本文へ移動
cccskills
無料GitHub で公開

vibe-pre-commit-audit

Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes. Use before creating any commit.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md3.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

vibe-pre-commit-audit

Catch the easy mistakes before they enter history.

When to Use This Skill

  • Before creating a git commit
  • When reviewing your own staged changes
  • Before pushing to a shared branch

When NOT to Use This Skill

  • Commits to personal scratch branches
  • When the user explicitly says to skip checks
  • Auto-generated code commits (lock files, etc.)
  • Private or draft content leaking through built output (use vibe-publication-leak-guard)

Tools First, Eyeballing Second

Pattern-matching a diff by eye misses things that a deterministic scanner catches. Before the manual checks:

  1. Run what the repo already has — pre-commit run, lefthook, husky, or a lint/check script. Check .pre-commit-config.yaml, package.json, and the Makefile.
  2. Run a secret scanner if one is installed (gitleaks protect --staged, trufflehog git file://. --since-commit HEAD) or vibe-cli pre-commit from this repo.
  3. If nothing is set up, suggest adding one (for example vibe-cli hook install, or a gitleaks pre-commit hook), then fall back to the manual checks below.

Tool findings are blocking. The manual checks cover what the tools don't.

Checks

1. Secrets & Credentials

Scan for patterns:

  • API_KEY=, SECRET=, PASSWORD=, TOKEN=
  • AWS keys: AKIA[0-9A-Z]{16}
  • Private keys: -----BEGIN.*PRIVATE KEY-----
  • Connection strings with credentials
  • .env files being staged

2. Debug Statements

  • console.log(, fmt.Println(, print(, debugger;
  • // DEBUG, # DEBUG, /* DEBUG
  • log.Debug in non-debug code paths

3. TODOs Without References

  • TODO without issue number: TODO: fix this (bad)
  • TODO(#123): fix this (good)
  • FIXME, HACK, XXX — flag all

4. Disabled Tests

  • t.Skip(, xit(, xdescribe(, @pytest.mark.skip
  • Commented-out test functions
  • //nolint without justification

5. Large Files

  • Files > 1MB
  • Binary files (images, compiled assets)
  • Lock files with excessive changes

6. Commented-Out Code

  • Blocks of 3+ consecutive commented-out lines of code
  • Not comments explaining code, but actual code that's commented out

Output Format

Pre-Commit Audit

Status: CLEAN / WARNINGS / BLOCKED Tools run: [e.g., pre-commit run, gitleaks protect --staged, or "none configured"]

CheckStatusFindings
Scanner / hooks✓/✗/n/aX findings
Secrets✓/✗X patterns found
Debug statements✓/✗X occurrences
TODOs✓/◐X without references
Disabled tests✓/✗X found
Large files✓/✗X over limit
Commented code✓/◐X blocks

Blocking Issues (must fix)

  1. [Secret found in file.go:42]

Warnings (should fix)

  1. [TODO without reference in handler.ts:15]

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Validates completed work against defined acceptance criteria. Use after completing a task that has specific success criteria defined in issues, specs, or task descriptions.

日本語の概要は準備中です。原文の説明を表示しています。

ash1794/vibe-engineering1632026年10月8日 更新

Generates edge case, failure mode, and spec-driven test cases. Covers boundary values, nil inputs, concurrency, resource exhaustion, malformed data, and requirement-linked traceability tests. Use after happy-path tests exist and before claiming coverage is complete, when requirements lack tests, or before a security review.

日本語の概要は準備中です。原文の説明を表示しています。

ash1794/vibe-engineering1632026年10月8日 更新

Catches shortcuts and reward hacking — weakening or deleting tests to make them pass, hard-coding expected outputs, silently dropping requirements, or claiming work is done without running it. Use before declaring a task complete and whenever a test or requirement feels like it's in the way.

日本語の概要は準備中です。原文の説明を表示しています。

ash1794/vibe-engineering1632026年10月8日 更新

Safely integrates commits from parallel agent branches using sequential cherry-pick. Use after parallel work completes in isolated branches or worktrees.

日本語の概要は準備中です。原文の説明を表示しています。

ash1794/vibe-engineering1632026年10月8日 更新

Audits tests for concurrency safety — race conditions, shared mock state, cleanup ordering. Use when writing tests that involve goroutines, async operations, or shared mutable state.

日本語の概要は準備中です。原文の説明を表示しています。

ash1794/vibe-engineering1632026年10月8日 更新

Enforces tiered test coverage standards with three dimensions — line coverage by tier, spec-to-test traceability, and spec-to-code implementation mapping. Use before claiming code is complete.

日本語の概要は準備中です。原文の説明を表示しています。

ash1794/vibe-engineering1632026年10月8日 更新

ash1794 のスキルをすべて見る

このスキルの問題を報告する