Skip to content

fix(gitops-kubernetes): retire unsafe repo audit skill - #184

Merged
devantler merged 4 commits into
mainfrom
codex/agentic-engineering-rollback-unsafe-sync
Sep 2, 2026
Merged

devantler merged 4 commits into
mainfrom
codex/agentic-engineering-rollback-unsafe-sync

Conversation

@devantler

@devantler devantler commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

A synced skills update reached main despite a verified command-execution blocker. The follow-up version bump then made that unreviewed bundle available under a fresh cache key.

What

  • Retire the affected bundled audit skill so consumers can no longer invoke it.
  • Publish the contained GitOps plugin under the fresh 1.0.2 cache key.
  • Keep the security reports open for a separately reviewed upstream repair and reintroduction.

Refs #164.
Refs #178.

@devantler devantler changed the title revert(plugins): roll back unsafe synced skills fix(gitops-kubernetes): retire unsafe repo audit skill Sep 2, 2026
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

Please review the current containment head 1824964c7e143125bc06780d866955646be22bb1. It retires the unsafe bundled audit capability, publishes the contained GitOps plugin under a fresh cache key, and removes the retired helpers' stale CI exemptions. Local membership, cache-version, manifest, provenance, and helper-suite checks are green.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="1824964c7e143125bc06780d866955646be22bb1"
parent="$(git rev-parse "${head}^")"

printf '%s\n' '=== Commit ==='
git show -s --format='Commit: %H%nParents: %P%nSubject: %s%n%n%b' "$head"

printf '%s\n' '=== Changed files ==='
git diff-tree --no-commit-id --name-status -r "$head"

printf '%s\n' '=== Diff stat ==='
git diff --stat "$parent" "$head"

printf '%s\n' '=== Full diff ==='
git diff --find-renames --find-copies --no-ext-diff "$parent" "$head"

printf '%s\n' '=== Candidate repository files ==='
fd -HI -t f . | rg -i '(gitops|audit|skill|plugin|manifest|provenance|cache|exempt|workflow|action)'

printf '%s\n' '=== Relevant references in tracked text files ==='
rg -n -i -C 2 \
  '(gitops-kubernetes|repo[ _-]?audit|audit[ _-]?repo|unsafe|cache[ _-]?version|1\.0\.[0-9]+|exempt(ion|ed)?|provenance)' \
  -g '!node_modules/**' -g '!dist/**' -g '!build/**' . || true

Length of output: 81542


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="devantler-tech/agent-plugins"
pr=184
head="1824964c7e143125bc06780d866955646be22bb1"

printf '%s\n' '=== Pull request metadata ==='
gh pr view "$pr" --repo "$repo" \
  --json number,title,baseRefName,baseRefOid,headRefName,headRefOid,commits,files \
  --jq '{number,title,baseRefName,baseRefOid,headRefName,headRefOid,
         commits:[.commits[]|{oid:.oid,messageHeadline:.messageHeadline}],
         files:[.files[]|{path:.path,additions:.additions,deletions:.deletions]}'

base="$(gh pr view "$pr" --repo "$repo" --json baseRefOid --jq -r .baseRefOid)"
printf '%s\n' '=== Complete PR diff stat ==='
git diff --stat "$base" "$head"

printf '%s\n' '=== Complete PR changed files ==='
git diff --name-status "$base" "$head"

printf '%s\n' '=== Complete PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"

printf '%s\n' '=== Current GitOps manifests and README row ==='
for file in \
  plugins/gitops-kubernetes/plugin.json \
  plugins/gitops-kubernetes/.claude-plugin/plugin.json \
  .claude-plugin/marketplace.json \
  .github/plugin/marketplace.json \
  README.md \
  .github/workflows/ci.yaml
do
  printf '\n--- %s ---\n' "$file"
  sed -n '1,260p' "$file"
done

printf '%s\n' '=== Retired skill path at base and head ==='
printf '%s\n' '-- base --'
git ls-tree -r --name-only "$base" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true
printf '%s\n' '-- head --'
git ls-tree -r --name-only "$head" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true

printf '%s\n' '=== Remaining audit-capability references at head ==='
git grep -n -i -E '(gitops-repo-audit|repository auditing|repo audit)' "$head" -- \
  ':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true

