Skip to content
Back to skills

Commit 7

ASecurity

Smart commit creation with conventional commits, emoji, and GPG signing. Use when user says "commit" or requests committing changes. Handles staged file detection, suggests splits for multi-concern changes, and applies proper commit format.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
documentationgobashgitdatabaseci/cdsecurityperformancedocumentation

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill commit-7 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Commit 7?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Commit 7
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-commit-7/badge)](https://www.skillsdirectory.com/skills/david-li0406-commit-7)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: commit
description: Smart commit creation with conventional commits, emoji, and GPG signing. Use when user says "commit" or requests committing changes. Handles staged file detection, suggests splits for multi-concern changes, and applies proper commit format.
allowed-tools: "Bash(git *)"
version: 1.0.0
---

# Commit Skill

Creates well-formatted commits following conventional commit standards with emoji prefixes.

## When to Use
- User says "commit", "commit these changes", or uses `/commit`
- After code changes are ready to be committed
- Need help with commit message formatting
- Want automatic detection of multi-concern changes

## Core Features
- **GPG signing** with cached passphrase (if `$GPG_PASSPHRASE` set)
- **Staged vs unstaged detection** - commits only staged files when present
- **Split suggestions** - analyzes diffs for multiple logical changes
- **Conventional commits** - `<emoji> <type>: <description>` format
- **Pre-commit hook integration** - respects Husky/other hooks
- **Always --signoff** - DCO compliance

---

## Process

### 1. Environment Check
```bash
# Check GPG passphrase availability
if [ -n "$GPG_PASSPHRASE" ]; then
  # Cache passphrase
  gpg --batch --pinentry-mode loopback \
      --passphrase-file <(echo "$GPG_PASSPHRASE") \
      --clearsign >/dev/null 2>&1 <<< "test"
  USE_GPG="yes"
else
  USE_GPG="no"
fi
```

### 2. Analyze Changes
```bash
git status --short

# Prefer staged files if any exist
if ! git diff --staged --quiet; then
  git diff --staged --stat    # Staged changes
else
  git diff HEAD --stat        # All changes
fi
```

### 3. Multi-Concern Detection
Suggest split if:
- **Different patterns**: `src/` + `test/` + `docs/`
- **Mixed types**: feat + fix + docs
- **Unrelated concerns**: auth logic + UI styling
- **Large changeset**: >500 lines

**Ask user:**
```
Multiple concerns detected:
1. Auth changes (src/auth/*)
2. UI updates (src/components/*)
3. Docs (README.md)

Split into 3 commits?
- ✨ feat: add JWT authentication
- πŸ’„ style: update login UI
- πŸ“ docs: update auth documentation

[split/all]
```

### 4. Create Commit
Format: `<emoji> <type>: <description>`

**Rules:**
- Imperative mood ("add" not "added")
- First line <72 chars
- Atomic (single purpose)
- Use body for "why" if needed

```bash
git commit --signoff ${USE_GPG:+--gpg-sign} -m "<emoji> <type>: <description>"
```

### 5. Handle --no-verify
If user requests `--no-verify`:
```
⚠️  Requested to skip pre-commit hooks.

Bypasses: linting, tests, formatting
Reason: [ask user]

Approve? [yes/no]
```

Only proceed if confirmed.

---

## Commit Types & Emoji

| Type | Emoji | Use Case |
|------|-------|----------|
| feat | ✨ | New feature |
| fix | πŸ› | Bug fix |
| docs | πŸ“ | Documentation |
| style | πŸ’„ | Formatting, styling |
| refactor | ♻️ | Code restructure |
| perf | ⚑ | Performance |
| test | βœ… | Tests |
| chore | πŸ”§ | Build/tools |
| ci | πŸš€ | CI/CD |
| security | πŸ”’οΈ | Security fix |
| build | πŸ—οΈ | Build system |
| revert | βͺ️ | Revert changes |
| wip | 🚧 | Work in progress |

