git:commit

SkillDev tools

Create properly formatted commits following Rossoctl conventions

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the git:commit skill

What this skill tells your AI

The instructions your AI receives, as published by rossoctl/rossoctl in .claude/skills/git:commit/SKILL.md and read by ahel’s review.

Create commits following Rossoctl conventions with proper formatting and sign-off.

When to Use

  • Every time you commit code
  • After TDD fix iterations
  • Before creating a PR

Quick Commit

git add <files>
git commit -s -m "🌱 Short descriptive message"

The -s flag adds the required Signed-off-by line.

Commit Format

<emoji> <Short descriptive message>

<Optional longer description>

Signed-off-by: <Name> <email>
Co-authored-by: Claude <noreply@anthropic.com>

Emoji Prefixes

EmojiTypeWhen
FeatureNew functionality
🐛Bug fixFixing broken behavior
📖DocsDocumentation only
📝ProposalDesign proposals
⚠️Breaking changeAPI or behavior changes
🌱OtherTests, CI, refactoring, tooling

Requirements

  1. Signed-off-by is MANDATORY — always use git commit -s
  2. Co-authored-by Claude — include when Claude creates the commit
  3. Imperative mood — "Add feature" not "Added feature"
  4. Under 72 characters — subject line
  5. No "Generated with Claude Code" line — removed per team preference

Examples

🌱 Add E2E testing infrastructure and deployment health tests

Implements initial end-to-end testing framework for Rossoctl platform.

Signed-off-by: Developer <dev@example.com>
Co-authored-by: Claude <noreply@anthropic.com>
🐛 Fix VPC cleanup order: delete subnets before route tables

Signed-off-by: Developer <dev@example.com>

CVE ID Check (Pre-Commit)

Before every commit, scan the commit message for CVE references:

  • Pattern: CVE-\d{4}-\d+ (e.g., CVE-2026-12345)
  • Also check for: "vulnerability", "exploit", "security flaw" combined with a package name

If found in the commit message:

WARNING: Commit message contains CVE reference.
This will be visible in public git history.

Rewrite using neutral language:
  BAD:  "Fix CVE-2026-12345 in requests library"
  GOOD: "Bump requests to 2.32.0"

  BAD:  "Patch security vulnerability in auth module"
  GOOD: "Update auth module for compatibility"

If a cve:brainstorm hold is active, also verify the staged file diffs don't contain CVE IDs in comments, docstrings, or documentation.

Sign All Commits in Branch

If you have unsigned commits in your branch, sign them all:

git rebase --signoff HEAD~$(git rev-list --count upstream/main..HEAD)

Amending

git commit --amend -s --no-edit

After Committing

Check the commit:

git log --oneline -1

Verify sign-off:

git log -1 --format='%B' | grep 'Signed-off-by'

Related Skills

  • repo:pr - PR creation conventions
  • git:rebase - Rebase before pushing
  • tdd:ci - TDD workflow commit step
  • cve:scan - CVE scanning (invoked by other workflows)
  • cve:brainstorm - CVE disclosure gate (blocks CVE references in commits)

Signals

GitHub stars
300
Forks
107
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
git-commit-rossoctl
Source
github.com/rossoctl/rossoctl