Agent skill

Vibe Pre Commit Audit

by ash1794 in ash1794/vibe-engineering

Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes.

MITAuto-check: notesDevelopment

Install Vibe Pre Commit Audit

skills CLI
$ npx skills add ash1794/vibe-engineering --skill vibe-pre-commit-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ash1794/vibe-engineering vibe-pre-commit-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ash1794/vibe-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vibe-engineering/skills/vibe-pre-commit-audit .claude/skills/vibe-pre-commit-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vibe-pre-commit-audit
GitHub stars
163
Token cost
~753 tokens
SKILL.md length
350 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
MIT

At a glance

Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes.

  • Works in 6 steps: Secrets & Credentials → Debug Statements → TODOs Without References → …
  • Development work in your project
  • SKILL.md covers When to Use This Skill, When NOT to Use This Skill, Tools First, Eyeballing Second and Checks, plus 1 more section
  • Calls gitleaks; needs API_KEY

What it does

Vibe Pre Commit Audit is an agent skill from ash1794/vibe-engineering. Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes. Use before creating any commit.

Its SKILL.md is about 750 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: 33 engineering discipline skills for Claude Code, OpenAI Codex & Gemini CLI + a CLI for CI/CD enforcement. Extracted from real-world multi-agent system development. Born from… The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “Use the vibe-pre-commit-audit skill to scan staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes”
  • “/vibe-pre-commit-audit”

Requirements

  • A credential in API_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Secrets & Credentials
  2. Debug Statements
  3. TODOs Without References
  4. Disabled Tests
  5. Large Files
  6. Commented-Out Code

What it can do on your machine

Read from SKILL.md and the folder at commit 8f1d71b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gitleaks

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vibe Pre Commit Audit loads about 753 tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 350 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~753

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:42
    - `.env` files being staged

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ash1794/vibe-engineering at commit 8f1d71b, republished under its MIT licence (© ash1794). 350 words, ~753 tokens.

Download SKILL.mdSave it as .claude/skills/vibe-pre-commit-audit/SKILL.md (or your agent's skills folder).
name
vibe-pre-commit-audit
description
Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes. Use before creating any commit.
user-invocable
true

vibe-pre-commit-audit

Catch the easy mistakes before they enter history.

When to Use This Skill

  • Before creating a git commit
  • When reviewing your own staged changes
  • Before pushing to a shared branch

When NOT to Use This Skill

  • Commits to personal scratch branches
  • When the user explicitly says to skip checks
  • Auto-generated code commits (lock files, etc.)
  • Private or draft content leaking through built output (use vibe-publication-leak-guard)

Tools First, Eyeballing Second

Pattern-matching a diff by eye misses things that a deterministic scanner catches. Before the manual checks:

  1. Run what the repo already has — pre-commit run, lefthook, husky, or a lint/check script. Check .pre-commit-config.yaml, package.json, and the Makefile.
  2. Run a secret scanner if one is installed (gitleaks protect --staged, trufflehog git file://. --since-commit HEAD) or vibe-cli pre-commit from this repo.
  3. If nothing is set up, suggest adding one (for example vibe-cli hook install, or a gitleaks pre-commit hook), then fall back to the manual checks below.

Tool findings are blocking. The manual checks cover what the tools don't.

Checks

1. Secrets & Credentials

Scan for patterns:

  • API_KEY=, SECRET=, PASSWORD=, TOKEN=
  • AWS keys: AKIA[0-9A-Z]{16}
  • Private keys: -----BEGIN.*PRIVATE KEY-----
  • Connection strings with credentials
  • .env files being staged
2. Debug Statements
  • console.log(, fmt.Println(, print(, debugger;
  • // DEBUG, # DEBUG, /* DEBUG
  • log.Debug in non-debug code paths
Show full SKILL.md (140 more words)Show less
3. TODOs Without References
  • TODO without issue number: TODO: fix this (bad)
  • TODO(#123): fix this (good)
  • FIXME, HACK, XXX — flag all
4. Disabled Tests
  • t.Skip(, xit(, xdescribe(, @pytest.mark.skip
  • Commented-out test functions
  • //nolint without justification
5. Large Files
  • Files > 1MB
  • Binary files (images, compiled assets)
  • Lock files with excessive changes
6. Commented-Out Code
  • Blocks of 3+ consecutive commented-out lines of code
  • Not comments explaining code, but actual code that's commented out

