- Home
- Skills
- DevOps & Cloud
- CommitComposer: Clean Git History Generator
Works with the AI tools you already use
CommitComposer: Clean Git History Generator
Enforce Conventional Commits and professional PR descriptions while preventing secret leaks in git history.
$9.99
CommitComposer: Clean Git History Generator
Example session with this skill installed
I've updated the auth token logic and added a test case. Commit this and write a PR description. I have a .env file staged by accident too.
- Read your context and instructions
- Compiled the commitcomposer
- Generated the document
The skill detected a security risk with your staged files. The commit has been blocked to prevent a secret leak.
Security Audit Results
| Status | Finding | Action Required |
|---|---|---|
| BLOCKED | ERR_PRIVACY_BLOCK | Potential secret file .env detected in staged changes. |
| WARNING | ERR_LAZY_SUBJECT | Initial intent was too vague for professional history. |
| CLEAN | VALID_SCOPE | Identified auth as the primary module impact. |
Proposed Commit Message
fix(auth): prevent token expiry during long-running requests
The token refresh was previously tied to a static wall clock. This
change anchors the refresh logic to the request start time to ensure
stability during high-latency operations.
Closes #142
Pull Request Description
Summary
Fixes a race condition where auth tokens would expire mid-request during long-running operations.
Changes
- fix(auth): Update refresh logic in
src/auth/token.py. - test(auth): Add integration test for 5-minute+ request cycles.
Testing
- Unit tests passed
- Manual verification of token persistence during simulated lag
Checklist
- No hardcoded secrets (Blocked: .env detected)
- Conventional Commits followed
- Changelog updated
Next steps
- Run
git reset .envto unstage the sensitive file. - Add
.envto your.gitignoreif not already present. - Proceed with the suggested commit message above.
commitcomposer-clean-git-history-generat.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Stop dealing with unreadable git histories filled with "fix", "update", and "wip" messages. This skill forces AI agents to follow strict Conventional Commit standards, generates professional PR descriptions, and blocks staged secrets before they leak.
Unlike prompt-only skills, this ships with a runnable checker and a test suite — so the rules are enforced, not just suggested.
Verified in a real run
Executed in Cursor on a fresh project. Output below is unedited:
$ python check.py --doctor OK: python - version 3.14.7 OK: git - version 2.55.0 OK: inside a git work tree OK: schema.json found
$ python check.py --input examples/pass.json PASS (exit 0)
$ python check.py --input examples/fail.json FAIL: 3 reasons (regex mismatch, subject 127 chars, lazy subject) exit 1 — expected FAIL
$ python tests/test_check.py ALL TESTS PASSED (exit 0)
Real scenario: with a .env file staged by accident, the skill returns BLOCKED / ERR_PRIVACY_BLOCK and refuses to produce the commit until the file is unstaged.
What you get
- SKILL.md — the agent instructions
- check.py — the runner that enforces the rules (stdlib only, Python 3.8+)
- schema.json — the output contract
- examples/pass.json, examples/fail.json — reference inputs
- tests/test_check.py — proof it works
- README.md — install in 3 commands
What it does
- Enforces Conventional Commits: every message follows type(scope): subject.
- Validates types: feat, fix, refactor, docs, test, chore, perf, ci, build, style, revert.
- Rejects lazy subjects and enforces a 72-character limit in imperative mood.
- Generates bodies and BREAKING CHANGE: footers for non-trivial changes.
- Builds structured PR descriptions and grouped CHANGELOG.md entries.
- Blocks staged .env files, credentials, and tokens before the commit.
Why this beats prompting it yourself
A generic prompt drifts across long sessions — the agent slowly reverts to fix, update, wip. This skill uses rigid validation logic: the checker exits non-zero, so a lazy or unsafe commit physically cannot pass. Plus it prevents accidental .env leaks, which a bare prompt will not catch.
Known limitations
- Stdlib only, no network calls.
- Reads staged file names and change types — never diff content.
- Requires Python 3.8+ and git.
- Does not support Gitmoji or custom non-conventional styles.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean today
- Passed all security checks, Safe to install