Git Repo Security Skills
Stop README-shopping. Start scoring the repos you actually trust.
Most of us still pick open-source like restaurants. Stars. Nice README. Maybe a glance at the last commit. That friction is real, and it's how vibe-coded slop ends up in the stack.
New classroom piece is live:
Git Repo Security: Why It Matters, and How We Actually Do It
Why this hits us: we pull public git constantly. Agents clone third-party skills. Volunteers don't have an AppSec team. Stars are a weak signal. The article folds OpenSSF / SLSA / CISA-style checks into two portable skills so the discipline gets cheap and repeatable.
How you run it (newbie path)
1. Open the article and download the zip.
2. Drop the zip into your harness (Claude Code, Cursor, OpenCode, Grok, etc.).
3. Prompt the agent like a colleague:
run repo-scorecard Egonex-AI/Understand-Anything (github username/repo)
or
run repo-eval Egonex-AI/Understand-Anything
=============================================================
Here's what you get from repo-scorecard:
Scorecard: Egonex-AI/Understand-Anything
Score: 9.50 / 10.00 — healthy, well-run project
What's good:
• Actively worked on — last update was yesterday.
• Very busy recently: 355 commits in the last 90 days.
• Many people involved — about 70 different contributors this year (though one person still does most of the commits).
• Has a clear license, a README, and a security contact policy.
• Has automatic quality checks and tests set up.
• Ships tagged releases (8 tags) and keeps a fixed parts-list for its building blocks.
Things to know:
• No automatic updates for the building blocks it depends on.
Score based on publicly visible project activity and housekeeping. It does not include a security scan of the code itself.
==============================================================
That's it. The agent reads the skill, runs the script, and hands you an auditable score. Swap in any public owner/repo you care about.
Want it always loaded without re-attaching the zip? Park the skill folders where your harness keeps skills. Optional. Not required to get value today.
What each skill delivers
repo-scorecard is the zero-friction gut check. Plain git only. No API keys. No accounts. Score from 1.00 to 10.00 plus plain-language flags a non-technical person can read. "Actively worked on." "Depends on one person." Health and housekeeping. Not a security scan.
repo-eval is the deep audit. Security-weighted. Pulls real signals (activity, security files, OpenSSF Scorecard, vuln lookups, more). Needs curl and jq (optional gh). Same 1.00 to 10.00 scale. Pick your output: card for chat, executive brief for decision-makers, detailed when the stakes are real.
Rule of thumb: scorecard first for "is this abandoned?" Eval before anything near real data, clients, or production.
Trust what you can inspect
Every claim should trace to a collected signal. You don't just get a number. You get a transparent thought process you can argue with.
Disclaimer: garage tinkering. Bash + git + public APIs. Not production gospel. Not a formal pen test. Can break. The standards underneath are solid. You still bring judgment.
Your move
1. Grab the zip from the article.
2. Attach it to your harness.
3. Run repo-scorecard on three deps you already use.
4. Run repo-eval on the scariest one.
5. Drop the card (or your worst surprise) below.
We stop renting our trust to star counts. We audit. We own the decision.
Full walkthrough:
7
8 comments
David Vogel
7
Git Repo Security Skills
Clief Notes
skool.com/cliefnotes
What we give away free beats most paid courses. Build durable AI systems with a Marine vet and Edinburgh researcher. 40+ lessons, growing.
Leaderboard (30-day)
Powered by