Repository navigation
chore(agents): stop bundling the gitops-repo-audit skill - #4138
Conversation
Its -E mode sources a caller-supplied dotenv as shell, so repository content under audit can execute commands with the auditor's credentials. The skill is third-party and the updater only refreshes installed skills, so removing it closes the path without editing upstream content. Fixes #3380 Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
@coderabbitai review |
|
|
Warning Review limit reachedNext included review available in 21 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository YAML (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (30)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. Another round soon, please! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Ready at
|
Why
A bundled third-party audit skill runs a settings file taken from the repository it audits as shell commands, so content under audit could execute commands with the auditor's credentials. The fix belongs to its upstream project, which an unattended run cannot contact, and the plugin marketplace already stopped shipping this skill for the same reason.
What
Stops bundling that skill in this repository. The daily skill updater only refreshes skills that are already installed, so the removal stays in place. Writing usage guidance for a skill we no longer ship is no longer needed.
Fixes #3380