Skip to content

chore(agents): stop bundling the gitops-repo-audit skill - #4138

Merged
devantler merged 1 commit into
mainfrom
claude/agents-retire-gitops-repo-audit-3380
Sep 24, 2026
Merged

devantler merged 1 commit into
mainfrom
claude/agents-retire-gitops-repo-audit-3380

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

A bundled third-party audit skill runs a settings file taken from the repository it audits as shell commands, so content under audit could execute commands with the auditor's credentials. The fix belongs to its upstream project, which an unattended run cannot contact, and the plugin marketplace already stopped shipping this skill for the same reason.

What

Stops bundling that skill in this repository. The daily skill updater only refreshes skills that are already installed, so the removal stays in place. Writing usage guidance for a skill we no longer ship is no longer needed.

Fixes #3380

Its -E mode sources a caller-supplied dotenv as shell, so repository
content under audit can execute commands with the auditor's credentials.
The skill is third-party and the updater only refreshes installed skills,
so removing it closes the path without editing upstream content.

Fixes #3380

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 21 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: baa570e9-d10b-4648-9af1-5c7d4e20ed58

📥 Commits

Reviewing files that changed from the base of the PR and between 93d71cb and b63fbde.

📒 Files selected for processing (30)
  • .agents/skills/gitops-repo-audit/SKILL.md
  • .agents/skills/gitops-repo-audit/assets/schemas/alert-notification-v1beta3.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/artifactgenerator-source-v1beta1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/bucket-source-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/externalartifact-source-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/fluxinstance-fluxcd-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/fluxreport-fluxcd-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/gitrepository-source-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/helmchart-source-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/helmrelease-helm-v2.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/helmrepository-source-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/imagepolicy-image-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/imagerepository-image-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/imageupdateautomation-image-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/kustomization-kustomize-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/ocirepository-source-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/provider-notification-v1beta3.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/receiver-notification-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/resourceset-fluxcd-v1.fields.txt
  • .agents/skills/gitops-repo-audit/assets/schemas/resourcesetinputprovider-fluxcd-v1.fields.txt
  • .agents/skills/gitops-repo-audit/evals/evals.json
  • .agents/skills/gitops-repo-audit/references/api-migration.md
  • .agents/skills/gitops-repo-audit/references/best-practices.md
  • .agents/skills/gitops-repo-audit/references/flux-api-summary.md
  • .agents/skills/gitops-repo-audit/references/flux-operator-api-summary.md
  • .agents/skills/gitops-repo-audit/references/repo-patterns.md
  • .agents/skills/gitops-repo-audit/references/security-audit.md
  • .agents/skills/gitops-repo-audit/scripts/check-deprecated.sh
  • .agents/skills/gitops-repo-audit/scripts/discover.sh
  • .agents/skills/gitops-repo-audit/scripts/validate.sh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T11:15:51.892490Z b63fbde Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Another round soon, please!

Reviewed commit: b63fbdee45

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Ready at b63fbdee4578afc997eb84e6835184db54ac944c.

  • Tested: all 29 CI checks are green (18 passed, 11 skipped by path filter). The change only deletes files.
  • Reviewed: Codex returned a clean review at this head (11:15Z). CodeRabbit declined this round with a rate limit at 11:14Z. There are no threads and no body findings.
  • Evaluated (static): this change has no runtime surface. It removes an agent skill that nothing in the cluster or CI runs. I checked instead that no other file in the repository references the skill, that the daily skill updater only refreshes skills already installed (gh skill update --dir), so it will not add the skill back, and that the vulnerable lines are still on main today. That last check is what makes the removal worth doing.

@devantler
devantler marked this pull request as ready for review September 24, 2026 11:16
@devantler
devantler added this pull request to the merge queue Sep 24, 2026
Merged via the queue into main with commit d0f3a23 Sep 24, 2026
29 checks passed
@devantler
devantler deleted the claude/agents-retire-gitops-repo-audit-3380 branch September 24, 2026 11:21
@github-project-automation github-project-automation Bot moved this from 🫴 Ready to ✅ Done in 🌊 Project Board Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

docs(agents): pin safe dotenv construction for the gitops-repo-audit -E flag

1 participant