Repository navigation
fix(gitops-kubernetes): retire unsafe repo audit skill - #184
Conversation
@coderabbitai full review Please review the current containment head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
head="1824964c7e143125bc06780d866955646be22bb1"
parent="$(git rev-parse "${head}^")"
printf '%s\n' '=== Commit ==='
git show -s --format='Commit: %H%nParents: %P%nSubject: %s%n%n%b' "$head"
printf '%s\n' '=== Changed files ==='
git diff-tree --no-commit-id --name-status -r "$head"
printf '%s\n' '=== Diff stat ==='
git diff --stat "$parent" "$head"
printf '%s\n' '=== Full diff ==='
git diff --find-renames --find-copies --no-ext-diff "$parent" "$head"
printf '%s\n' '=== Candidate repository files ==='
fd -HI -t f . | rg -i '(gitops|audit|skill|plugin|manifest|provenance|cache|exempt|workflow|action)'
printf '%s\n' '=== Relevant references in tracked text files ==='
rg -n -i -C 2 \
'(gitops-kubernetes|repo[ _-]?audit|audit[ _-]?repo|unsafe|cache[ _-]?version|1\.0\.[0-9]+|exempt(ion|ed)?|provenance)' \
-g '!node_modules/**' -g '!dist/**' -g '!build/**' . || trueLength of output: 81542 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="devantler-tech/agent-plugins"
pr=184
head="1824964c7e143125bc06780d866955646be22bb1"
printf '%s\n' '=== Pull request metadata ==='
gh pr view "$pr" --repo "$repo" \
--json number,title,baseRefName,baseRefOid,headRefName,headRefOid,commits,files \
--jq '{number,title,baseRefName,baseRefOid,headRefName,headRefOid,
commits:[.commits[]|{oid:.oid,messageHeadline:.messageHeadline}],
files:[.files[]|{path:.path,additions:.additions,deletions:.deletions]}'
base="$(gh pr view "$pr" --repo "$repo" --json baseRefOid --jq -r .baseRefOid)"
printf '%s\n' '=== Complete PR diff stat ==='
git diff --stat "$base" "$head"
printf '%s\n' '=== Complete PR changed files ==='
git diff --name-status "$base" "$head"
printf '%s\n' '=== Complete PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"
printf '%s\n' '=== Current GitOps manifests and README row ==='
for file in \
plugins/gitops-kubernetes/plugin.json \
plugins/gitops-kubernetes/.claude-plugin/plugin.json \
.claude-plugin/marketplace.json \
.github/plugin/marketplace.json \
README.md \
.github/workflows/ci.yaml
do
printf '\n--- %s ---\n' "$file"
sed -n '1,260p' "$file"
done
printf '%s\n' '=== Retired skill path at base and head ==='
printf '%s\n' '-- base --'
git ls-tree -r --name-only "$base" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true
printf '%s\n' '-- head --'
git ls-tree -r --name-only "$head" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true
printf '%s\n' '=== Remaining audit-capability references at head ==='
git grep -n -i -E '(gitops-repo-audit|repository auditing|repo audit)' "$head" -- \
':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || trueLength of output: 2351 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="devantler-tech/agent-plugins"
pr=184
head="1824964c7e143125bc06780d866955646be22bb1"
printf '%s\n' '=== Pull request metadata ==='
gh pr view "$pr" --repo "$repo" \
--json number,title,baseRefName,baseRefOid,headRefName,headRefOid,commits,files \
--jq '{number,title,baseRefName,baseRefOid,headRefName,headRefOid,
commits:[.commits[]|{oid:.oid,messageHeadline:.messageHeadline}],
files:[.files[]|{path:.path,additions:.additions,deletions:.deletions}]}'
base="$(gh pr view "$pr" --repo "$repo" --json baseRefOid --jq -r .baseRefOid)"
printf '%s\n' '=== Complete PR diff stat ==='
git diff --stat "$base" "$head"
printf '%s\n' '=== Complete PR changed files ==='
git diff --name-status "$base" "$head"
printf '%s\n' '=== Complete PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"
printf '%s\n' '=== Current GitOps manifests and README row ==='
for file in \
plugins/gitops-kubernetes/plugin.json \
plugins/gitops-kubernetes/.claude-plugin/plugin.json \
.claude-plugin/marketplace.json \
.github/plugin/marketplace.json \
README.md \
.github/workflows/ci.yaml
do
printf '\n--- %s ---\n' "$file"
sed -n '1,260p' "$file"
done
printf '%s\n' '=== Retired skill path at base and head ==='
printf '%s\n' '-- base --'
git ls-tree -r --name-only "$base" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true
printf '%s\n' '-- head --'
