Repo status
Skill VictorAurelius/claude-starter-kit/skills/workflow/repo-status
Use when the user says 'status', 'repo status', 'tình trạng repo', 'health check', 'is the repo OK?', 'security', 'CVE', 'vuln', or when starting a conversation that needs a quick remote-repo assessment. Checks: CI, PRs/branches, audit gaps, GitHub Security (Dependabot + code-scanning + secret-scanning) → output level GREEN/YELLOW/ORANGE/RED/BLACK.From its SKILL.md
npx -y skills add VictorAurelius/claude-starter-kit --skill repo-statusAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- runs commandsInstructs the agent to run 8 commands, including `./scripts/repo-status.sh` and 7 more.
SKILL.md
6.3 KB, ~1.6k tokens by cl100k_base, as published. Nobody here has run it
/repo-status — Remote Repo Health Check
Usage: /repo-status or /repo-status --quick
Assess remote-repo health across 4 factors, output a status level.
Instructions
Step 1: Gather data
If the project provides a helper script scripts/repo-status.sh, use it:
./scripts/repo-status.sh # full report
./scripts/repo-status.sh --json # JSON for parsing
./scripts/repo-status.sh --level # level only (quick check)
If no such script exists, gather the 4 factors directly with gh / git (Steps below). If --quick: report the level in one line and stop.
Step 2: Analyze the 4 factors
Factor 1 — CI: if CI is failing on the default branch, find root cause:
DEFAULT=$(git symbolic-ref --quiet --short refs/remotes/origin/HEAD | sed 's@^origin/@@'); DEFAULT=${DEFAULT:-main}
FAILED_RUN=$(gh run list --branch "$DEFAULT" --limit 5 \
--json databaseId,workflowName,conclusion \
--jq '.[] | select(.conclusion=="failure") | .databaseId' | head -1)
gh run view "$FAILED_RUN" --log-failed 2>/dev/null | tail -30
Factor 2 — PRs/Branches: check whether stale branches are WIP or abandoned:
git for-each-ref --sort=-committerdate \
--format='%(refname:short) %(committerdate:relative)' refs/remotes/ \
| grep -vE "main|master|HEAD"
Factor 3 — Audit Gaps (optional — only if the project runs audits): read the latest audit report under documents/04-quality/audits/** (if present) to understand gap context. Cross-check: do gaps already have a merged PR fix? (compare against gh pr list --state merged since the audit date). If the project has no audit pipeline, skip this factor.
Factor 4 — GitHub Security: 3 endpoints via gh api:
REPO=$(gh repo view --json nameWithOwner --jq .nameWithOwner)
gh api "repos/$REPO/dependabot/alerts?state=open" # → 403 if disabled
gh api "repos/$REPO/code-scanning/alerts?state=open" # → [] if no scanner
gh api "repos/$REPO/secret-scanning/alerts?state=open" # → public/enterprise only
Severity mapping:
- Dependabot
critical→ BLACK;high→ RED;medium→ YELLOW - Code scanning
error→ HIGH (counts as CVE);warning→ MEDIUM;note→ LOW - Any secret-scanning alert → BLACK (credential exposure)
- Dependabot disabled (HTTP 403) → minimum ORANGE (silent-drift risk)
If Dependabot is disabled, prompt the user to enable it (repo Settings → Code security and analysis).
