Files
holocron/plugins/gitea/skills/gitea-branches/references/commits.md
Defame1297 18ec0ab0ff fix(gitea): correct token-scope claim in gitea-branches docs
SKILL.md, README.md, and references/{branches,commits}.md claimed
list_branches, list_commits, and get_commit "work with write:issue
alone." This contradicted docs/research/docs/gitea/overview.md, which
documents write:repository as gating both reads and writes for
repo-scoped tool families (Gitea hides these reads behind write
scope). The prior empirical justification was invalid: it tested under
a token holding both write:issue and write:repository simultaneously,
which doesn't isolate which scope actually enabled the reads.

Corrected all four files to state that list_branches, create_branch,
and delete_branch require write:repository, confirmed directly by
overview.md's scope enumeration. list_commits/get_commit are flagged
as inferred to need the same scope by analogy rather than an
overview.md-confirmed fact, since overview.md's write:repository
enumeration names PR/branch/file/release/tag but not commits — this
distinction surfaced during an independent audit pass and is now
called out explicitly so the claim isn't overstated.

Bumped SKILL.md metadata.version 0.1.0 -> 0.1.1 (patch: doc
correction, no behavior change).
2026-07-05 19:14:57 +00:00

3.1 KiB

topic, source_keys
topic source_keys
commits
gitea-mcp-repo
gitea-mcp-slim-go

Commit operations

Read-only commit history, scoped to a repo (optionally to one branch or one path). Call signatures below were verified live against the deployed gitea-mcp server via ToolSearch at authoring time, not copied from research docs, for the same drift-avoidance reason noted in references/branches.md.

This domain has no prior skill precedent — it's new coverage added alongside branches because commit history is naturally scoped to a branch (a "what happened on this branch" question), not because it shares any tool family with branch create/delete.

list_commits

Parameters:

  • owner (string, required)
  • repo (string, required)
  • sha (string, optional) — starting SHA or branch name; if omitted, gitea-mcp uses the repo's default branch
  • path (string, optional) — restrict results to commits that touched this file/path
  • page (number, optional, default: 1, minimum: 1)
  • per_page (number, optional, default: 30, minimum: 1)

Call:

list_commits owner: <owner> repo: <repo> sha: <branch-or-sha> path: <optional-path>

Dispatch defaults:

  • "commits on <branch>" → pass <branch> as sha.
  • "commits touching <path>" (no branch mentioned) → pass path alone, sha omitted (defaults to the repo's default branch).
  • Both given → pass both; the result is history for that path, walked from that branch/SHA.
  • Neither given → omit both; this returns default-branch history, which is a reasonable default for an open-ended "what's the recent history here" question.

Response: one object per commit: sha, html_url, created, message (when available), author ({name, email, date}, when available).

Paginate per the manual-pagination Gotcha in SKILL.md if you need more than one page of history.

get_commit

Parameters:

  • owner (string, required)
  • repo (string, required)
  • sha (string, required)

Call:

get_commit owner: <owner> repo: <repo> sha: <commit-sha>

Response: same shape as a list_commits entry, but always fully populated (message and author are guaranteed present, not conditional). Use this when the user asks about one specific commit by SHA rather than browsing history — list_commits entries may omit message/author in edge cases, get_commit will not.

Token scope

Both tools are believed to require write:repository, even though they're read-only — inferred by analogy with the scope-gating principle in overview.md (Gitea gates reads behind write scope for repo-scoped operations), not a claim overview.md makes for commits by name: its explicit write:repository enumeration lists PR, branch, file, release, and tag operations, but doesn't mention commits. An earlier version of this doc claimed write:issue alone worked, based on empirical testing under a token that held both write:issue and write:repository simultaneously — that test didn't isolate the variable either. Treat this as unverified until tested under a token scoped to write:issue only (no write:repository).