Settings / Integrations

Integrations

Every integration is read-only by default and least-privilege by design. Writes always require explicit approval.

GitHub

Not connectedRead-only

Repository metadata, releases, commits, diffs, issues, pull requests, security advisories, archive and ownership changes.

Least-privilege scopes. SkillPilot never pushes commits or opens pull requests on your behalf.

YouTube Data API v3

Not connectedRead-only

Channel and video metadata, transcript availability, embed player. Direct canonical video URLs only.

Search redirects, tracking wrappers and result pages are rejected before storage.

Package registries

Not connectedRead-only

npm, PyPI, GitHub Releases and Docker registries where a project publishes artifacts.

Used to resolve the latest published version when a repository has no release feed.

Configuration upload

3 sources connectedRedacted at upload

Uploaded or pasted configuration used for impact analysis.

API keys, tokens, passwords, private keys and cookies are detected and redacted before storage. You can inspect the redaction before saving.

Prompt-injection protection

Repository files, release notes, issues, comments and transcripts are untrusted input. The analysis pipeline keeps source data separated from system instructions, never obeys instructions found inside scanned content, never executes code or commands discovered there, restricts tool access during summarisation, and retains citations and confidence signals on every conclusion.

Safety Secrets are redacted before any AI processing. Raw secret values are avoided entirely wherever possible, and data is encrypted in transit and at rest with deletion and retention controls available.