Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
152Thin · 40–59
139Opaque · 0–39
17security candidates with opaque commit messaging
This commit only updates marketing materials: it refreshes the README wording, adds an F-Droid badge, swaps screenshots and feature graphics, and edits the app store description. No program code, configuration, or dependency files were cha…
This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …
New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…
Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…
This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …
Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…
This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …
This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…
This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …
Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.
This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…
Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…
This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…
This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…
This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…
Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.
This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…
Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…
Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.
! Generic or placeholder subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 12/100
This commit is a routine code cleanup. It removes several unused or dead utility files, widgets, and tests, and moves one small status icon definition into the screen that uses it. There is no change to how the app handles money, keys, network connections, or user data, and nothing in the commit suggests a security fix.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is purely a visual redesign of the app's dark theme. It changes color values—making backgrounds darker and switching accent colors to a Monero orange shade—but does not alter any security logic, data handling, or network behavior.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 18/100
This is a large user-interface refresh for the Skylight Monero wallet. Most changes are cosmetic: new logo, fonts, colors, labels, and screen flows. The only functional security-relevant change visible in the diff is that the app now derives whether a server connection uses HTTPS automatically from the address type (routable vs. onion/local), instead of letting the user toggle an 'useSsl' switch. This is a hardening move, not a vulnerability. There is no evidence in the commit of an exploit, backdoor, or data leak.
AI review queuedRename verbose loggingby Keeqler · 17ee48d9 · Aug 20, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Rename verbose logging
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only renames the user-facing label for a setting from 'Verbose Logging' to 'Enable Logging to File' (and the Portuguese equivalent). It changes displayed text strings in localization files, not how logging works, what data is logged, or any security behavior. There is no security issue here.
AI review queuedAdopt shared wallet_ui dialogs, logging, and biometric auth from wallet-core; Bug fixesby Keeqler · eb5494df · Aug 19, 2026 · 10 filesMessage 55 · ThinInformational 17Details
Commit message · Keeqler
Adopt shared wallet_ui dialogs, logging, and biometric auth from wallet-core; Bug fixes
55/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100
This commit mostly moves existing features—log exporting, delete-wallet dialog, and biometric unlock—into a shared library called wallet-core, and tweaks on-screen keyboard behavior. It is a refactoring and bug-fix patch, not a clear security fix. There is no direct evidence in the commit that it repairs a vulnerability, though centralizing sensitive code like biometric auth and wallet deletion in a shared library can make future security maintenance easier.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100
This commit is a routine UI refactor. It removes the app's own transaction-details popup and starts using a shared one from a related 'wallet-core' library. It also adds a couple of new translated labels, such as 'Change' and 'Copied to clipboard'. There is nothing in the diff that looks like a security fix or vulnerability.
AI review queuedAdopt wallet-core packages for fiat, background sync, notifications, and preferencesby Keeqler · e190e085 · Aug 18, 2026 · 15 filesMessage 50 · ThinLow 31Details
Commit message · Keeqler
Adopt wallet-core packages for fiat, background sync, notifications, and preferences
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 31/100
This commit is a large refactoring change that moves several wallet features—fiat exchange rates, background syncing, notifications, and preference storage—out of the Skylight Wallet app and into shared 'wallet-core' packages. The app now imports and configures those packages instead of containing its own implementations. The change itself is architectural: it deletes hundreds of lines of local code and replaces them with thin wrappers and configuration calls. There is no obvious new security bug in the diff, but because the actual logic now lives in external packages that are not shown, the full security effect cannot be judged from this commit alone.
AI review queuedGet rid of legacy WalletModelby Keeqler · 10a9192c · Aug 12, 2026 · 11 filesMessage 45 · ThinInformational 20Details
Commit message · Keeqler
Get rid of legacy WalletModel
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100
This commit removes the old 'WalletModel' wallet engine and switches the Skylight Wallet app to use only the newer 'wallet-core' engine. It is a large cleanup/refactoring change: about 2,000 lines of the old engine code are deleted, feature flags are removed, and screens now always talk to the shared wallet-core adapter. There is no direct evidence in the commit of a security vulnerability being fixed; it reads as a completion of a migration that had already been running behind a feature flag.
