Source profileQuality 81/100Review permissions

gadievron/raptor/.claude/skills/oss-forensics/github-commit-recovery/SKILL.md

github-commit-recovery

Recover deleted commits from GitHub using REST API, web interface, and git fetch. Use when you have commit SHAs and need to retrieve actual commit content, diffs, or patches. Includes techniques for accessing "deleted" commits that remain on GitHub servers.

Source repository stars
3,413
Declared platforms
0
Static risk flags
3
Last source update
2026-07-28
Source checked
2026-07-28

Decision brief

What it does—and where it fits

Purpose: Access commit content, diffs, and metadata directly from GitHub when you have commit SHAs. Includes methods for retrieving "deleted" commits that remain accessible on GitHub servers.

Best for

  • You have commit SHAs and need actual code content
  • Investigating commits that were force-pushed over ("deleted")
  • Need commit diffs, patches, or full file contents

Not for

  • Check authentication token is valid
  • Verify token has required scopes (repo for private repos)

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeNot declaredNo explicit evidencePortability before use
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/gadievron/raptor --skill ".claude/skills/oss-forensics/github-commit-recovery"
Safe inspection promptEditorial

Inspect the Agent Skill "github-commit-recovery" from https://github.com/gadievron/raptor/blob/e63c1b0ae449516f50ab510226ceb09a0edb3895/.claude/skills/oss-forensics/github-commit-recovery/SKILL.md at commit e63c1b0ae449516f50ab510226ceb09a0edb3895. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    Quick Start

    Access a "deleted" commit via web browser:

    Access a "deleted" commit via web browser:Get commit as patch file:
  2. 02

    When to Use This Skill

    SHA Sources: GitHub Archive, git reflog, CI/CD logs, PR comments, issue references, external archives, security reports.

    You have commit SHAs and need actual code contentInvestigating commits that were force-pushed over ("deleted")Need commit diffs, patches, or full file contents
  3. 03

    Core Principles

    Deleted Commits Are Never Really Deleted: - When developers force push to "delete" commits, GitHub keeps them indefinitely - Any commit SHA remains accessible if you know the hash - GitHub displays a warning ("This commit does not belong to any branch") but serves the content -…

    When developers force push to "delete" commits, GitHub keeps them indefinitelyAny commit SHA remains accessible if you know the hashGitHub displays a warning ("This commit does not belong to any branch") but serves the content
  4. 04

    Accessing Deleted Commits

    GitHub serves "deleted" commits at predictable URLs. These commits show a warning banner but content remains fully accessible.

    GitHub serves "deleted" commits at predictable URLs. These commits show a warning banner but content remains fully accessible.Patch Format (raw diff with headers):Diff Format (unified diff only):
  5. 05

    Method 1: Direct Web Access

    GitHub serves "deleted" commits at predictable URLs. These commits show a warning banner but content remains fully accessible.

    GitHub serves "deleted" commits at predictable URLs. These commits show a warning banner but content remains fully accessible.Patch Format (raw diff with headers):Diff Format (unified diff only):

Permission review

Static risk signals and limitations

Network access

medium · line 33

The documentation includes network, browsing, or remote request actions.

https://github.com/org/repo/commit/FULL_COMMIT_SHA

Writes files

medium · line 36

The documentation asks the agent to create, modify, or delete local files.

*Get commit as patch file**:

Network access

medium · line 38

The documentation includes network, browsing, or remote request actions.

curl -L https://github.com/org/repo/commit/FULL_COMMIT_SHA.patch

Runs scripts

medium · line 135

The documentation asks the agent to run terminal commands or scripts.

git clone --filter=blob:none --no-checkout https://github.com/org/repo.git

Runs scripts

medium · line 139

The documentation asks the agent to run terminal commands or scripts.

git fetch origin <COMMIT_SHA>

Writes files

medium · line 180

The documentation asks the agent to create, modify, or delete local files.

patch = download_commit_patch(commit["repo"], commit["sha"])

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score81/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars3,413SourceRepository attention, not individual Skill quality
Compatibility0 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
gadievron/raptor
Skill path
.claude/skills/oss-forensics/github-commit-recovery/SKILL.md
Commit
e63c1b0ae449516f50ab510226ceb09a0edb3895
License
NOASSERTION
Collected
2026-07-28
Default branch
main
View the original SKILL.md

GitHub Commit Recovery

Purpose: Access commit content, diffs, and metadata directly from GitHub when you have commit SHAs. Includes methods for retrieving "deleted" commits that remain accessible on GitHub servers.

