Back to the marketplace · Skill
Commit after confirmation
Prepares one local Git commit: picks the files of the change, checks for credentials, drafts a message in the repository's style and shows you the list and commands; git add and git commit run only after you confirm. Derived from /commit in Anthropic's Claude Code plugin commit-commands: explicit paths only, a credential check first, no push, amend or hook bypass, and unattended AI colleague tasks hand over the proposal.
Copy this sentence and send it to any employee in Teloa:In Teloa, open Marketplace, search for "Commit after confirmation" and add it (Skill anthropic.commit).
- Source
- Teloa official · Derived from Anthropic (anthropics/claude-plugins-official)
Change list (8)
Security fix (1)
Adds a credential check before staging: files that normally hold credentials are left out (`.env`/`.env.*` except templates, `*.pem`, `*.key`, `*.p12`, `*.pfx`, private keys, `credentials.json`, service-account JSON, `.npmrc`/`.pypirc`/`.netrc` with tokens, and similar); the text to be committed is scanned for private key blocks, cloud access keys, `ghp_`/`github_pat_`/`xox`/`sk-` tokens and password/secret/token/api_key assignments with literal values; a hit is reported by file:line, kind and at most a 2-4 character mask, the file is left out and the user decides; a suspicious staged file gets a proposed `git restore --staged`, run only after confirmation. `git add -A`, `git add .` and `git commit -a` are forbidden; only explicit paths are staged.
Why: The original pre-approves `git add` with any arguments and asks for staging and committing in one step, "do not ... do anything else", with no credential check; the plugin README claims it "Avoids committing files with secrets (.env, credentials.json)", but the command text contains no such instruction. Verified on a sample repository: without a .gitignore, `git add .`, which the original pre-approves, stages a .env holding AWS's example key.
SKILL.md · Boundary (new); Step 2 (new)CMT-M06 · View original
Removed (1)
The original Claude Code slash-command file is not shipped; its text is rewritten as SKILL.md at the resource root (each change is listed in the other entries).
Why: Teloa loads skills from SKILL.md and does not support the Claude Code command format (`allowed-tools` and `!` command expansion).
commands/commit.mdCMT-M01 · View original
Adapted (4)
The frontmatter keeps only `name: commit` and a single-line `description` (runs only after confirmation; never pushes, amends or bypasses hooks); `allowed-tools: Bash(git add:*), Bash(git status:*), Bash(git commit:*)` is removed.
Why: Skills in the Teloa marketplace may only have single-line name and description frontmatter keys; Teloa does not honour Claude Code's allowed-tools pre-approval, and bash goes through the host's confirmation.
SKILL.md · frontmatter (L1-4)CMT-M02 · View originalAdds a visible change notice below the title, "Derived work: modified by Teloa from anthropics/claude-plugins-official@fa59bc90…", naming the original file and license and pointing to MODIFICATIONS.md.
Why: Apache-2.0 section 4(b) requires modified files to carry a prominent change notice; visible text is used instead of an HTML comment, which security scans would flag as hidden content.
SKILL.md · below the titleCMT-M03 · View originalThe four "!`git status`"-style lines that Claude Code expands at load time become read-only commands the model runs itself; `git status` becomes `git status --porcelain=v1 -uall` (lists each new file), and `git diff HEAD` gets an alternative for repositories without commits yet.
Why: Teloa skills have no `!` command expansion; plain git status collapses an untracked directory into one line (such as `tests/`), hiding the new files inside.
SKILL.md · Context (L6-11)CMT-M04 · View originalRemoves "Stage and create the commit using a single message. Do not use any other tools or do anything else. Do not send any other text…". Instead it first shows the branch, the files to commit and those left out, the credential check, the full message and the exact commands, and runs them only after the user confirms in the conversation; a request like "commit my changes" starts the preparation and is not that confirmation; a changed proposal needs a new confirmation; unattended AI colleague tasks stop at the proposal; and it lists what it never does (push, pull, merge, rebase, reset, stash, amend, force, create or switch branches, change Git configuration, --no-verify).
Why: In Claude Code the original pre-approves git add and git commit through allowed-tools, so a commit is made before the user sees what goes into it. In Teloa writes need the person's confirmation and AI colleagues cannot commit on their own.
SKILL.md · Boundary (new); Your task (L13-17); Steps 4-5 (new)CMT-M05 · View original
Added (1)
Adds: start from what is staged; with nothing staged, propose only the files of one logical change and list the rest as left out with a reason; read each new file before including it; with nothing to commit, say so and stop, never an empty commit; if a commit hook fails, stop and report, no --no-verify retry, no amend; afterwards report the new commit hash and anything left uncommitted.
Why: The original only says "create a single git commit" from the changes, with nothing on what to include, empty commits or failing hooks (the README's troubleshooting section mentions the empty-commit case).
SKILL.md · Steps 1 and 5 (new)CMT-M07 · View original
Improved (1)
Adds message guidance: follow the style of recent commits (language, `feat:` / `fix(scope):` prefix, capitalization, subject length), say why the change was made and not only what changed, and add no sign-off, co-author or tool attribution lines unless the repository's commits or the user ask for them.
Why: The original provides the last 10 commits as context but never asks to follow their style; the README says it matches the repository's style.
SKILL.md · Step 3 (new)CMT-M08 · View original
The other file matches the original (verified)
- GitHub
- Resource file: catalog/skills/anthropic.commit.json
Files kept by the marketplace: artifacts/skills/anthropic.commit/1.0.0/
Original source (locked version): GitHub anthropics/claude-plugins-official@fa59bc9 - License
- Apache-2.0
License files: LICENSE - Review
- Reviewed by Teloa on 2026-09-28
- Compatibility
- Needs configuration · Teloa >=0.2.0-alpha.7 · DSH 0.1.7-rc.1
- Needs Git and the bash tool. Apart from read-only git status / diff / branch / log, git add and git commit run only after you confirm the file list and message in the conversation; the host's own confirmation for bash applies on top.
- One local commit only: no push, pull, amend, branch or Git configuration changes, no --no-verify. Unattended AI colleague tasks hand over the proposal and do not commit.
- The credential check is the model's judgement on file names and common credential patterns, not a scanner, and can miss things; use a dedicated secret scanner for important repositories.
- Run with a local qwen3:14b model on a sample repository containing a .env file (3 attended and 5 unattended runs); not validated end to end in a Teloa host.
- Permissions and requirements
- Tools: bash, read
Required software: git
Uses the network: no - Data flow
- The files come with Teloa; nothing is downloaded when you add it. You can browse without signing in. Page views are counted with Cloudflare Web Analytics, which uses no cookies and does not record who you are. Data used for sign-in and reviews: privacy and community rules
Skill anthropic.commit · version 1.0.0