pre-commit-audit

Featured

Deliver a fast pre-commit safety scan: file size, anonymity (author / affiliation strings in tex/bib), hardcoded secrets, and invisible-Unicode carriers. Use when the user requests a fast pre-commit safety scan: file size, anonymity (author / affiliation strings in tex/bib), hardcoded secrets, and invisible-Unicode carriers. Triggers: 'audit before commit', 'check before push', 'pre-commit scan', 'safety check'.

Code & Development 144 stars 27 forks Updated 3 days ago MIT

Install

View on GitHub

Quality Score: 90/100

Stars 20%
72
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Pre-Commit Audit — File Size, Anonymity, Secrets > Three-pass safety scan before commit. Blocks pain-points: oversized commits (1.3GB parquet incident), CCS-style anonymity breaches, leaked credentials. Each pass is a hard gate; user OKs proceed. ## Hard Rules ### Existential — block proceed 1. **Size pass blocks anything >10MB unless gitignored OR user explicitly approves.** Threshold matches `block-large-files.sh` hook for consistency. 2. **Anonymity pass runs only on paper-relevant paths**: `paper-*/`, `*.tex`, `*.bib`, `*.md` inside paper directories. Scope is data-driven — we don't false-flag README authorship. 3. **Secrets pass uses an entropy heuristic + known-prefix list.** No regex-only matching that misses high-entropy keys. Block on confirmed secret; warn on suspicious-but-uncertain. 4. **All four passes run on the same file set** (default: staged for commit). Don't mix staged-only size check with all-files anonymity check. 5. **The Unicode pass is the one pass that is always in scope**, including infra-only commits. It is identity-blind — it reads codepoints, never names — so it cannot false-flag authorship the way the anonymity pass can. ### Format — catch in review 6. Output a single consolidated table (file × pass × verdict) — not four separate reports. 7. Severity tiers: BLOCK (must fix), WARN (proceed with confirm), OK. 8. Always show the file path and line number when flagging — make it copy-paste-fixable. ## When to Use - Before any `git commit` o...

Details

Author
flonat
Repository
flonat/flonat-research
Created
7 months ago
Last Updated
3 days ago
Language
Python
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category