Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
152Thin · 40–59
139Opaque · 0–39
17security candidates with opaque commit messaging
This commit only updates marketing materials: it refreshes the README wording, adds an F-Droid badge, swaps screenshots and feature graphics, and edits the app store description. No program code, configuration, or dependency files were cha…
This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …
New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…
Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…
This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …
Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…
This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …
This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…
This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …
Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.
This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…
Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…
This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…
This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…
This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…
Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.
This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…
Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…
Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
AI review queuedBetterby Keeqler · 6794aec4 · Oct 16, 2025 · 1 fileMessage 0 · OpaqueLow 38Details
Commit message · Keeqler
Better
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 38/100
This commit changes how a wallet app connects to its backend server. It adds automatic detection of IP addresses, Tor onion addresses, and regular domain names, and adjusts security settings (Tor and SSL) based on what the user types. It also adds a 10-second timeout for Tor connection tests and prevents the 'Continue' button from appearing until a successful test has completed. The changes appear aimed at preventing users from accidentally using insecure combinations, such as SSL over Tor or clearnet HTTP without SSL.
AI review queuedDark themeby Keeqler · e4903391 · Oct 15, 2025 · 11 filesMessage 0 · OpaqueInformational 15Details
Commit message · Keeqler
Dark theme
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit adds a dark theme option to the Skylight Wallet app. It lets users choose between light, dark, or system theme in settings, and adjusts QR code and status icon colors so they remain visible in dark mode. There is no security-relevant change here.
AI review queuedAdd verbose logging settingby Keeqler · 54a66dde · Oct 14, 2025 · 11 filesMessage 35 · OpaqueLow 41Details
Commit message · Keeqler
Add verbose logging setting
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 41/100
This commit adds an optional 'Verbose Logging' setting to the Skylight Wallet app. When enabled, the app writes detailed logs of wallet operations to a plain text file stored in the app's data folder. The logs include sensitive details such as wallet addresses, transaction destinations, amounts, daemon/proxy addresses, and some API responses. The setting is off by default and must be manually enabled by the user. The main risk is that a user who turns this on may later share the log file with a support person or expose it through a backup, accidentally leaking private wallet activity. The commit itself does not appear to be malicious; it is a debugging feature, but it increases the app's overall sensitivity to data exposure.
AI review queuedCert verification fixby Keeqler · 069e243f · Oct 14, 2025 · 6 filesMessage 38 · OpaqueHigh 77Details
Commit message · Keeqler
Cert verification fix
38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · High 77/100
This commit updates the list of trusted root certificates used by the Skylight Wallet app and changes how the app verifies HTTPS certificates. The main risk is that before this fix, the app may have trusted too many old or wrong certificates, or may not have properly checked the certificate chain, which could let an attacker intercept or fake wallet server connections. The patch itself is large because it adds a fresh bundle of trusted certificates, but the actual code changes are small and the commit message only says 'Cert verification fix' without explaining what was broken.
AI review queuedRemove unused assetsby Keeqler · 94dea722 · Oct 10, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Remove unused assets
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit simply removes two unused legal/policy text files (privacy policy and terms of service) from the app's asset list. There is no code change, no security fix, and no vulnerability introduced. The files themselves are not deleted from the repository, only excluded from being bundled into the built app.
Security candidateBranding, terms of service and privacy policyby Keeqler · a64659f8 · Oct 10, 2025 · 95 filesMessage 45 · ThinInformational 15Details
Commit message · Keeqler
Branding, terms of service and privacy policy
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet pathauthentication path
AI analysis · Informational 15/100
This commit is a routine rebranding and legal-disclosure update. It renames the app from 'monero_light_wallet' to 'skylight_wallet' across Android, iOS, macOS, Linux, Windows, and web; swaps the package name/namespace to 'org.magicgrants.skylight'; adds new launcher icons; and introduces in-app Terms of Service and Privacy Policy screens. There are no code changes that alter security behavior, cryptography, network handling, or data flow.
AI review queuedAdd AppBar where missingby Keeqler · 137a0bdd · Oct 10, 2025 · 7 filesMessage 28 · OpaqueInformational 15Details
Commit message · Keeqler
Add AppBar where missing
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is a routine user-interface polish change. It adds a top navigation bar (AppBar) to the 'Receive' and 'Send' screens and moves the screen title from the body into that bar. There is no security-relevant change in the code.
AI review queuedApp lockby Keeqler · eee1f0ef · Oct 10, 2025 · 18 filesMessage 0 · OpaqueInformational 12Details
Commit message · Keeqler
App lock
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 12/100
This commit adds an optional app-lock feature to the Skylight Wallet app. When enabled, the user must authenticate with their device's biometric or PIN before accessing the wallet. It is a security improvement, not a vulnerability fix or a new security flaw.