git ls-tree -r --name-only "$head" -- plugins/gitops-kubernetes/skills/gitops-repo-audit || true
printf '%s\n' '=== Remaining audit-capability references at head ==='
git grep -n -i -E '(gitops-repo-audit|repository auditing|repo audit)' "$head" -- \
':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || trueLength of output: 7216 🏁 Script executed: #!/bin/bash
set -euo pipefail
base="04c49dd3bae09ef29d7286d4ba3cdcc882a5f92e"
head="1824964c7e143125bc06780d866955646be22bb1"
range="${base}..${head}"
printf '%s\n' '=== Complete PR diff stat and name status ==='
git diff --stat "$range"
git diff --name-status "$range"
printf '%s\n' '=== Metadata and README diffs ==='
git diff --no-ext-diff "$range" -- \
.claude-plugin/marketplace.json \
.github/plugin/marketplace.json \
plugins/gitops-kubernetes/plugin.json \
plugins/gitops-kubernetes/.claude-plugin/plugin.json \
README.md \
.github/workflows/ci.yaml
printf '%s\n' '=== GitOps metadata at head ==='
for file in \
plugins/gitops-kubernetes/plugin.json \
plugins/gitops-kubernetes/.claude-plugin/plugin.json \
.claude-plugin/marketplace.json \
.github/plugin/marketplace.json
do
printf '\n--- %s ---\n' "$file"
jq . "$file"
done
printf '%s\n' '=== Audit-related text at head ==='
git grep -n -i -E '(gitops-repo-audit|repository auditing|repo audit)' "$head" -- . \
':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true
printf '%s\n' '=== CI helper pairing section ==='
sed -n '70,160p' .github/workflows/ci.yaml
printf '%s\n' '=== Helpers without adjacent tests at head ==='
while IFS= read -r helper; do
case "$helper" in
*.test.sh) continue ;;
esac
test_file="${helper%.sh}.test.sh"
if [ ! -f "$test_file" ]; then
printf '%s -> missing %s\n' "$helper" "$test_file"
fi
done < <(fd -HI -t f -e sh . plugins scripts | sort)
printf '%s\n' '=== Retired directory presence at head ==='
if git cat-file -e "${head}:plugins/gitops-kubernetes/skills/gitops-repo-audit" 2>/dev/null; then
echo 'ERROR: retired directory still exists'
else
echo 'PASS: retired directory does not exist'
fiLength of output: 26572
The skill removal, version bump, and CI exemption removal are otherwise consistent with the containment objective. The attempted standalone helper-pairing check was inconclusive because the sandbox failed to open its process-substitution file descriptor. You are interacting with an AI system. |
@coderabbitai full review Please review the current containment head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="devantler-tech/agent-plugins"
pr="184"
head="ca1c615d9f9d950b97cf5db53c62401cdd083181"
printf '%s\n' '=== PR metadata ==='
gh pr view "$pr" --repo "$repo" \
--json number,title,baseRefName,baseRefOid,headRefName,headRefOid,commits,files \
--jq '{number,title,baseRefName,baseRefOid,headRefName,headRefOid,
commits:[.commits[]|{oid,messageHeadline}],
files:[.files[]|{path,additions,deletions}]}'
base="$(gh pr view "$pr" --repo "$repo" --json baseRefOid --jq -r .baseRefOid)"
test "$head" = "$(git rev-parse HEAD)"
printf '%s\n' '=== Full PR diff stat and paths ==='
git diff --stat "$base" "$head"
git diff --name-status "$base" "$head"
printf '%s\n' '=== Full PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"
printf '%s\n' '=== Published GitOps plugin metadata ==='
for file in \
plugins/gitops-kubernetes/plugin.json \
plugins/gitops-kubernetes/.claude-plugin/plugin.json \
.claude-plugin/marketplace.json \
.github/plugin/marketplace.json
do
printf '\n--- %s ---\n' "$file"
jq . "$file"
done
printf '%s\n' '=== Retired skill and residual discoverability references ==='
if git cat-file -e "${head}:plugins/gitops-kubernetes/skills/gitops-repo-audit" 2>/dev/null; then
echo 'ERROR: retired skill directory exists'
else
echo 'PASS: retired skill directory is absent'
fi
git grep -n -i -E \
'(gitops-repo-audit|repository auditing|repository-audit|repo audit)' \
"$head" -- . ':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true
printf '%s\n' '=== CI helper exemption changes ==='
git diff --no-ext-diff "$base" "$head" -- .github/workflows/ci.yamlLength of output: 7245 🏁 Script executed: #!/bin/bash
set -euo pipefail
base="04c49dd3bae09ef29d7286d4ba3cdcc882a5f92e"
head="ca1c615d9f9d950b97cf5db53c62401cdd083181"
range="${base}..${head}"
