Agent skill

Create Commit

by penpot in penpot/penpot

Stage, review, and commit files following Penpot commit conventions.

MPL-2.0Auto-check: notesDevelopment

Install Create Commit

skills CLI
$ npx skills add penpot/penpot --skill create-commit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install penpot/penpot create-commit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/penpot/penpot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/create-commit .claude/skills/create-commit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-commit
GitHub stars
61k
Token cost
~690 tokens
SKILL.md length
382 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MPL-2.0

At a glance

Stage, review, and commit files following Penpot commit conventions.

  • Works in 4 steps: Wrap every body line at 76 characters or… → Subject ≤70 chars, imperative,… → Blank line between subject and body. → …
  • Tasks that involve Commit messages
  • SKILL.md covers When to Use, Required Reading, Iron Rules (non-negotiable) and Workflow, plus 1 more section
  • Calls git

What it does

Create Commit is an agent skill from penpot/penpot. Stage, review, and commit files following Penpot commit conventions.

Its SKILL.md is about 690 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Commit messages. It works with Git. The repository describes itself as: Penpot: The open-source design platform for Product teams that need scalable collaboration. The licence is MPL-2.0.

When your agent uses it

  • Tasks that involve Commit messages

Example prompts

  • “/create-commit”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Wrap every body line at 76 characters or fewer. Count characters, do
  2. Subject ≤70 chars, imperative, capitalized, no trailing period.
  3. Blank line between subject and body.
  4. Run ./scripts/check-commit and require exit code 0. It mechanically

What it can do on your machine

Read from SKILL.md and the folder at commit fc8a126. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Create Commit loads about 690 tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 382 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~690

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:40
    tokens, passwords, private keys, `.env` values), debug prints, or anything

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from penpot/penpot at commit fc8a126, republished under its MPL-2.0 licence (© penpot). 382 words, ~690 tokens.

Download SKILL.mdSave it as .claude/skills/create-commit/SKILL.md (or your agent's skills folder).
name
create-commit
description
Stage, review, and commit files following Penpot commit conventions.
slash
true

Skill: create-commit

Produce a git commit that follows Penpot's commit message conventions. This skill owns the commit format, staging review, and safety checks — it does not implement features or push.

When to Use

  • After code changes are complete and files need to be committed
  • When delegated by a workflow step (e.g. implement-plan) to handle the commit

Required Reading

Before drafting any commit, read mem:workflow/creating-commits end-to-end. It is the authoritative source for the commit message format, the emoji menu, subject/body limits, and the AI-assisted-by trailer. Follow it exactly.

Iron Rules (non-negotiable)

  1. Wrap every body line at 76 characters or fewer. Count characters, do not eyeball. Exceptions: Signed-off-by: / AI-assisted-by: trailers and lines carrying a URL. This is the rule agents skip most often.
  2. Subject ≤70 chars, imperative, capitalized, no trailing period.
  3. Blank line between subject and body.
  4. Run ./scripts/check-commit and require exit code 0. It mechanically checks rules 1–3. A non-zero exit is a hard blocker: fix the message and re-commit. Never report the commit as done with a failing checker.

Workflow

  1. Stage the files specified by the calling context. Do not ask for confirmation.
  2. Run git diff --staged to review the content. If you see secrets (API keys, tokens, passwords, private keys, .env values), debug prints, or anything that does not match the stated intent, STOP and tell the user before committing.
  3. Draft the message following the format in the memory doc, wrapping the body at 76 characters per line, and run:
    bash
    git commit -m "<subject>" -m "<body>"
    (or git commit -F - if the body has unusual characters).
  4. Verify the message with the checker:
    bash
    ./scripts/check-commit
    If it fails, amend the message (git commit --amend) until it passes. Do not finish with a failing checker.
  5. The AI-assisted-by trailer value is provided by the calling context — use it verbatim.
Show full SKILL.md (84 more words)Show less

Constraints

  • Do not push. Pushing is a separate workflow handled by the user.
  • Do not run git reset, git checkout, git restore, git clean, or rm.
  • Do not pass --author. Author identity comes from the local git config.
  • Do not amend a commit you did not create in this session, unless explicitly asked.
  • Do not bypass pre-commit hooks (--no-verify) unless explicitly asked.
  • Do not add untracked files that were not created in this session.
  • Do not skip the scripts/check-commit verification step (Iron Rule 4).

