Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
37/100 average clarity
0Strong · 80–100
10Adequate · 60–79
152Thin · 40–59
139Opaque · 0–39
17security candidates with opaque commit messaging
This commit only updates marketing materials: it refreshes the README wording, adds an F-Droid badge, swaps screenshots and feature graphics, and edits the app store description. No program code, configuration, or dependency files were cha…
This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is …
New native TLS integration test workflow covering all shipped platformsCA bundle asset handling moved into wallet-core (assets/cacert.pem removed from app asset list, copyCacertToAppDocumentsDir removed)Debian launcher LD_LIBRARY_PATH no longer includes empty trailing entry
This commit only updates version numbers and the pinned Git commit references (called 'pins') for several software libraries the project depends on. No actual code in this repository was changed. The commit message simply says 'Update pins…
Dependency pin update to new commit hashes in external repositoriesNo source code changes in the skylight-wallet repository itselfNo commit message or in-diff indication of security relevance
This commit is a routine Git merge that brings the latest changes from the 'main' branch into a release-fixes branch. The only changed files are precompiled binary libraries for Monero wallet support on Android, iOS, Linux, and Windows. No…
This commit changes three build scripts so they only download two specific submodules ('monero' and 'lwsf') instead of all submodules. The stated reason is reliability: unused submodules for other coins can cause build failures when their …
Build script change limiting submodule checkout scopeReduced fetch of third-party dependencies during buildNo direct vulnerability or exploit mechanism introduced
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no description of what changed in the libraries is provided. We cannot det…
This commit only updates precompiled Monero wallet library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no security-related information is provided in the commit title or …
This commit fixes broken build pipelines for Linux and Windows desktop releases. It pins the Rust toolchain version used during the Linux build and installs the NASM assembler on Windows so that a cryptography library can compile. There is…
This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android …
Android MainActivity blocks route/deeplink intent injection by returning null initial route and disabling deeplink handlingAndroid build split into Play and FOSS source sets to keep Google Play review library out of F-Droid/GitHub APKsNew StoreReview method channels on Android and iOS
This commit only changes the app's version number in a configuration file, bumping it from 2.0.0+410 to 2.1.0+411. There are no code changes, no security fixes, and no behavior changes visible in the diff.
This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands fro…
Exported Android MainActivity previously accepted route-bearing intents that could bypass App LockNew getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on AndroidSubmodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
This commit updates pre-compiled Monero wallet library files across Android, iOS, Linux, and Windows. The actual code changes are inside binary files, so the diff shows no readable source changes. There is no information in the commit titl…
This commit only updates precompiled Monero library files (binary .so and .dll files) across Android, iOS, Linux, and Windows. No source code changes are shown, and no commit message or vendor reference explains what changed in these libra…
This commit is a cosmetic user-interface change. It swaps a text-based fiat exchange-rate error message for a warning-triangle icon with a tooltip and shows the coin balance more clearly when the fiat rate is unavailable. There is no secur…
This commit changes how screen transitions (animations) work in a mobile/desktop wallet app. It disables animated transitions on desktop entirely and keeps them only between navigation-bar screens on mobile. There is no security-relevant c…
This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the…
Flow change: mobile wallet creation/restoration bypasses app-level password screenMobile now relies on device app lock instead of an in-app passwordDuplicate-submission guard added via _committing flag
This commit is a routine merge that moves fiat-currency handling into a shared library and adds a 'switch amount unit' feature on the send screen. There is no security-relevant change visible in the diff.
This commit adds an in-app store review prompt. After a successful cryptocurrency send, it marks the user as eligible, and the next time they open the wallet home screen it may ask for a Google Play or App Store rating. The code deliberate…
Third-party SDK inclusion gated by build flavor (Google Play only)Install-source check before invoking Play review APIF-Droid reproducible-build compatibility via source-set exclusion and recipe deletion
This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious securit…
Large feature merge with 43 changed files and thousands of linesBuild script updates pinned appimagetool SHA256 and filenameNew desktop UI screens added; no security-critical logic visible
This commit only increases the app's internal build number from 409 to 410 in a configuration file. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.
Merge pull request #178 from MAGICGrants/2.1.0-release-fixes
2.1.0 release fixes
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet pathmerge-commit duplicate discount
AI analysis · Low 32/100
This is a routine version-2.1.0 bug-fix merge for the Skylight Monero wallet. The visible changes fix small packaging and platform-detection issues, add a new automated TLS test suite, and update pinned internal library versions. There is no direct evidence in the commit of a security vulnerability being patched, but the TLS-related test additions and library bumps suggest the release is hardening how the app validates encrypted connections. The patch is best treated as a maintenance/hardening update rather than a confirmed fix for an exploitable flaw.
Merge pull request #176 from MAGICGrants/desktop-ui
Desktop UI
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet pathmerge-commit duplicate discount
AI analysis · Low 34/100
This is a large feature merge that adds a desktop user interface, re-enables Linux and Windows release builds, and makes several Android build and security-related changes. The most notable security-relevant change is a fix in the Android MainActivity that prevents external apps or links from launching the app straight into a specific screen, which could have bypassed the app lock. The rest of the diff is UI/UX refactoring, localization updates, and build plumbing.
