Agent skill

Spec Commit

by leo-kuang-ai in leo-kuang-ai/spec-first

Internal commit helper for public workflows that already hold explicit commit authorization; creates scoped, value-communicating commits without owning push or PR landing.

MITAuto-check: notesDevelopment

Install Spec Commit

skills CLI
$ npx skills add leo-kuang-ai/spec-first --skill spec-commit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install leo-kuang-ai/spec-first spec-commit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spec-commit .claude/skills/spec-commit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spec-commit
GitHub stars
107
Token cost
~2.1k tokens
SKILL.md length
1,109 words
Files
9
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Internal commit helper for public workflows that already hold explicit commit authorization; creates scoped, value-communicating commits without owning push or PR landing.

  • Works in 5 steps: Gather context → Determine commit message convention → Consider logical commits → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Invocation And Authorization…, Context and Workflow
  • Runs Shell and JavaScript scripts from its folder; calls git and gh

What it does

Spec Commit is an agent skill from leo-kuang-ai/spec-first. Internal commit helper for public workflows that already hold explicit commit authorization; creates scoped, value-communicating commits without owning push or PR landing.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files (for example `evals/cases/fresh-tree-logical-grouping.yaml`, `evals/cases/no-auth-stops-before-staging.yaml` and `evals/eval.yaml`).

It sits in Development, covering Authorization and RBAC and Commit messages. It works with Git. The repository describes itself as: 仓库原生 AI Coding Harness —— 把一次性 AI 对话变成可治理、可验证、可沉淀的工程闭环 · spec-first.cn. The licence is MIT.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve Commit messages

Example prompts

  • “/spec-commit”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Gather context
  2. Determine commit message convention
  3. Consider logical commits
  4. Stage and commit
  5. Confirm

What it can do on your machine

Read from SKILL.md and the folder at commit 74655dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell and JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spec Commit loads about 2.1k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,109 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:103
    accidentally including sensitive files (.env, credentials) or unrelated changes. Write the message to a temp file and c

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from leo-kuang-ai/spec-first at commit 74655dc, republished under its MIT licence (© leo-kuang-ai). 1,109 words, ~2,081 tokens.

Download SKILL.mdSave it as .claude/skills/spec-commit/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
spec-commit
description
Internal commit helper for public workflows that already hold explicit commit authorization; creates scoped, value-communicating commits without owning push or PR landing.
user-invocable
false

Git Commit

Create a single, well-crafted git commit from the current working tree changes.

Invocation And Authorization Boundary

This is an internal-only helper. A public workflow may delegate here only after the current user or a visible upstream handoff has established commit_authorization: authorized for the intended run-owned paths. Record branch authority separately:

yaml
commit_authorization: authorized | missing
branch_mutation_authorization: authorized | missing

workflow invocation does not authorize commit; tool permission, a dirty tree, a branch name, or successful verification are execution facts, not authority. Explicit commit authorization does not imply branch mutation authorization. When any commit intent is expressed while commit authorization is missing, stop before branch mutation, staging, or commit and return commit_authorization_missing. When a checkout or new branch is needed but branch authority is missing, stop before that Git mutation and return branch_mutation_authorization_missing or obtain approval for the exact branch action. A pure status question about uncommitted changes (no commit intent expressed) does not trigger this gate: answer the query directly, mutate nothing, and do not stage or commit.

This helper owns commit composition and the authorized commit checkpoint only. It does not own push, PR creation/update, plan lifecycle, or unrelated dirty paths. If branch creation would be required, obtain explicit approval for that concrete branch mutation before creating it.

Context

Gather Git context by running each command as its own argv-style shell tool call. Do not join commands with shell separators, pipes, substitutions, or redirects; those forms are host-shell-specific and can hide the real exit status.

CommandPurposeNon-zero or empty result
git statusWorking-tree stateNot a Git repository: stop
git diff HEADUncommitted changesAn unborn repo may have no HEAD; inspect tracked changes directly
git branch --show-currentCurrent branchEmpty output means detached HEAD
git log --oneline -10Commit-message conventionAn unborn repo has no history
git rev-parse --abbrev-ref origin/HEADRemote default branchResolve it using the fallback in Step 1

These facts are a snapshot. Re-read the branch and staged paths immediately before committing because the working tree may change after intake.


Workflow

Step 1: Gather context

Run every command in the Context section as a separate shell tool call.

The remote default branch value returns something like origin/main. Strip the origin/ prefix to get the branch name. If the command exited non-zero or returned a bare HEAD, try:

bash
gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name'

If both fail, fall back to main.

If the git status from the context above shows a clean working tree (no staged, modified, or untracked files), report that there is nothing to commit and stop.

