All skills
acedergren avatar

/quality-commit

@9d099e9
by Alexander Cedergrenacedergren/agentic-tools26 stars
4

Use when committing code changes. Runs lint, typecheck, Semgrep security scan, optional CodeRabbit review, and related tests before creating a quality-gated commit. Flags: --review, --push, --dry-run, --message. Keywords: commit, quality gates, lint, typecheck, semgrep, coderabbit, stage, push. Triggers on "commit changes" or "run quality commit".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/quality-commit

This session only. Nothing lands on disk.

SKILL.md

โ‰ˆ91 tokens always: the name and description. โ‰ˆ858 when used: this file. โ‰ˆ1.7k more on demand in 1 file.

Quality Commit

When to Use

Load this skill when the user request matches the frontmatter description for Quality Commit.

Run all quality gates on staged changes, then commit. Replaces manual multi-step commit prep that frequently causes pre-commit hook friction.

NEVER

  • Never run git add . or git add -A โ€” always stage specific files by name.
  • Never commit after partial gate failures by bypassing hooks โ€” gates exist for correctness.
  • Never let optional tools (CodeRabbit, Semgrep) block the workflow when not installed โ€” skip with warning.
  • Never widen scope to unrelated repo cleanup during commit prep.
  • Never attempt to auto-fix gate failures and retry โ€” report errors, let the agent fix first.

Decision: What Gates to Run

Has staged files?
โ”œโ”€ No โ†’ Print warning, exit
โ””โ”€ Yes โ†’
    โ”œโ”€ Always: Lint โ†’ TypeCheck โ†’ Semgrep โ†’ Tests โ†’ Commit
    โ”œโ”€ --review or --full: Add CodeRabbit (slow, ~30s) before commit
    โ””โ”€ --push: After commit, Semgrep committed files, push to remote

Gate Execution

Scope detection

STAGED=$(git diff --cached --name-only --diff-filter=ACMR)
bash scripts/classify-staged-files.sh  # categorizes into frontend/api/shared

Semgrep: file-at-a-time (critical workaround)

Semgrep 1.146.0+ crashes with multiple file arguments (Invalid_argument: invalid path). Always loop:

for f in $STAGED_FILES; do
  semgrep scan --config auto --json "$f" 2>/dev/null || true
done

Block on critical/high findings. Warn on medium/low. Skip if not installed.

TypeCheck workspace commands

  • frontend: npx svelte-check --tsconfig ./tsconfig.json --threshold error (11 pre-existing errors in test files are known baseline โ€” ignore)
  • api: npx tsc --noEmit
  • shared: npx tsc --noEmit

Related test discovery

node scripts/find-related-tests.js <staged-file>
# src/lib/server/auth/rbac.ts โ†’ src/lib/server/auth/rbac.test.ts

Run discovered tests: npx vitest run <test-files> --reporter=verbose

Commit message format

type(scope): description

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

Types: feat, fix, refactor, test, docs, chore Scopes: security, phaseX.Y, api, frontend, database, auth, workflows

Push flow (--push only)

  1. Re-run Semgrep on committed files (same file-at-a-time loop, use git diff --name-only HEAD~1)
  2. Detect upstream: git rev-parse --abbrev-ref @{u} 2>/dev/null
  3. If no upstream: git push -u origin $BRANCH, else git push
  4. Abort push on critical/high Semgrep findings โ€” commit stays intact, do NOT undo it

Summary table

| Gate       | Status | Details                    |
|------------|--------|----------------------------|
| Lint       | PASS   | 5 files, 0 errors          |
| TypeCheck  | PASS   | api + frontend             |
| Semgrep    | PASS   | 0 findings                 |
| CodeRabbit | SKIP   | (use --review to enable)   |
| Tests      | PASS   | 3 test files, 12 tests     |
| Commit     | DONE   | abc1234                    |
| Push       | SKIP   | (use --push to enable)     |

Arguments

  • (empty): lint + typecheck + semgrep + tests + commit
  • --review / --full: Add CodeRabbit review
  • --dry-run: Run all gates, skip actual commit and push
  • --push: Commit then semgrep + push to remote
  • --message "...": Use custom commit message

Source: SKILL.md on GitHub

1 warning5mo5 checks ยท Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill automates quality gates for git commits, including linting, type checking, security scanning, and testing. It is safe for its intended purpose but contains a potential surface for indirect prompt injection as it processes untrusted code content from staged changes.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW ยท No issues

  • Runlayer6mo

    3/4 files flagged

  • ZeroLeaks5mo

    Score: 93/100 ยท 2 sections analyzed

Signed by skilld at 9d099e9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago

README badge

README badge for acedergren/agentic-tools/quality-commit