Security candidateFix create password screen showing up on mobile; formatby Keeqler · 6483d8a1 · Oct 1, 2026 · 9 filesMessage 50 · ThinInformational 18Details
Commit message · Keeqler
Fix create password screen showing up on mobile; format
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 18/100
This commit fixes a UI bug where mobile users were incorrectly shown a 'create wallet password' screen that should only appear on desktop. On mobile, the app now skips that screen and creates or restores the wallet directly, relying on the device's own lock instead. Most of the changes are just code formatting.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
seed or entropy pathsigning or wallet pathmerge-commit duplicate discount
AI analysis · Informational 17/100
This is a large merge commit that brings a new desktop user interface into the Skylight Wallet app. Most of the changes are UI layout, new desktop-specific screens, updated text strings, and build script tweaks. There is no obvious security bug in the diff, but the commit is a merge of two feature branches and the diff is huge, so a complete security review of every line is not practical from the supplied excerpt alone.
Merge pull request #164 from MAGICGrants/moneroc-pin-update
Update wallet-core and monero_c pin
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
access controlmerge-commit duplicate discount
AI analysis · Informational 3/100
This commit only updates version pins (commit hash references) for two external code libraries used by the Skylight Wallet app: monero_c and wallet-core. The actual code changes in those libraries are not shown in this commit. There is no description of any security fix, bug fix, or feature change. Based on this commit alone, we cannot determine whether the update fixes a security issue, introduces one, or is a routine maintenance change.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Informational 3/100
This commit only changes which version of an internal software library (wallet-core) the Skylight Wallet app depends on. It updates a reference code (a Git commit hash) in two package-management files. The commit message does not say why the update was made, and no security-related explanation is provided. Without seeing what actually changed inside the wallet-core library between the two referenced versions, we cannot tell whether this fixes a security problem, adds a feature, or is just routine maintenance.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Informational 4/100
This commit only changes how the app pulls in its shared wallet library. It switches from a local folder reference to a pinned Git commit from the same project's online repository, and updates that pinned version to a newer commit. There is no visible code change in the app itself, and nothing in the commit message or diff indicates a security fix or vulnerability.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access control
AI analysis · Low 25/100
This commit updates a dependency pin for the core Monero library used by the Skylight Wallet app and switches several wallet helper packages from remote Git downloads to local file paths. The change itself is a routine dependency bump and local development path change. There is no direct evidence in the commit that this fixes a security vulnerability, but updating a pinned cryptographic/wallet library can sometimes include security fixes from upstream. We cannot confirm that without inspecting the upstream library changes, which are not provided.
We don't want to accidentally send the view key to a node
60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · High 72/100
This commit fixes a Monero wallet bug where the app could accidentally save a private 'view key' to a regular Monero node instead of a lightweight wallet server (LWS). The fix separates saved server addresses for the two connection modes so that switching modes doesn't leave the wrong server address in the settings field. If the wrong address were saved, the user's private view key could be exposed to a node operator, allowing them to see all incoming transactions for that wallet.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access control
AI analysis · Informational 3/100
This commit only updates the app's version number and switches its internal wallet-core library to a newer pinned commit. No actual code changes are shown, and the commit message does not say anything about fixing a security problem. On its own, this diff does not demonstrate any vulnerability or security fix.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 47/100
This commit fixes a security bug in how the Skylight Wallet app copies sensitive information to the clipboard. Previously, some screens copied wallet addresses and secret keys using the regular system clipboard, which could leave that data exposed in the clipboard history. The patch makes those screens use the app's secure clipboard helper instead, which marks the data as sensitive and clears it automatically. It also adjusts Android 13+ so the app doesn't show a duplicate 'copied' confirmation when the operating system already shows one.
Pin Rust toolchain to 1.96 via single-source rust-toolchain.toml
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access controlauthentication path
AI analysis · Informational 15/100
This commit is a build-maintenance change, not a security fix. It creates one central file (rust-toolchain.toml) that declares which Rust compiler version to use, and updates build scripts and Docker configuration to read from that file instead of hard-coding an older version. There is no change to wallet logic, cryptography, or user-facing behavior.
! Generic or placeholder subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 12/100
This commit is a routine code cleanup. It removes several unused or dead utility files, widgets, and tests, and moves one small status icon definition into the screen that uses it. There is no change to how the app handles money, keys, network connections, or user data, and nothing in the commit suggests a security fix.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 18/100
This is a large user-interface refresh for the Skylight Monero wallet. Most changes are cosmetic: new logo, fonts, colors, labels, and screen flows. The only functional security-relevant change visible in the diff is that the app now derives whether a server connection uses HTTPS automatically from the address type (routable vs. onion/local), instead of letting the user toggle an 'useSsl' switch. This is a hardening move, not a vulnerability. There is no evidence in the commit of an exploit, backdoor, or data leak.
