r-git-commit

A Git commit review and message-formatting procedure. It checks code changes for risks before creating a commit and uses a structured format for the commit message.

In plain words
What is it for?
Use it to review changes, describe their impact, check formatting, and create commits with types such as feature, fix, documentation, test, or refactoring.
Why use it?
It helps catch secrets, destructive changes, performance concerns, formatting problems, and unclear descriptions before changes are recorded in Git.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/xyzbit/ai-coding/r-git-commit
Clone the repo
git clone --depth 1 https://github.com/xyzbit/AI-Coding
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 664 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00664
Opus 5 $0.00000 $0.00332
Sonnet 5 $0.00000 $0.00133
Haiku 4.5 $0.00000 $0.00066

Measured yesterday against content hash f37031714f59, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

r-git-commit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

cursor/rules/review/r-git-commit.mdc · 105 lines

What it actually says

Git 提交流程

步骤一

进行 Code Review,若遇到 git 命令分页的情况,请加上| cat,分析是存在以下几种级别的问题:

严重

  • 分析是否包含敏感信息,如密码、密钥、证书等

警告

  • 分析是否有破坏性的代码改动,如有则需要全部列举出来
  • 分析是否有明显的性能问题,进行说明并给出优化建议

提醒

  • 分析本次代码改动的影响范围,以简洁的语言进行描述
  • 分析代码是否已经格式化

步骤二

提交信息格式

提交信息应遵循以下格式:

<type>(<scope>): <subject>

<body>

<footer>

提交信息涉及换行时使用多个 -m 参数提交,如:

git commit -m "feat(auth): 添加用户登录功能" -m "实现了基于 JWT 的用户登录认证功能:" -m "- 添加登录接口" -m "- 实现 token 生成和验证" -m "- 添加用户信息缓存" -m "Closes #123"

Type 类型

必须是以下类型之一:

  • feat: 新功能(feature)
  • fix: 修复 bug
  • docs: 文档变更
  • style: 代码格式调整,不影响代码逻辑
  • refactor: 重构代码,不修复 bug 也不添加新功能
  • perf: 性能优化
  • test: 添加或修改测试代码
  • chore: 构建过程或辅助工具的变动
  • revert: 回滚之前的提交

Scope 范围

可选的提交范围,用于说明提交影响的范围,例如:

  • cli.admin: App配置后台服务
  • cli.agent: App配置网关服务
  • dev.admin: 开发配置后台服务

Subject 主题

  • 用简短的语言描述本次提交的主要内容
  • 不超过 50 个字符
  • 以动词开头,使用第一人称现在时
  • 第一个字母小写
  • 结尾不加句号

Body 正文

  • 对本次提交的详细描述
  • 可以分成多行
  • 说明代码变动的动机,以及与以前行为的对比

Footer 页脚

  • 用于关联 Issue 或破坏性变更说明
  • Breaking Changes 必须以 BREAKING CHANGE: 开头
  • 关联 Issue 使用 Closes #123, #456

示例

feat(auth): 添加用户登录功能

实现了基于 JWT 的用户登录认证功能:
- 添加登录接口
- 实现 token 生成和验证
- 添加用户信息缓存

Closes #123
fix(api): 修复用户查询接口返回错误

修复了当用户不存在时返回 500 错误的问题,
现在会正确返回 404 状态码。

Closes #456
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 105 lines · 0 tokens per session scan A f37031714f59

Subscribe to this mod's changes

r-git-commit is a cursor rule published in the GitHub repository xyzbit/AI-Coding (21 stars, last pushed 10mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 664 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.