vibe-pre-commit-audit
SkillProductivityScans staged changes for secrets, debug statements, TODOs without references, and other common commit mistakes. Use before creating any commit.
Use vibe-pre-commit-audit in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add vibe-pre-commit-audit and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the vibe-pre-commit-audit skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by ash1794/vibe-engineering in plugins/vibe-engineering/skills/vibe-pre-commit-audit/SKILL.md and read by Ahel’s review.
Catch the easy mistakes before they enter history.
When to Use This Skill
- Before creating a git commit
- When reviewing your own staged changes
- Before pushing to a shared branch
When NOT to Use This Skill
- Commits to personal scratch branches
- When the user explicitly says to skip checks
- Auto-generated code commits (lock files, etc.)
- Private or draft content leaking through built output (use
vibe-publication-leak-guard)
Tools First, Eyeballing Second
Pattern-matching a diff by eye misses things that a deterministic scanner catches. Before the manual checks:
- Run what the repo already has —
pre-commit run,lefthook,husky, or a lint/checkscript. Check.pre-commit-config.yaml,package.json, and theMakefile. - Run a secret scanner if one is installed (
gitleaks protect --staged,trufflehog git file://. --since-commit HEAD) orvibe-cli pre-commitfrom this repo. - If nothing is set up, suggest adding one (for example
vibe-cli hook install, or a gitleaks pre-commit hook), then fall back to the manual checks below.
Tool findings are blocking. The manual checks cover what the tools don't.
Checks
1. Secrets & Credentials
Scan for patterns:
API_KEY=,SECRET=,PASSWORD=,TOKEN=- AWS keys:
AKIA[0-9A-Z]{16} - Private keys:
-----BEGIN.*PRIVATE KEY----- - Connection strings with credentials
.envfiles being staged
2. Debug Statements
console.log(,fmt.Println(,print(,debugger;// DEBUG,# DEBUG,/* DEBUGlog.Debugin non-debug code paths
3. TODOs Without References
TODOwithout issue number:TODO: fix this(bad)TODO(#123): fix this(good)FIXME,HACK,XXX— flag all
4. Disabled Tests
t.Skip(,xit(,xdescribe(,@pytest.mark.skip- Commented-out test functions
//nolintwithout justification
5. Large Files
- Files > 1MB
- Binary files (images, compiled assets)
- Lock files with excessive changes
6. Commented-Out Code
- Blocks of 3+ consecutive commented-out lines of code
- Not comments explaining code, but actual code that's commented out
Output Format
Pre-Commit Audit
Status: CLEAN / WARNINGS / BLOCKED
Tools run: [e.g., pre-commit run, gitleaks protect --staged, or "none configured"]
| Check | Status | Findings |
|---|---|---|
| Scanner / hooks | ✓/✗/n/a | X findings |
| Secrets | ✓/✗ | X patterns found |
| Debug statements | ✓/✗ | X occurrences |
| TODOs | ✓/◐ | X without references |
| Disabled tests | ✓/✗ | X found |
| Large files | ✓/✗ | X over limit |
| Commented code | ✓/◐ | X blocks |
Blocking Issues (must fix)
- [Secret found in file.go:42]
Warnings (should fix)
- [TODO without reference in handler.ts:15]
Signals
- GitHub stars
- 162
- Forks
- 40
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
vibe-pre-commit-audit- Source
- github.com/ash1794/vibe-engineering
github.com/ash1794/vibe-engineering
Related picks
Skill · mattpocock
The pick for TypeScripttypescript-pro
Skill · jeffallan
The pick for TypeScriptaws-architecture-diagram
Skill · awslabs
The pick for AWSaws-health-events
Skill · aws
The pick for AWSdetecting-aws-cloudtrail-anomalies
Skill · mukul975
The pick for AWSaws-networking-audit
Skill · leoyeai
The pick for AWS