© penpot, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/create-commit of penpot/penpot.

Open the folder on GitHubat commit fc8a126

Compare with similar skills

Create Commit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Commit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Commit this skillpenpot/penpot61k—~690Automated safety check: NotesMPL-2.0
React Router Release Notes Prepremix-run/react-router57k—~1.1kAutomated safety check: PassMIT
ToolJet Multi-Repo CommitToolJet/ToolJet41k—~1.3kAutomated safety check: PassAGPL-3.0
Git Workflow and Versioningaddyosmani/agent-skills102k2 repos~3.5kAutomated safety check: NotesMIT
React Router Pull Request Creatorremix-run/react-router57k—~2.5kAutomated safety check: PassMIT
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT

Similar skills

  • React Router Release Notes Prep

    remix-run/react-router

    Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.

    57k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Commits changes across ToolJet's root repo and its server/ee and frontend/ee submodules, writing messages from the diffs and updating submodule pointers in order.

    41k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Git Workflow and Versioning

    addyosmani/agent-skills

    Sets git habits for every change: short-lived branches, atomic commits with descriptive messages, clean pull requests, plus versioning, tagging and changelogs for releases.

    102k GitHub starsUsed in 2 repos~3.5k tokens
    DevelopmentAuto-check: notes
  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Commits changes in the Saleor codebase and works through pre-commit hook failures from ruff, mypy, the GraphQL schema check and the migrations check.

    23k GitHub stars~575 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from penpot/penpot

All 24 skills in this repo
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    Auto-check: notes
  • Create PR

    penpot/penpot

    PR flow — open a new PR for the current task branch (validates base branch, commits, issue and push state) or update an existing PR's title or description to match Penpot conventions.

    61k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Bat Cat

    penpot/penpot

    A cat clone with syntax highlighting, line numbers, and Git integration - a modern replacement for cat.

    61k GitHub starsUsed in 2 repos~1.1k tokens
    Auto-check passed
  • Local CI

    penpot/penpot

    Run local CI-style checks with ./scripts/ci (lint, tests, format) per monorepo module.

    61k GitHub stars~822 tokensUpdated today
    Auto-check passed
  • Ste

    penpot/penpot

    Write or rewrite text in ASD-STE100 Simplified Technical English.

    61k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Code review criteria — the five review axes, core principles, severity format, and verdict for reviewing code changes.

    61k GitHub stars~3.6k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Create Commit

What does Create Commit do?

Stage, review, and commit files following Penpot commit conventions. Create Commit is an agent skill from penpot/penpot. Stage, review, and commit files following Penpot commit conventions.

When should I use Create Commit?

Create Commit fits situations like: tasks that involve Commit messages.

How do I install Create Commit in Claude Code?

Run `npx skills add penpot/penpot --skill create-commit -a claude-code`. Or copy the skill folder (.agents/skills/create-commit in penpot/penpot) into .claude/skills/create-commit in your project. Claude Code loads it when a task matches its description.

How do I install Create Commit in Codex?

Run `npx skills add penpot/penpot --skill create-commit -a codex`. Or copy the skill folder (.agents/skills/create-commit in penpot/penpot) into .agents/skills/create-commit in your project. Codex loads it when a task matches its description.

Can I use Create Commit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add penpot/penpot --skill create-commit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-commit, .gemini/skills/create-commit, .github/skills/create-commit and .opencode/skills/create-commit in your project.

What does Create Commit need to run?

Going by SKILL.md and its folder, Create Commit needs the command-line tools its instructions call (git).

Does Create Commit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Create Commit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Create Commit use?

Create Commit is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Commit use?

About 690 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Create Commit?

Skills that share tags, products or a category with Create Commit: React Router Release Notes Prep (remix-run/react-router, 57k stars), ToolJet Multi-Repo Commit (ToolJet/ToolJet, 41k stars), Git Workflow and Versioning (addyosmani/agent-skills, 102k stars) and React Router Pull Request Creator (remix-run/react-router, 57k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Commit?

penpot (a GitHub organization) maintains it in penpot/penpot, which has 60,770 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 7, 2026.

Source: penpot/penpot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.