If the current branch from the context above is empty, the repository is in detached HEAD state. Explain that a branch is required if the user wants this work attached to a branch. When branch_mutation_authorization: missing, ask whether to create the exact proposed feature branch now and do not run checkout first. Use the platform's blocking question tool: AskUserQuestion in Claude Code (call ToolSearch with select:AskUserQuestion first if its schema isn't loaded) or request_user_input in Codex. Fall back to presenting options in chat only when no blocking tool exists in the harness or the call errors (e.g., Codex edit modes) — not because a schema load is required. Never silently skip the question.

  • If the user authorizes the displayed branch creation, set branch_mutation_authorization: authorized, derive the name from the change content, create it with git checkout -b <branch-name>, then run git branch --show-current again and use that result as the current branch name for the rest of the workflow.
  • If the user declines, continue with the detached HEAD commit.
Show full SKILL.md (530 more words)Show less
Step 2: Determine commit message convention

Follow this priority order:

  1. Repo conventions already in context -- If project instructions (AGENTS.md, CLAUDE.md, or similar) are already loaded and specify commit message conventions, follow those. Do not re-read these files; they are loaded at session start.
  2. Recent commit history -- If no explicit convention is documented, examine the 10 most recent commits from Step 1. If a clear pattern emerges (e.g., conventional commits, ticket prefixes, emoji prefixes), match that pattern.
  3. Default: conventional commits -- If neither source provides a pattern, use conventional commit format: type(scope): description where type is one of feat, fix, docs, refactor, test, chore, perf, ci, style, build.

When using conventional commits, choose the type that most precisely describes the change (the type list above). Where fix: and feat: both seem to fit, default to fix:: a change that remedies broken or missing behavior is fix: even when implemented by adding code. Reserve feat: for capabilities the user could not previously accomplish. Other types remain primary when they fit better. The user may override for a specific change.

Step 3: Consider logical commits

Before staging everything together, scan the changed files for naturally distinct concerns. If modified files clearly group into separate logical changes (e.g., a refactor in one directory and a new feature in another, or test files for a different change than source files), create separate commits for each group.

Keep this lightweight:

  • Group at the file level only -- do not use git add -p or try to split hunks within a file.
  • If the separation is obvious (different features, unrelated fixes), split. If it's ambiguous, one commit is fine.
  • Two or three logical commits is the sweet spot. Do not over-slice into many tiny commits.
Step 4: Stage and commit

If the current branch from the context above is main, master, or the resolved default branch from Step 1, committing directly is not an option in this workflow. Display the proposed feature-branch name and require branch_mutation_authorization: authorized before creation; otherwise return branch_mutation_authorization_missing before staging or committing.

Derive the branch name from the change content, validate it, and create it from the current HEAD so uncommitted work and any local-only commits stay attached to the new branch:

bash
BRANCH_NAME="<branch-name>"
git check-ref-format --branch "$BRANCH_NAME"
git checkout -b "$BRANCH_NAME"
git branch --show-current

Use the confirmed branch name for the rest of the workflow. If the branch already exists, derive a safe unique name and retry once. If branch creation still fails, stop before staging and report the failure; do not commit on the default branch.

Write the commit message:

  • Subject line: Concise, imperative mood, focused on why not what. Follow the convention determined in Step 2.
  • Body (when needed): Add a body separated by a blank line for non-trivial changes. Explain motivation, trade-offs, or anything a future reader would need. Omit the body for obvious single-purpose changes.

For each commit group, stage specific files by name over git add -A or git add . to avoid accidentally including sensitive files (.env, credentials) or unrelated changes. Write the message to a temp file and commit with -F so multi-line bodies are preserved without shell interpolation:

bash
COMMIT_MSG=$(mktemp "${TMPDIR:-/tmp}/spec-commit-message.XXXXXX")
cat > "$COMMIT_MSG" <<'EOF'
type(scope): subject line here

Optional body explaining why this change was made,
not just what changed.
EOF
git add file1 file2 file3
git commit -F "$COMMIT_MSG"
Step 5: Confirm

Run git status after the commit to verify success. Report the commit hash(es) and subject line(s).

© leo-kuang-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files in skills/spec-commit of leo-kuang-ai/spec-first.

  • SKILL.md
  • evals/cases/fresh-tree-logical-grouping.yaml
  • evals/cases/no-auth-stops-before-staging.yaml
  • evals/eval.yaml
  • evals/fixtures/repos/mini-ledger/README.md
  • evals/fixtures/repos/mini-ledger/package.json
  • evals/fixtures/repos/mini-ledger/src/server.js
  • evals/fixtures/scripts/check-auth-gate.sh
  • evals/fixtures/scripts/check-logical-grouping.sh

Open the folder on GitHubat commit 74655dc

Compare with similar skills

Spec Commit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spec Commit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spec Commit this skillleo-kuang-ai/spec-first107—~2.1kAutomated safety check: NotesMIT
React Router Release Notes Prepremix-run/react-router57k—~1.1kAutomated safety check: PassMIT
ToolJet Multi-Repo CommitToolJet/ToolJet41k—~1.3kAutomated safety check: PassAGPL-3.0
Git Workflow and Versioningaddyosmani/agent-skills103k2 repos~3.5kAutomated safety check: NotesMIT
React Router Pull Request Creatorremix-run/react-router57k—~2.5kAutomated safety check: PassMIT
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT

Similar skills

  • React Router Release Notes Prep

    remix-run/react-router

    Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.

