Pre-commit quality gate - run lint, typecheck, test LOCALLY before committing. Prevents wasted CI time and embarrassing build failures.
Pro shows the line behind each finding and how to fix it
Scanned 10/6/2026
npx -y skills add bordenet/superpowers-plus --skill pre-commit-gate --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Pre Commit Gate?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/bordenet-pre-commit-gate)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: pre-commit-gate
disable-model-invocation: true
source: superpowers-plus
triggers: ["/sp-precommit", "commit:pre-check"]
anti_triggers: ["review PR", "review this PR", "output looks wrong", "debug this"]
description: Pre-commit quality gate - run lint, typecheck, test LOCALLY before committing. Prevents wasted CI time and embarrassing build failures.
summary: "Use when: about to commit code. Skip when: drafting or exploring."
coordination:
group: commit-gates
order: 1
requires: []
enables: ["enforce-style-guide"]
escalates_to: []
internal: false
composition:
consumes: [code-changes]
produces: [lint-results, test-results]
capabilities: [gates-quality]
priority: 30
---
# Pre-Commit Quality Gate
> **Wrong skill?** Reviewing a PR → `providing-code-review`. Output verification → `output-verification`. Completion check → `verification-before-completion`.
>
> **Source:** `superpowers-plus`
> **Part of:** Engineering Rigor skill family
## When to Use
- Before every `git commit` — run local lint, typecheck, and tests first
- Before pushing to any remote branch (CI should confirm, not discover)
- After resolving merge conflicts to verify nothing broke
- When preparing a hotfix under time pressure (especially then)
## The Rule
**RUN THESE LOCALLY BEFORE EVERY `git commit`.** Not after CI fails — BEFORE you commit.
## This Gate's Checks: Safety Scan → Lint → Typecheck → Test
```bash
# 0. Dangerous pattern scan (MUST pass if .sh files are staged)
~/.codex/superpowers-plus/tools/dangerous-pattern-scan.sh
# 1. Lint (MUST pass with zero errors)
npm run lint # or: pnpm run lint, biome check .
# 2. Typecheck (MUST pass with zero errors)
npm run typecheck # or: tsc --noEmit
# 3. Test (MUST pass — excluding known infrastructure failures)
npm test # or: vitest --run
```
**After this gate passes, the remaining commit gates run in order:**
enforce-style-guide (2) → progressive-code-review-gate (3) → professional-language-audit (4) → public-repo-ip-audit (5) → commit → push.
> **Preferred:** `use-skill unified-commit-gate` loads all 5 gates in one load. Use individual skills for deep-dive when a specific gate fails.
> **Step 0** only runs when `.sh` files are staged. It detects unguarded `rm -rf`,
> `chmod 777`, `curl | bash`, and other destructive patterns. Hardcoded safe paths
> (e.g., `rm -rf ~/.codex/something`) produce warnings, not blocks. <!-- doctor-ignore -->
> Use `--all` flag to scan the entire repo: `dangerous-pattern-scan.sh --all`
## Why This Gate Exists
> **Common failure:** Pushing code without running local checks, then debugging CI failures. Lint errors, type errors, and test failures are all detectable locally. Instead of running checks locally first, developers push, wait for CI, read logs, fix, push again — wasting multiple CI cycles that could have been zero.
## Pre-Commit Checklist
- [ ] `dangerous-pattern-scan.sh` — no blocked patterns (if .sh files staged)
- [ ] `npm run lint` — zero errors (warnings OK if project allows)
- [ ] `npm run typecheck` — zero errors
- [ ] `npm test` — all tests pass (or only pre-existing failures)
- [ ] Reviewed staged changes (`git diff --staged`)
**Skip any step = wasted CI time + embarrassing build failures**
## Acceptable vs. Not Acceptable
| Acceptable | Not Acceptable |
|------------|----------------|
| Pre-existing infrastructure test failures (e.g., lockfile conflict) | New failures you introduced |
| Lint warnings if project config allows them | Lint errors |
| Skipped tests marked `@skip` | Tests you broke |
## The Gate Function
```text
BEFORE EVERY COMMIT:
0. Did I run `dangerous-pattern-scan.sh`? (if .sh files staged — zero blocked patterns)
1. Did I run the lint command AND show the output in my response? (zero errors)
2. Did I run the typecheck command AND show the output? (zero errors)
3. Did I run the test command AND show the output? (all pass or only pre-existing failures)
4. Did I review staged changes? (`git diff --staged`)
If NO to any → DO NOT COMMIT
```
## Chain to Next Gate
**When this gate passes, IMMEDIATELY load the next gate in the chain:**
```
use-skill enforce-style-guide
```
Then continue: `progressive-code-review-gate` → `professional-language-audit` → `public-repo-ip-audit` (gates 4–5 when applicable). Do NOT commit between gates.
## Post-Commit: Verify Build Status
**DO NOT update ticket status or claim "done" until ALL builds pass.**
```bash
# Check CI status for your PR
# Look for: all checks passing
# NOT just merge status (that only means merge is possible)
```
| Check | Required Before "Done" |
|-------|------------------------|
| PR created/merged | ✅ Yes |
| Build triggered | ✅ Yes |
| Build result = succeeded | ✅ Yes |
| No lint/test failures in CI logs | ✅ Yes |
**If build fails after push:**
1. Check pipeline logs immediately
2. Fix the issue locally
3. Push fix to branch
4. Verify new build passes
5. THEN update ticket status
## Companion Skills
- **enforce-style-guide**: Style fixes (step 2 in commit chain)
- **progressive-code-review-gate**: Code review (step 3)
- **professional-language-audit**: Language check (step 4)
- **public-repo-ip-audit**: IP/license audit (step 5)
- **verification-before-completion**: After commit gates, before "done"
- **blast-radius-check**: Before modifying existing code
- **output-verification**: Before claiming generated artifacts correct
## Failure Modes
| Failure | Recovery |
|---------|----------|
| Claiming 'lint passes' without showing output | VIOLATION: Every gate claim requires visible tool output in response |
| Running tests after push (CI-first anti-pattern) | Run ALL gates locally before `git commit`. CI confirms, not discovers. |
| Skipping dangerous-pattern-scan for .sh files | Step 0 is mandatory when .sh files are staged |
| Not re-running gates after fixing gate failures | Fixes are new code. They need their own gate pass. |
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!