Pre-push hygiene check for GitHub repositories. An agent skill from thatrebeccarae/claude-marketing.

MITAuto-check passedDevelopment

Install Safe Push

skills CLI
$ npx skills add thatrebeccarae/claude-marketing --skill safe-push -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install thatrebeccarae/claude-marketing safe-push --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/thatrebeccarae/claude-marketing.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/safe-push .claude/skills/safe-push && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
safe-push
GitHub stars
162
Token cost
~1.9k tokens
SKILL.md length
775 words
Files
5
Skills in repo
55
Repo updated
First seen
Licence
MIT

At a glance

Pre-push hygiene check for GitHub repositories. An agent skill from thatrebeccarae/claude-marketing.

  • Works in 6 steps: Classify the repo → PII and secrets scan → Commit message audit → …
  • Tasks that involve Commit messages
  • SKILL.md covers Trigger, Install, Procedure and Configuration files, plus 1 more section
  • Calls git

What it does

Safe Push is an agent skill from thatrebeccarae/claude-marketing. Pre-push hygiene check for GitHub repositories. Scans for PII, secrets, and sensitive data before pushing. Audits commit messages, enforces repo-specific blocklists, and rate-limits pushes to avoid GitHub abuse detection. Use before any git push, especially to public repos.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `EXAMPLES.md` and `REFERENCE.md`).

It sits in Development, covering Commit messages and Rate limiting. It works with GitHub, Git and Slack. The repository describes itself as: A full marketing department for Claude Code. Skill packs for Klaviyo, Shopify, GA4, Looker Studio, paid media, and more. Audit, optimize, and report using natural language. The licence is MIT.

When your agent uses it

  • Tasks that involve Commit messages
  • Tasks that involve Rate limiting

Example prompts

  • “/safe-push”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Classify the repo
  2. PII and secrets scan
  3. Commit message audit
  4. Staggered push (rate limiting)
  5. Final confirmation
  6. Push and verify

What it can do on your machine

Read from SKILL.md and the folder at commit a8a63ec. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Safe Push loads about 1.9k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 775 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from thatrebeccarae/claude-marketing at commit a8a63ec, republished under its MIT licence (© thatrebeccarae). 775 words, ~1,941 tokens.

Download SKILL.mdSave it as .claude/skills/safe-push/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
safe-push
description
Pre-push hygiene check for GitHub repositories. Scans for PII, secrets, and sensitive data before pushing. Audits commit messages, enforces repo-specific blocklists, and rate-limits pushes to avoid GitHub abuse detection. Use before any git push, especially to public repos.
license
MIT
origin
custom
author
Rebecca Rae Barton
author_url
https://github.com/thatrebeccarae
metadata.version
1.2.0
metadata.category
devops
metadata.domain
git
metadata.updated
2026-05-08
metadata.tested
2026-05-08
metadata.tested_with
Claude Code v2.1

Safe Push

Pre-push hygiene check for GitHub repositories. Use when the user asks to push code, especially to public repos.

Trigger

When the user says "push", "safe push", "push to GitHub", or runs /safe-push.

Install

The skill loads patterns from ~/.claude/safe-push-blocklist. Copy the bundled template and customize:

bash
cp safe-push-blocklist.template ~/.claude/safe-push-blocklist
$EDITOR ~/.claude/safe-push-blocklist

The template includes commented-out examples for client names, hostnames, IP ranges, tracking IDs, and Slack token shapes. Replace them with values specific to your environment.

If the file is missing, the skill runs with a warning instead of erroring — but personal pattern checks are skipped, so creating it is strongly recommended.

Procedure

1. Classify the repo
bash
# Check if public repo
git remote -v
# Check for .public-repo marker
test -f .public-repo && echo "PUBLIC" || echo "private or unmarked"

If public (or pushing to a public remote): apply ALL checks below. If private: apply only the PII scan (step 2).

2. PII and secrets scan

Load your personal pattern list from ~/.claude/safe-push-blocklist and scan against it. The same patterns apply to diff content (step 2) AND commit messages (step 3) — both run from the same source of truth.

Default mode — scan the diff against the target branch:

bash
# Load personal patterns (graceful fallback if file missing):
if [ -f ~/.claude/safe-push-blocklist ]; then
  PATTERNS=$(grep -v '^#' ~/.claude/safe-push-blocklist | grep -v '^$' | paste -sd '|' -)
else
  PATTERNS=""
  echo "WARNING: ~/.claude/safe-push-blocklist not found. Personal pattern checks skipped."
fi

git diff origin/main...HEAD
[ -n "$PATTERNS" ] && git diff origin/main...HEAD | grep -nE "$PATTERNS" \
  || echo "NO MATCHES IN DIFF"

Full repo mode (/safe-push --full) — scan ALL tracked files, not just the diff. Use this for baseline audits, first-time pushes of existing repos, or periodic hygiene checks:

bash
git ls-files | xargs grep -n -E "$PATTERNS" \
  --include='*.md' --include='*.py' --include='*.js' --include='*.ts' \
  --include='*.html' --include='*.sh' --include='*.json' \
  --include='*.yml' --include='*.yaml'

