Claude Skill

trace-mcp-pre-commit

Run trace-mcp security, quality-gate, and antipattern checks before committing or opening a PR. Activate when the agent is about to create a commit or pull request in a project indexed by trace-mcp.

LLM Mart · 0 points · 14 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download nikolai-vysotskyi-trace-mcp-skills_trace-mcp-pre-commit-23dd625.zip · 1 KB
Part of nikolai-vysotskyi/trace-mcp — 5 skills

Install

skills CLI npx skills add https://github.com/nikolai-vysotskyi/trace-mcp/tree/master/skills/trace-mcp-pre-commit
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install nikolai-vysotskyi-trace-mcp@llmmart
Git git clone https://github.com/nikolai-vysotskyi/trace-mcp.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole nikolai-vysotskyi/trace-mcp collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

trace-mcp — Pre-Commit & Pre-PR Checks

Before creating a commit or opening a pull request, run the trace-mcp validation suite. Fix any critical or high findings before committing.

When to Use

  • The user asks to commit, stage, or push changes
  • The user asks to open a PR
  • The agent has finished implementing a feature or fix and is about to hand off

Checklist

1. Security scan

scan_security({ rules: ["all"] })

OWASP Top-10 vulnerability scan across the changed scope. If the change touches untrusted data flows, add:

taint_analysis({})

Trace untrusted sources to sensitive sinks (SQL, shell, file system, HTTP).

2. Quality gates on the changed scope

check_quality_gates({ scope: "changed" })

Validates complexity, coverage, duplication, and any project-configured gates on only the files you changed.

3. Antipattern scan

detect_antipatterns({})

Flags N+1 queries, eager loading, inefficient iteration, and language-specific performance footguns.

4. Symbol-level diff for the PR description

compare_branches({ branch: "current" })

Produces a symbol-level diff (functions added/removed/modified, signatures changed, exports changed). Use this as the basis for an accurate PR description instead of a raw line diff.

5. Bug prediction (optional, for risky changes)

predict_bugs({})
get_risk_hotspots({})

Flags files where the combination of high complexity and high churn makes regressions likely. If your change touches a hotspot, add extra tests.

Fix or Escalate

  • Critical / High findings: fix before committing. Do not suppress without discussion.
  • Medium findings: fix if cheap, otherwise note in the PR description.
  • Low / Info findings: note in the PR description.

After Commit

If the commit is part of a larger series, consider:

get_changed_symbols({ since: "<base-ref>" })

to generate an accurate changelog entry grounded in the symbol graph rather than commit messages.

Files (trace-mcp)
  • SKILL.md 2.2 KB
    ---
    name: trace-mcp-pre-commit
    description: Run trace-mcp security, quality-gate, and antipattern checks before committing or opening a PR. Activate when the agent is about to create a commit or pull request in a project indexed by trace-mcp.
    ---
    
    # trace-mcp — Pre-Commit & Pre-PR Checks
    
    Before creating a commit or opening a pull request, run the trace-mcp validation suite. Fix any critical or high findings before committing.
    
    ## When to Use
    
    - The user asks to commit, stage, or push changes
    - The user asks to open a PR
    - The agent has finished implementing a feature or fix and is about to hand off
    
    ## Checklist
    
    ### 1. Security scan
    
    ```
    scan_security({ rules: ["all"] })
    ```
    
    OWASP Top-10 vulnerability scan across the changed scope. If the change touches untrusted data flows, add:
    
    ```
    taint_analysis({})
    ```
    
    Trace untrusted sources to sensitive sinks (SQL, shell, file system, HTTP).
    
    ### 2. Quality gates on the changed scope
    
    ```
    check_quality_gates({ scope: "changed" })
    ```
    
    Validates complexity, coverage, duplication, and any project-configured gates on only the files you changed.
    
    ### 3. Antipattern scan
    
    ```
    detect_antipatterns({})
    ```
    
    Flags N+1 queries, eager loading, inefficient iteration, and language-specific performance footguns.
    
    ### 4. Symbol-level diff for the PR description
    
    ```
    compare_branches({ branch: "current" })
    ```
    
    Produces a symbol-level diff (functions added/removed/modified, signatures changed, exports changed). Use this as the basis for an accurate PR description instead of a raw line diff.
    
    ### 5. Bug prediction (optional, for risky changes)
    
    ```
    predict_bugs({})
    get_risk_hotspots({})
    ```
    
    Flags files where the combination of high complexity and high churn makes regressions likely. If your change touches a hotspot, add extra tests.
    
    ## Fix or Escalate
    
    - **Critical / High findings:** fix before committing. Do not suppress without discussion.
    - **Medium findings:** fix if cheap, otherwise note in the PR description.
    - **Low / Info findings:** note in the PR description.
    
    ## After Commit
    
    If the commit is part of a larger series, consider:
    
    ```
    get_changed_symbols({ since: "<base-ref>" })
    ```
    
    to generate an accurate changelog entry grounded in the symbol graph rather than commit messages.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related