trace-scan · git:20260707.abd2d2b · 2026-07-07 · sha256 1a0094c839fb95fd
trace-scan git:20260707.abd2d2bA
Immutable. This exact content is served forever at /api/v1/blob/1a0094c839fb95fd.
--- name: trace-scan description: | Trace scan discipline (§4.1/§4.2): before a commit, scans the staged changes and the commit message for AI traces (co-author trailers, auto-generation footers, robot emoji, tool names) and third-party template/vendor names. commit-agent-cck triggers it at work closure; the git hooks apply the same scan automatically. Trigger phrases: "scan traces", "trace scan", "AI trace", "check vendor name", "pre-commit audit" --- # Trace Scan (trace-scan) Purpose: to bind §4.1/§4.2 to a *gate* rather than to *memory*. If the rule lives only in text, a trace leaks sooner or later; this skill + the hooks stop the leak at commit time. ## When - Before every commit (automatic: `pre-commit` + `commit-msg` hooks). - Before commit-agent-cck proposes a message (manual verification). ## How Pattern list: `./.claude/hooks/trace-blocklist.txt` (grep -iE, one pattern per line). - **Defaults are high-hit:** co-author trailers, auto-generation footers, robot emoji, and AI-assistant/tool brand names. Standalone words that occur too often (model/assistant) are DELIBERATELY excluded. See trace-blocklist.txt for the exact list. - **Vendor name is project-specific:** ADD the name of the third-party template in use to the list (§4.2). Manual scan (a quick look without the hook): ```bash git diff --cached --unified=0 | grep -E '^\+' | grep -Ev '^\+\+\+' \ | grep -iEf .claude/hooks/trace-blocklist.txt ``` ## Hook setup `start.sh` sets `git config core.hooksPath .claude/hooks` (if there is a git repo). The hooks live under `.claude` → they are in gitignore and stay local (§4.3). To do it later for a repo: ```bash git config core.hooksPath .claude/hooks chmod +x .claude/hooks/pre-commit .claude/hooks/commit-msg ``` ## Rules - If there is a finding, the commit STOPS; the phrase is removed and the real rationale is written in human Turkish. - Skipping with `--no-verify` only on an EXPLICIT request (§4.5); the hook is not skipped silently. - On a false positive, narrow/remove the pattern — the list is set up by the project owner.