Length of output: 2351


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="devantler-tech/agent-plugins"
pr=184
head="1824964c7e143125bc06780d866955646be22bb1"

printf '%s\n' '=== Pull request metadata ==='
gh pr view "$pr" --repo "$repo" \
  --json number,title,baseRefName,baseRefOid,headRefName,headRefOid,commits,files \
  --jq '{number,title,baseRefName,baseRefOid,headRefName,headRefOid,
         commits:[.commits[]|{oid:.oid,messageHeadline:.messageHeadline}],
         files:[.files[]|{path:.path,additions:.additions,deletions:.deletions}]}'

base="$(gh pr view "$pr" --repo "$repo" --json baseRefOid --jq -r .baseRefOid)"
printf '%s\n' '=== Complete PR diff stat ==='
git diff --stat "$base" "$head"

printf '%s\n' '=== Complete PR changed files ==='
git diff --name-status "$base" "$head"

printf '%s\n' '=== Complete PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"

printf '%s\n' '=== Current GitOps manifests and README row ==='
for file in \
  plugins/gitops-kubernetes/plugin.json \
  plugins/gitops-kubernetes/.claude-plugin/plugin.json \
  .claude-plugin/marketplace.json \
  .github/plugin/marketplace.json \
  README.md \
  .github/workflows/ci.yaml
do
  printf '\n--- %s ---\n' "$file"
  sed -n '1,260p' "$file"
done

printf '%s\n' '=== Retired skill path at base and head ==='
printf '%s\n' '-- base --'
git ls-tree -r --name-only "$base" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true
printf '%s\n' '-- head --'
git ls-tree -r --name-only "$head" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true

printf '%s\n' '=== Remaining audit-capability references at head ==='
git grep -n -i -E '(gitops-repo-audit|repository auditing|repo audit)' "$head" -- \
  ':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true

Length of output: 7216


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="04c49dd3bae09ef29d7286d4ba3cdcc882a5f92e"
head="1824964c7e143125bc06780d866955646be22bb1"
range="${base}..${head}"

printf '%s\n' '=== Complete PR diff stat and name status ==='
git diff --stat "$range"
git diff --name-status "$range"

printf '%s\n' '=== Metadata and README diffs ==='
git diff --no-ext-diff "$range" -- \
  .claude-plugin/marketplace.json \
  .github/plugin/marketplace.json \
  plugins/gitops-kubernetes/plugin.json \
  plugins/gitops-kubernetes/.claude-plugin/plugin.json \
  README.md \
  .github/workflows/ci.yaml

printf '%s\n' '=== GitOps metadata at head ==='
for file in \
  plugins/gitops-kubernetes/plugin.json \
  plugins/gitops-kubernetes/.claude-plugin/plugin.json \
  .claude-plugin/marketplace.json \
  .github/plugin/marketplace.json
do
  printf '\n--- %s ---\n' "$file"
  jq . "$file"
done

printf '%s\n' '=== Audit-related text at head ==='
git grep -n -i -E '(gitops-repo-audit|repository auditing|repo audit)' "$head" -- . \
  ':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true

printf '%s\n' '=== CI helper pairing section ==='
sed -n '70,160p' .github/workflows/ci.yaml

printf '%s\n' '=== Helpers without adjacent tests at head ==='
while IFS= read -r helper; do
  case "$helper" in
    *.test.sh) continue ;;
  esac
  test_file="${helper%.sh}.test.sh"
  if [ ! -f "$test_file" ]; then
    printf '%s -> missing %s\n' "$helper" "$test_file"
  fi
done < <(fd -HI -t f -e sh . plugins scripts | sort)

printf '%s\n' '=== Retired directory presence at head ==='
if git cat-file -e "${head}:plugins/gitops-kubernetes/skills/gitops-repo-audit" 2>/dev/null; then
  echo 'ERROR: retired directory still exists'
else
  echo 'PASS: retired directory does not exist'
fi

Length of output: 26572


@devantler I found one medium-priority issue.