AI review queuedCorrectly show sync status in continuous sync notificationby Keeqler · 025a6a20 · Aug 12, 2026 · 4 filesMessage 50 · ThinInformational 15Details
Commit message · Keeqler
Correctly show sync status in continuous sync notification
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit fixes a small user-interface timing bug in the Skylight Wallet mobile app. It makes the ongoing background-sync notification show 'Wallet up to date' only when the wallet is actually caught up, instead of briefly showing it too early or staying stuck on 'Syncing…' when the wallet is already synced. There is no security-relevant change here.
AI review queuedFix fiat api warn icon showing up when api disabledby Keeqler · b02ff9e0 · Aug 12, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · Keeqler
Fix fiat api warn icon showing up when api disabled
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit fixes a minor user-interface bug in a cryptocurrency wallet app. When the user had disabled the fiat price API, a red warning icon was incorrectly shown as if the API had failed. The change simply hides that warning icon when the API is intentionally disabled. There is no security issue here.
Security candidateOnly show wallet details screen when appropriateby Keeqler · 3d9f84fc · Aug 12, 2026 · 2 filesMessage 45 · ThinInformational 19Details
Commit message · Keeqler
Only show wallet details screen when appropriate
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 19/100
This commit changes two wallet setup screens so that users running a 'full node' mode skip a 'wallet details' screen that is only relevant to users relying on a third-party light wallet service. It also moves the start of a fiat-rate service earlier in the flow. There is no direct security vulnerability in the diff; it is a UI/routing correction that may reduce user confusion and avoid exposing unnecessary setup steps.
AI review queuedBg/fg sync and tx notificationsby Keeqler · 689d81c4 · Aug 11, 2026 · 7 filesMessage 45 · ThinInformational 19Details
Commit message · Keeqler
Bg/fg sync and tx notifications
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit is a routine feature patch that wires up background and foreground wallet synchronization and adds incoming transaction notifications across mobile and desktop. It does not appear to fix a security vulnerability; it is part of an ongoing migration to a shared 'wallet-core' backend. The changes mostly move existing logic into helper functions and add notification gating so users are not spammed or re-notified.
AI review queuedFix delayed connection status changeby Keeqler · 373937fd · Aug 10, 2026 · 1 fileMessage 45 · ThinInformational 24Details
Commit message · Keeqler
Fix delayed connection status change
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100
This commit changes how the wallet reacts when the user switches between server types (a local node versus a lightweight server). Instead of immediately rebuilding and resyncing the wallet in the foreground, the app now delegates that work to a dedicated method. The stated goal is to fix a delayed or stale connection-status display. The diff itself is a one-line refactor and does not contain any obvious security bug or fix for one.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 10/100
This is a large feature/refactoring commit that introduces a new shared wallet-core integration path behind a compile-time flag, while keeping the existing legacy wallet code intact. It also removes the old in-tree openalias_ffi plugin and switches OpenAlias resolution to a new wallet_openalias package. There is no direct evidence in the diff of a security vulnerability, malicious change, or undisclosed fix. The work appears to be a normal architectural migration.
AI review queuedUpdate release.ymlby Licaon_Kter · 3dded6fa · Aug 7, 2026 · 1 fileMessage 28 · OpaqueInformational 17Details
Commit message · Licaon_Kter
Update release.yml
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit changes the automated release build script to add `--enforce-lockfile` to a Flutter package command. That flag tells the build tool to use exactly the dependency versions recorded in the project's lock file and not silently upgrade or change packages. It is a supply-chain hardening measure that reduces the chance of an unexpected or malicious package version sneaking into a release build, but it is not a fix for a known active vulnerability.
AI review queuedenforce flutter lockfileby Licaon_Kter · bcdcf738 · Aug 7, 2026 · 1 fileMessage 28 · OpaqueLow 29Details
Commit message · Licaon_Kter
enforce flutter lockfile
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 29/100
This commit changes the F-Droid build script to add the '--enforce-lockfile' flag when Flutter downloads its package dependencies. In plain terms, it tells the build tool: 'only install the exact versions of dependencies recorded in the lockfile, and fail if the lockfile is missing or out of sync.' This is a supply-chain hardening measure. It reduces the risk that a build silently picks up a newer, potentially malicious or buggy version of a dependency, but it is not a fix for a known active vulnerability.
AI review queuedBump build numberby Keeqler · 572b280e · Aug 7, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Bump build number
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only increases the app's build number from 403 to 404 in a configuration file. It makes no code changes and has no security relevance.
