Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…
Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …
New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …
This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…
Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…
Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…
New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…
New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…
Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…
New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…
Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…
No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …
No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…
Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…
Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…
Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…
No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…
Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…
Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…
Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…
Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 59/100
This commit fixes how Stack Wallet's desktop app parses token amounts for Solana tokens and other tokens. Previously, the app used simple string replacement for commas and periods, which could misinterpret numbers depending on the user's locale. For example, in some countries '1,000' means one thousand, while in others it means one. The fix uses locale-aware parsing and rejects inputs containing plus, minus, or space characters. The change also affects how displayed amounts are formatted, using the token's own decimal places instead of the coin's.
Lower-prioritybetter handling of localized group and decimal separators in amountsby Julian · 5e2eeba3 · Aug 14, 2026 · 4 filesMessage 50 · ThinTriage 0Details
Commit message · Julian
better handling of localized group and decimal separators in amounts
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityuse payInAmount if available, not as a fallbackby Julian · 81638409 · Aug 14, 2026 · 5 filesMessage 45 · ThinTriage 0Details
Commit message · Julian
use payInAmount if available, not as a fallback
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Moderate 59/100
This commit fixes a bug in the Stack Wallet app where Firo (a cryptocurrency) address validation was incorrectly accepting Bitcoin-style 'bc1' and 'tb1' addresses. Because Firo does not use SegWit/Bech32 addresses, treating these as valid could let a user accidentally send Firo funds to a Bitcoin address, likely resulting in permanent loss of money. The patch changes the wallet to reject Bitcoin Bech32 addresses and adds tests to make sure it does so.
AI review queuedfix possible nano send amount bugby Julian · 00a81912 · Aug 14, 2026 · 2 filesMessage 45 · ThinModerate 56Details
Commit message · Julian
fix possible nano send amount bug
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 56/100
This commit fixes a bug in how Stack Wallet prepares Nano cryptocurrency sends. Previously, the app calculated the remaining balance after a send using a locally cached balance, which could be outdated. It now fetches the live balance from the network and explicitly checks that the user has enough funds. If the cached balance was higher than the real balance, the old code could have created an invalid or over-spending transaction.
AI review queuedflatpak: add :create to data-dir filesystem grants so first-run persistsby Dan Miller · 5e411341 · Aug 13, 2026 · 3 filesMessage 50 · ThinInformational 18Details
Commit message · Dan Miller
flatpak: add :create to data-dir filesystem grants so first-run persists
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100
This change updates three Flatpak app permission files so the apps can create their own data folders (like ~/.stackwallet) on first launch. Previously, the apps could only access those folders if they already existed, which could cause first-run setup to fail. The change is a sandbox permission tweak, not a fix for a code vulnerability.
Lower-priorityupdate xelis to use tagged rust instead of ref dev branchby Julian · 3aeefefe · Aug 12, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Julian
update xelis to use tagged rust instead of ref dev branch
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedeth fees update/fixby Julian · 3af51469 · Aug 12, 2026 · 3 filesMessage 28 · OpaqueLow 41Details
Commit message · Julian
eth fees update/fix
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 41/100
This commit changes how Ethereum transaction fees are calculated in Stack Wallet. Previously, the wallet set the maximum base fee equal to the current network base fee, which could cause transactions to fail if network fees rose even slightly. The fix doubles the maximum base fee for preset fee options to give transactions more headroom. It also removes a check that prevented the priority fee from exceeding the maximum base fee. The commit adds extra logging for fee values but does not otherwise change security-sensitive code.
AI review queuedfiro temp SISTby Julian · 8f849d6b · Aug 12, 2026 · 8 filesMessage 8 · OpaqueLow 30Details
Commit message · Julian
firo temp SIST
8/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Contains work-in-progress language
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 30/100
This commit changes how the Stack Wallet mobile app handles private Firo (Spark) transactions. It temporarily blocks sending private Firo funds to exchange addresses, and rewrites the internal logic for preparing and broadcasting Spark spends so that each transaction uses only a single Spark coin input. It also adds a new planner that can split one payment across multiple single-input transactions when needed. The change appears to be a defensive measure rather than a fix for an active exploit, but it touches sensitive transaction-building code and removes some previously available functionality.
Lower-priorityxelis: bump both xelis deps, tezart ref, and Flutter 3.38.1 -> 3.44.8by Dan Miller · 32487519 · Aug 6, 2026 · 5 filesMessage 50 · ThinTriage 0Details
Commit message · Dan Miller
xelis: bump both xelis deps, tezart ref, and Flutter 3.38.1 -> 3.44.8
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedmaybeby Julian · c6a23088 · Aug 1, 2026 · 1 fileMessage 0 · OpaqueInformational 22Details
Commit message · Julian
maybe
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 22/100
This commit changes how transaction fees are calculated for a specific type of Litecoin transaction called 'mwebPegIn' (Mimblewimble peg-in). Previously, the fee was estimated once and the transaction was built. Now, for mwebPegIn transactions, it loops: builds the transaction, checks the actual fee based on the final transaction size, and rebuilds if the fee is too low. This is a bug fix to ensure users pay the correct network fee and their transactions don't get stuck or fail. There is no clear security vulnerability here; it appears to be a correctness/reliability improvement.