Security candidateOnly show wallet details screen when appropriateby Keeqler · 3d9f84fc · Aug 12, 2026 · 2 filesMessage 45 · ThinInformational 19Details
Commit message · Keeqler
Only show wallet details screen when appropriate
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 19/100
This commit changes two wallet setup screens so that users running a 'full node' mode skip a 'wallet details' screen that is only relevant to users relying on a third-party light wallet service. It also moves the start of a fiat-rate service earlier in the flow. There is no direct security vulnerability in the diff; it is a UI/routing correction that may reduce user confusion and avoid exposing unnecessary setup steps.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 10/100
This is a large feature/refactoring commit that introduces a new shared wallet-core integration path behind a compile-time flag, while keeping the existing legacy wallet code intact. It also removes the old in-tree openalias_ffi plugin and switches OpenAlias resolution to a new wallet_openalias package. There is no direct evidence in the diff of a security vulnerability, malicious change, or undisclosed fix. The work appears to be a normal architectural migration.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 18/100
This commit improves build reliability and supply-chain consistency for the Skylight Wallet. It switches the source of a key Monero-related library from a personal GitHub account (vtnerd) to the project's own organization (magicgrants), and it replaces a script that pinned the Rust compiler version for only the Tor plugin with a script that also pins the version for the OpenAlias plugin. There is no direct evidence of a security vulnerability being fixed; the changes are best described as hardening build reproducibility and reducing trust in an external repository.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 35/100
This is a large feature update for the Skylight Monero wallet that brings in improvements from another project called Spice. It adds support for connecting directly to a full Monero node (not just a light wallet server), background and continuous syncing, a more secure clipboard for copying sensitive data, QR-code wallet restoration, and a new OpenAlias resolver. The changes are mostly defensive: they improve privacy, reduce clipboard leaks, and make transaction sending more precise. There is no clear security vulnerability introduced by the patch, but because it is a very large change touching many security-sensitive areas (wallet files, network connections, background services, and clipboard handling), it deserves careful review and testing before release.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access controlauthentication path
AI analysis · Informational 16/100
This commit fixes the mobile wallet's automated build process so it always uses the same Rust compiler version when building a privacy-sensitive networking component (the Tor plugin). Without the fix, the build could silently use whatever the latest 'stable' Rust release is at the time, making releases non-reproducible and potentially introducing unexpected behavior or compiler-related issues. It also copies a pre-installed Rust toolchain into the build container so the build does not fail from a missing rustup. This is a build-hardening and reliability change, not a direct fix for an active security vulnerability in the wallet itself.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
access controldocumentation-only discount
AI analysis · Informational 19/100
This commit updates the versions of third-party GitHub Actions used in the project's automated build and release pipelines and locks them to specific, unchangeable commit hashes. It also adds a minor workaround for a Homebrew warning. The change is a routine supply-chain hardening measure; it does not introduce any obvious security vulnerability and likely reduces the risk of a compromised or malicious action update silently affecting future builds.
Add instructions for release signature verification
65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification✓ Names security-relevant behavior explicitly! No meaningful explanatory body
This commit only adds documentation to the README explaining how users can verify that downloaded release files are genuine using GPG signatures. It does not change any code, build process, or signing keys, and it does not fix or introduce any security vulnerability.
Security candidateSetup ios signing and do UISceneDelegate migrationby Keeqler · 27272608 · Feb 12, 2026 · 4 filesMessage 50 · ThinInformational 15Details
Commit message · Keeqler
Setup ios signing and do UISceneDelegate migration
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing boundary
AI analysis · Informational 15/100
This commit is a routine iOS build-configuration update for a Flutter wallet app. It adds Apple code-signing settings, migrates the app to use the newer iOS scene-delegate API, and registers Flutter plugins in a slightly different way. None of these changes introduce a security vulnerability or fix one; they are standard project maintenance needed to keep the app building and running on modern iOS.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
credential or privilege state
AI analysis · Informational 13/100
This commit removes a Docker command-line flag that made the build container run as the current host user instead of the container's default user. The stated goal is to fix build permission problems. In itself, the change does not add a known vulnerability, but it means the build will now run as whatever user is configured inside the builder image. If that image runs as root, files created in the mounted workspace could end up owned by root, and any build-time scripts or tools will execute with the container user's privileges. There is no direct evidence in the commit that this is a security fix or that it introduces an exploitable flaw.
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 34/100
This commit adds user-configurable Tor settings to the Skylight Wallet app. Users can now choose between built-in Tor, an external Tor proxy, or disabling Tor entirely. It also updates how the app fetches exchange rates and blockchain heights so they respect the new Tor setting. There is no clear security bug in the patch itself, but it introduces a 'Tor disabled' mode and changes how network traffic is routed, which could affect user privacy if the settings are mishandled or bypassed.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
signing boundarydocumentation-only discount
AI analysis · Informational 18/100
This commit fixes a GitHub Actions release workflow that was supposed to sign Android and Linux app files with GPG. Before the fix, the signing command likely failed because it could not unlock the GPG private key without a passphrase. The change passes the GPG passphrase from a GitHub secret into the signing step so the automated signing can complete. It is a build-pipeline fix, not a vulnerability in the wallet application itself.