    57k GitHub stars~1.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Commits changes across ToolJet's root repo and its server/ee and frontend/ee submodules, writing messages from the diffs and updating submodule pointers in order.

    41k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Git Workflow and Versioning

    addyosmani/agent-skills

    Sets git habits for every change: short-lived branches, atomic commits with descriptive messages, clean pull requests, plus versioning, tagging and changelogs for releases.

    103k GitHub starsUsed in 2 repos~3.5k tokens
    DevelopmentAuto-check: notes
  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Commits changes in the Saleor codebase and works through pre-commit hook failures from ruff, mypy, the GraphQL schema check and the migrations check.

    23k GitHub stars~575 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from leo-kuang-ai/spec-first

All 35 skills in this repo
  • Spec App Consistency Audit

    leo-kuang-ai/spec-first

    Audit mobile App PRD/Figma/local-source consistency across page routes, KMP/Clean Architecture, components, analytics, i18n, engineering quality, and industry lenses before runtime validation; use…

    107 GitHub stars~4.6k tokensUpdated 14 days ago
    Auto-check passed
  • Spec Handoff

    leo-kuang-ai/spec-first

    Create a durable cross-session handoff or resume from a user-selected continuity source.

    107 GitHub stars~1.8k tokensUpdated 14 days ago
    Auto-check passed
  • Spec Pov

    leo-kuang-ai/spec-first

    Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract.

    107 GitHub stars~4.5k tokensUpdated 14 days ago
    Auto-check passed
  • Spec Resolve PR Feedback

    leo-kuang-ai/spec-first

    Resolve PR review feedback by evaluating validity and fixing issues with conflict-aware resolver dispatch.

    107 GitHub stars~1.8k tokensUpdated 14 days ago
    Auto-check: notes
  • Spec Riffrec Feedback Analysis

    leo-kuang-ai/spec-first

    Analyze explicit Riffrec product-feedback captures, including riffrec-.zip, the Riffrec session.json + events.json + recording.webm + voice.webm bundle, or media/notes the user identifies as a…

    107 GitHub stars~1.4k tokensUpdated 14 days ago
    Auto-check passed
  • Spec Compound

    leo-kuang-ai/spec-first

    Document a recently solved problem or durable project vocabulary in docs/solutions/ or CONCEPTS.md.

    107 GitHub stars~18k tokensUpdated 14 days ago
    Auto-check passed

Works with

Categories

Questions about Spec Commit

What does Spec Commit do?

Internal commit helper for public workflows that already hold explicit commit authorization; creates scoped, value-communicating commits without owning push or PR landing. Spec Commit is an agent skill from leo-kuang-ai/spec-first. Internal commit helper for public workflows that already hold explicit commit authorization; creates scoped, value-communicating commits without owning push or PR landing.

When should I use Spec Commit?

Spec Commit fits situations like: tasks that involve Authorization and RBAC; tasks that involve Commit messages.

How do I install Spec Commit in Claude Code?

Run `npx skills add leo-kuang-ai/spec-first --skill spec-commit -a claude-code`. Or copy the skill folder (skills/spec-commit in leo-kuang-ai/spec-first) into .claude/skills/spec-commit in your project. Claude Code loads it when a task matches its description.

How do I install Spec Commit in Codex?

Run `npx skills add leo-kuang-ai/spec-first --skill spec-commit -a codex`. Or copy the skill folder (skills/spec-commit in leo-kuang-ai/spec-first) into .agents/skills/spec-commit in your project. Codex loads it when a task matches its description.

Can I use Spec Commit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add leo-kuang-ai/spec-first --skill spec-commit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spec-commit, .gemini/skills/spec-commit, .github/skills/spec-commit and .opencode/skills/spec-commit in your project.

What does Spec Commit need to run?

Going by SKILL.md and its folder, Spec Commit needs a shell and JavaScript for the scripts in its folder and the command-line tools its instructions call (git and gh). Our summary lists: Node.js; A Bash shell.

Does Spec Commit access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Spec Commit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Spec Commit use?

Spec Commit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spec Commit use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spec Commit?

Skills that share tags, products or a category with Spec Commit: React Router Release Notes Prep (remix-run/react-router, 57k stars), ToolJet Multi-Repo Commit (ToolJet/ToolJet, 41k stars), Git Workflow and Versioning (addyosmani/agent-skills, 103k stars) and React Router Pull Request Creator (remix-run/react-router, 57k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spec Commit?

leo-kuang-ai (a GitHub user) maintains it in leo-kuang-ai/spec-first, which has 107 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 24, 2026.

Source: leo-kuang-ai/spec-first on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.