Agent skill

Commit Message

by ctrsploit in ctrsploit/ctrsploit

Generate semantic commit messages and commit safely. An agent skill from ctrsploit/ctrsploit.

No licenceAuto-check passedDevelopment

Install Commit Message

skills CLI
$ npx skills add ctrsploit/ctrsploit --skill commit-message -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ctrsploit/ctrsploit commit-message --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ctrsploit/ctrsploit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/commit-message .claude/skills/commit-message && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
commit-message
GitHub stars
154
Token cost
~823 tokens
SKILL.md length
380 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
None found

At a glance

Generate semantic commit messages and commit safely. An agent skill from ctrsploit/ctrsploit.

  • Works in 4 steps: Analyze staged changes (files, logic,… → Check atomicity → Draft output using the template below. → …
  • Tasks that involve Commit messages
  • SKILL.md covers Goal, Workflow, Commit Message Format… and Common Types for This Project, plus 5 more sections
  • Calls git

What it does

Commit Message is an agent skill from ctrsploit/ctrsploit. Generate semantic commit messages and commit safely

Its SKILL.md is about 820 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Commit messages. The repository describes itself as: A penetration toolkit for container environment.

When your agent uses it

  • Tasks that involve Commit messages

Example prompts

  • “/commit-message”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Analyze staged changes (files, logic, and config).
  2. Check atomicity
  3. Draft output using the template below.
  4. If committing is requested, follow the commit execution protocol exactly.

What it can do on your machine

Read from SKILL.md and the folder at commit 0fe4d82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Commit Message loads about 823 tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 380 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~823

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 380 words (~823 tokens).

name
commit-message

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .opencode/skills/commit-message of ctrsploit/ctrsploit.

Open the folder on GitHubat commit 0fe4d82

Compare with similar skills

Commit Message next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Commit Message compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Commit Message this skillctrsploit/ctrsploit154—~823Automated safety check: PassNone
Contextual Commit Messagesyamadashy/repomix29k1 repos~2.7kAutomated safety check: PassMIT
React Router Release Notes Prepremix-run/react-router57k—~1.1kAutomated safety check: PassMIT
Caveman Commitvishiri/fantasia-archive40913 repos~642Automated safety check: PassGPL-3.0
PR Finalize Reviewmicrosoft/garnet12k—~3.1kAutomated safety check: PassMIT
ToolJet Multi-Repo CommitToolJet/ToolJet41k—~1.3kAutomated safety check: PassAGPL-3.0

Similar skills

  • Writes Conventional Commits whose bodies carry action lines recording the intent, decisions and constraints behind a change, not only what changed.

    29k GitHub starsUsed in 1 repo~2.7k tokens
    DevelopmentAuto-check passed
  • React Router Release Notes Prep

    remix-run/react-router

    Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.

    57k GitHub stars~1.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Caveman Commit

    vishiri/fantasia-archive

    Ultra-compressed commit message generator. An agent skill from vishiri/fantasia-archive.

    409 GitHub starsUsed in 13 repos~642 tokens
    DevelopmentAuto-check passed
  • PR Finalize Review

    microsoft/garnet

    Official

    Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.

    12k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Commits changes across ToolJet's root repo and its server/ee and frontend/ee submodules, writing messages from the diffs and updating submodule pointers in order.

    41k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Git Workflow and Versioning

    addyosmani/agent-skills

    Sets git habits for every change: short-lived branches, atomic commits with descriptive messages, clean pull requests, plus versioning, tagging and changelogs for releases.

    103k GitHub starsUsed in 2 repos~3.5k tokens
    DevelopmentAuto-check: notes

More from ctrsploit/ctrsploit

  • Dqd Lab

    ctrsploit/ctrsploit

    Manage ctrsploit dqd lab environments from github.com/ctrsploit/dqd.

    154 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Record Terminal Session

    ctrsploit/ctrsploit

    Record terminal demonstrations for ctrsploit vulnerabilities and convert asciinema .cast captures into project-style SVG or GIF artifacts.

    154 GitHub stars~5.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Release Notes

    ctrsploit/ctrsploit

    Draft ctrsploit release notes for a target version by comparing git tags, mapping merge commits to GitHub PRs, and grouping user-visible changes by module and object.

    154 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Commit Message

What does Commit Message do?

Generate semantic commit messages and commit safely. An agent skill from ctrsploit/ctrsploit. Commit Message is an agent skill from ctrsploit/ctrsploit.

When should I use Commit Message?

Commit Message fits situations like: tasks that involve Commit messages.

How do I install Commit Message in Claude Code?

Run `npx skills add ctrsploit/ctrsploit --skill commit-message -a claude-code`. Or copy the skill folder (.opencode/skills/commit-message in ctrsploit/ctrsploit) into .claude/skills/commit-message in your project. Claude Code loads it when a task matches its description.

How do I install Commit Message in Codex?

Run `npx skills add ctrsploit/ctrsploit --skill commit-message -a codex`. Or copy the skill folder (.opencode/skills/commit-message in ctrsploit/ctrsploit) into .agents/skills/commit-message in your project. Codex loads it when a task matches its description.

Can I use Commit Message in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ctrsploit/ctrsploit --skill commit-message -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/commit-message, .gemini/skills/commit-message, .github/skills/commit-message and .opencode/skills/commit-message in your project.

What does Commit Message need to run?

Going by SKILL.md and its folder, Commit Message needs the command-line tools its instructions call (git).

Does Commit Message access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Commit Message safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Commit Message use?

No licence was found for Commit Message or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Commit Message use?

About 823 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Commit Message?

Skills that share tags, products or a category with Commit Message: Contextual Commit Messages (yamadashy/repomix, 29k stars), React Router Release Notes Prep (remix-run/react-router, 57k stars), Caveman Commit (vishiri/fantasia-archive, 409 stars) and PR Finalize Review (microsoft/garnet, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Commit Message?

ctrsploit (a GitHub organization) maintains it in ctrsploit/ctrsploit, which has 154 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on August 20, 2026.

Source: ctrsploit/ctrsploit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.