Generating Conventional CommitsSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Bundled resources for devops-automation-pack skill
- [ ] commitmessagetemplate.txt: A template for creating commit messages.
- [ ] examplecodediff.txt: An example code diff used for generating commit messages.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: generating-conventional-commits description: 'Execute generates conventional commit messages using AI. It analyzes code changes and suggests a commit message adhering to the conventional commits specification. Use this skill when you need help writing clear, standardized commit messages, especially a... Use when managing version control. Trigger with phrases like ''commit'', ''branch'', or ''git''. ' allowed-tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*) version: 1.30.0 author: Jeremy Longshore <[email protected]> license: MIT tags: - packages - conventional-commits compatibility: Designed for Claude Code --- # Devops Automation Pack Generate conventional commit messages by analyzing staged Git changes, selecting the correct type prefix (feat/fix/refactor/etc.), and producing concise, standards-compliant messages. ## Overview Create well-formatted, informative commit messages that follow the conventional commits standard, improving collaboration and automation in your Git workflow. It saves you time and ensures consistency across your project. ## How It Works 1. **Analyze Changes**: The skill analyzes the staged changes in your Git repository. 2. **Generate Suggestion**: It uses AI to generate a commit message based on the analyzed changes, adhering to the conventional commits format (e.g., `feat: add new feature`, `fix: correct bug`). 3. **Present to User**: The generated commit message is presented to you for review and acceptance. ## When to Use This Skill This skill activates when you need to: - Create a commit message after making code changes. - Ensure your commit messages follow the conventional commits standard. - Save time writing commit messages manually. ## Examples ### Example 1: Adding a New Feature User request: "Generate a commit message for these changes." The skill will: 1. Analyze the staged changes related to a new feature. 2. Generate a commit message like `feat: Implement user authentication`. ### Example 2: Fixing a Bug User request: "Create a commit for the bug fix." The skill will: 1. Analyze the staged changes related to a bug fix. 2. Generate a commit message like `fix: Resolve issue with incorrect password reset`. ## Best Practices - **Stage Changes**: Ensure all relevant changes are staged before using the skill. - **Review Carefully**: Always review the generated commit message before accepting it. - **Customize if Needed**: Feel free to customize the generated message to provide more context. ## Integration This skill integrates with your Git workflow, providing a convenient way to generate commit messages directly within Claude Code. It complements other Git-related skills in the DevOps Automation Pack, such as `/branch-create` and `/pr-create`. ## Prerequisites - Appropriate file access permissions - Required dependencies installed ## Instructions 1. Invoke this skill when the trigger conditions are met 2. Provide necessary context and parameters 3. Review the generated output 4. Apply modifications as needed ## Output The skill produces structured output relevant to the task. ## Error Handling - Invalid input: Prompts for correction - Missing dependencies: Lists required components - Permission errors: Suggests remediation steps ## Resources - Project documentation - Related skills and commands
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__generating-conventional-commits.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Generating Conventional Commits skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Generating Conventional Commits safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Generating Conventional Commits access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Generating Conventional Commits work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.