Case 04609
A fast, offline static risk analysis CLI for AI agent skill files. Detects malicious instructions, steganographic payloads, and dangerous capability chains.
npx -y skills add knownasnaffy/prompthound --skill case_04609Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use this skill for any git commit, pull request, or release task. Invoke immediately when the user wants to: stage and commit changes, write a commit message, push code, create a PR or MR, tag a release, or update CHANGELOG. Triggers on: 「帮我提交」「commit」「提交代码」「创建 PR」「发布版本」「打 tag」 「推代码」, or English equivalents like "commit my changes", "create a pull request", "release v", "write a commit message", "push this branch". Do NOT trigger for: bulk repo syncing (use code-sync), general git questions without commit/PR intent, or Yunxiao MR creation (use yunxiao skill).
SKILL.md
4.7 KB, 976 tokens by cl100k_base, as published. Nobody here has run it
Git Workflow
Standardized Git workflow for commits, pull requests, and releases using conventional commits format and semantic versioning.
Prerequisites
| Tool | Type | Required | Install |
|---|---|---|---|
| git | cli | Yes | brew install git or git-scm.com |
| gh | cli | No | brew install gh then gh auth login (required for PR and Release) |
Do NOT proactively verify these tools on skill load. If a command fails due to a missing tool, directly guide the user through installation and configuration step by step.
When to Use
- Creating commits: Follow conventional commits with concise, imperative messages
- Creating pull requests: Generate PR with clear description and test plan
- Creating releases: Update versions, CHANGELOG, tags, and GitHub releases
These workflows can be used independently or together as needed.
Platform Detection
Check git remote get-url origin to select workflow:
| Remote URL contains | Commits/Tags/Releases | PR/MR |
|---|---|---|
github.com | This skill | This skill (gh pr create) |
codeup.aliyun.com | This skill | Switch to yunxiao skill |
gitlab.com | This skill | This skill (adapt for GitLab CLI) |
Quick Reference
Commit Format
type(scope): concise summary
- Optional bullet points (max 3-4)
- Keep short and focused
Types: feat, fix, refactor, docs, test, chore
Branch Naming
feature/descriptionfix/descriptiondocs/descriptionrefactor/descriptiontest/description
Release Checklist
- Update version in project files
- Update CHANGELOG.md
- Commit:
chore(release): bump version to x.y.z - Tag:
git tag v{version} && git push upstream v{version} - Create GitHub release with
gh release create
Default Behaviors
- Keep messages concise: Commit messages and PR titles must be short and to the point. Omit filler words. The diff shows "what" — the message explains "why".
- No AI signatures: Never include
Co-Authored-By: Claude,Generated with Claude Code, or any AI markers in commits or PRs. - Commit always pushes: After commit, always push immediately. Do not ask.
- Has upstream tracking →
git push - No upstream tracking →
git push -u origin <branch>
- Has upstream tracking →
Detailed Guides
See examples-and-templates.md for commit examples (good/bad), PR body template, and CHANGELOG format.
Validation
Use scripts/validate_commit.py to validate commit messages:
python3 scripts/validate_commit.py "feat(auth): add OAuth2 support"
python3 scripts/validate_commit.py --file .git/COMMIT_EDITMSG
The validator checks:
- Conventional commits format
- Subject line length (< 72 chars)
- Imperative mood usage
- Absence of AI-generated markers
- Body format and bullet point count
Common Workflows
Commit (default: commit + push)
git add <files>
git commit -m "feat(component): add new feature" && git push
Pull Request
git checkout -b feature/new-feature
# ... make changes, commit (auto-pushes per default behavior) ...
gh pr create --title "feat(component): add new feature" --body "..."
Release
# Update version files + CHANGELOG.md
git add .
git commit -m "chore(release): bump version to 1.2.0" && git push
git tag v1.2.0 && git push upstream v1.2.0
gh release create v1.2.0 -R owner/repo --title "v1.2.0" --notes "..."
Common Issues
| Issue | Cause | Fix |
|---|---|---|
| Subject line > 72 chars | Description too long | Shorten summary, put details in body |
| Multiple types in one commit | Scope too large | Split into single-purpose commits |
| Merge commits appear | Used merge | Use git pull --rebase |
| Validator script errors | Format mismatch | Check type(scope): format |
What ships with it: 2 files
6.2 KB alongside SKILL.md, 1 of them executable
references/
scripts/
- validate_commit.pyruns3.9 KB