跳到主要内容
知仓学习社ZHICANG

commit

Stage, commit, create PR, and merge to main. Use for the standard commit-PR-merge cycle.

读凭据写文件严重 1 · 高危 1brycewang-stanford/Auto-Empirical-Research-Skills

它会碰到什么

扫了多少1 个文本文件,1 KB
它会碰到什么读凭据写文件
命中总数2 处
命中统计严重 1 · 高 1 · 中 0 · 低 0
逐条看命中(2 条严重或高危)
  • 严重 SKILL.md:26cred-paths
    - Exclude: `settings.local.json`, `.env`, credentials, large data files
  • SKILL.md:26identity-config-write
    - Exclude: `settings.local.json`, `.env`, credentials, large data files

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Commit Workflow

Perform the full commit-PR-merge cycle.

Steps

  1. Check current state:
   git status
   git diff --stat
   git log --oneline -5
  1. Create branch: git checkout -b [descriptive-branch-name]
  1. Stage files:
  • Stage specific files (never git add -A)
  • Exclude: settings.local.json, .env, credentials, large data files
  • Review what's being staged
  1. Commit:
  • Use $ARGUMENTS as commit message if provided
  • Otherwise, analyze changes and write a descriptive message
  • Format: imperative mood, concise, explains WHY not WHAT
  1. Push and create PR:
   git push -u origin [branch-name]
   gh pr create --title "[message]" --body "[summary of changes]"
  1. Merge (with user approval):
   gh pr merge --merge --delete-branch
   git checkout main
   git pull

Important

  • Never commit directly to main
  • Never use git add -A or git add .
  • Never commit sensitive files
  • Always review staged changes before committing

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 4 个不同仓库或目录里都有叫 commit 的技能。它们内容并不相同,别混用: