SKILL.md
Repo Hardening
Audit and fix GitHub repository security settings using the bundled scripts/harden.sh.
Prerequisites
Before running the script, ensure:
ghCLI is installed and authenticated (gh auth login)jqis installed- The user has sufficient access to the target repository:
- audit can run with read access, with inaccessible endpoints reported as skip - fix requires admin access
The script checks prerequisites and exits with a clear error if required tools, authentication, or fix permissions are missing.
Workflow
Always follow this sequence:
- Resolve the script path — run the bundled script via the path to this skill directory, not the current project directory:
``bash SKILLDIR="/path/to/repo-hardening" # directory containing this SKILL.md HARDENSCRIPT="$SKILL_DIR/scripts/harden.sh" ``
- Audit first — run the audit to see current state:
``bash bash "$HARDEN_SCRIPT" audit --repo OWNER/REPO ``
- Present findings — summarise the audit results to the user, highlighting
failandwarnitems grouped by severity (critical > high > medium > low).
- Dry-run before fixing — ask the user which categories to fix. Use explicit
--checksto scope fixes to the confirmed categories, then run--dry-runbefore any mutation:
``bash bash "$HARDEN_SCRIPT" fix --repo OWNER/REPO --checks branches,security --dry-run ``
If branch protection has no existing required status checks, pass each CI context explicitly: ``bash bash "$HARDEN_SCRIPT" fix --repo OWNER/REPO --checks branches --required-check "test" --dry-run ``
- Apply the exact approved plan — once confirmed, rerun the exact dry-run command with only
--dry-runremoved. Keep the same scoped--checksand any--required-checkoptions from the preview:
```bash bash "$HARDEN_SCRIPT" fix --repo OWNER/REPO --checks branches,security
# If the approved dry-run included required checks: bash "$HARDEN_SCRIPT" fix --repo OWNER/REPO --checks branches --required-check "test" ```
- Verify — run audit again to confirm all checks pass.
Check Categories
| Category | Flag | What it covers |
|---|---|---|
repo |
--checks repo |
Auto-delete branches, suggest PR updates, wiki/projects |
branches |
--checks branches |
Branch protection: require PRs, reviews, code owners, checks |
security |
--checks security |
Dependabot, secret scanning, push protection |
merge |
--checks merge |
Merge strategy enforcement (rebase by default) |
actions |
--checks actions |
Actions permissions, workflow token, PR approval restrictions |
access |
--checks access |
CODEOWNERS, deploy keys, outside collaborators (report only) |
Audits run all categories by default. Fixes require an explicit --checks value; use --checks all only when the user has approved changing every category.
Key Options
--merge-strategy rebase|squash|any— which merge method to enforce (default: rebase)--min-reviewers N— minimum required PR reviewers, 1-6 (default: 1)--branch BRANCH— branch to protect (default: repo's default branch)--required-check NAME— required status check context to add for branch protection; repeat for multiple checks. Existing required contexts and app-backed checks are preserved.--format json|text— output format (default: json)
Interpreting Results
Audit statuses:
pass— meets the hardened policyfail— does not meet policy; fixable by the scriptwarn— informational; needs human review (e.g. deploy keys, wiki)skip— not applicable or insufficient permissions (e.g. GHAS features on private repos)
Severity levels: critical > high > medium > low
For detailed documentation of each check, see [references/checks.md](references/checks.md).
Multi-Repo Hardening
To audit all repos in an org:
gh repo list ORGNAME --limit 1000 --json nameWithOwner -q '.[].nameWithOwner' | \
while read -r repo; do bash "$HARDEN_SCRIPT" audit --repo "$repo"; done
Limitations
- GHAS features: Secret scanning push protection requires GitHub Advanced Security on private repos. The script skips these gracefully.
- Org-level overrides: Some settings (Actions policies, required workflows) can be locked at the org level and cannot be changed per-repo.
- CODEOWNERS content: The script checks for the file's existence but does not validate its contents.
- Access checks: Deploy keys and outside collaborators are reported but not modified — they require human judgement.