Skip to content
Back to skills

Commit

ASecurity

Use when committing changes to git - provides best practices for staging, commit messages, signing, and handling hook failures

  • 10 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added February 9, 2026
code-qualityshellgitdocumentation

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add technicalpickles/pickled-claude-plugins --skill commit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Commit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Commit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/technicalpickles-commit/badge)](https://www.skillsdirectory.com/skills/technicalpickles-commit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: commit
description: Use when committing changes to git - provides best practices for staging, commit messages, signing, and handling hook failures
---

# Git Commit

Preferences and best practices for interacting with a git repository.

## git add

ALWAYS use `git add` with specific files that have been updated. NEVER use `git add .` or `git add -A`.

IF adding files that look like they are agent configuration, or adding planning documentation, ALWAYS prompt the user to confirm if they should be included or not.

## git commit

PREFER writing the commit message to a file under `$TMPDIR`, named for what is being committed, then commit with `git commit -F "$TMPDIR/path-to-message.txt"`.

Use `-F` (`--file`), NEVER `-t` (`--template`). A template opens the message in an editor and git aborts if it comes back unchanged (`Aborting commit; you did not edit the message.`). Agent shells run with a no-op editor, so `-t` always aborts. The abort comes after pre-commit hooks run, so the failure looks like a hook problem. It isn't; don't reach for `--no-verify`.

Put any trailers your instructions require (e.g. `Co-Authored-By:`) at the end of the message file. Writing the message to a file first makes these easy to forget.

### scope the commit to your paths

PREFER `git commit -F <file> -- <path>...` over a bare `git commit`. A bare commit takes everything currently staged, including files another session or tool staged in the same working tree between your `git add` and your `git commit`. Naming the paths commits only what you meant to.

Path-limited commits take the working-tree version of those files, so skip `-- <path>` when you deliberately staged only some hunks of a file.

### signing

We have git commit signing setup. If it fails due to a message like:

    error: 1Password: failed to fill whole buffer

    fatal: failed to write commit object

... it is because the user was being prompted to authorize signing, and didn't see it or missed it. Do not try to fix or bypass it. Stop and prompt the user about either fixing it, or confirm bypassing it.

## hooks

### pre-commit failures

When git precommit checks fail, analyze what the failures are, and try to autofix when possible, otherwise think through how to fix it. Ask the user how to proceed when it's unclear if how to fix.

DO NOT follow sorbet's autocorrection advice.
DO NOT skip verification without confirmation from the user.

### prepare-commit-msg and post-commit

If we see errors like:

```
git: 'duet-prepare-commit-msg' is not a git command. See 'git --help'.
```

it is because we previously were using git-duet. It uses a git template, with hooks that call `git duet-prepare-commit-msg`. We've sinced moved, but the files will still be present

In this case, check .git/hooks/ for references to these. Remove files that call it.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…