# Trace Scan

> |

- **Type:** Skill
- **Install:** `agentstack add skill-crewforth-crewforth-trace-scan`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [crewforth](https://agentstack.voostack.com/s/crewforth)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [crewforth](https://github.com/crewforth)
- **Source:** https://github.com/crewforth/crewforth/tree/main/kit/skills/trace-scan
- **Website:** https://crewforth.com/

## Install

```sh
agentstack add skill-crewforth-crewforth-trace-scan
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Trace Scan (trace-scan)

Trigger phrases: "scan traces", "trace scan", "AI trace", "check vendor name", "pre-commit audit"

Purpose: to bind §4.1/§4.2 to a *gate* rather than to *memory*. If the rule lives only in text,
a trace leaks sooner or later; this skill + the hooks stop the leak at commit time.

## When
- Before every commit (automatic: `pre-commit` + `commit-msg` hooks).
- Before crew-commit-agent proposes a message (manual verification).

## How
Pattern list: `./.claude/hooks/trace-blocklist.txt` (grep -iE, one pattern per line).
- **Defaults are high-hit:** co-author trailers, auto-generation footers, robot emoji, and AI-assistant/tool
  brand names. Standalone words that occur too often (model/assistant) are DELIBERATELY excluded. See trace-blocklist.txt for the exact list.
- **Vendor name is project-specific:** ADD the name of the third-party template in use to the list (§4.2).

Manual scan (a quick look without the hook):
```bash
git diff --cached --unified=0 | grep -E '^\+' | grep -Ev '^\+\+\+' \
  | grep -iEf .claude/hooks/trace-blocklist.txt
```

## Hook setup
`start.sh` sets `git config core.hooksPath .claude/hooks` (if there is a git repo). The hooks live
under `.claude` → they are in gitignore and stay local (§4.3). To do it later for a repo:
```bash
git config core.hooksPath .claude/hooks
chmod +x .claude/hooks/pre-commit .claude/hooks/commit-msg
```

## Rules
- If there is a finding, the commit STOPS; the phrase is removed and the real rationale is written in the project's commit language (CLAUDE.md).
- Skipping with `--no-verify` only on an EXPLICIT request (§4.5); the hook is not skipped silently.
- On a false positive, narrow/remove the pattern — the list is set up by the project owner.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [crewforth](https://github.com/crewforth)
- **Source:** [crewforth/crewforth](https://github.com/crewforth/crewforth)
- **License:** MIT
- **Homepage:** https://crewforth.com/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-crewforth-crewforth-trace-scan
- Seller: https://agentstack.voostack.com/s/crewforth
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