**Extended emoji map:**
🚚 move | βž• add-dep | βž– remove-dep | 🌱 seed | πŸ§‘β€πŸ’» dx | 🏷️ types | πŸ‘” business | 🚸 ux | 🩹 minor-fix | πŸ₯… errors | πŸ”₯ remove | 🎨 structure | πŸš‘οΈ hotfix | πŸŽ‰ init | πŸ”– release | πŸ’š ci-fix | πŸ“Œ pin-deps | πŸ‘· ci-build | πŸ“ˆ analytics | ✏️ typos | πŸ“„ license | πŸ’₯ breaking | 🍱 assets | ♿️ a11y | πŸ’‘ comments | πŸ—ƒοΈ db | πŸ”Š logs | πŸ”‡ remove-logs | πŸ™ˆ gitignore | πŸ“Έ snapshots | βš—οΈ experiment | 🚩 flags | πŸ’« animations | ⚰️ dead-code | 🦺 validation | ✈️ offline

---

## Split Decision Examples

### ❌ Bad - Mixed concerns
```diff
+ src/auth/login.ts (feat)
+ src/components/Button.css (style)
+ README.md (docs)
```
**Split into:** 3 separate commits

### βœ… Good - Single concern
```diff
+ src/auth/login.ts
+ src/auth/middleware.ts
+ tests/auth.test.ts
```
**One commit:** ✨ feat: add authentication

### ❌ Bad - Mixed types
```diff
+ Add export feature (feat)
+ Fix date bug (fix)
```
**Split into:** 2 commits by type

### ❌ Bad - Large multi-feature
```diff
300+ lines: auth system
200+ lines: UI components
150+ lines: database
```
**Split into:** 3 commits by feature

---

## Critical Rules

### NEVER
- ❌ Add Claude signature to commits
- ❌ Commit without checking staged status
- ❌ Skip split suggestions for multi-concern
- ❌ Use past tense ("added" β†’ "add")
- ❌ Make first line >72 chars
- ❌ Bypass hooks without asking

### ALWAYS
- βœ… Use --signoff flag
- βœ… Check GPG passphrase first
- βœ… Analyze diff before commit
- βœ… Suggest splits when appropriate
- βœ… Use imperative mood
- βœ… Pick correct emoji + type
- βœ… Ask approval for --no-verify

---

## Integration Notes

### With CLAUDE.md
CLAUDE.md references this skill: "Use `/commit` or say 'commit changes'"

### With spec-kit
Reference planning docs in commit body:
```
✨ feat: add user authentication

- JWT token validation
- Protected routes middleware
- Tests cover happy/error paths

Related to Stage 2 of PLAN.md (User Story 1.2)
```

### With Husky
Hooks run automatically unless --no-verify used (requires approval).

---

## Example Sessions

### Simple commit
```
User: "commit these changes"

Process:
1. Check GPG βœ“
2. Analyze: src/auth/login.ts (modified)
3. Single concern βœ“
4. Create: ✨ feat: add login endpoint
5. Execute: git commit --signoff --gpg-sign -m "..."
```

### Split required
```
User: "commit"

Process:
1. Detect: auth + UI + docs
2. Suggest split (3 commits)
3. User confirms "split"
4. Commit each separately with proper emoji/type
```

### Skip hooks
```
User: "/commit --no-verify"

Response:
"⚠️ Skip hooks? Bypasses linting/tests.
Reason: [wait]"

User: "hotfix for production"

Action: Proceed with --no-verify
```

---

## Troubleshooting

### GPG fails
```bash
echo $GPG_PASSPHRASE  # Check set
gpg --clearsign <<< "test"  # Test manually
# If fails: commit without --gpg-sign
```

### Hook fails
Check output β†’ fix issue β†’ retry
Critical case only: ask about --no-verify

### No changes
```bash
git status
# No changes: inform user
# Unstaged only: "Stage files first?"
```

---

## Progressive Disclosure

Keep this main file under 500 lines. For extensive reference:
- Emoji cheatsheet β†’ See `emoji-reference.md` (if needed)
- Advanced patterns β†’ See `advanced-commits.md` (if needed)

Current approach: All essential info in this file for immediate use.

---

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…