATHRepository pathCurrent directory
--branch BRANCHScan a specific branchAll branches
--since DATEStart dateNone
--format FORMATOutput format: table / csv / jsontable
--severity LEVELMinimum severity level: low / medium / highlow

Use Cases

  • Security audits: Scan history for leaked secrets before deploying to production
  • Code review optimization: Identify hotspot files and prioritize reviewing high-risk areas
  • Team collaboration: Understand who knows which parts of the code best, and assign reviews accordingly
  • Tech debt assessment: Frequently changed files are strong candidates for refactoring

Dependencies

  • git (>= 2.20)
  • bash (>= 4.0)
  • Standard Unix utilities: awk, sort, head, grep

No additional dependencies or paid APIs required.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Simulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with actionable feedback. Triggers when a user asks to "review my paper," "simulate peer review," or "give my paper a peer review.

日本語の概要は準備中です。原文の説明を表示しています。

zebbern/claude-code-guide4,6552026年10月10日 更新

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.

日本語の概要は準備中です。原文の説明を表示しています。

zebbern/claude-code-guide4,6552026年10月10日 更新

This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.

日本語の概要は準備中です。原文の説明を表示しています。

zebbern/claude-code-guide4,6552026年10月10日 更新

Generate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explore interface options, compare module shapes, or mentions "design it twice".

日本語の概要は準備中です。原文の説明を表示しています。

zebbern/claude-code-guide4,6552026年10月10日 更新

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.

日本語の概要は準備中です。原文の説明を表示しています。

zebbern/claude-code-guide4,6552026年10月10日 更新

Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.

日本語の概要は準備中です。原文の説明を表示しています。

zebbern/claude-code-guide4,6552026年10月10日 更新

zebbern のスキルをすべて見る

このスキルの問題を報告する