AI review queuedUse a generated password when creating walletby Keeqler · 73ab901a · Oct 8, 2025 · 11 filesMessage 45 · ThinHigh 74Details
Commit message · Keeqler
Use a generated password when creating wallet
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · High 74/100
This commit fixes a security weakness where the Monero wallet was created and opened with a hardcoded password, 'pass'. Now the app generates a random 16-byte password for each wallet and stores it in the device's secure storage (like a keychain). It also disables Android's automatic cloud backup of app data. This makes it much harder for someone who gets access to the wallet file to unlock it, because the password is no longer a public, guessable word.
AI review queuedIn send screen, allow address input to be expanded and add paste from clipboard iconby Keeqler · 4e47c803 · Oct 8, 2025 · 3 filesMessage 50 · ThinInformational 20Details
Commit message · Keeqler
In send screen, allow address input to be expanded and add paste from clipboard icon
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100
This commit is mostly a user-interface convenience update for a cryptocurrency wallet app. It adds a 'paste from clipboard' button on the send screen, lets the address box expand to multiple lines, removes a couple of unnecessary 'const' keywords, and waits for the Tor privacy network to finish connecting before continuing setup. The changes do not appear to fix a security vulnerability, but the Tor wait could prevent a rare race condition where the app tries to use Tor before it is ready.
AI review queuedRemove debug codeby Keeqler · 1f5c5eee · Oct 8, 2025 · 1 fileMessage 28 · OpaqueInformational 22Details
Commit message · Keeqler
Remove debug code
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 22/100
A developer removed leftover debug code that artificially inflated the number of new transactions detected by one. With the extra '+1' in place, the wallet would think there was one more new transaction than actually existed, which could trigger a notification or UI update for a non-existent transaction. The fix simply deletes that '+1' so the count is accurate.
AI review queuedFixesby Keeqler · 696af0a9 · Oct 8, 2025 · 14 filesMessage 0 · OpaqueLow 32Details
Commit message · Keeqler
Fixes
0/100 · OpaqueMessage clarity
! Generic or placeholder subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 32/100
This commit is a general bug-fix and reliability update for a Monero wallet app. It tightens balance checks when sending money, improves how pending and confirmed transactions are tracked, replaces an old notification system with a background task, and fixes some UI status icons. There is no clear security vulnerability being patched, but the changes reduce the chance of users accidentally creating invalid transactions or seeing misleading balances.
AI review queuedFix restore height showing up as 0 for new walletby Keeqler · 5fce750b · Oct 3, 2025 · 3 filesMessage 45 · ThinInformational 19Details
Commit message · Keeqler
Fix restore height showing up as 0 for new wallet
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit fixes a UI bug where a newly created wallet's 'restore height' was displayed as 0 instead of the current blockchain height. The restore height tells the wallet from which point in the blockchain to start scanning for transactions. Showing 0 was incorrect and could mislead users, but it did not expose funds or allow unauthorized access. The fix stores the correct height when a wallet is created and reads it back reliably.
AI review queuedFix connecting status conditionby Keeqler · d0e4eb7b · Oct 3, 2025 · 2 filesMessage 35 · OpaqueInformational 17Details
Commit message · Keeqler
Fix connecting status condition
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 17/100
This commit fixes a UI status bug in the Skylight Wallet app. The wallet home screen could incorrectly show a 'connected' status when it should still show 'connecting' because the logic didn't account for a wallet that reports itself synced but has a synced block height of zero. The patch also removes two leftover debug print statements. There is no direct security vulnerability visible in the diff.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 31/100
This commit appears to be a routine bug-fix and polish update for a Monero light wallet app. It fixes a broken wallet-delete routine (the old code compared a variable to null instead of actually setting it to null), improves connection status display, adds a timeout to stats loading, and ensures Tor is ready before fetching blockchain height. There is no clear security vulnerability being patched, and no vendor disclosure or researcher attribution is present.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 31/100
This commit is a routine development progress patch for a Monero light wallet app. It restructures how the wallet connects to the network, moves some work onto background threads, fixes a bug where a fiat-exchange-rate timer was not being stored/cancelled correctly, and adds a wait-until-Tor-is-ready helper. There is no clear security vulnerability in the diff, but the changes touch sensitive areas (network/Tor setup, wallet refresh, FFI pointer handling) and the patch is incomplete in places (debug print statements left in, a TODO comment, hardcoded wallet password still present).
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 4/100
This commit updates a precompiled Monero wallet library (monero_c) used by the Skylight Wallet Android app. The actual code inside the updated .so files is not shown in the diff, so we cannot determine from this commit alone whether the update fixes a security bug, adds a feature, or is a routine dependency refresh. No security relevance is stated by the project.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 26/100
This commit is a routine development update titled 'Progress' for the Skylight Wallet app. It mainly refactors how the wallet object is handled (making it nullable to avoid crashes before a wallet is loaded), moves timer logic out of the home screen into a shared model, updates native Monero library files, and adjusts balance/transaction getters. There is no clear security fix or vulnerability being patched in the visible code changes.