fix(gitea): correct token-scope claim in gitea-branches docs

SKILL.md, README.md, and references/{branches,commits}.md claimed
list_branches, list_commits, and get_commit "work with write:issue
alone." This contradicted docs/research/docs/gitea/overview.md, which
documents write:repository as gating both reads and writes for
repo-scoped tool families (Gitea hides these reads behind write
scope). The prior empirical justification was invalid: it tested under
a token holding both write:issue and write:repository simultaneously,
which doesn't isolate which scope actually enabled the reads.

Corrected all four files to state that list_branches, create_branch,
and delete_branch require write:repository, confirmed directly by
overview.md's scope enumeration. list_commits/get_commit are flagged
as inferred to need the same scope by analogy rather than an
overview.md-confirmed fact, since overview.md's write:repository
enumeration names PR/branch/file/release/tag but not commits — this
distinction surfaced during an independent audit pass and is now
called out explicitly so the claim isn't overstated.

Bumped SKILL.md metadata.version 0.1.0 -> 0.1.1 (patch: doc
correction, no behavior change).
This commit is contained in:
2026-07-05 19:12:09 +00:00
parent 3a4ae44500
commit 18ec0ab0ff
4 changed files with 21 additions and 10 deletions

View File

@@ -12,9 +12,11 @@ explicit confirmation, and treating unexpected 404s as possible masked 403s).
## Before you start
Requires a Gitea MCP server configured with a token. `list_branches`, `list_commits`, and
`get_commit` work with `write:issue` alone; `create_branch` and `delete_branch` need
`write:repository`. Requires a git remote named `origin` pointing at the Gitea instance.
Requires a Gitea MCP server configured with a token that has `write:repository` scope. This is
confirmed for `list_branches`, `create_branch`, and `delete_branch` (Gitea gates reads behind write
scope for repo-scoped operations); `list_commits` and `get_commit` are inferred to need the same
scope by analogy, not explicitly confirmed — see `references/commits.md`. Requires a git remote
named `origin` pointing at the Gitea instance.
## Usage