commit-message — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited commit-message (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Draft a Conventional Commit message from staged changes.
commit-message.--cached / staged SCM state) as input, unless the user invokes the Context Override path.AI-assistant: <AGENT> footer.These rules govern body content. Apply them at draft time (step 7) and re-check before output (step 9).
Your reader meets this commit in two phases: Scan mode — they see the subject in git log, git blame, or a bisect and decide whether to open it. Read mode — once opened, they read the diff to understand what changed.
The subject carries scan mode — name the area and effect concretely enough to distinguish from neighbors.
The body exists only when read mode leaves a question unanswered. If no gap exists, ship subject-only — most commits. Conversation weight is not reader weight: what felt load-bearing in the dialogue is rarely what the diff fails to convey.
The diff shows what changed and where, but not why or how to act on it. A body line is warranted only when it fires one of these 5 triggers:
For every body line you are about to write, name which of the 5 cold-reader triggers it fires. If you can't name one, don't write the line — it's conversation weight or file inventory, not reader signal. "It feels useful to mention" is not a trigger.
Could the subject alone carry this commit? Drop the body entirely. Does any body line restate the subject? Drop it.
If the user directs you to draft from prior conversation work or a working document (e.g. "use what we just did", "based on the todo list above", "from our discussion", "skip the diff"), follow the Context Override path below instead of the rest of this workflow.
Prefer workspace root when known; otherwise run git rev-parse --show-toplevel.
Prefer get_changed_files with repositoryPath: <repo-root> and staged state. If that tool is unavailable, use SCM tooling with explicit repo context. If SCM tooling is unavailable, use git -C <repo-root> diff --cached.
If empty, retry once with explicit repo root; if still empty, inform user and stop.
Identify changed files, behavior impact, logical scope, and likely commit type.
Preserve explicit issue refs and constraints from user input.
references/conventional-commit-rules.md.Then draft the message covering only the lines named in step 7, applying those rules.
Revise or drop any failing lines before output.
git commit -F -.Use this path when the user explicitly directs you to draft from prior conversation work or a working document rather than from the staged diff. Body Discipline applies here too — conversation-derived drafts are the highest-risk source for conversation weight.
Do not run git diff, get_changed_files, or any other SCM inspection.
references/conventional-commit-rules.md.Then draft the message, preserving any explicit issue refs and constraints the user provided.
git commit -F -.references/conventional-commit-rules.md - subject/body/footer rules and examples.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.