{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=himanshu-jha/org-public-exposure-audit@0.1.1","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Answers one question about a whole GitHub organisation or account: which of our public repositories carry credentials in their git history, and which public repositories did we fail to check at all. The second half is the point. Every scanner reports what it found, but a compliance answer is only usable if it also reports what it never looked at, because \"we found nothing\" and \"we scanned 6 of 84\" are different sentences that a summary count silently merges. This refuses to merge them: unscanned public repositories are listed by name with the reason, and the verdict cannot be CLEAN while any remain. It asks GitHub for the inventory and the filesystem for what is reachable as two independent parallel steps, scans the intersection, then joins all three. It never clones anything: fetching an organisation onto the caller's disk is a large surprising write, so the gap is reported instead, which is both safer and the honest answer. The one network call is your own authenticated gh session; this play carries no toke","distribution":{"digest":"sha256:8880796aada497b7e2420ff1fa45e1323fd0fb6635bacb6a510288708ccd7c1a","mediaType":"application/vnd.modiqo.rote-flow","size":31782,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"license":"MIT","links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1.json"},"name":"org-public-exposure-audit","owner":{"kind":"org","slug":"himanshu-jha"},"parameters":[{"description":"The GitHub organisation or account to audit. Leave it out and the account your gh session is logged in as is used, which the report names.","example":"my-company","input":{"allowCustom":true,"choices":[],"label":"Owner"},"name":"owner","required":false,"type":"string"},{"default":"200","description":"Maximum repositories to pull into the inventory. An inventory that hits this ceiling says so, because a truncated inventory makes even the coverage count a floor.","example":"200","input":{"allowCustom":true,"choices":[],"label":"Limit"},"name":"limit","required":false,"type":"string"},{"default":"20000","description":"Maximum history objects to walk per repository. A scan that hits this says so rather than reporting a clean result it did not earn.","example":"20000","input":{"allowCustom":true,"choices":[],"label":"Budget"},"name":"budget","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1","headlessCommandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/org-public-exposure-audit@0.1.1 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.78.0"},"publishedAt":"2026-09-02T10:22:46.722735+00:00","reference":"himanshu-jha/org-public-exposure-audit@0.1.1","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3","git","gh"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":3,"installs":0},"steps":{"count":5,"names":["assess_exposure","list_repositories","locate_clones","scan_public","validate_scope"]},"title":"org-public-exposure-audit","type":"play","version":"0.1.1","visibility":"public"}