printf '%s\n' '=== Full PR diff stat and paths ==='
git diff --stat "$range"
git diff --name-status "$range"
printf '%s\n' '=== Full PR diff ==='
git diff --find-renames --find-copies --no-ext-diff "$range"
printf '%s\n' '=== Plugin metadata source files ==='
for file in \
plugins/gitops-kubernetes/plugin.json \
plugins/gitops-kubernetes/.claude-plugin/plugin.json
do
printf '\n--- %s ---\n' "$file"
jq '{name,version,description,keywords}' "$file"
done
printf '%s\n' '=== GitOps marketplace entries ==='
for file in .claude-plugin/marketplace.json .github/plugin/marketplace.json; do
printf '\n--- %s ---\n' "$file"
jq '.. | objects | select(.name? == "gitops-kubernetes") | {name,version,description,keywords,source}' "$file"
done
printf '%s\n' '=== Metadata parity ==='
python3 - <<'PY'
import json
from pathlib import Path
portable = json.loads(Path("plugins/gitops-kubernetes/plugin.json").read_text())
strict = json.loads(Path("plugins/gitops-kubernetes/.claude-plugin/plugin.json").read_text())
print("portable/strict name:", portable.get("name") == strict.get("name"))
print("portable/strict version:", portable.get("version") == strict.get("version"))
print("portable/strict description:", portable.get("description") == strict.get("description"))
print("portable/strict keywords:", portable.get("keywords") == strict.get("keywords"))
for filename in [".claude-plugin/marketplace.json", ".github/plugin/marketplace.json"]:
data = json.loads(Path(filename).read_text())
entries = []
def walk(value):
if isinstance(value, dict):
if value.get("name") == "gitops-kubernetes":
entries.append(value)
for child in value.values():
walk(child)
elif isinstance(value, list):
for child in value:
walk(child)
walk(data)
print(f"{filename} GitOps entries:", len(entries))
for entry in entries:
print(f"{filename} version matches:", entry.get("version") == portable.get("version"))
print(f"{filename} description matches:", entry.get("description") == portable.get("description"))
PY
printf '%s\n' '=== Retired skill and residual discoverability references ==='
if git cat-file -e "${head}:plugins/gitops-kubernetes/skills/gitops-repo-audit" 2>/dev/null; then
echo 'ERROR: retired skill directory exists'
else
echo 'PASS: retired skill directory is absent'
fi
git grep -n -i -E \
'(gitops-repo-audit|repository auditing|repository-audit|repo audit)' \
"$head" -- . ':!plugins/gitops-kubernetes/skills/gitops-knowledge/references/*' || true
printf '%s\n' '=== CI workflow diff ==='
git diff --no-ext-diff "$range" -- .github/workflows/ci.yamlLength of output: 194545 🏁 Script executed: #!/bin/bash
set -euo pipefail
base="04c49dd3bae09ef29d7286d4ba3cdcc882a5f92e"
head="ca1c615d9f9d950b97cf5db53c62401cdd083181"
range="${base}..${head}"
printf '%s\n' '=== Non-deleted changes ==='
git diff --no-ext-diff "$range" -- \
.claude-plugin/marketplace.json \
.github/plugin/marketplace.json \
.github/workflows/ci.yaml \
README.md \
plugins/gitops-kubernetes/plugin.json \
plugins/gitops-kubernetes/.claude-plugin/plugin.json
printf '%s\n' '=== GitOps plugin files at head ==='
fd -HI -t f . plugins/gitops-kubernetes | sort
printf '%s\n' '=== All current references to retired skill path ==='
git grep -n -F 'skills/gitops-repo-audit' "$head" -- . || true
printf '%s\n' '=== Current GitOps README catalogue row ==='
rg -n -C 2 'gitops-kubernetes' README.mdLength of output: 17263
The PR removes the retired skill directory and all tracked references to The two plugin manifests now have matching Both marketplace manifests match the plugin version and description. The README catalogue entry also removes the retired skill and audit claim. The CI change removes only exemptions for deleted helpers. The general helper self-test enforcement remains. I did not execute repository test commands because the review sandbox does not permit execution of repository files. The static review is complete. If you found this review helpful, would you consider giving us a shout-out on X? Thank you for using CodeRabbit! You are interacting with an AI system. |
Why
A synced skills update reached
maindespite a verified command-execution blocker. The follow-up version bump then made that unreviewed bundle available under a fresh cache key.What
1.0.2cache key.Refs #164.
Refs #178.