When to Use This Skill

  • You have commit SHAs and need actual code content
  • Investigating commits that were force-pushed over ("deleted")
  • Need commit diffs, patches, or full file contents
  • Verifying commit authorship or metadata
  • Retrieving content from dangling commits

SHA Sources: GitHub Archive, git reflog, CI/CD logs, PR comments, issue references, external archives, security reports.

Core Principles

Deleted Commits Are Never Really Deleted:

  • When developers force push to "delete" commits, GitHub keeps them indefinitely
  • Any commit SHA remains accessible if you know the hash
  • GitHub displays a warning ("This commit does not belong to any branch") but serves the content
  • Even 4 hex digits can access commits (with collision risk)

Rate Limits Matter:

  • Authenticated API: 5,000 requests/hour
  • Unauthenticated API: 60 requests/hour
  • Web interface: Undocumented limits, WAF may block heavy usage
  • Git operations: No explicit limit, but excessive cloning may trigger throttling

Quick Start

Access a "deleted" commit via web browser:

https://github.com/org/repo/commit/FULL_COMMIT_SHA

Get commit as patch file:

curl -L https://github.com/org/repo/commit/FULL_COMMIT_SHA.patch

Query via REST API:

curl -H "Authorization: Bearer $GITHUB_TOKEN" \
  https://api.github.com/repos/org/repo/commits/FULL_COMMIT_SHA

Accessing Deleted Commits

Method 1: Direct Web Access

GitHub serves "deleted" commits at predictable URLs. These commits show a warning banner but content remains fully accessible.

Commit View:

https://github.com/<ORG>/<REPO>/commit/<SHA>

Patch Format (raw diff with headers):

https://github.com/<ORG>/<REPO>/commit/<SHA>.patch

Diff Format (unified diff only):

https://github.com/<ORG>/<REPO>/commit/<SHA>.diff

Example:

# View commit that was force-pushed over
curl -L https://github.com/grapefruit623/gcloud-python/commit/e9c3d31212847723aec86ef96aba0a77f9387493

# Download as patch
curl -L -o leaked_commit.patch \
  https://github.com/grapefruit623/gcloud-python/commit/e9c3d31212847723aec86ef96aba0a77f9387493.patch

Short SHA Access: GitHub allows accessing commits with just 4+ hex characters (if unique):

https://github.com/org/repo/commit/e9c3

Method 2: REST API

The GitHub REST API provides structured commit data including file changes, author info, and commit message.

Endpoint:

GET https://api.github.com/repos/{owner}/{repo}/commits/{ref}

Example Request:

curl -H "Accept: application/vnd.github+json" \
     -H "Authorization: Bearer $GITHUB_TOKEN" \
     https://api.github.com/repos/org/repo/commits/abc123def456

Response Structure:

{
  "sha": "abc123def456...",
  "commit": {
    "author": {
      "name": "Developer Name",
      "email": "[email protected]",
      "date": "2025-06-15T14:23:11Z"
    },
    "message": "Commit message here"
  },
  "files": [
    {
      "filename": "src/config.js",
      "status": "added",
      "patch": "@@ -0,0 +1,3 @@\n+// config"
    }
  ]
}

Rate Limit Headers:

x-ratelimit-limit: 5000
x-ratelimit-remaining: 4999
x-ratelimit-reset: 1623456789

Method 3: Git Fetch

For bulk analysis or when you need full repository context, fetch specific commits via Git.

Minimal Clone + Fetch Specific Commit:

# Clone without file contents (just history/trees/commits)
git clone --filter=blob:none --no-checkout https://github.com/org/repo.git
cd repo

# Fetch the specific "deleted" commit
git fetch origin <COMMIT_SHA>

# View the commit
git show FETCH_HEAD

# View specific file from that commit
git show FETCH_HEAD:path/to/file.txt

Why This Works:

  • --filter=blob:none: Omits file contents initially (fast clone)
  • --no-checkout: Doesn't populate working directory
  • git fetch origin <SHA>: Retrieves specific commit even if "deleted"
  • Blobs are fetched on-demand when you access them

