Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning, security audits of commit history, or optimizing code review assignments.
npx skills add https://github.com/zebbern/claude-code-guide --skill repo-audit
Perform three-dimensional analysis on a Git repository: hotspot file detection, code ownership analysis, and secret leak scanning.
scripts/hotfiles.sh)Identify the most frequently changed files in a repository to help spot:
Usage:
bash scripts/hotfiles.sh [options]
| Option | Description | Default |
|--------|-------------|---------|
| --repo PATH | Repository path | Current directory |
| --top N | Show top N files | 20 |
| --since DATE | Start date (e.g. 2024-01-01) | None |
| --until DATE | End date | None |
| --author AUTHOR | Filter by author | None |
| --format FORMAT | Output format: table / csv / json | table |
scripts/ownership.sh)Analyze actual code ownership, reporting for each contributor within the specified scope:
Usage:
bash scripts/ownership.sh [options]
| Option | Description | Default |
|--------|-------------|---------|
| --repo PATH | Repository path | Current directory |
| --path SUBPATH | Analyze a specific subdirectory or file | Entire repo |
| --top N | Show top N contributors | 10 |
| --since DATE | Start date | None |
| --format FORMAT | Output format: table / csv / json | table |
scripts/secret-scan.sh)Scan the full Git history (including deleted commits) for common secrets and sensitive information:
Usage:
bash scripts/secret-scan.sh [options]
| Option | Description | Default |
|--------|-------------|---------|
| --repo PATH | Repository path | Current directory |
| --branch BRANCH | Scan a specific branch | All branches |
| --since DATE | Start date | None |
| --format FORMAT | Output format: table / csv / json | table |
| --severity LEVEL | Minimum severity level: low / medium / high | low |
git (>= 2.20)bash (>= 4.0)awk, sort, head, grepNo additional dependencies or paid APIs required.
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
Package entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with customizable include/exclude patterns, generate multiple output formats (XML, Markdown, plain text), preserve file structure and context, optimize for AI consumption with token counting, filter by file types and directories, add custom headers and summaries. Use when packaging codebases for AI analysis, creating repository snapshots for LLM context, analyzing third-party libraries, preparing for security audits, generating documentation context, or evaluating unfamiliar codebases.
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects. Covers Node.js and Python SDKs.
Perform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly requests security best practices guidance, a security review or report, or secure-by-default coding help. Supports Python, JavaScript/TypeScript, and Go. Do NOT use for general code review, debugging, threat modeling (use security-threat-model), or non-security tasks.
Configures API gateways for routing, authentication, rate limiting, and request transformation in microservice architectures. Use when setting up Kong, Nginx, AWS API Gateway, or Traefik for centralized API management.
Take zebbern/repo-audit from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.