  • P2 — Remove audit claims from the published manifests. plugins/gitops-kubernetes/plugin.json at Line 3 and plugins/gitops-kubernetes/.claude-plugin/plugin.json at Line 3 still advertise “repository auditing”. Both files also retain the repository-audit keyword. The same stale description is published through .claude-plugin/marketplace.json and .github/plugin/marketplace.json. The skill directory is deleted, but consumers can still discover and install version 1.0.2 expecting the retired capability. Update the description and remove the audit keyword in the two plugin manifests. Then synchronize both marketplace manifests.

The skill removal, version bump, and CI exemption removal are otherwise consistent with the containment objective.

The attempted standalone helper-pairing check was inconclusive because the sandbox failed to open its process-substitution file descriptor.

You are interacting with an AI system.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

Please review the current containment head ca1c615d9f9d950b97cf5db53c62401cdd083181. It removes the retired audit capability from both portable and strict plugin manifests and synchronizes both marketplace descriptions. The exact catalogue regression probe, manifest parity, version gate, desired-state digest check, and 181 validator self-tests are green.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="devantler-tech/agent-plugins"
pr="184"
head="ca1c615d9f9d950b97cf5db53c62401cdd083181"

printf '%s\n' '=== PR metadata ==='
gh pr view "$pr" --repo "$repo" \
  --json number,title,baseRefName,baseRefOid,headRefName,headRefOid,commits,files \
  --jq '{number,title,baseRefName,baseRefOid,headRefName,headRefOid,
         commits:[.commits[]|{oid,messageHeadline}],
         files:[.files[]|{path,additions,deletions}]}'

base="$(gh pr view "$pr" --repo "$repo" --json baseRefOid --jq -r .baseRefOid)"
test "$head" = "$(git rev-parse HEAD)"

printf '%s\n' '=== Full PR diff stat and paths ==='
git diff --stat "$base" "$head"
git diff --name-status "$base" "$head"

printf '%s\n' '=== Full PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"

printf '%s\n' '=== Published GitOps plugin metadata ==='
for file in \
  plugins/gitops-kubernetes/plugin.json \
  plugins/gitops-kubernetes/.claude-plugin/plugin.json \
  .claude-plugin/marketplace.json \
  .github/plugin/marketplace.json
do
  printf '\n--- %s ---\n' "$file"
  jq . "$file"
done

printf '%s\n' '=== Retired skill and residual discoverability references ==='
if git cat-file -e "${head}:plugins/gitops-kubernetes/skills/gitops-repo-audit" 2>/dev/null; then
  echo 'ERROR: retired skill directory exists'
else
  echo 'PASS: retired skill directory is absent'
fi
git grep -n -i -E \
  '(gitops-repo-audit|repository auditing|repository-audit|repo audit)' \
  "$head" -- . ':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true

printf '%s\n' '=== CI helper exemption changes ==='
git diff --no-ext-diff "$base" "$head" -- .github/workflows/ci.yaml

Length of output: 7245


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="04c49dd3bae09ef29d7286d4ba3cdcc882a5f92e"
head="ca1c615d9f9d950b97cf5db53c62401cdd083181"
range="${base}..${head}"

printf '%s\n' '=== Full PR diff stat and paths ==='
git diff --stat "$range"
git diff --name-status "$range"

printf '%s\n' '=== Full PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$range"

printf '%s\n' '=== Plugin metadata source files ==='
for file in \
  plugins/gitops-kubernetes/plugin.json \
  plugins/gitops-kubernetes/.claude-plugin/plugin.json
do
  printf '\n--- %s ---\n' "$file"
  jq '{name,version,description,keywords}' "$file"
done

