# Git Security

> Use this tool when you need to identify security risks in GitHub repositories, such as secret exposures and vulnerability exploits, to ensure the integrity of your codebase. It analyzes commit history, dependencies, and package manifests to detect potential threats, providing a comprehensive security audit. Ideal for use in CI/CD pipelines and automated security monitoring, Git Security offers standardized output for easy integration with AI agents.

Canonical page: https://skillsregistry.net/skills/felip3s-git-security  
JSON: https://api.skillsregistry.net/v1/skills/felip3s-git-security

## Description

Analyzes GitHub repositories for security risks with four scanning tools: secret detection in commit history via TruffleHog, CVE vulnerability scanning of dependencies via Trivy, high-churn hotspot file identification from git history, and full dependency inventory extraction from package manifests. Designed for reliable agent integration with standardized response structures.

## Trust

- **Trust score (0–1):** 0.98
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** version-control
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/felip3s-git-security)
- **Repository:** <https://github.com/felip3s/git_sec_mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "felip3s-git-security"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/felip3s-git-security` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/felip3s-git-security/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
