Use when committing and pushing to GitHub — guarantees every commit passes lint/format checks, has no Claude co-author or generated-with footer, uses the user's real identity (Fqih / mhmdfkih21@gmail.com), and lands on the remote as a single all-or-nothing unit. Trigger on "commit and push", "push to github", "atomic push", "/atomic-push".
2 stars
0 votes
0 copies
2 views
Added September 19, 2026
ai-agentsbashgitapi
Works with
claude code
api
Security analysis
A96/100
mediumInstalls packages at runtime which could introduce malicious dependencies
Installs into .claude/skills of the current project.
Are you the author of Atomic Github Push?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/fqih-atomic-github-push)
---
name: atomic-github-push
description: Use when committing and pushing to GitHub — guarantees every commit passes lint/format checks, has no Claude co-author or generated-with footer, uses the user's real identity (Fqih / mhmdfkih21@gmail.com), and lands on the remote as a single all-or-nothing unit. Trigger on "commit and push", "push to github", "atomic push", "/atomic-push".
---
# atomic-github-push
Commit + push sebagai **satu unit atomik**. Satu cek gagal = abort total, tidak ada commit setengah jadi, tidak ada push tanpa lint bersih.
## Identity (wajib, hard fail)
Verifikasi sebelum commit apa pun:
```bash
git config user.name # harus: Fqih
git config user.email # harus: mhmdfkih21@gmail.com
```
Salah satu salah → **STOP**. Jangan commit. Jangan bypass dengan `-c user.name=...`. Minta user koreksi via `git config --global`.
Per-repo override yang salah (FQIH/school alias) → tulis ulang dengan `git config --global`, lalu ulang di repo target dengan `--local`.
## Pre-commit checks (wajib, run berurutan)
Jalankan dari root repo:
```bash
# 1. ruff lint
ruff check .
# 2. ruff format cek (tidak write, hanya verify)
ruff format --check .
# 2b. notebook output strip (jika ada .ipynb di staged)
if git diff --cached --name-only | grep -q '\.ipynb$'; then
if command -v nbstripout >/dev/null 2>&1; then
# strip output dari staged notebook
git diff --cached --name-only --diff-filter=AM | grep '\.ipynb$' | xargs -I{} nbstripout {}
git add '*.ipynb'
else
echo "BLOCKED: .ipynb di staged tapi nbstripout tidak terinstall"
echo "Install: pip install nbstripout && nbstripout --install"
exit 1
fi
fi
```
Dua-duanya exit 0. Salah satu exit non-zero → **abort**. Jangan `--no-verify`. Jangan commit dengan `--no-edit` setelah auto-fix; minta user konfirmasi perubahan format dulu.
> Catatan: jika project tidak punya `ruff` (mis. JS-only), skip cek ruff dan laporkan ke user, jangan auto-install.
## Commit message rules
- Subject ≤ 72 char, imperative mood ("Add", "Fix", "Refactor", bukan "Added" / "Added X").
- Conventional commits prefix bila repo sudah pakai: `feat:`, `fix:`, `refactor:`, `test:`, `docs:`, `chore:`.
- Body kosong kecuali user minta detail.
### **DILARANG KERAS** di commit message (cek via grep sebelum commit)
- `Co-Authored-By: ...Claude` (apa pun variannya)
- `Co-Authored-By: ...Anthropic`
- `Co-Authored-By: ...noreply@anthropic.com`
- `🤖 Generated with [Claude Code]`
- `Generated by Claude`
- Footer kedua atau lebih dari satu `Co-Authored-By:` (cuma boleh Fqih jika ada)
Cek otomatis:
```bash
MSG_FILE=$(mktemp)
# tulis message ke $MSG_FILE
grep -E -i 'co-authored-by.*(claude|anthropic|noreply@anthropic)' "$MSG_FILE" && { echo "BLOCKED: Claude co-author terdeteksi"; rm "$MSG_FILE"; exit 1; }
grep -q 'Generated with \[Claude Code\]' "$MSG_FILE" && { echo "BLOCKED: Claude generator footer"; rm "$MSG_FILE"; exit 1; }
```
## Push rules
```bash
# rebase tipis agar fast-forward, bukan merge commit
git pull --rebase origin "$(git branch --show-current)" || { echo "BLOCKED: rebase conflict, resolve manual"; exit 1; }
# push
git push origin HEAD
```
Push gagal (non-fast-forward, rejected) → **STOP**. Jangan `--force` kecuali user eksplisit minta. Jangan `--force-with-lease` pun tanpa konfirmasi.
## Workflow urutan
1. Cek `git status` — working tree harus clean atau staged saja, tidak ada untracked yang akan ikut.
2. Cek identity (atas).
3. **Scan staged files untuk secret** (invoke skill `secret-scan`). Leak detected → **abort**.
4. Stage: `git add -A` (atau file eksplisit jika user minta).
5. Run ruff checks.
6. Tulis commit message ke temp file.
7. Grep blocker patterns (Claude co-author + generator footer).
8. `git commit -F "$MSG_FILE"`.
9. `git pull --rebase`.
10. **Pre-push scan secret** (skill `secret-scan`, mode detect).
11. `git push origin HEAD`.
12. Lapor ringkas: branch, commit hash, files changed.
## Bila gagal
| Gagal di langkah | Tindak |
|---|---|
| Identity salah | STOP, minta user fix `git config` |
| Ruff lint fail | Tampilkan error, jangan auto-fix tanpa izin |
| Format check fail | Tampilkan diff, minta user jalankan `ruff format .` manual |
| Co-author terdeteksi | Hapus dari message, ulang langkah 5–7 |
| Push rejected | STOP, jangan force, lapor ke user |
| Rebase conflict | STOP, serahkan ke user |
## Invokation
Skill ini auto-trigger saat user bilang:
- "commit and push"
- "push to github"
- "atomic push"
- "/atomic-push"
Atau saat context jelas: ada staged changes + user minta "push" / "commit" di repo dengan origin GitHub.
## Bukan untuk
- Repo tanpa `origin` GitHub remote (skill ini asumsi GitHub push)
- Commit tanpa push (gunakan git biasa)
- Force push / history rewrite (tindakan terpisah, butuh konfirmasi manual user)