Git workflow
Inspect, stage and commit through RepoTunnel's fixed Git capability surface.
Guides follow the current project source. Check the release notes for your installed version.
Inspection
- Status
- Diff
- Branch/upstream
- Recent commits
Mutation safeguards
- Explicit relative staging paths
- Symlink/protected/secret-bearing path rejection
- Staged-state and HEAD revalidation
- Hooks/GPG signing disabled for controlled commit execution
Push
Push remains separate from normal in-project autonomy and requires a current explicit human instruction.
Inspect before publishing
Use RepoTunnel's bounded Git status/diff/log tools. Staging accepts specific project-relative paths, rechecks the live file/index state and blocks protected/secret-bearing content. Committing operates on the exact staged snapshot, not an arbitrary shell command.
Use safe restore-to-HEAD only for eligible files and remember that it still passes the normal history/review boundary.
Publishing is a separate decision
AI Auto permits compatible local edits and commits, but it does not mean the user permanently authorized pushing code. A push must represent the current user's explicit publishing intent and passes a final secret preflight.
Avoid broad force/mirror/delete/all/tags pushes through RepoTunnel's controlled flow. If the user has not requested publication, stop at a locally verified commit.
Know which repository layouts are supported
The approved workspace root must contain its own .git directory. Parent-repository and linked-worktree layouts are rejected because their metadata can live outside the approved root.
Restore-to-HEAD is limited to eligible unstaged, non-conflicted tracked text files and uses the safe-editing path. Staged changes are not silently discarded.
Inspect GitHub connection state
RepoTunnel can broker supported authenticated GitHub work without exposing its credential to the AI shell. A sandboxed command not seeing a token is not proof that GitHub is disconnected.
Keep account/security changes local and check the app’s authoritative connection status.