fix(gitea-branches): repoint dangling overview.md citation

references/commits.md cited overview.md as the authority for a
scope-gating claim, but no such file exists in this skill's package —
the only overview.md is an external research doc not shipped with the
skill. Repoint to branches.md's own Token scope section, which states
and confirms the same principle, and drop the unverifiable
write:repository enumeration detail no file in this skill actually
makes.

Found by an independent post-closure audit of #99 (agent-audit +
skill-audit re-run against every changed skill/agent).
This commit is contained in:
2026-08-30 19:31:15 +00:00
parent 92ba9abe7c
commit 59aaec4ed6
2 changed files with 8 additions and 8 deletions

View File

@@ -64,10 +64,10 @@ edge cases, `get_commit` will not.
## Token scope
Both tools are believed to require `write:repository`, even though they're read-only — inferred by
analogy with the scope-gating principle in `overview.md` (Gitea gates reads behind write scope for
repo-scoped operations), not a claim `overview.md` makes for commits by name: its explicit
`write:repository` enumeration lists PR, branch, file, release, and tag operations, but doesn't
mention commits. An earlier version of this doc claimed `write:issue` alone worked, based on
analogy with the scope-gating principle confirmed for branch operations in `branches.md`'s Token
scope section (Gitea gates reads behind write scope for repo-scoped operations), not a claim any
doc in this skill makes for commits by name: nothing here enumerates commits under
`write:repository` explicitly. An earlier version of this doc claimed `write:issue` alone worked, based on
empirical testing under a token that held both `write:issue` and `write:repository`
simultaneously — that test didn't isolate the variable either. Treat this as unverified until
tested under a token scoped to `write:issue` only (no `write:repository`).

View File

@@ -64,10 +64,10 @@ edge cases, `get_commit` will not.
## Token scope
Both tools are believed to require `write:repository`, even though they're read-only — inferred by
analogy with the scope-gating principle in `overview.md` (Gitea gates reads behind write scope for
repo-scoped operations), not a claim `overview.md` makes for commits by name: its explicit
`write:repository` enumeration lists PR, branch, file, release, and tag operations, but doesn't
mention commits. An earlier version of this doc claimed `write:issue` alone worked, based on
analogy with the scope-gating principle confirmed for branch operations in `branches.md`'s Token
scope section (Gitea gates reads behind write scope for repo-scoped operations), not a claim any
doc in this skill makes for commits by name: nothing here enumerates commits under
`write:repository` explicitly. An earlier version of this doc claimed `write:issue` alone worked, based on
empirical testing under a token that held both `write:issue` and `write:repository`
simultaneously — that test didn't isolate the variable either. Treat this as unverified until
tested under a token scoped to `write:issue` only (no `write:repository`).