Skip to content
Back to skills

Commit Security Scan

ASecurity

Analyze code changes (commits, PRs, diffs) for security vulnerabilities using STRIDE analysis and CWE mapping

  • 40 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 6, 2026
toolsrustbashnodesecurity

Security analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add oimiragieo/agent-studio --skill commit-security-scan --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Commit Security Scan?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Commit Security Scan
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/oimiragieo-commit-security-scan/badge)](https://www.skillsdirectory.com/skills/oimiragieo-commit-security-scan)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: commit-security-scan
description: Analyze code changes (commits, PRs, diffs) for security vulnerabilities using STRIDE analysis and CWE mapping
version: 1.0
model: sonnet
invoked_by: both
user_invocable: true
tools: [Read, Write, Bash, Grep]

verified: true
lastVerifiedAt: 2026-03-16T08:04:10.005Z
best_practices:
  - Follow existing project patterns
  - Document all outputs clearly
  - Handle errors gracefully
error_handling: graceful
streaming: supported
source: builtin
trust_score: 100
provenance_sha: ac8c5507731d6d2c
---

# Commit Security Scan

<identity>
Commit Security Scan Skill - Analyze code changes (commits, PRs, diffs) for security vulnerabilities using STRIDE analysis and CWE mapping
</identity>

<capabilities>
- Commit Security Scan primary function
- Integration with agent ecosystem
- Standardized output generation
</capabilities>

<instructions>
<execution_process>

### Step 1: Gather Context

Read relevant files and understand requirements

### Step 2: Execute

Perform the skill's main function using available tools

### Step 3: Output

Return results and save artifacts if applicable

</execution_process>

<best_practices>

1. **Follow existing project patterns**: Follow this practice for best results
2. **Document all outputs clearly**: Follow this practice for best results
3. **Handle errors gracefully**: Follow this practice for best results

</best_practices>
</instructions>

<examples>
<usage_example>
**Example Commands**:

```bash
# Invoke this skill
/commit-security-scan [arguments]

# Or run the script directly
node .claude/skills/commit-security-scan/scripts/main.cjs --help
```

</usage_example>
</examples>

## Search Protocol

For code discovery and search tasks, follow this priority order:

1. \`pnpm search:code "<query>"\` (Primary intent-based search).
2. \`ripgrep\` (for exact keyword/regex matches).
3. semantic/structural search via code tools if available.

## Memory Protocol (MANDATORY)

**Before starting:**
\`\`\`bash
cat .claude/context/memory/learnings.md
cat .claude/context/memory/decisions.md
\`\`\`

**After completing:**

- New pattern -> \`.claude/context/memory/learnings.md\`
- Issue found -> \`.claude/context/memory/issues.md\`
- Decision made -> \`.claude/context/memory/decisions.md\`

> ASSUME INTERRUPTION: Your context may reset. If it's not in memory, it didn't happen.

Files in this skill

  • SKILL.md2.3 KB
  • commands/commit-security-scan.md323 B
  • hooks/post-execute.cjs242 B
  • hooks/pre-execute.cjs239 B
  • references/.gitkeep37 B
  • references/research-requirements.md229 B
  • rules/commit-security-scan.md114 B
  • schemas/input.schema.json277 B
  • schemas/output.schema.json638 B
  • scripts/main.cjs541 B
  • templates/implementation-template.md170 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…