printf '%s\n' '=== GitOps marketplace entries ==='
for file in .claude-plugin/marketplace.json .github/plugin/marketplace.json; do
  printf '\n--- %s ---\n' "$file"
  jq '.. | objects | select(.name? == "gitops-kubernetes") | {name,version,description,keywords,source}' "$file"
done

printf '%s\n' '=== Metadata parity ==='
python3 - <<'PY'
import json
from pathlib import Path

portable = json.loads(Path("plugins/gitops-kubernetes/plugin.json").read_text())
strict = json.loads(Path("plugins/gitops-kubernetes/.claude-plugin/plugin.json").read_text())
print("portable/strict name:", portable.get("name") == strict.get("name"))
print("portable/strict version:", portable.get("version") == strict.get("version"))
print("portable/strict description:", portable.get("description") == strict.get("description"))
print("portable/strict keywords:", portable.get("keywords") == strict.get("keywords"))
for filename in [".claude-plugin/marketplace.json", ".github/plugin/marketplace.json"]:
    data = json.loads(Path(filename).read_text())
    entries = []
    def walk(value):
        if isinstance(value, dict):
            if value.get("name") == "gitops-kubernetes":
                entries.append(value)
            for child in value.values():
                walk(child)
        elif isinstance(value, list):
            for child in value:
                walk(child)
    walk(data)
    print(f"{filename} GitOps entries:", len(entries))
    for entry in entries:
        print(f"{filename} version matches:", entry.get("version") == portable.get("version"))
        print(f"{filename} description matches:", entry.get("description") == portable.get("description"))
PY

printf '%s\n' '=== Retired skill and residual discoverability references ==='
if git cat-file -e "${head}:plugins/gitops-kubernetes/skills/gitops-repo-audit" 2>/dev/null; then
  echo 'ERROR: retired skill directory exists'
else
  echo 'PASS: retired skill directory is absent'
fi
git grep -n -i -E \
  '(gitops-repo-audit|repository auditing|repository-audit|repo audit)' \
  "$head" -- . ':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true

printf '%s\n' '=== CI workflow diff ==='
git diff --no-ext-diff "$range" -- .github/workflows/ci.yaml

Length of output: 194545


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="04c49dd3bae09ef29d7286d4ba3cdcc882a5f92e"
head="ca1c615d9f9d950b97cf5db53c62401cdd083181"
range="${base}..${head}"

printf '%s\n' '=== Non-deleted changes ==='
git diff --no-ext-diff "$range" -- \
  .claude-plugin/marketplace.json \
  .github/plugin/marketplace.json \
  .github/workflows/ci.yaml \
  README.md \
  plugins/gitops-kubernetes/plugin.json \
  plugins/gitops-kubernetes/.claude-plugin/plugin.json

printf '%s\n' '=== GitOps plugin files at head ==='
fd -HI -t f . plugins/gitops-kubernetes | sort

printf '%s\n' '=== All current references to retired skill path ==='
git grep -n -F 'skills/gitops-repo-audit' "$head" -- . || true

printf '%s\n' '=== Current GitOps README catalogue row ==='
rg -n -C 2 'gitops-kubernetes' README.md

Length of output: 17263


@devantler No findings.

The PR removes the retired skill directory and all tracked references to skills/gitops-repo-audit.

The two plugin manifests now have matching 1.0.2 metadata. They no longer claim repository auditing or include the repository-audit keyword.

Both marketplace manifests match the plugin version and description. The README catalogue entry also removes the retired skill and audit claim.

The CI change removes only exemptions for deleted helpers. The general helper self-test enforcement remains.

I did not execute repository test commands because the review sandbox does not permit execution of repository files. The static review is complete.


If you found this review helpful, would you consider giving us a shout-out on X?

Thank you for using CodeRabbit!

You are interacting with an AI system.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

1 participant