{"id":18914,"plugin_id":"plugins_6a8d4dc60bf081918a06094873890eb4","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:02.314Z","digest":"74eebfb484bd4068c2225985d36c1aedc81dcb9fce7abeacfd7c694a8a7f6fec","against":null,"payload":{"description":"Use this when a user needs live, read-only evidence about a public GitHub repository, from a quick map to a broad readiness audit, environment review, secret-risk scan, API review or migration review. Do not use it for private repositories, credentials, code execution or write actions.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":450}],"name":"audit-repository","skill_md_contents":"---\nname: audit-repository\ndescription: Use this when a user needs live, read-only evidence about a public GitHub repository, from a quick map to a broad readiness audit, environment review, secret-risk scan, API review or migration review. Do not use it for private repositories, credentials, code execution or write actions.\n---\n\n# Audit Repository\n\nRequire a public GitHub repository URL or `owner/name`. Never ask for a token or secret.\n\n1. Call `opstruth_inspect_repository` when the user needs orientation or a bounded map.\n2. Call `opstruth_audit_repository` when the user requests a broad audit.\n3. Use the narrower audit tools only when the request targets one concern.\n4. Call `opstruth_check_github_handoff` when the answer depends on current public workflow, check-run, commit-status or branch-protection evidence.\n5. Distinguish verified observations from warnings, skipped checks and facts that remain unverified.\n6. Call `opstruth_snapshot_evidence` when repository, CI and optional runtime evidence must be bound into one portable signed graph.\n7. State that public CI evidence proves only the reported commit and run, not a fresh local execution by OpsTruth.\n8. Use `opstruth_prepare_sandbox_verification` when build or test execution is required. Treat its output as an approval-gated handoff, never as execution evidence.\n9. Do not deploy, commit, merge, install packages or claim that the public plugin executed repository code.\n10. Offer `opstruth_render_evidence` after the evidence is complete when a visual summary would help.\n\nTreat signed receipts as integrity and signer evidence, not proof that the repository is correct. Use `opstruth_verify_evidence_receipt` when independent receipt verification is requested.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}