inspect-repository skillA
inspect-repository is agent-read markdown (skill) from gke-labs/kube-agents: Read and analyze the source of any GitHub repository — public or one this install has a token for — without a local checkout. Clones broker-side and pulls file content back; use it to answer questions about code, not to change it..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# inspect-repository - Read a repository this pod has no checkout of This pod has no `git` of its own and no `.git` anywhere it can write. To read somebody else's code, ask the credential broker to clone it and pull the file content back. What lands locally is source without a repository around it: files you can open, grep and reason about, and no `.git/config` for anything to execute out of. The script is `./skills/inspect-repository/scripts/inspect_repository.py`. Every subcommand prints one JSON object on stdout. ## When to Use - **Answering a question about code you do not have.** "How does upstream implement this controller?", "which release added this flag?" - **Reading a dependency or an upstream project** named in an issue, a design doc, or a user's question. - **Reading the GitOps repository for context** when you are not editing it. ## When NOT to Use - **Changing a repository.** Use **submit-suggestion** (a pull request against the GitOps repo) or **fleet-audit** (fixes for its own findings). This skill opens read-only workspaces and the broker refuses to commit from one. - **Reading a file the GitOps workflow already handed you.** `fleet-audit` and …
Read the whole file at its exact version.
How to install
mdr add gke-labs/kube-agents/inspect-repository@git:20260915.fe062d3mdr add gke-labs/kube-agents/inspect-repository@sha256:f6faac9e5ad6a271Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_da4saeit4blndkmp)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260915.fe062d3 latest | 2026-09-15 | fe062d3 | 5,394 B | A | view · diff |
| git:20260905.f66d195 | 2026-09-05 | f66d195 | 5,071 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (5394 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
gke-labs/kube-agents · 64 stars · license Apache-2.0 · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_da4saeit4blndkmp GET https://markdownregistry.com/api/v1/resolve?ref=gke-labs/kube-agents/inspect-repository GET https://markdownregistry.com/api/v1/blob/f6faac9e5ad6a271bc2acd92dae4cf02912a0b4a6e627add761dd6a3401d893b
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.