git-hygiene
A focused set of bash git hooks that keep AI-tool attribution out of commit messages, secrets out of staged files, and operator infrastructure identifiers (hostnames, agent handles, codenames) out of public diffs. No hard dependencies beyond bash, grep, awk, and git — gitleaks drops in for ~700 extra secret detectors.
At a glance
Highlights
Stack
Three positions, held firmly.
- AI tools are tools. Claude, Copilot, Cursor, Gemini, ChatGPT, ZCode — they’re how the work gets done, not who did the work. The author is the human; the tool is the tool. You don’t credit DeWalt on the shed you built with their drill.
- Secrets stay out of git. API keys, tokens, passwords — pre-commit’s regex layer catches the high-precision patterns, gitleaks catches the long tail when installed.
- Operator identifiers stay out of public diffs. The OPSEC scan layer catches hostnames, agent handles, and codenames that credential-shaped regex can’t — patterns you define once at machine level, applied to every repo you commit to.
- Local enforcement, no SaaS dependency. The hooks run on your machine against your staged files. No telemetry, no cloud calls, no third-party scans beyond gitleaks (which is itself local).
Install
Per-user (recommended — applies to every repo you own):
git clone https://github.com/JordanNewell/git-hygiene.git ~/git-hygiene
mkdir -p ~/.githooks
ln -s ~/git-hygiene/hooks/commit-msg ~/.githooks/commit-msg
ln -s ~/git-hygiene/hooks/pre-commit ~/.githooks/pre-commit
chmod +x ~/.githooks/*
git config --global core.hooksPath ~/.githooks
Live across the fleet — 7 of 10 hosts run it globally. The position became policy on 2026-07-18 and has been hardened three times since: pre-commit gained gitleaks + OPSEC content scan (Layer 2 + Layer 3), the OPSEC pattern library became machine-level, and per-repo opt-out shipped for internal repos.
See the repo README for the full Layer 1/2/3 breakdown, the OPSEC scan setup recipe, and the layered-defense model (editor setting → hook → CLAUDE.md instruction).