github-audit skillA
github-audit is agent-read markdown (skill) from avalonreset/legends-github: Audit local, remote, or portfolio GitHub repositories using traceable evidence, repository-specific applicability, and actionable verification. Distinguishes defects from unavailable checks..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# GitHub audit Find obstacles to the user's objective and provide a practical remediation plan. Inspect functionality and user journeys as well as repository presentation. ## Runtime and scope Resolve **GITHUB_HOME** from this skill directory: `../../github` in source, `../github` in an installed layout. Select the candidate containing `scripts/run_headless.py`, then read `GITHUB_HOME/references/portable-workflows.md`. Resolve the target repository independently as **TARGET**. ```text python "<GITHUB_HOME>/scripts/run_headless.py" audit --help python "<GITHUB_HOME>/scripts/run_headless.py" audit --path "<TARGET>" ``` The deterministic audit accepts a local path, not a remote identifier. It writes `audit-data.json`, `repo-context.json`, and reports such as `GITHUB-AUDIT-REPORT.md`, `ACTION-PLAN.md`, and `SUMMARY.json` under the returned artifact paths. Interpret versioned findings alongside legacy scores. For a remote-only audit, use explicit GitHub API reads or an authorized isolated checkout. Label remote default-branch findings separately from local changes. Portfolio audits enumerate the requested owner/scope and repeat a bounded review; …
Read the whole file at its exact version.
How to install
mdr add avalonreset/legends-github/github-audit@git:20260921.a2e8de7mdr add avalonreset/legends-github/github-audit@sha256:911c0b4fe93595a9Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_cddk6iqjilqqo6ot)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260921.a2e8de7 latest | 2026-09-21 | a2e8de7 | 7,046 B | A | view · diff |
| git:20260509.b2d3e98 | 2026-05-09 | b2d3e98 | 22,967 B | A | view · diff |
| git:20260316.3ae820d | 2026-03-16 | 3ae820d | 22,459 B | A | view · diff |
| git:20260316.34b3e2a | 2026-03-16 | 34b3e2a | 22,006 B | A | view · diff |
| git:20260313.aa9b904 | 2026-03-13 | aa9b904 | 19,186 B | A | view · diff |
| git:20260313.cf36c6f | 2026-03-13 | cf36c6f | 19,225 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (7046 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
avalonreset/legends-github · 4 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_cddk6iqjilqqo6ot GET https://markdownregistry.com/api/v1/resolve?ref=avalonreset/legends-github/github-audit GET https://markdownregistry.com/api/v1/blob/911c0b4fe93595a933ed70bfbecf3936392ca0a29e944f2a9ef1cc44d3c1b95c
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.