Check for these categories (your ~/.claude/safe-push-blocklist covers the regex-able ones):

  • Client names or internal project codenames
  • Personal infrastructure: hostnames, internal directory names, device IDs, hardware models, self-hosted service names
  • Email addresses (personal or client), phone numbers, addresses
  • API keys, tokens, secrets (AWS, GitHub, Slack, Telegram, generic)
  • Private IP addresses, internal hostnames
  • Private key material
  • Slack tokens (xoxb-), Slack channel IDs
  • Tracking IDs: GA4 (G-XXXXXXXXXX), GTM (GTM-XXXXXXX)

Edit ~/.claude/safe-push-blocklist to maintain your personal patterns. Never hardcode real client names or infrastructure identifiers inside this skill file — the blocklist is the source of truth.

If anything is found:

  • List each finding with file, line number, and what was detected
  • Ask the user to fix before proceeding
  • Do NOT push until resolved
3. Commit message audit

Review the FULL commit message — both subject (title) and body (description) — for every commit in the push range. Sensitive patterns can hide in either:

bash
# Print the full message (subject + body) for every commit:
git log origin/main..HEAD --format="===%h %s===%n%b"

# Programmatically scan the full message text against the same
# blocklist used for diff content (graceful fallback if file missing):
if [ -f ~/.claude/safe-push-blocklist ]; then
  PATTERNS=$(grep -v '^#' ~/.claude/safe-push-blocklist | grep -v '^$' | paste -sd '|' -)
  git log origin/main..HEAD --format="%B" | grep -nE "$PATTERNS" \
    || echo "NO MATCHES IN MESSAGES"
else
  echo "WARNING: ~/.claude/safe-push-blocklist not found. Personal pattern checks skipped on commit messages."
fi

The same patterns from ~/.claude/safe-push-blocklist that block diff content (step 2) ALSO block commit messages. Apply the full blocklist to BOTH title and body — not just the diff. For public repos, also flag:

  • Personal info (email, phone, address) — categorical, not always pattern-matched
  • Private repo names you own (e.g., upstream dev mirrors) — soft-warn, ask user before pushing
  • Vague messages ("fix", "update", "wip") — suggest rewrites

If issues found, suggest interactive rebase to clean messages (with user approval).

Show full SKILL.md (355 more words)Show less
4. Staggered push (rate limiting)

To avoid triggering GitHub bulk action / automation abuse detection:

  • If pushing a single branch with < 50 commits: push normally
  • If pushing multiple branches or > 50 commits:
    • Push one branch at a time
    • Wait 5 seconds between branch pushes
    • For very large pushes (100+ commits), break into batches of 50 and wait 10 seconds between batches
  • If creating a new repo and pushing initial content with multiple branches:
    • Push main/default branch first
    • Wait 10 seconds
    • Push remaining branches one at a time with 5-second gaps
  • NEVER use git push --all or git push --mirror to a public remote without staggering
bash
# Example staggered multi-branch push
for branch in main develop feature/foo; do
  git push origin "$branch"
  sleep 5
done
5. Final confirmation

Before executing the push, present a summary:

  • Repository: name and public/private status
  • Branch(es) being pushed
  • Number of commits
  • Full commit message preview for every commit in the push range (both title and body) — even on amended commits and commits authored in this session
  • Any warnings from steps 2-4
  • Push strategy (direct or staggered)

Show the full commit messages with:

bash
git log origin/main..HEAD --format="commit %h%n%n%s%n%n%b%n---"

The user must visually confirm each message before push. This catches:

  • Amended commits where the original audit no longer applies
  • Body content that wasn't surfaced in step 3 because of grep gaps
  • Anything authored ad-hoc in this session that didn't go through a content review

Wait for explicit user confirmation before pushing.

6. Push and verify

After pushing:

bash
git push origin <branch>
# Verify
git log origin/<branch> --oneline -5

Report success and the remote URL.

Configuration files

  • ~/.claude/safe-push-blocklist — Your personal pattern blocklist. One regex per line; comments start with #. Loaded on every /safe-push invocation. Edit this file to add or remove patterns; never hardcode patterns in this skill file. See Install above for setup.
  • Repo-local .pii-allowlist — One regex per line, matches are excluded from PII scan (used to allow false positives like example keys in docs).
  • Repo-local .commit-msg-blocklist — Terms that should never appear in public commit messages for this specific repo.

Notes

  • This skill does NOT bypass the global pre-commit hook — they work together
  • For projects with a public/private repo split (dev mirror → public release): always push to the dev repo first, sync via your sync script, then safe-push the public repo
  • When in doubt, treat a repo as public

© thatrebeccarae, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/safe-push of thatrebeccarae/claude-marketing.

