Atlas / Skills / openkursar / Code Commit

Code CommitSAFE

skills/openkursar/code-commit

7×24 Desktop AI Agent for Everyone. Visual AI assistant with remote access, file management, and built-in AI browser.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
NOASSERTION
Stars
1,715
01

Overview

7×24 Desktop AI Agent for Everyone. Visual AI assistant with remote access, file management, and built-in AI browser.

Read from source at commit e0e9be0da18eOBSERVED · 2026-10-08
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: code-commit
description: Must be invoked when the user asks to commit code, submit code, or any similar request.
---

# Code Commit Skill

## Commit Workflow

### 1. Review Changes

Run `git status` and `git diff` in the repository to understand all current changes.

### 2. Pre-commit Checks

Review all changed files. **If any issues are found, report them to the user and wait for confirmation before committing.**

#### 2.1 Temporary Code Detection

Use your judgment to identify code that looks temporary or was clearly left in by accident -- things like `debugger` statements, placeholder values (`test123`, `asdf`, `foo`), commented-out code blocks, or anything that reads like a quick hack not meant for production. Don't be overly rigid; focus on what obviously doesn't belong.

#### 2.2 Temporary File Detection

Check whether any files that should not be committed are included in the changes:

- OS files: `.DS_Store`, `Thumbs.db`, etc.
- Temp files: `*.log`, `*.tmp`, `*.bak`, `*.swp`, etc.
- IDE configs: non-shared files under `.idea/`, `.vscode/`, etc.
- Build artifacts: `node_modules/`, `dist/`, `build/`, etc.
- Sensitive files: `.env`, `credentials.json`, private keys, etc.

#### 2.3 Internationalization & Open-source Readiness

Ensure the code is suitable for an internationalized, open-source project:

- **No hardcoded Chinese strings** in user-facing text (UI labels, prompts, error messages). These should go through the project's i18n mechanism.
- **Comments in English** to align with open-source conventions.
- **No pinyin naming** for variables, functions, or identifiers. Use meaningful English names.
- **No internal/private information** such as internal IP addresses, intranet domains, personal emails, phone numbers, API keys, or secrets.
- **No specific company or brand names** in code, comments, or commit messages — this includes but is not limited to Microsoft, Google, Tencent, Alibaba, Apple, Meta, Amazon, Baidu, ByteDance, etc. Use generic terms instead (e.g., "cloud provider", "search engine", "platform").

### 3. Generate Commit Message

Format:

```
<type>: #AI commit# <concise description>. collaboration and commit by halo
```

**Supported types:**

| type     | usage                                      |
|----------|--------------------------------------------|
| feat     | New feature                                |
| fix      | Bug fix                                    |
| docs     | Documentation changes                      |
| style    | Code formatting (no logic changes)         |
| refactor | Refactoring (no new features or bug fixes) |
| perf     | Performance improvement                    |
| test     | Test-related changes                       |
| chore    | Build, tooling, dependency updates, etc.   |

**Examples:**

```bash
git commit -m "feat: #AI commit# add user authentication module. collaboration and commit by halo"
git commit -m "fix: #AI commit# resolve memory leak in event listener. collaboration and commit by halo"
```

### 4. Execute Commit

```bash
git add <relevant files>
git commit -m "<generated commit message>"
```

- Only stage files that pass the checks. Do not blindly `git add .`.
- Run `git status` after committing to verify.

## Notes

- If there are no changes, inform the user that there is nothing to commit.
- Do not run `git push` unless the user explicitly asks.
- When issues are found during checks, list all of them and ask the user how to proceed. Do not skip issues on your own.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e0e9be0da18efull audit observations/trust-audit/skill/openkursar__code-commit.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-08e0e9be0da18eSAFEB89first audit
05

Questions

What does the Code Commit skill do?

7×24 Desktop AI Agent for Everyone. Visual AI assistant with remote access, file management, and built-in AI browser.

Is Code Commit safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Code Commit access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (e0e9be0da18e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement