vibe-pre-commit-audit

SkillProductivity

Scans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes. Use before creating any commit.

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the vibe-pre-commit-audit skill

What this skill tells your AI

The instructions your AI receives, as published by ash1794/vibe-engineering in plugins/vibe-engineering/skills/vibe-pre-commit-audit/SKILL.md and read by ahel’s review.

Catch the easy mistakes before they enter history.

When to Use This Skill

  • Before creating a git commit
  • When reviewing your own staged changes
  • Before pushing to a shared branch

When NOT to Use This Skill

  • Commits to personal scratch branches
  • When the user explicitly says to skip checks
  • Auto-generated code commits (lock files, etc.)
  • Private or draft content leaking through built output (use vibe-publication-leak-guard)

Tools First, Eyeballing Second

Pattern-matching a diff by eye misses things that a deterministic scanner catches. Before the manual checks:

  1. Run what the repo already has — pre-commit run, lefthook, husky, or a lint/check script. Check .pre-commit-config.yaml, package.json, and the Makefile.
  2. Run a secret scanner if one is installed (gitleaks protect --staged, trufflehog git file://. --since-commit HEAD) or vibe-cli pre-commit from this repo.
  3. If nothing is set up, suggest adding one (for example vibe-cli hook install, or a gitleaks pre-commit hook), then fall back to the manual checks below.

Tool findings are blocking. The manual checks cover what the tools don't.

Checks

1. Secrets & Credentials

Scan for patterns:

  • API_KEY=, SECRET=, PASSWORD=, TOKEN=
  • AWS keys: AKIA[0-9A-Z]{16}
  • Private keys: -----BEGIN.*PRIVATE KEY-----
  • Connection strings with credentials
  • .env files being staged

2. Debug Statements

  • console.log(, fmt.Println(, print(, debugger;
  • // DEBUG, # DEBUG, /* DEBUG
  • log.Debug in non-debug code paths

3. TODOs Without References

  • TODO without issue number: TODO: fix this (bad)
  • TODO(#123): fix this (good)
  • FIXME, HACK, XXX — flag all

4. Disabled Tests

  • t.Skip(, xit(, xdescribe(, @pytest.mark.skip
  • Commented-out test functions
  • //nolint without justification

5. Large Files

  • Files > 1MB
  • Binary files (images, compiled assets)
  • Lock files with excessive changes

6. Commented-Out Code

  • Blocks of 3+ consecutive commented-out lines of code
  • Not comments explaining code, but actual code that's commented out

Output Format

Pre-Commit Audit

Status: CLEAN / WARNINGS / BLOCKED Tools run: [e.g., pre-commit run, gitleaks protect --staged, or "none configured"]

CheckStatusFindings
Scanner / hooks✓/✗/n/aX findings
Secrets✓/✗X patterns found
Debug statements✓/✗X occurrences
TODOs✓/◐X without references
Disabled tests✓/✗X found
Large files✓/✗X over limit
Commented code✓/◐X blocks

Blocking Issues (must fix)

  1. [Secret found in file.go:42]

Warnings (should fix)

  1. [TODO without reference in handler.ts:15]

Signals

GitHub stars
85
Forks
20
Last commit
Oct 2026
Advanced
Item type
skill
Key
vibe-pre-commit-audit
Source
github.com/ash1794/vibe-engineering