  • SKILL.md
  • EXAMPLES.md
  • LICENSE
  • REFERENCE.md
  • safe-push-blocklist.template

Open the folder on GitHubat commit a8a63ec

Compare with similar skills

Safe Push next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Safe Push compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Safe Push this skillthatrebeccarae/claude-marketing162—~1.9kAutomated safety check: PassMIT
React Router Pull Request Creatorremix-run/react-router57k—~2.5kAutomated safety check: PassMIT
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Draft Pull Request Creatorwordpress-mobile/WordPress-Android3.2k—~881Automated safety check: NotesGPL-2.0
Submit PRtisfeng/Easydict15k—~595Automated safety check: PassGPL-3.0
Create PREmiyaaaaa/HiveMind1.1k—~1.7kAutomated safety check: PassCustom licence

Similar skills

  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Draft Pull Request Creator

    wordpress-mobile/WordPress-Android

    Commits and pushes current changes, writes a pull request title and body from the branch history and template, and opens a draft PR on GitHub after you approve it.

    3.2k GitHub stars~881 tokensUpdated today
    DevelopmentAuto-check: notes
  • Submit PR

    tisfeng/Easydict

    创建或复用当前 checkout 已提交变更的 GitHub PR,必要时推送任务分支。PR 审查使用 review-pr;仅本地提交使用 git-commit。

    15k GitHub stars~595 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Create PR

    Emiyaaaaa/HiveMind

    Create a GitHub pull request with gh pr create. An agent skill from Emiyaaaaa/HiveMind.

    1.1k GitHub stars~1.7k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Publishes a GitHub PR for the checked-out branch with a Conventional Commits style title, a description backed by commands run, and screenshots when the UI changed.

    6k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from thatrebeccarae/claude-marketing

All 55 skills in this repo
  • Google Analytics

    thatrebeccarae/claude-marketing

    Analyze Google Analytics data, review website performance metrics, identify traffic patterns, and suggest data-driven improvements.

    162 GitHub starsUsed in 3 repos~1.3k tokens
    Auto-check: notes
  • Content Creator

    thatrebeccarae/claude-marketing

    Comprehensive content marketing toolkit with brand voice analysis, SEO optimization scripts, content frameworks, social media strategy, and content calendar planning.

    162 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Klaviyo Analyst

    thatrebeccarae/claude-marketing

    Klaviyo marketing operations and analyst expertise. An agent skill from thatrebeccarae/claude-marketing.

    162 GitHub stars~5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Klaviyo Developer

    thatrebeccarae/claude-marketing

    Klaviyo API and developer integration expertise. An agent skill from thatrebeccarae/claude-marketing.

    162 GitHub stars~4.9k tokensUpdated 4 mo ago
    Auto-check: notes
  • Looker Studio

    thatrebeccarae/claude-marketing

    Looker Studio (formerly Google Data Studio) expertise. An agent skill from thatrebeccarae/claude-marketing.

    162 GitHub stars~3.6k tokensUpdated 4 mo ago
    Auto-check: notes
  • Shopify

    thatrebeccarae/claude-marketing

    Shopify e-commerce platform marketing expertise. An agent skill from thatrebeccarae/claude-marketing.

    162 GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Safe Push

What does Safe Push do?

Pre-push hygiene check for GitHub repositories. An agent skill from thatrebeccarae/claude-marketing. Safe Push is an agent skill from thatrebeccarae/claude-marketing. Pre-push hygiene check for GitHub repositories.

When should I use Safe Push?

Safe Push fits situations like: tasks that involve Commit messages; tasks that involve Rate limiting.

How do I install Safe Push in Claude Code?

Run `npx skills add thatrebeccarae/claude-marketing --skill safe-push -a claude-code`. Or copy the skill folder (skills/safe-push in thatrebeccarae/claude-marketing) into .claude/skills/safe-push in your project. Claude Code loads it when a task matches its description.

How do I install Safe Push in Codex?

Run `npx skills add thatrebeccarae/claude-marketing --skill safe-push -a codex`. Or copy the skill folder (skills/safe-push in thatrebeccarae/claude-marketing) into .agents/skills/safe-push in your project. Codex loads it when a task matches its description.

Can I use Safe Push in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thatrebeccarae/claude-marketing --skill safe-push -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/safe-push, .gemini/skills/safe-push, .github/skills/safe-push and .opencode/skills/safe-push in your project.

What does Safe Push need to run?

Going by SKILL.md and its folder, Safe Push needs the command-line tools its instructions call (git).

Does Safe Push access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Safe Push safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Safe Push use?

Safe Push is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Safe Push use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Safe Push?

Skills that share tags, products or a category with Safe Push: React Router Pull Request Creator (remix-run/react-router, 57k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Draft Pull Request Creator (wordpress-mobile/WordPress-Android, 3.2k stars) and Submit PR (tisfeng/Easydict, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Safe Push?

thatrebeccarae (a GitHub user) maintains it in thatrebeccarae/claude-marketing, which has 162 GitHub stars. The repository holds 55 skills in this directory. The repository was last updated on May 14, 2026.

Source: thatrebeccarae/claude-marketing on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.