Investigation Patterns

Batch Download Patches

Scenario: You have a list of commit SHAs to investigate and need their content.

import requests
import time

def download_commit_patch(repo, sha, token=None):
    url = f"https://github.com/{repo}/commit/{sha}.patch"
    headers = {"Authorization": f"Bearer {token}"} if token else {}

    response = requests.get(url, headers=headers, allow_redirects=True)
    if response.status_code == 200:
        return response.text
    return None

# Download patches for a list of commits
commits = [
    {"repo": "org/repo1", "sha": "abc123..."},
    {"repo": "org/repo2", "sha": "def456..."},
]

for commit in commits:
    patch = download_commit_patch(commit["repo"], commit["sha"])
    if patch:
        with open(f"{commit['sha'][:8]}.patch", "w") as f:
            f.write(patch)
    time.sleep(0.5)  # Rate limit courtesy

Verifying Commit Authorship

Scenario: Need to verify who actually authored a suspicious commit (committer vs author can differ).

API Query:

curl -s -H "Authorization: Bearer $GITHUB_TOKEN" \
  "https://api.github.com/repos/org/repo/commits/SHA" | \
  jq '{
    author: .commit.author,
    committer: .commit.committer,
    verified: .commit.verification.verified
  }'

Response Analysis:

{
  "author": {
    "name": "Real Developer",
    "email": "[email protected]",
    "date": "2025-06-15T10:00:00Z"
  },
  "committer": {
    "name": "CI Bot",
    "email": "[email protected]",
    "date": "2025-06-15T10:05:00Z"
  },
  "verified": false
}

Forensic Notes:

  • Author: Who wrote the code (can be forged via git commit --author)
  • Committer: Who created the commit object
  • Verified: Whether commit has valid GPG signature
  • Discrepancies between author/committer warrant investigation

Real-World Examples

Istio Supply Chain Attack Prevention

Discovery: Security researcher Sharon Brizinov used GitHub Archive to find zero-commit PushEvents, recovering commit SHAs of "deleted" commits. Using GitHub API to fetch commit content, discovered a leaked GitHub PAT token.

Impact: The token had admin access to ALL Istio repositories (36k stars, used by Google, IBM, Red Hat). Could have enabled:

  • Reading environment variables and secrets
  • Modifying CI/CD pipelines
  • Pushing malicious code releases
  • Deleting entire repositories

Resolution: Reported via Istio's security disclosure process; token was immediately revoked.

Technique Chain:

  1. GitHub Archive → Found zero-commit PushEvent with before SHA
  2. GitHub API → GET /repos/istio/istio/commits/{SHA}.patch
  3. TruffleHog → Identified valid GitHub PAT in commit diff
  4. GitHub API → Verified token permissions via /user endpoint

High-Value Secret Categories

From scanning recovered force-pushed commits, the most impactful secrets found in order:

  1. GitHub PATs - Often have org-wide or admin permissions
  2. AWS Credentials - IAM keys with production access
  3. MongoDB Connection Strings - Direct database access
  4. API Keys - Stripe, Twilio, SendGrid with billing access

Files Most Likely to Contain Secrets:

  • .env, .env.local, .env.production
  • config.js, config.py, config.json
  • docker-compose.yml, docker-compose.yaml
  • application.properties, application.yml
  • hardhat.config.js (crypto/web3 projects)

Troubleshooting

403 Forbidden on API requests:

  • Check authentication token is valid
  • Verify token has required scopes (repo for private repos)
  • May have hit rate limit - check x-ratelimit-remaining header

404 Not Found for commit:

  • Verify SHA is complete (at least 7 characters recommended)
  • Repository may have been deleted (try searching forks)
  • Commit may be in private repo (requires authenticated access)

Rate limit exceeded:

  • Wait for reset (check x-ratelimit-reset header for Unix timestamp)
  • Use authenticated requests for 5000/hour vs 60/hour
  • Implement exponential backoff in automation

Web access blocked by WAF:

  • Reduce request frequency
  • Use API instead of web scraping
  • Consider using Git fetch method for bulk operations

Git fetch fails for commit:

  • Some very old dangling commits may be garbage collected (rare)
  • Try accessing via web interface first to confirm availability
  • Check if repo has been transferred to different org

Learn More

Alternatives

Compare before choosing