librarian
Cache and refresh remote git repositories under ~/.cache/checkouts/<host>/<org>/<repo> so future references can reuse a local copy. Use this skill when the user points you to a remote git repository as reference or you encountered a remote git repo through other means.
How do I install this agent skill?
npx skills add https://github.com/mitsuhiko/agent-stuff --skill librarianIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
The skill is vulnerable to path traversal, which could allow a malicious repository identifier to trigger clones into unintended directory locations outside the designated cache. It is also susceptible to indirect prompt injection via untrusted repository links encountered in external content.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
- Runlayerwarn
1/2 files flagged
- ZeroLeakspass
Score: 93/100 · 2 sections analyzed
What does this agent skill do?
Use this skill when the user points you to a remote git repository (GitHub/GitLab/Bitbucket URLs, git@..., or owner/repo shorthand).
The goal is to keep a reusable local checkout that is:
- stable (predictable path)
- up to date (periodic fetch + fast-forward when safe)
- efficient (partial clone with
--filter=blob:none, no repeated full clones)
Cache location
Repositories are stored at:
~/.cache/checkouts/<host>/<org>/<repo>
Example:
github.com/mitsuhiko/minijinja → ~/.cache/checkouts/github.com/mitsuhiko/minijinja
Command
bash checkout.sh <repo> --path-only
Examples:
bash checkout.sh mitsuhiko/minijinja --path-only
bash checkout.sh github.com/mitsuhiko/minijinja --path-only
bash checkout.sh https://github.com/mitsuhiko/minijinja --path-only
The script will:
- Parse the repo reference into host/org/repo.
- Clone if missing.
- Reuse existing checkout if present.
- Fetch from
originwhen stale (default interval: 300s). - Attempt a fast-forward merge if the checkout is clean and has an upstream.
Update strategy
- Default behavior is throttled refresh (every 5 minutes) to avoid unnecessary network calls.
- Force immediate refresh with:
bash checkout.sh <repo> --force-update --path-only
Recommended workflow
- Resolve repository path via
checkout.sh --path-only. - Use that path for searching, reading, and analysis.
- On later references to the same repo, call
checkout.shagain; it will find and update the cached checkout.
If edits are needed
Prefer not to edit directly in the shared cache. Create a separate worktree or copy from the cached checkout for task-specific modifications.
Notes
owner/repodefaults togithub.com.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/mitsuhiko/agent-stuff/librarian">View librarian on skillZs</a>