Writing Commit MessagesSAFE
the runtime your coding agents live on
Overview
the runtime your coding agents live on
a48e292f4ab2OBSERVED · 2026-10-08What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: writing-commit-messages description: >- Writes Git commit messages. Activates when the user asks to write a commit message, draft a commit message, or similar. --- # Writing Commit Messages Write commit messages that follow commit style guidelines for the project. ## Format ``` <subsystem>: <summary> <reference issues/PRs/etc.> <long form description> ``` ## Rules ### Subject line - **Subsystem prefix**: Use a short, lowercase identifier for the area of code changed (e.g., `terminal`, `vt`, `lib`, `config`, `font`). Determine this from the file paths in the diff. If changes span the macOS app, use `macos`. For GTK, use `gtk`. For build system, use `build`. Use nested subsystems with `/` when helpful and exclusive (e.g., `terminal/osc`). - **Summary**: Lowercase start (not capitalized), imperative mood, no trailing period. Keep it concise—ideally under 60 characters total for the whole subject line. ### References - If the change relates to a GitHub issue, PR, or discussion, list the relevant numbers on their own lines after the subject, separated by a blank line. E.g. `#1234` - If there are no references, omit this section entirely (no blank line). ### Long form description - Describe **what changed**, **what the previous behavior was**, and **how the new behavior works** at a high level. - Use plain prose, not bullet points. Wrap lines at ~72 characters. - Focus on the _why_ and _how_ rather than restating the diff. - Keep the tone direct and technical without filler phrases. - Don't exceed a handful of paragraphs; less is more. ## Workflow - If `.jj` is present, use `jj` instead of `git` for all commands. - Run a diff to see what changes are present since the last commit. - Identify the subsystem from the changed file paths. - Identify any referenced issues/PRs from the diff context or branch name. - Draft the commit message following the format above. - Apply the commit - Don't push the commit; leave that to the user.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
CLAUDE.md
Gates applied: no_behavioural_pass.
a48e292f4ab2full audit observations/trust-audit/skill/ogulcancelik__writing-commit-messages.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a48e292f4ab2 | SAFE | B | 89 | first audit |
Questions
What does the Writing Commit Messages skill do?
the runtime your coding agents live on
Is Writing Commit Messages safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Writing Commit Messages access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (a48e292f4ab2), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.