git-staging

A set of Git rules for staging only the files you intend to commit and adding a sign-off line to every commit. Git is the tool that records changes to source code.

In plain words
What is it for?
Use it when preparing commits, choosing precise git add commands, and creating signed-off commit messages.
Why use it?
It reduces the chance of accidentally committing unrelated files and ensures commits include the required author-attestation line.

Cursor rule for Codex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/prisma/orm/git-staging
Clone the repo
git clone --depth 1 https://github.com/prisma/orm

Made for: Codex.

Per session 744 This file is loaded in full into every session.
When invoked 744 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00744 $0.00744
Opus 5 $0.00372 $0.00372
Sonnet 5 $0.00149 $0.00149
Haiku 4.5 $0.00074 $0.00074

Measured 2d ago against content hash 5d206d2271e0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

git-staging scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.agents/rules/git-staging.mdc · 86 lines

How it starts

The opening of the file, as written. The whole thing — 86 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Git Commit Best Practices

Never Use git add -A or git add .

CRITICAL: Do not use git add -A, git add ., or git add --all when staging changes. These commands stage all changes including unrelated or untracked files.

Correct Approach

Always stage files explicitly:

# Stage specific files
git add path/to/file1.ts path/to/file2.ts

# Stage modified files only (doesn't add untracked files)
git add -u

# Stage files matching a pattern (be specific)
git add packages/1-framework/1-core/*/package.json

Always Sign Off Commits

CRITICAL: Every git commit you author MUST include a Signed-off-by: trailer. Pass -s (or --signoff) on every commit.

# Correct
git commit -s -m 'fix(foo): correct null handling in bar'

# Correct (with HEREDOC for multi-line messages)
git commit -s -m "$(cat <<'EOF'
fix(foo): correct null handling in bar

Explains why ...
EOF
)"

# WRONG — no signoff trailer
git commit -m 'fix(foo): correct null handling in bar'

Common pitfalls:

  • The format.signoff=true git config option only affects git format-patch, not git commit. Do not assume the user's global config will add the trailer.
  • There is no commit.signoff git config option. The trailer must be added explicitly per commit, or via a prepare-commit-msg hook owned by the user.
  • When using git commit --amend (rare — see "Never Amend Pushed Commits" below), pass --signoff to ensure the trailer is present after the amend.
  • When rebasing with --exec or --signoff, ensure the trailer is preserved.

Verify before pushing:

# Last commit must show a Signed-off-by line under the message body
git log -1 --format='%B' | tail -3

Never Amend Pushed Commits

Do not use git commit --amend on commits that have already been pushed to the remote. This rewrites history and causes problems for anyone else working with the branch.

Instead, create a new commit with the fix.

Best Practices

  1. Review before staging: Run git status to see what will be staged
  2. Stage explicitly: List the specific files or use -u for modified files only
  3. Verify before committing: Run git diff --cached to review staged changes
  4. Sign off every commit: Pass -s to every git commit invocation
  5. Keep commits focused: Each commit should contain related changes only
  6. Don't amend pushed commits: Only amend commits that haven't been pushed yet

Read the full file on GitHub · 86 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 86 lines · 744 tokens per session scan A 5d206d2271e0

Subscribe to this mod's changes

git-staging is a cursor rule published in the GitHub repository prisma/orm (47,579 stars, last pushed yesterday), licensed Apache-2.0. It adds 744 tokens to every session, about $0.0037 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.