Safe Git surface
RepoTunnel exposes a fixed Git capability surface rather than arbitrary Git arguments.
- Bounded status, diff, branch and log
- Protected credential paths omitted
- External diff/text conversion disabled
- Explicit staging paths
- Secret preflight before staging and publishing
- Hooks and GPG signing disabled for controlled commit execution
Push is different
AI Auto is not standing permission to publish. A push is accepted only when the current human instruction explicitly authorizes publishing, and RepoTunnel performs a committed-tree secret preflight before the push.
From a change to a local commit
Choose the repository in Git, inspect its branch and changed paths, and review the relevant staged or unstaged diff. Stage only the intended files before requesting a commit.
RepoTunnel validates the selected content and staged state. It does not stage unrelated changes implicitly while committing.
Recover a tracked text file
Restore-to-HEAD is available for eligible unstaged, non-conflicted tracked text files. The restoration goes through the safe-editing layer and applicable review policy.
RepoTunnel avoids silently discarding staged changes. For broader saved file state, inspect History or checkpoints.
Use the connected GitHub identity
Supported workflows use RepoTunnel’s trusted GitHub connection without passing its credential to the AI shell or chat. Authentication management stays local and user-controlled.
A missing token inside a sandbox is not enough to conclude that the app’s GitHub connection is broken. Check the authoritative connection state.