push — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited push (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Preferences for git push, especially diagnosing failures.
When git push exits non-zero, output mixes three layers:
Identify the failed layer before debugging:
lefthook or hook: pre-push → pre-push hook failed; transport was finePermission denied (publickey) → SSH auth refused! [rejected] / non-fast-forward → push needs rebaseA wall of test or coverage output is NOT an SSH problem. The hook ran tests, the tests failed, the push was blocked.
Same rules as pre-commit failures in the commit skill: analyze the failures, autofix when possible, ask the user when unclear. Do NOT skip with --no-verify without explicit confirmation.
Before adding -v to debug an SSH issue, check whether core.sshCommand is configured:
git config --get core.sshCommandIf it returns nothing, GIT_SSH_COMMAND="ssh -v" git push origin <branch> is fine.
If it returns anything (custom IdentityFile, IdentityAgent, deploy-key flags, etc.), DO NOT use GIT_SSH_COMMAND="ssh -v". It REPLACES core.sshCommand entirely, dropping every flag. Output will look like the wrong keys are being offered, because they are, but only because you removed the constraint.
Append -v to the existing command instead:
GIT_SSH_COMMAND="$(git config core.sshCommand) -v" git push origin <branch>If you started a push with run_in_background and then ran a foreground retry (e.g., because the first looked stuck), the background push may have already succeeded. Before re-investigating "why is push failing":
git -C <worktree> log --oneline origin/<branch>..HEAD. Empty output means the push went through.pwd and git rev-parse --show-toplevel.gh pr view <pr> to see if the commit landed.Don't escalate to "SSH might be broken" before confirming the push didn't already complete.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.