Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
51/100 average clarity
32Strong · 80–100
307Adequate · 60–79
505Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …
This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…
Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…
Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…
New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…
New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…
Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…
New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…
Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…
No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …
No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…
Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…
Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…
Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…
No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…
Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…
Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…
Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…
Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
This commit simply runs a cleanup tool on three SVG image files used for the rsFIRO cryptocurrency icon. It removes unnecessary formatting and metadata from the image files without changing their visual appearance. There is no security rel…
This commit is a routine merge from a staging branch that mostly tidies up build scripts and CI. The only user-visible change is that the Firo wallet now groups 'revoked' and 'banned' masternodes together under a single red 'banned' label,…
Dependency version bump for mobile_app_privacy (git ref changed).gitignore relaxation for cs_monero build artifacts and diff filesCI/build scripts now auto-generate API key template with additional Trocador placeholders
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access control
AI analysis · Low 32/100
This commit changes which version of the 'Spark Mobile' cryptographic library Stack Wallet uses. It switches from the official Firo project repository to a fork maintained by Cypher Stack (the same company that makes Stack Wallet) and updates the pinned commit hash. The change itself does not show any vulnerability in the code, but it is a supply-chain-style update: the wallet now depends on a different copy of a library that handles sensitive private-key and transaction operations for the Firo cryptocurrency. Without knowing what changed between the two commit hashes, we cannot say whether this makes users safer or less safe.
sib: (delivery) state parsing fix and loading message changed
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100
This commit fixes a small parsing bug in the Stack Wallet app's ShopInBit feature. The app reads a 'state/province' line from a support ticket message. Previously it only looked for lines starting with 'Delivery state:', but now it also accepts 'State:'. A user-facing loading message was also reworded from 'Updating available countries' to 'Checking available countries'. There is no clear security relevance in the change itself.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 16/100
This tiny commit reverts a database version bump and fixes a typo in a messaging refresh call. It appears to be a quick correction of an accidental change rather than a security fix. There is no clear security relevance visible in the code itself.
Security candidaterefactor notifications setup so we can add sib notifsby Julian · 16b90ff6 · Jul 11, 2026 · 19 filesMessage 50 · ThinInformational 19Details
Commit message · Julian
refactor notifications setup so we can add sib notifs
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 19/100
This commit is a feature refactor that adds a new in-app notification system for ShopInBit support tickets. It introduces a local database table for notifications, merges those notifications into the existing notification feed, and marks tickets/notifications as read when the user views them. There is no clear security vulnerability in the diff, but the change touches notification plumbing and local database migrations, so it carries normal implementation risk.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit only changes the marketing description text for a third-party concierge shopping service called ShopinBit. It rewords what users see on screen but does not alter any code behavior, security logic, or data handling.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 26/100
This commit adds the ability to attach files to customer-support messages in the ShopInBit feature of Stack Wallet. It introduces file picking, client-side type and size checks, and a multipart upload path to the server. The change is a feature addition, not a documented security fix. There are no obvious remote-code-execution or data-theft bugs visible in the diff, but the new code handles user-chosen files and uploads them over the network, which always carries some privacy and abuse risk.
Security candidatefix datetime sub second truncationby julian · b06e16d8 · Jul 10, 2026 · 3 filesMessage 45 · ThinInformational 20Details
Commit message · julian
fix datetime sub second truncation
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 20/100
This commit fixes how timestamps are stored for a built-in shopping/ticket feature. Previously, database columns used Drift's default dateTime type, which truncates fractional seconds. The patch switches those columns to store ISO 8601 UTC strings with millisecond precision and normalizes message timestamps to UTC. This is a data-integrity/correctness fix rather than a security vulnerability; it prevents subtle ordering or duplicate-detection bugs but does not create a direct path for an attacker to steal funds or run code.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 16/100
This commit refines how the wallet app checks for updates to ShopInBit support tickets. It reduces unnecessary API calls by only fetching full ticket details and messages when something has actually changed, and it tightens the code so that newly created ticket records must always have complete data. There is no obvious security vulnerability here; it is primarily a performance and robustness improvement.
