Code CommitSAFE
7×24 Desktop AI Agent for Everyone. Visual AI assistant with remote access, file management, and built-in AI browser.
Overview
7×24 Desktop AI Agent for Everyone. Visual AI assistant with remote access, file management, and built-in AI browser.
e0e9be0da18eOBSERVED · 2026-10-08What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: code-commit description: Must be invoked when the user asks to commit code, submit code, or any similar request. --- # Code Commit Skill ## Commit Workflow ### 1. Review Changes Run `git status` and `git diff` in the repository to understand all current changes. ### 2. Pre-commit Checks Review all changed files. **If any issues are found, report them to the user and wait for confirmation before committing.** #### 2.1 Temporary Code Detection Use your judgment to identify code that looks temporary or was clearly left in by accident -- things like `debugger` statements, placeholder values (`test123`, `asdf`, `foo`), commented-out code blocks, or anything that reads like a quick hack not meant for production. Don't be overly rigid; focus on what obviously doesn't belong. #### 2.2 Temporary File Detection Check whether any files that should not be committed are included in the changes: - OS files: `.DS_Store`, `Thumbs.db`, etc. - Temp files: `*.log`, `*.tmp`, `*.bak`, `*.swp`, etc. - IDE configs: non-shared files under `.idea/`, `.vscode/`, etc. - Build artifacts: `node_modules/`, `dist/`, `build/`, etc. - Sensitive files: `.env`, `credentials.json`, private keys, etc. #### 2.3 Internationalization & Open-source Readiness Ensure the code is suitable for an internationalized, open-source project: - **No hardcoded Chinese strings** in user-facing text (UI labels, prompts, error messages). These should go through the project's i18n mechanism. - **Comments in English** to align with open-source conventions. - **No pinyin naming** for variables, functions, or identifiers. Use meaningful English names. - **No internal/private information** such as internal IP addresses, intranet domains, personal emails, phone numbers, API keys, or secrets. - **No specific company or brand names** in code, comments, or commit messages — this includes but is not limited to Microsoft, Google, Tencent, Alibaba, Apple, Meta, Amazon, Baidu, ByteDance, etc. Use generic terms instead (e.g., "cloud provider", "search engine", "platform"). ### 3. Generate Commit Message Format: ``` <type>: #AI commit# <concise description>. collaboration and commit by halo ``` **Supported types:** | type | usage | |----------|--------------------------------------------| | feat | New feature | | fix | Bug fix | | docs | Documentation changes | | style | Code formatting (no logic changes) | | refactor | Refactoring (no new features or bug fixes) | | perf | Performance improvement | | test | Test-related changes | | chore | Build, tooling, dependency updates, etc. | **Examples:** ```bash git commit -m "feat: #AI commit# add user authentication module. collaboration and commit by halo" git commit -m "fix: #AI commit# resolve memory leak in event listener. collaboration and commit by halo" ``` ### 4. Execute Commit ```bash git add <relevant files> git commit -m "<generated commit message>" ``` - Only stage files that pass the checks. Do not blindly `git add .`. - Run `git status` after committing to verify. ## Notes - If there are no changes, inform the user that there is nothing to commit. - Do not run `git push` unless the user explicitly asks. - When issues are found during checks, list all of them and ask the user how to proceed. Do not skip issues on your own.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
e0e9be0da18efull audit observations/trust-audit/skill/openkursar__code-commit.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e0e9be0da18e | SAFE | B | 89 | first audit |
Questions
What does the Code Commit skill do?
7×24 Desktop AI Agent for Everyone. Visual AI assistant with remote access, file management, and built-in AI browser.
Is Code Commit safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Code Commit access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (e0e9be0da18e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.