Step 3: Output Report
## Repo Status: [LEVEL] — [Label]
**Date:** [date]
**Branch:** [default] @ [commit hash]
### Factor 1: CI
- Status: ✅/❌ [details]
- Days since green: [N]
- Root cause (if fail): [description]
### Factor 2: PRs & Branches
- Open PRs: [N]
- Stale branches: [N]
- Details: [list]
### Factor 3: Audit Gaps (omit if no audit pipeline)
- Latest audit: [date] — [score]
- Unfixed P0/P1/P2: [counts]
### Factor 4: GitHub Security
- Dependabot: enabled/disabled — [critical/high/medium/low counts]
- Code scanning: [N errors / N warnings / N notes] — top finding: [rule.id + file]
- Secret scanning: [N open alerts] (BLACK if >0)
### Recommended Actions
1. [Highest priority]
2. [Next]
Step 4: Recommend actions
| Level | Action |
|---|---|
| GREEN | Continue normal development |
| YELLOW | Note minor items, fix when convenient |
| ORANGE | Fix before opening new PRs |
| RED | Fix now — top priority |
| BLACK | Stop all work, fix CI/security first |
Level Definitions
Detail: reference/level-definitions.md
| Level | Label | Trigger |
|---|---|---|
| GREEN | Healthy | CI green + 0 open PRs/stale branches + 0 P0/P1 gaps + 0 CVE + Dependabot enabled |
| YELLOW | Minor Issues | CI green + minor gaps (P2/P3) OR 1-2 stale branches OR code-scan warnings |
| ORANGE | Needs Attention | CI green + P1 gaps, OR >2 stale items, OR Dependabot disabled, OR ≥3 warnings |
| RED | Degraded | CI red on default branch OR unfixed P0 gaps OR ≥1 HIGH CVE |
| BLACK | Broken | CI red >7 days OR CRITICAL CVE OR secret-scanning alert |
Rules
- Run the helper script first if it exists — don't infer status by hand.
- LUÔN giao tiếp tiếng Việt (per kit bilingual convention).
- If a check fails (GitHub API unavailable) → report it, don't guess.
- Cross-reference audit gaps with merged PRs — a gap may already be fixed but not re-audited.
- Recommended actions must be actionable (PR scope, estimate).
Gotchas
- All checks need
ghauthenticated (gh auth status). ci_days_redis based on last-success date, not first-failure date.- Audit gaps (Factor 3) parse via P0/P1/P2 markers — if a project's report format differs, adapt the parse.
- Stale branches = unmerged into default branch, may be valid WIP — check commit date before recommending delete.
- Security factor (F4):
gh apisecurity endpoints return 403 if Dependabot disabled. Use a jq type-check (type=="array"= enabled) to distinguish a disabled object from an empty-but-enabled array. Do NOT grep the response body — CVE descriptions may contain the word "disabled" and cause false positives. - Secret-scanning endpoint is only available for public repos or GitHub Enterprise — returns 404 for private repos → treat as "disabled".
- Code-scanning alerts only populate when a CodeQL/Trivy/SARIF upload workflow runs. No scanner = empty
[], not disabled.
Skill contents
SKILL.md— this filereference/level-definitions.md— 5-level definitions + decision matrix + per-factor detail
Related
.claude/skills/workflow/start-session/SKILL.md— faster routine entry (consumes repo level).claude/rules/mcp-first-with-fallback.md— prefer GitHub MCP overghCLI when connected.claude/rules/output-review-mandate.md— health reports are reviewable outputs
What ships with it: 1 file
5.7 KB alongside SKILL.md
reference/
- level-definitions.md5.7 KB
Gives 0 of the 12 instructions most vulnerability scanning skills give in ~1.6k tokens
Counted across 223 of the 238 authors here whose files we hold, read 2026-09-06
- Fix critical findings immediatelyin 21 of 223, across 14 files
- Fix high findings before productionin 18 of 223, across 12 files
- Check and install AgentShield before scanningin 18 of 223, across 12 files
- Scaffold a secure configuration with initin 16 of 223, across 10 files
- Add the AgentShield GitHub Action to CIin 16 of 223, across 10 files
- Run the three-agent opus pipeline for deeper analysisin 14 of 223, across 8 files
- Apply safe auto-fixes onlyin 14 of 223, across 8 files
- Use JSON output for CI/CD integrationin 13 of 223, across 7 files
- Filter findings with a minimum severityin 12 of 223, across 10 files
- Classify each finding by severityin 10 of 223
- Use parameterized queries for all database accessin 10 of 223, across 9 files
- Write tests before writing the rulein 9 of 223, across 4 files
Said here and by no other author read
- Run the helper script first if it exists
- Report the level in one line for --quick
- Find the root cause when default-branch CI fails
- Check whether stale branches are WIP or abandoned
- Skip the audit factor when no audit pipeline exists
- Cross-check audit gaps against merged PRs
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.