Visibility — govern what git is allowed to see
Two modes, defined by which .gitignore is active. The templates live in
templates/; the first line of the active .gitignore names the current
mode.
- public (default): fail-closed whitelist — only framework files can be committed. Safe to attach a public remote.
- private: life content (area folders,
inbox.md,CLAUDE.local.md,.claude/rules/) is versioned too, so git history becomes memory.private/, secrets,artifacts/,tmp/, and.claude/settings.local.jsonstay ignored in BOTH modes.
$ARGUMENTS is public, private, or status. With no argument, report
status and ask which mode the user wants.
status
Report: current mode (first line of .gitignore), git remote -v, and the
history audit result (see below). Recommend nothing unless asked.
Switching to private
- Check remotes first. If any remote could be public (for GitHub remotes
verify with
gh repo view --json visibilitywhen available), STOP and warn: private mode must never feed a public remote. Proceed only after the user confirms the remote is private or removes it. - Copy
templates/gitignore-privateover.gitignore. - Show what would now be tracked (
git status --short) and offer to commit the personal layer. - If no remote exists, suggest — do not create unasked — a PRIVATE GitHub remote as an off-machine backup.
Switching to public
- Copy
templates/gitignore-publicover.gitignore. - Re-apply ignores to the index:
git rm -r --cached .thengit add .(files stay on disk). Show the resulting status before any commit. - HISTORY AUDIT — the step that keeps this safe. List every path ever
committed (
git log --all --diff-filter=A --name-only --pretty=format:) and compare against the framework whitelist in the public template. If personal paths appear in ANY commit, say clearly:- This branch's HISTORY still contains personal content. Untracking does not remove it from history. This branch must never be pushed anywhere public.
- The safe publish path is an orphan branch holding only framework files
(
git checkout --orphan public→ commit framework → publish that), while the full-history branch stays private. Offer it; never rewrite history unasked.
- Report "safe to publish" ONLY when the audit finds framework-only history.
Rules
- Never push, change a remote's visibility, or rewrite history without explicit confirmation — show every irreversible step before taking it.
- If the current
.gitignorematches neither template, the mode is unknown: show the diff against the nearest template and ask before overwriting.