AI review queuedAdd some useful scriptsby Keeqler · 760a10f8 · Aug 6, 2026 · 6 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Add some useful scripts
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only adds helper shell scripts for building and verifying the app. There is no change to the app itself, no new feature, and no security fix or vulnerability introduced. The scripts are developer tooling for reproducible-build testing.
AI review queuedFix fiat rate loading foreverby Keeqler · 57dad25f · Aug 6, 2026 · 3 filesMessage 45 · ThinLow 46Details
Commit message · Keeqler
Fix fiat rate loading forever
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 46/100
This commit fixes two reliability problems in a cryptocurrency wallet app. First, it adds a 20-second timeout when fetching fiat exchange rates, so the app no longer waits forever if the network stalls. Second, it adds a 5-second timeout when closing the Tor/ SOCKS network socket, preventing a slow shutdown from hanging the app. It also removes a line that set wallet key-derivation rounds to 1, which is a very low, insecure value. The commit message only mentions the fiat-rate loading issue, not the security change.
AI review queuedIgnore connection error on seed restoreby Keeqler · 8293e8b0 · Aug 6, 2026 · 1 fileMessage 45 · ThinLow 35Details
Commit message · Keeqler
Ignore connection error on seed restore
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 35/100
This commit changes how a cryptocurrency wallet app handles errors when restoring a wallet from a seed phrase. It now ignores certain 'connection' errors that occur before the wallet has actually connected to a server, and it also lowers the password-stretching strength (kdfRounds) to 1 during this restore step. The change appears aimed at letting users restore wallets even when the app cannot immediately reach its backend server, but it may also hide real errors and weakens the cryptographic protection of the wallet file during restore.
AI review queuedUpdate monero_c librariesby Keeqler · 338db7ef · Aug 6, 2026 · 7 filesMessage 35 · OpaqueInformational 0Details
Commit message · Keeqler
Update monero_c libraries
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 0/100
This commit only swaps out precompiled Monero wallet library files (binary blobs) for Android, iOS, Linux, and Windows. There is no source code change, no description of what changed in the libraries, and no security context provided. On its own, this diff tells us nothing about whether the update fixes a security issue, introduces one, or is simply routine maintenance.
AI review queuedUpdate monero_cby Keeqler · 660395e1 · Aug 6, 2026 · 3 filesMessage 18 · OpaqueInformational 15Details
Commit message · Keeqler
Update monero_c
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit simply updates the version of a Monero library dependency (monero_c) used by the Skylight Wallet app. The actual code changes are not shown in the diff—only the version reference was changed. There is no information in the commit or supplied references indicating this update fixes or introduces any security issue.
AI review queuedUpdate monero_cby Keeqler · 11c7bcdd · Aug 5, 2026 · 3 filesMessage 18 · OpaqueInformational 4Details
Commit message · Keeqler
Update monero_c
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 4/100
This commit simply updates the version of an external Monero library (monero_c) that the Skylight Wallet app depends on. The actual code changes are not shown in this diff—only the version reference was changed. There is no visible security fix or security problem in the commit itself.
AI review queuedBring spice's restore date selector and sync progress when loading icon is tappedby Keeqler · d238d6bc · Aug 4, 2026 · 8 filesMessage 50 · ThinInformational 15Details
Commit message · Keeqler
Bring spice's restore date selector and sync progress when loading icon is tapped
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit adds a user-friendly date picker for wallet restoration and makes tooltips show when tapping a status icon. It is a routine feature improvement with no apparent security relevance.
AI review queuedFix app crash when attempting to delete walletby Keeqler · 464219ad · Aug 4, 2026 · 1 fileMessage 45 · ThinLow 46Details
Commit message · Keeqler
Fix app crash when attempting to delete wallet
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Low 46/100
This update fixes a crash that could happen when a user tries to delete or switch their cryptocurrency wallet in the Skylight Wallet app. The crash occurred because the app might free the wallet's underlying native memory while a background task (like checking the network connection or refreshing balances) was still using it. The patch adds a simple 'busy' flag and a wait step so the app finishes any in-flight task before closing the wallet. There is no direct evidence this crash can be exploited by an attacker to steal funds or data, but any use-after-free bug in native code is a security concern worth treating carefully.