Pre-Commit Guard
A lightweight commit gate for AI agents that prevents accidental debug code, secrets, broken builds, and unchecked changes from being committed.
Use loop copies the kickoff prompt. Copy Markdown and Download loop include the complete Markdown page with context, source attribution, anchors, and guardrails. Cursor / Claude Code buttons prepare the shorter kickoff prompt only.
Supported agents
Goal
Block commits that contain secrets, debug switches, or unverified broken code.
Feedback gate
git diff --cached --checkStop condition
Staged diff is clean, no obvious secrets/debug flags are present, and relevant validation passes or is explained.
Give the agent these inputs before it starts the loop. This keeps discovery bounded and prevents vague retries.
The loop assumes these commands or integrations are available. Missing tools should be reported as blockers, not ignored.
Two separate pieces: the kickoff prompt starts the loop, while the downloaded Markdown carries the complete reference page.
1. Copy or download
Use the kickoff for a fast agent run. Download the full Markdown when you need source, context, and attribution in one file.
2. Paste into the agent
Start a fresh agent session in the target repo and provide the requested project context if the loop asks for it.
3. Let it self-pace
The agent should act, check evidence, retry only when the gate fails, and stop at the stated exit condition.
The diagram shows the order. This checklist keeps only the action, command, and failure handling needed during a real pass.
1. Inspect staged diff
Check exactly what is about to be committed.
git diff --cached --stat && git diff --cached --check2. Scan for risky strings
Search staged changes for secrets, debug flags, and local-only config.
git diff --cached | rg -n "(SECRET|TOKEN|API_KEY|debug=true|console.log)"3. Run validation
Run the closest meaningful project check.
4. Report commit readiness
Return pass/fail with evidence.
This is the text copied by Use loop. It is intentionally shorter than the Markdown export.
Before committing, inspect the staged diff, scan for secrets/debug flags, run relevant validation, and only commit if the guard passes.
Goal: Block commits that contain secrets, debug switches, or unverified broken code.
Check command: git diff --cached --check
Exit condition: Staged diff is clean, no obvious secrets/debug flags are present, and relevant validation passes or is explained.
Max iterations: 3
Guardrails:
- Do not weaken, skip, delete, or rewrite the validation command to force success.
- Do not claim completion until the stated exit condition is actually satisfied.
- If blocked, report the blocker, evidence, and next safest action instead of gaming the metric.
- Do not commit secrets, local env files, debug flags, or generated private artifacts.Quality
90/100
Safety
96/100
Expected output
A clean pre-commit report and safe commit readiness verdict.
Related loops
Browse allSecret Leak Scan Loop
Scan repository changes for leaked credentials, local env files, and unsafe debug output before publishing.
Kickoff preview
Scan changed and staged files for secrets, local env files, and debug leaks. Remove or redact unsafe values and repeat until clean. Goal: Prevent secrets and local credentials from leaving the working tree. Check command: git diff --cached | rg -n "(API_KEY|SECRET|TOKEN|PASSWORD|PRIVATE_KEY|BEGIN RSA|BEGIN OPENSSH)" Exit condition: No unapproved secrets or local credentials are present in staged or changed files. Max iterations: 4 Guardrails: - Do not weaken, skip, delete, or rewrite the validation command to force success. - Do not claim completion until the stated exit condition is actually satisfied. - If blocked, report the blocker, evidence, and next safest action instead of gaming the metric. - Never print raw secrets in the final answer. Redact values if they appear in output.
Post-Edit Test Guard
After code edits, detect the affected surface and run the closest relevant validation before declaring completion.
Kickoff preview
After every code edit, list changed files, choose the closest meaningful validation, run it, and report evidence before claiming completion. Goal: Run the closest meaningful verification after edits and report evidence. Check command: git diff --name-only HEAD Exit condition: Relevant validation has been run and either passes or failures are reported with evidence. Max iterations: 4 Guardrails: - Do not weaken, skip, delete, or rewrite the validation command to force success. - Do not claim completion until the stated exit condition is actually satisfied. - If blocked, report the blocker, evidence, and next safest action instead of gaming the metric. - Do not say “not run” without explaining why no meaningful check exists.
npm Audit Fix Loop
Review npm audit findings, apply safe upgrades, and verify the app still builds and tests.
Kickoff preview
Run audit, review safe remediation paths, update targeted dependencies, verify build/tests, and report remaining vulnerability risk. Goal: Remediate actionable vulnerabilities without unsafe forced upgrades. Check command: npm audit --audit-level=high Exit condition: No high/critical audit findings remain, or remaining findings are documented with blockers. Max iterations: 5 Guardrails: - Do not weaken, skip, delete, or rewrite the validation command to force success. - Do not claim completion until the stated exit condition is actually satisfied. - If blocked, report the blocker, evidence, and next safest action instead of gaming the metric. - Do not run force upgrades without explaining breaking-change risk and receiving approval.
Ship PR Until Green
Implement a scoped change, open or update a pull request, inspect CI, and continue until all required PR checks pass.
Kickoff preview
Take this branch to a green pull request. Implement the requested change, run local verification, open or update the PR, run `gh pr checks`, inspect failures, fix root causes, and repeat until every required check passes or you hit the iteration cap. Goal: Open or update a pull request and stop only when all required PR checks are green. Check command: gh pr checks Exit condition: All required pull request checks are successful and the PR is ready for review or merge. Max iterations: 10 Guardrails: - Do not weaken, skip, delete, or rewrite the validation command to force success. - Do not claim completion until the stated exit condition is actually satisfied. - If blocked, report the blocker, evidence, and next safest action instead of gaming the metric. - Do not disable required checks, edit loops to skip jobs, or remove tests to make CI green. - Do not merge the PR unless the user explicitly asked for merge authority.