All skills

Install the external repo-scan skill from a fixed commit that can be reviewed first. Use this pointer before a source code audit when repo-scan is not installed. It supports audits across C++, Android, iOS, and web code. This pointer installs the skill. It does not scan a repo.

  • 1 file
  • 6.1 KB
  • Updated 2 weeks ago
  • GitHub

Use this Skill: https://skilld.dev/gh/agenticluke/safe-repo-scan-plus/skill

This session only. Nothing lands on disk.

SKILL.md

≈71 tokens always: the name and description. ≈1.5k when used: this file.

repo-scan installer

Created by haibindev. Full credit goes to the original author.

repo-scan helps show:

  • Which code belongs to the project
  • Which code came from other groups
  • Which files are build waste
  • Which parts should be kept, moved, rebuilt, or removed

This file only installs repo-scan. It does not run an audit.

Install

Before you start:

  • Make sure git, tar, mktemp, and mv are installed.
  • Make sure the install folder has free space.
  • Close any other repo-scan install job.
  • Review the source before you type install.
  • Do not run this script in a job that cannot read user input.

Run:

set -euo pipefail

REPO_SCAN_COMMIT=2742664ebcad1450c208eda0ae45d3c17fad5dd8
REPO_SCAN_INSTALL_DIR="${CLAUDE_CONFIG_DIR:-$HOME/.claude}/skills/repo-scan"
REPO_SCAN_INSTALL_PARENT="$(dirname "$REPO_SCAN_INSTALL_DIR")"
REPO_SCAN_LOCK="$REPO_SCAN_INSTALL_PARENT/.repo-scan-install.lock"

for REPO_SCAN_TOOL in git tar mktemp mv mkdir rm rmdir dirname; do
  if ! command -v "$REPO_SCAN_TOOL" >/dev/null 2>&1; then
    printf 'Missing tool: %s\n' "$REPO_SCAN_TOOL" >&2
    exit 1
  fi
done

mkdir -p "$REPO_SCAN_INSTALL_PARENT"
REPO_SCAN_TMP="$(mktemp -d "$REPO_SCAN_INSTALL_PARENT/.repo-scan-install.XXXXXX")"
REPO_SCAN_STAGE="$REPO_SCAN_TMP/stage"
REPO_SCAN_BACKUP="$REPO_SCAN_TMP/backup"
REPO_SCAN_LOCK_HELD=0
REPO_SCAN_INSTALLED=0
REPO_SCAN_KEEP_TMP=0

cleanup_repo_scan_install() {
  if [ "$REPO_SCAN_INSTALLED" -eq 0 ] && \
    { [ -e "$REPO_SCAN_BACKUP" ] || [ -L "$REPO_SCAN_BACKUP" ]; } && \
    ! { [ -e "$REPO_SCAN_INSTALL_DIR" ] || [ -L "$REPO_SCAN_INSTALL_DIR" ]; }; then
    if ! mv -- "$REPO_SCAN_BACKUP" "$REPO_SCAN_INSTALL_DIR"; then
      REPO_SCAN_KEEP_TMP=1
      printf 'Restore failed. The old install is at %s\n' \
        "$REPO_SCAN_BACKUP" >&2
    fi
  fi

  if [ "$REPO_SCAN_LOCK_HELD" -eq 1 ]; then
    rmdir -- "$REPO_SCAN_LOCK" 2>/dev/null || true
  fi

  if [ "$REPO_SCAN_KEEP_TMP" -eq 0 ]; then
    rm -rf -- "$REPO_SCAN_TMP"
  else
    printf 'Saved recovery files at %s\n' "$REPO_SCAN_TMP" >&2
  fi
}
trap cleanup_repo_scan_install EXIT HUP INT TERM

git clone --filter=blob:none --no-checkout \
  https://github.com/haibindev/repo-scan.git \
  "$REPO_SCAN_TMP/source"

git -C "$REPO_SCAN_TMP/source" checkout --detach "$REPO_SCAN_COMMIT"

REPO_SCAN_ACTUAL_COMMIT="$(
  git -C "$REPO_SCAN_TMP/source" rev-parse HEAD
)"
if [ "$REPO_SCAN_ACTUAL_COMMIT" != "$REPO_SCAN_COMMIT" ]; then
  printf 'Commit check failed.\n' >&2
  exit 1
fi

mkdir "$REPO_SCAN_STAGE"
git -C "$REPO_SCAN_TMP/source" archive "$REPO_SCAN_COMMIT" |
  tar -xf - -C "$REPO_SCAN_STAGE"

if [ ! -f "$REPO_SCAN_STAGE/SKILL.md" ]; then
  printf 'The pinned source has no SKILL.md at its root.\n' >&2
  exit 1
fi

printf 'Review this source before install:\n  %s\n' \
  "$REPO_SCAN_TMP/source" >&2
printf 'Type install to replace %s: ' "$REPO_SCAN_INSTALL_DIR" >&2

if ! read -r REPO_SCAN_CONFIRM; then
  printf 'No answer was read. Install stopped.\n' >&2
  exit 1
fi

if [ "$REPO_SCAN_CONFIRM" != "install" ]; then
  printf 'Install stopped.\n' >&2
  exit 1
fi

if ! mkdir -- "$REPO_SCAN_LOCK" 2>/dev/null; then
  printf 'Another install may be running.\nLock: %s\n' \
    "$REPO_SCAN_LOCK" >&2
  exit 1
fi
REPO_SCAN_LOCK_HELD=1

if [ -e "$REPO_SCAN_INSTALL_DIR" ] || [ -L "$REPO_SCAN_INSTALL_DIR" ]; then
  mv -- "$REPO_SCAN_INSTALL_DIR" "$REPO_SCAN_BACKUP"
fi

if ! mv -- "$REPO_SCAN_STAGE" "$REPO_SCAN_INSTALL_DIR"; then
  printf 'The new install failed. The old install will be restored.\n' >&2
  exit 1
fi

REPO_SCAN_INSTALLED=1
printf 'Installed repo-scan at %s\n' "$REPO_SCAN_INSTALL_DIR"

The script keeps the old install until the new one is in place. If the new move fails, it tries to put the old install back.

If the process stops and leaves a lock:

  1. Check that no other install is running.
  2. Read the lock path shown in the error.
  3. Remove only that lock folder.
  4. Run the install again.

Do not remove a lock while another install is active.

After install, reload the agent tool. Then call repo-scan again.

Usage example

User request:

Use repo-scan on ./my-app at standard depth. Find copied libraries,
build files in Git, old code, and code that appears more than once.
Create the normal summary and HTML report. Do not change any files.

If repo-scan is not loaded after install, restart or reload the agent tool. Do not try to run the audit with this installer skill.

Scan depth

Level Files read in each module Use
fast 1 to 2 Quick check of a very large repo
standard 2 to 5 First full audit
deep 5 to 10 Check threads, memory, and API rules
full All files Full review before a large merge

Start with standard. Use fast when a repo has more than 100 modules. Use deep only on parts that need more care. Use full when the time and file access cost are clear.

What repo-scan does

  1. Lists files and groups them by module.
  2. Marks project code, copied code, and build files.
  3. Looks for known libraries and version signs.
  4. Finds old copies, repeated wrappers, and other waste.
  5. Gives each module one result:
    • Keep as core code
    • Move and join
    • Rebuild
    • Remove
  6. Makes a short summary and an HTML report.

A match is a lead, not proof. Check license files, file history, and real use before you remove or rename code. A version guess can be wrong when files were changed by hand.

Common findings

A large C++ repo may show:

  • An old FFmpeg copy
  • The same SDK wrapper in three places
  • Debug, ipch, and obj files saved in Git
  • Much more copied code than project code

Do not delete files from the report alone. Check build rules, tests, owners, and licenses first.

Link

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at f471af1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 weeks ago
origin
community

README badge

README badge for agenticluke/safe-repo-scan-plus