Commit
Claude Code skills for git workflows, GitHub automation, security audits, code refactoring, and project tooling
npx -y skills add tartinerlabs/skills --skill commitAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 7 stars7 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when committing changes, staging files, saving work, or making a git commit. Creates clean commits in the repository's own convention (conventional commits, area prefix, tracker ID, or plain) with secret scanning (GitLeaks).
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
3.3 KB, as published. Nobody here has run it
You create git commits with short, readable messages that match the repository's existing convention.
Load an ecosystem guide only when rules/convention-detection.md reaches Tier 3 and the manifest matches it: references/go.md, references/swift.md, references/python.md, references/systems.md.
Rules Overview
| Rule | Impact | File |
|---|---|---|
| Convention detection | HIGH | rules/convention-detection.md |
| Message format | HIGH | rules/message-format.md |
| Commit type selection | HIGH | rules/commit-type.md |
| Issue references | MEDIUM | rules/issue-references.md |
| Change scope | MEDIUM | rules/change-scope.md |
Pre-Commit Security Check
Scan staged changes for secrets before every commit, using the project's secret scanner. GitLeaks is the default; TruffleHog is accepted if the project already uses it.
- Run the scanner over staged changes after staging — GitLeaks:
gitleaks git --staged --redact --verbose; TruffleHog:trufflehog git file://. --since-commit HEAD --results=verified,unknown --fail(includeunknownso credentials TruffleHog cannot verify online still block the commit, matching GitLeaks). - If the scanner reports a leak, STOP — do not commit. Report the finding and ask the user to remove the secret (and rotate it if it was ever pushed).
- If no secret scanner is installed (command not found), STOP — do not commit and do not install one implicitly. Tell the user to install one (
brew install gitleaksor equivalent) and re-run.
Never edit .husky/, commitlint, or other project tooling as part of a commit. If pre-commit hooks are missing, report that and point the user to the setup skill instead of configuring it yourself.
Workflow
A commit request stages and commits only — it must never pull, stash, restore stashes, or rewrite project tooling.
- Show current
git statusand analyse all changes - Detect the repository's commit convention (see
rules/convention-detection.md) - Check conversation context for issue references (see
rules/issue-references.md) - Assess scope of changes (see
rules/change-scope.md) - Stage only the explicit, related paths for this change — never blanket-stage unrelated modifications
- Choose the commit type or leading verb from branch context, not the staged diff alone (see
rules/commit-type.md) - Run the Pre-Commit Security Check above
- Create the commit with a message following
rules/message-format.md
When the convention came from Tier 3 or Tier 4 of detection — an ecosystem default or the plain fallback rather than enforced tooling or clear history — state which convention was used and why, so a wrong guess is visible.