# Github Repo Scout

> Investigate a GitHub repository from a URL by reviewing its README, file tree, local clone status, and recommended next steps. Use for: GitHub URL, check this repository, scout repository, understand this project.

- Skill: `stijnman/github-repo-scout` (Agent Skill)
- Install (CLI): `npx skillmds@latest add stijnman/github-repo-scout`
- Raw SKILL.md: https://api.skillmd.com/api/skills/stijnman/github-repo-scout/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- License: MIT
- Author: Stijnman (https://skillmd.com/u/stijnman)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/stijnman/github-repo-scout

---

# GitHub Repo Scout
## When to Use

- User says **github.com** or task matches this capability
- User says **check this repo** or task matches this capability
- User says **scout repo** or task matches this capability
- User says **what is this project** or task matches this capability

## Workflow

1. Parse owner/repo from URL; reject non-GitHub hosts unless user confirms.
2. Fetch README and top-level tree via public API or git clone (read-only).
3. Compare README claims vs actual committed files (note drift).
4. Check if repo exists locally in workspace or common clone paths.
5. Summarize: purpose, install steps, risks, suggested actions (clone, audit, review).
6. Do not access private repos without authenticated user context.

## Integrations

- `oss-repo-maintainer`
- `defensive-mcp-audit`
- `skill-rubric-reviewer`

## Error Handling

| Failure | Response |
|---------|----------|
| 404/private repo | State access limitation; ask user to clone locally. |
| Rate limited | Backoff; use local clone if available. |

## Gotchas

- Public repos only unless user has authenticated MCP/GitHub access.

## Safety & Ethics (Publication-Ready)

This skill is designed for public distribution. Constraints:

- Read-only repository inspection.
- No harvesting of tokens, secrets, or private issue content.
- Do not auto-clone into system directories without user approval.

### Prohibited actions

- No unauthorized access, malware, or harmful automation
- No silent exfiltration of data, credentials, or telemetry
- No destructive system changes without hitl-approver
- No publication of user PII or environment secrets in outputs

## Example

**Input:** User request matching triggers above.
**Output:** Structured result per workflow; local artifacts only unless user opts in.

