Skip to content
Back to skills

Git Mirror Audit

ASecurity

Verify configured secondary git mirrors are present and not drifting from the primary remote/default branch

  • 207 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 29, 2026
ai-agentsgobashgitsecurity

Security analysis

A100/100

Scanned May 29, 2026

npx -y skills add jmagly/aiwg --skill git-mirror-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Git Mirror Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Git Mirror Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jmagly-git-mirror-audit/badge)](https://www.skillsdirectory.com/skills/jmagly-git-mirror-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
namespace: aiwg
name: git-mirror-audit
platforms: [all]
description: Verify configured secondary git mirrors are present and not drifting from the primary remote/default branch
requires:
  - git: repository with remotes
  - config: .aiwg/aiwg.config remotes.secondary[] entries
ensures:
  - report: mirror drift per configured secondary remote
  - exit-code: non-zero when drift exists and --fail-on-drift is set
errors:
  - config-missing: no remotes.secondary[] configured
  - remote-missing: configured secondary remote does not exist in git remote
invariants:
  - read-only audit; never pushes to mirrors
  - backup-mirror semantics are reported separately from active replication
commandHint:
  argumentHint: "[--fail-on-drift] [--default-branch <name>] [--format text|json]"
  allowedTools: Read, Bash
  model: sonnet
  category: maintenance
  orchestration: false
---

# Git Mirror Audit

Audit redundant git mirrors declared in `.aiwg/aiwg.config`:

```json
{
  "remotes": {
    "primary": "origin",
    "secondary": [
      {
        "name": "github",
        "purpose": "backup-mirror",
        "push_on_release": true
      }
    ]
  }
}
```

## Execution Flow

1. Read `remotes.primary`, `delivery.default_branch`, and `remotes.secondary[]`.
2. Confirm every configured secondary exists in `git remote`.
3. Fetch remote refs in read-only mode when the operator permits network access.
4. Compare `refs/remotes/{primary}/{default_branch}` with each secondary's default branch ref.
5. Report drift, missing remotes, and last known commit for each mirror.

## Semantics

- `purpose: backup-mirror` means the mirror is a disaster-recovery copy and should receive release pushes.
- `push_on_release: true` means release procedures must push tags and release commits to that mirror before declaring release complete.
- This skill audits state; it never performs the push.

## References

- `agentic/code/addons/aiwg-utils/rules/delivery-policy.md`
- `.aiwg/security/curl-checklist-gap-analysis.md` row 3, Practice 21

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…