Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Help

ASecurity

Explain what the gitreceipts plugin can do — its commands, scopes, switches, and setup. Use when the user asks for gitreceipts help, how to use the gitreceipts plugin, or what its skills can do.

2 stars
0 votes
0 copies
0 views
Added 9/19/2026
developmentgobashrailsgit

Works with

claude code

Security Analysis

A100/100

Scanned 9/19/2026

$npx -y skills add jagmeetchawla/gitreceipts --skill help --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Help?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Help
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jagmeetchawla-help/badge)](https://www.skillsdirectory.com/skills/jagmeetchawla-help)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
description: Explain what the gitreceipts plugin can do — its commands, scopes, switches, and setup. Use when the user asks for gitreceipts help, how to use the gitreceipts plugin, or what its skills can do.
---

# gitreceipts plugin — help

Present this reference to the user, concisely and formatted:

**What it is.** gitreceipts reads a Claude Code session against the repo's
git history: each prompt you typed → the work it drove → the commit it
became. Runs locally; nothing leaves the machine.

**Setup.** Needs the `git-receipts` binary (0.1.1+, identity needs 0.1.3 — the skills offer the
upgrade if yours is older, and work either way). If it's missing, the
skills detect what you have and offer to install it — your approval, your
choice of route: `brew install cloudcraft-ai/tap/gitreceipts` ·
`cargo install gitreceipts` (then `git-receipts man --install` once) · or a
checksum-verified prebuilt binary, no package manager needed.

**Two skills, one receipt.**

| | |
|---|---|
| **`/gitreceipts:recap`** | *where are things* — the state-face: what you asked, what the agent did, what landed. Fires on "what happened here", "catch me up", "recap that commit". |
| **`/gitreceipts:audit`** | *where should I look* — the attention-ladder: every claimed edit checked against the real commit blobs, and the broken-promise count. Fires on "did that land", "any broken promises", and when a delegated lane reports done. |

Same receipt and the same checking underneath — recap just doesn't lead with
the score. Recap orients; the audit escalates.

**Say it however you like** — both skills map plain language to scopes:

| You say | It runs |
|---|---|
| nothing / "what happened" | all sessions for this repo |
| "this session" | the live one, found by identity (not newest-file guessing) |
| "the last run" | `--latest` |
| "what happened in commit X" | `--commit <hash>` |
| "all my repos here" | `--project` |
| "more detail" | `--verbose` |
| "just the problems" | `--filter red-amber` |
| "include my own commits" | `--full-history` (yours, outside this session) |
| "include everyone's commits" | `--all-authors` (other contributors too) |
| "that old email is me too" | `--me <name\|email>` |

**It follows git's conventions.** Git decides whose commits are yours —
`user.name`/`user.email`, matched on author or committer, `.mailmap`
honoured — and `.gitignore` decides which paths git was never going to take,
so a claimed edit to one of those is an explained finding, not a broken
promise. Every report states the identity it used and how much of the window
it covered; if nothing matches it refuses to run rather than print an empty
green report.

**Reading the marks.** 🟢 nothing to report · ⚪ explained findings, each
with its reason · 🟡 unexplained residue — a loose end with no answer on
record · 🔴 a broken promise: a claimed edit git never got. The verdict is
what git can witness; everything else is a finding. `broken promises: 0`
is earned, not assumed — and a red is a question, not a conviction.

**Three ways to keep it** — same receipt, different artifact:

| | |
|---|---|
| **`/gitreceipts:HTMLReport-Compact`** | a small page that renders right here in the preview. One commit is ~20KB; a whole repo a few hundred. Findings keep their full detail; everything else collapses, and every cap says what it hid. |
| **`/gitreceipts:HTMLReport-Full`** | the complete record — every commit's files, commands and conversation — opened in your browser. Too big for a preview pane by design. |
| **`/gitreceipts:JSONExport`** | the data: a versioned receipt to commit, diff between runs, or feed to another tool. Same numbers as both pages. |

**Sharing.** Reports are built from your prompts and command output —
private by default. For a shareable one: `--no-intent` (drops the
conversation, keeps every count), `--no-identity`, `--redact <word>`. Home
paths are masked automatically.

**Guardrails.** Never disables the secret/PII scanner, never installs the
binary unasked (it offers; you approve and pick the route), never loads a
full report into the conversation, and every run goes through your normal
Bash permission prompt.

**More:** README, docs/WHAT-GETS-AUDITED.md and KNOWN-LIMITATIONS.md at
https://github.com/jagmeetchawla/gitreceipts

Attribution

jagmeetchawlajagmeetchawla
View sourceSee grades on GitHubMore from jagmeetchawla →
SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills Directory ProSkills Directory

Get any skill into Claude in one click.

Download any skill as a ZIP for Claude.ai, Claude Desktop, or .claude/skills. $9/mo.

See Pro

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

285172 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10341 votes
View all in development →