security-precommit-check

security-precommit-check is a skill for Claude Code, Codex from noique/cross-border-ecommerce-skills. It costs 112 tokens per session (1,931 once invoked), scanned A, original, no licence file.

A check that scans a Git repository before a commit, which is the step where changes are saved to version control, for exposed secrets such as API keys and private keys.

In plain words
What is it for?
Use it to install a pre-commit check, apply shared or repository-specific secret rules, and block commits containing detected credentials.
Why use it?
It helps prevent credentials from being included in code and later sent to a shared remote repository.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/noique/cross-border-ecommerce-skills/security-precommit-check
Any agent
npx skills add noique/cross-border-ecommerce-skills --skill security-precommit-check
Clone the repo
git clone --depth 1 https://github.com/noique/cross-border-ecommerce-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-precommit-check

README.md
[![agentmods](https://agentmods.dev/badge/skills/noique/cross-border-ecommerce-skills/security-precommit-check.svg)](https://agentmods.dev/skills/noique/cross-border-ecommerce-skills/security-precommit-check)
Your own site
<a href="https://agentmods.dev/skills/noique/cross-border-ecommerce-skills/security-precommit-check"><img src="https://agentmods.dev/badge/skills/noique/cross-border-ecommerce-skills/security-precommit-check.svg" alt="Measured on agentmods" height="20"></a>
Per session 112 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,931 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00112 $0.01931
Opus 5 $0.00056 $0.00966
Sonnet 5 $0.00022 $0.00386
Haiku 4.5 $0.00011 $0.00193

Measured 5d ago against content hash a9cd455c1ea6, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

security-precommit-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

The scan reads SKILL.md. This mod also ships 4 executable files (scripts/install-hook.sh, scripts/scan-history.sh, scripts/scan.sh, …), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

tools/security-precommit-check/SKILL.md · 157 lines

The source is not reproduced here

A licence we could not identify

The repository carries a LICENSE file, but it is custom or dual enough that GitHub cannot name it and neither can this catalogue. Unknown terms are not permission, so the body is not copied here. Read the licence at the source and decide for yourself.

Read it on GitHub

Files

What ships with it

8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 157 lines · 112 tokens per session scan A a9cd455c1ea6

Subscribe to this mod's changes

security-precommit-check is a skill published in the GitHub repository noique/cross-border-ecommerce-skills (47 stars, last pushed 1mo ago), with no licence file. It adds 112 tokens to every session and 1,931 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

zach-product-research

基于Sorftime MCP的选品分析,发现高潜力市场机会、多维度属性标注与交叉分析、验证竞争格局、测算投入产出、输出Go/No-Go决策与选品报告。 使用时机:选品立项前的市场调研。新品上架工作流第一步。 触发词:/zach-product-research.

zach22-1999/amazon-skills · 89 tokens

zach-seller-skill-creator

亚马逊卖家专用的 skill 创建器(中文)。当用户想把一个亚马逊运营/自媒体/日常工作流程变成可复用的 skill 时使用。触发场景包括但不限于:用户说"我想做一个 skill""把这个流程变成 skill""帮我写个自动化""优化我已有的 skill""给这个工作流做个自动化",即使用户没用"skill"这个词,只要在描述"以后每次都这样做"的重复性工作时也应触发。本 skill 的核心差异:强制用户先回答 6 个业务问题(业务目标/过去做法/具体步骤/方法论/调用方式/期望输出)再进入创建流程,防止产出空洞 skill。Create new skills, improve existing skills, run evals…

zach22-1999/amazon-skills · 203 tokens

zach-listing-health-checker

以真实消费者视角检查亚马逊Listing健康状态。通过网页抓取模拟消费者浏览体验, 检查页面可见性、价格、卖家信息、购物车、配送、类目节点、排名、差评等关键指标, 并验证关键词搜索可见性。使用时机:新品上架后验收、日常巡检、排查Listing异常。 触发词:/zach-listing-health-checker.

zach22-1999/amazon-skills · 101 tokens

zach-feature-demand-validator

功能需求真伪验证器。用三维数据(Review/关键词/社区)验证微创新是否真实需求。 使用时机:品类选定后评估微创新、竞品分析发现差异点后判断要不要跟进。 触发词:/zach-feature-demand-validator.

zach22-1999/amazon-skills · 71 tokens

zach-search-term-analyzer

分析 Amazon Brand Analytics 热门搜索词报告(Top Search Terms)。场景化框架:自家 ASIN 在/不在该词点击 TOP3 走完全不同的业务判断(存量经营 vs 市场进入),确定性脚本输出场景状态、市场结构象限与成交系数,直接对接广告分池和 Listing 关键词布局。 使用时机:拿到 Brand Analytics Top Search Terms(热门搜索词)报告后,做关键词策略、市场进入判断或自家词份额监控。 触发词:/zach-search-term-analyzer.

zach22-1999/amazon-skills · 133 tokens

zach-search-term-report-analyzer

分析 Amazon Ads SP / SB / SD 搜索词报告。确定性脚本负责清洗、时间窗聚合、词根聚类和决策计算,AI 助手或人工负责词根级语义分类;通过词根继承减少长尾词的待判定比例,输出 Markdown、CSV、HTML 和 JSON 六类结果。 使用时机:判断搜索词是否应该否定、控成本、继续测试或放量,分析 7/14/30 天 CVR 与 ACOS 变化,或者提炼可反馈给 Listing 的属性词和场景词。 触发词:/zach-search-term-report-analyzer.

zach22-1999/amazon-skills · 149 tokens