skills/git-safe-workflow/SKILL.md
Safely inspect, stage, commit, and (only if asked) push changes made by an AI agent. Use for commit/push requests, end-of-task checkpoints, merge conflict resolution, worktree safety checks, or deciding whether to use git commit --amend.
npx skillsauth add regenrek/agent-skills git-safe-workflowInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Collect repo context first (non-destructive):
Collect worktree context when relevant (also non-destructive):
Run worktree context when:
Never run destructive or high-risk commands unless explicitly requested:
Avoid interactive prompts and editors unless the user says it is OK:
Confirm you are in the intended worktree and branch before staging or committing:
Detached HEAD safety:
Branch checked out in another worktree:
Worktree lifecycle operations:
Guidance:
Prefer explicit paths when practical:
Otherwise stage tracked modifications and deletions:
Avoid staging everything blindly unless user explicitly wants it:
Use Conventional Commits when reasonable:
Include:
Use amend when:
Common safe commands:
Do not amend when:
In that case:
Collect context:
Identify conflicted files:
Resolve conflicts carefully (no automation that discards intent).
Continue the operation:
Verify:
tools
Live-test any Electron desktop app with native-devtools-mcp, Chrome DevTools Protocol, screenshots, OCR, and accessibility tools. Use when the user asks for Electron UI verification, MCP-driven app control, renderer CDP interaction, native desktop automation, screenshots, or OCR-driven checks.
testing
Find, clone, inspect, and summarize high-quality GitHub reference repositories for coding agents. Use when a user asks for GitHub reference projects, examples, prior art, inspiration, implementation patterns, or includes "$search-context" in a coding prompt.
testing
Run or install repo security leak checks with BetterLeaks and Trivy. Use when asked to scan for leaked secrets, vulnerable dependencies, misconfigurations, add secret-leak guardrails, add BetterLeaks, add forbidden-path hooks, or run secleak-check before release.
development
Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident IOC profiles.