Output Format

Pre-Commit Audit

Status: CLEAN / WARNINGS / BLOCKED Tools run: [e.g., pre-commit run, gitleaks protect --staged, or "none configured"]

CheckStatusFindings
Scanner / hooks✓/✗/n/aX findings
Secrets✓/✗X patterns found
Debug statements✓/✗X occurrences
TODOs✓/◐X without references
Disabled tests✓/✗X found
Large files✓/✗X over limit
Commented code✓/◐X blocks
Blocking Issues (must fix)
  1. [Secret found in file.go:42]
Warnings (should fix)
  1. [TODO without reference in handler.ts:15]

© ash1794, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/vibe-engineering/skills/vibe-pre-commit-audit of ash1794/vibe-engineering.

Open the folder on GitHubat commit 8f1d71b

Compare with similar skills

Vibe Pre Commit Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vibe Pre Commit Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vibe Pre Commit Audit this skillash1794/vibe-engineering163—~753Automated safety check: NotesMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from ash1794/vibe-engineering

All 33 skills in this repo
  • Vibe Concurrent Test Safety

    ash1794/vibe-engineering

    Audits tests for concurrency safety — race conditions, shared mock state, cleanup ordering.

    163 GitHub stars~665 tokensUpdated today
    Auto-check passed
  • Vibe Fuzz Parser Inputs

    ash1794/vibe-engineering

    Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

    163 GitHub stars~722 tokensUpdated today
    Auto-check passed
  • Vibe Golden File Testing

    ash1794/vibe-engineering

    Implements snapshot/golden file tests with temporal normalization so tests don't break daily.

    163 GitHub stars~669 tokensUpdated today
    Auto-check passed
  • Vibe Parallel Task Decomposition

    ash1794/vibe-engineering

    Analyzes large tasks for independent subtasks that can be safely parallelized.

    163 GitHub stars~717 tokensUpdated today
    Auto-check passed
  • Vibe Slop Filter

    ash1794/vibe-engineering

    Strips AI-generation "smell" from prose before it ships (READMEs, docs, release notes, PR descriptions, posts, emails).

    163 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Vibe Spec Sync

    ash1794/vibe-engineering

    Keeps specification documents and code in agreement. An agent skill from ash1794/vibe-engineering.

    163 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Vibe Pre Commit Audit

What does Vibe Pre Commit Audit do?

Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes. Vibe Pre Commit Audit is an agent skill from ash1794/vibe-engineering. Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes.

When should I use Vibe Pre Commit Audit?

Vibe Pre Commit Audit fits situations like: development work in your project.

How do I install Vibe Pre Commit Audit in Claude Code?

Run `npx skills add ash1794/vibe-engineering --skill vibe-pre-commit-audit -a claude-code`. Or copy the skill folder (plugins/vibe-engineering/skills/vibe-pre-commit-audit in ash1794/vibe-engineering) into .claude/skills/vibe-pre-commit-audit in your project. Claude Code loads it when a task matches its description.

How do I install Vibe Pre Commit Audit in Codex?

Run `npx skills add ash1794/vibe-engineering --skill vibe-pre-commit-audit -a codex`. Or copy the skill folder (plugins/vibe-engineering/skills/vibe-pre-commit-audit in ash1794/vibe-engineering) into .agents/skills/vibe-pre-commit-audit in your project. Codex loads it when a task matches its description.

Can I use Vibe Pre Commit Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ash1794/vibe-engineering --skill vibe-pre-commit-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vibe-pre-commit-audit, .gemini/skills/vibe-pre-commit-audit, .github/skills/vibe-pre-commit-audit and .opencode/skills/vibe-pre-commit-audit in your project.

What does Vibe Pre Commit Audit need to run?

Going by SKILL.md and its folder, Vibe Pre Commit Audit needs the command-line tools its instructions call (gitleaks) and credentials named API_KEY. Our summary lists: A credential in API_KEY.

Does Vibe Pre Commit Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vibe Pre Commit Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vibe Pre Commit Audit use?

Vibe Pre Commit Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vibe Pre Commit Audit use?

About 753 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vibe Pre Commit Audit?

Skills that share tags, products or a category with Vibe Pre Commit Audit: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vibe Pre Commit Audit?

ash1794 (a GitHub user) maintains it in ash1794/vibe-engineering, which has 163 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 7, 2026.

Source: ash1794/vibe-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.