Commit HistorySAFE
#1 Persistent memory for AI coding agents based on real-world benchmarks
Overview
#1 Persistent memory for AI coding agents based on real-world benchmarks
739684e68e2eOBSERVED · 2026-10-06What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: commit-history
description: List recent git commits linked to agent sessions, optionally filtered by branch or repo. Use when the user asks "show agent commits", "what has the agent shipped", "list linked commits", or wants commits with their session context.
argument-hint: "[branch=... repo=... limit=...]"
user-invocable: true
---
The user wants a list of agent-linked commits. Filter args: $ARGUMENTS
## Quick start
```json
memory_commits { "branch": "main", "limit": 20 }
```
Expected output:
```text
9a1b2c3 main 2026-06-07 "rotate refresh tokens" · session 7f3a9c2 (14 obs)
b21d004 main 2026-06-05 "rate limiter audit" · session b21d004 (9 obs)
```
## Why
Render only the commits the tool returned, newest first. An empty result means
the filter matched nothing, not that work is missing.
## Workflow
1. Parse `$ARGUMENTS` for `branch=<name>`, `repo=<url-or-fragment>`,
`limit=<n>`. A bare numeric token is the limit. Defaults: no branch, no repo,
limit 100, max 500.
2. Call `memory_commits` with the parsed filters.
3. Render reverse-chronologically: short sha, branch, authored timestamp, first
line of the message, linked session id(s) (first 8) with observation counts,
and file count when `files` is present.
4. Empty result: tell the user the filter matched nothing and suggest dropping
the branch or repo filter.
## Anti-patterns
WRONG (REST fallback): concatenate `?branch=` + raw branch name, so a name with
`?`, `&`, or `#` corrupts the query string.
RIGHT: URL-encode every value with `URLSearchParams`/`encodeURIComponent` before
appending to `GET /agentmemory/commits`.
## Checklist
- Filters parsed; bare number treated as limit; limit capped at 500.
- Output is reverse-chronological.
- Session ids and observation counts come straight from the response.
- REST fallback URL-encodes branch, repo, and limit.
## See also
- `commit-context`: drill into one commit's session.
- `recall`: search the observations behind a linked session.
## Troubleshooting
See ../_shared/TROUBLESHOOTING.md if `memory_commits` is not available.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
739684e68e2efull audit observations/trust-audit/skill/rohitg00__commit-history.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 739684e68e2e | SAFE | B | 89 | first audit |
Questions
What does the Commit History skill do?
#1 Persistent memory for AI coding agents based on real-world benchmarks
Is Commit History safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Commit History access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (739684e68e2e), read on 2026-10-06. The repository is watched, and a new audit runs when it changes — this is the first audit.