commitclerk is a single script distributed from the main branch. Only the
latest commit on main is supported β please verify a problem still reproduces
there before reporting it.
Do not open a public issue for a security problem.
Report it privately through GitHub Security Advisories:
Please include:
- A description of the issue and its impact
- Steps to reproduce, or a proof of concept
- The commit SHA you tested against, plus your OS and Python version
You can expect an acknowledgement within 7 days and a status update within 30 days. This is a volunteer-maintained project, so please be patient β and credit will be given in the advisory unless you prefer to stay anonymous.
- Command injection or arbitrary code execution through crafted repository contents, filenames, branch names, or CLI arguments
- Leakage of an API key (
OPENAI_API_KEY,ANTHROPIC_API_KEY) to disk, logs, process arguments, or any destination other than the configured API endpoint - Sending repository content anywhere other than the configured API endpoint
- Anything that causes an unintended, destructive git operation
commitclerk makes exactly one network request per run: an HTTPS POST of the
prompt (the staged diff, the staged file list, and the rules) to the endpoint you
configured. Nothing else is transmitted β no telemetry, no analytics, no remote
config, no second call.
That endpoint is https://api.openai.com/v1/chat/completions by default, and it
is under your control:
| What you set | Effect |
|---|---|
| nothing | The default OpenAI endpoint, https://api.openai.com/v1/chat/completions. |
--provider anthropic |
Anthropic's Messages API, https://api.anthropic.com/v1/messages, authenticated with ANTHROPIC_API_KEY. |
--provider ollama |
A local server at http://localhost:11434/v1, with no API key and nothing sent over the network. |
--base-url / a provider's base-url variable |
The diff goes to that host instead β including any other http://localhost:... server, in which case nothing leaves the machine. |
Two consequences worth being explicit about: a custom base URL is a deliberate
change of destination for your source code, so point it only at a host you trust;
and because a plain http:// URL is accepted (local servers rarely have TLS), a
non-loopback http:// endpoint sends your diff over the network in the clear.
Only http:// and https:// are accepted at all β anything else is rejected
before the request is built.
- The staged diff being sent to the configured API endpoint. This is the
documented, intentional behavior of the tool β see
Privacy and cost. Do not use
commitclerkon repositories whose contents may not leave your machine, unless you are running a local model (--provider ollama, or--base-urlpointed at your own server). run-commit.cmd/run-commit.shstaging every change withgit add -A. This is documented behavior of the wrappers. Stage manually and callcommitclerk.pydirectly if you need control over what is committed.- Vulnerabilities in a provider's API (OpenAI, Anthropic), in
git, or in CPython itself β report those to their respective maintainers. - The quality or accuracy of generated commit messages. That is a bug report, not a security issue.
commitclerkreads the selected provider's key (OPENAI_API_KEYorANTHROPIC_API_KEY) from the environment only. It is never written to a file, never printed, and never passed as a command-line argument. Only the selected provider's key is read β choosing one provider does not touch the other's key.- The key is sent to whatever
--base-urlnames. Do not pair a real OpenAI key with a third-party base URL you do not trust β use a key issued by that host. - Never paste a key into an issue, pull request, or discussion. If you do, revoke it immediately.
- Prefer a key scoped to the minimum permissions your workflow needs, and rotate it periodically.