Lower-priorityat least try for an imageby julian · b28fec01 · Jul 31, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · julian
at least try for an image
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedclean up remaining pointlessnessby julian · 07398235 · Jul 31, 2026 · 1 fileMessage 35 · OpaqueLow 27Details
Commit message · julian
clean up remaining pointlessness
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 27/100
This commit removes two blocks of code that added an API key to outgoing requests for a cryptocurrency exchange integration called CypherGoat. The commit message calls this 'pointlessness,' suggesting the API key was unused or unnecessary. There is no direct evidence in the commit that this fixes a security vulnerability, but sending API keys when they are not needed can slightly increase exposure risk if those requests or logs are intercepted.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 18/100
This commit is a minor cleanup: it swaps two ordinary print statements for Flutter's debugPrint (which only shows in debug builds), removes a leftover debug print of a transaction map, and stops sending an API key in requests to the CypherGoat exchange service. The API-key removal is the only change with any security angle, but the diff does not show what the key was, how it was stored, or whether it was sensitive. There is no evidence of an active vulnerability being fixed.
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 21/100
This commit updates a database migration in the Stack Wallet app. It bumps the database version from 2 to 3 and changes the upgrade logic so that, when upgrading from any version below 3, two tables related to a 'Shop in Bit' feature are deleted and recreated, plus an app notifications table is created. The commit message and code comment state this is needed to 'recreate sib tables correctly.' There is no explicit mention of a security issue in the commit or supplied references. The main risk is that deleting and recreating tables during migration could cause data loss if the tables already contained user data, but the developer comment claims the feature was not used before this point. No independent security disclosure or vendor security advisory was provided.
AI review queuedcyphergoat related tweaksby Julian · 903aac9d · Jul 30, 2026 · 10 filesMessage 35 · OpaqueInformational 22Details
Commit message · Julian
cyphergoat related tweaks
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 22/100
This commit makes several small adjustments to the CypherGoat exchange integration in Stack Wallet. It adds a new 'other' field to trade records to store a tracking URL, makes some CypherGoat API response fields optional instead of required, filters out some competing exchange providers from CypherGoat rate quotes, and fixes a minor error-message formatting bug. There is no clear security vulnerability being patched, and the commit message does not describe any security relevance.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit simply adds three identical SVG image files for a new exchange partner icon named 'cyphergoat' to the project's asset folders. It is a routine asset-only change with no code modifications and no apparent security relevance.
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only updates the .gitignore file to ignore the android/build/ directory. It is a routine repository hygiene change with no security relevance.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 31/100
This commit fixes how Stack Wallet handles Firo masternode collateral UTXOs. Previously, the wallet could auto-freeze a UTXO, the user could deliberately unfreeze it, and then a later sync would re-freeze it automatically. The patch prevents that automatic re-freezing once a user has unfrozen a UTXO, while still allowing a first-time auto-freeze when masternode collateral is newly detected. It also improves the labels shown to users when collateral is detected with certainty versus only suspected. The pubspec.lock changes update unrelated dependencies and are not directly security-relevant.
Security candidatesib: remove full service arrangementby julian · 84436b7e · Jul 30, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · julian
sib: remove full service arrangement
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit simply removes one travel booking option ('Full Service') from a list of choices in the Stack Wallet app's ShopinBit travel form. It is a routine product or UI change, not a security fix.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 20/100
This commit is a UI refactor for the masternode feature in Stack Wallet. It removes a hard-coded note-based detection system for masternode collateral transactions and instead lets the user explicitly start the masternode registration flow from the masternode screen. It also fixes a couple of small UI bugs, such as showing the wrong error message text in slatepack/slate failure dialogs and properly formatting pre-filled amounts in the desktop send form. There is no obvious security vulnerability introduced, but the change removes a large block of auto-detection logic that previously tried to identify 1000-FIRO self-sends as collateral.
AI review queuedcyphergoat: use Decimal for money values, error instead of default on missing fieldsby 4rkal · 26e0a0cb · Jul 27, 2026 · 5 filesMessage 50 · ThinLow 44Details
Commit message · 4rkal
cyphergoat: use Decimal for money values, error instead of default on missing fields
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 44/100
This commit hardens how Stack Wallet's CypherGoat exchange integration handles API responses. It replaces imprecise floating-point math with exact decimal arithmetic for money amounts, and stops silently substituting default values (like 0 or empty strings) when expected fields are missing. Instead, the app now throws a clear error if required fields are absent or malformed. This reduces the risk of incorrect trade amounts being shown or accepted, and makes the app fail more safely if the exchange server sends an unexpected or malformed response.
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 23/100
This commit updates the Stack Wallet app's ShopInBit payment flow to support a new version of the ShopInBit backend API (1.0.7). It mainly adds handling for expired and underpaid invoices, allowing users to refresh or retry invoices instead of being stuck. There is no clear security vulnerability in the diff itself; it appears to be a feature/bug-fix update for payment recovery.