Security candidateShould continue polling while app is not the active/focused window on desktopby julian · 649cecf4 · Jul 10, 2026 · 1 fileMessage 50 · ThinInformational 18Details
Commit message · julian
Should continue polling while app is not the active/focused window on desktop
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100
This small change makes the app keep checking for updates on a 'ShopInBit ticket' page even when the desktop app window is not in focus. Previously, the app would pause polling when backgrounded and resume when the user returned. Now on desktop it never pauses. This is a behavior change, not a clear security fix or vulnerability. It could slightly increase background network activity and keep a connection alive longer, but there is no direct evidence it introduces a security flaw.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100
This commit is a small code-quality cleanup in a cryptocurrency wallet app. It replaces a hardcoded text string ('NEW') and a hardcoded status value with references to a shared enum definition. There is no direct evidence in the commit that this fixes an exploitable security vulnerability; it appears to be a maintainability improvement that reduces the chance of future typos or mismatched status values.
Security candidatehardcoded sib text logo colors to match previous icon styleby julian · 0142537c · Jul 9, 2026 · 6 filesMessage 50 · ThinInformational 15Details
Commit message · julian
hardcoded sib text logo colors to match previous icon style
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 15/100
This commit is a purely cosmetic UI change. It swaps the ShopinBit service icon from a generic settings-style icon to a dedicated 'SIB' logo, hard-coding the logo colors to match the previous style. It also removes a settings gear icon from the mobile services page. There is no security-relevant change visible in the diff.
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit is a routine UI cleanup of a travel-booking form inside the Stack Wallet app. It removes unused date-mode options (flexible dates, trip length, month/year pickers), simplifies the arrangement choices, reorders a text box, and changes one label to mention that users can paste a link. There is no security-relevant change visible in the code.
Security candidateget full ticket probably doesn't return different responses for the same id. Assuming this, we can safely poll status and messages more frequentlyby julian · 92b4dac9 · Jul 9, 2026 · 2 filesMessage 50 · ThinInformational 18Details
Commit message · julian
get full ticket probably doesn't return different responses for the same id. Assuming this, we can safely poll status and messages more frequently
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100
This commit changes how often the app checks for updates on a support ticket and skips re-downloading the full ticket details when the app already has them. It is a routine performance and responsiveness improvement, not a security fix. There is no indication it addresses a vulnerability.
Security candidateSIB and GCs accessed from home screen on mobileby julian · f8dcdd8b · Jul 9, 2026 · 10 filesMessage 45 · ThinInformational 17Details
Commit message · julian
SIB and GCs accessed from home screen on mobile
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 17/100
This commit moves two existing app features—gift cards and concierge services—from a wallet-specific menu to the main home screen on mobile. It is a user-interface navigation change, not a security fix or vulnerability patch. There is no indication it fixes a bug that could be exploited.
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body! Contains work-in-progress language! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 17/100
This commit adds on-screen warnings telling users to send only USDT (TRC20) to a displayed address and not to send plain TRX. It is a user-interface safety hint, not a code change that fixes a software vulnerability. There is no evidence in the commit of an exploit, bug, or security flaw being patched.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit is a purely cosmetic UI change. It adjusts the width and button height of a confirmation dialog on desktop versions of the app. There is no security relevance.
Security candidatesplit full name into separate fields for first and last nameby julian · d94c789f · Jul 8, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · julian
split full name into separate fields for first and last name
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit simply changes the user interface for entering a billing/shipping name. Instead of one 'Full name' text box that the app later tried to split into first and last names, it now shows two separate boxes labeled 'First name' and 'Last name'. There is no security fix or vulnerability here; it is a routine UI and data-handling refactor.
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 21/100
This commit fixes a programming crash in the Stack Wallet app's checkout screen. In some countries, the app was forcing a 'State' field to be shown even when no state was selected, which could cause the app to crash with a null error. The fix hides the state field when it isn't needed and only forces it when it is required.
Security candidateload offer before view/dialog opens so the accept button isn't disabled for a second or two without any info as to why displayedby julian · 5c94aa00 · Jul 8, 2026 · 2 filesMessage 62 · AdequateInformational 12Details
Commit message · julian
load offer before view/dialog opens so the accept button isn't disabled for a second or two without any info as to why displayed
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Explains rationale or failure mode! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 12/100
This commit is a user-experience refactor, not a security fix. It moves the loading of a ShopInBit offer from inside the offer screen to the moment the user taps the 'Review offer' button, so the screen opens with data already loaded. The 'Accept offer' button no longer needs to be temporarily disabled while waiting. There is no indication this change addresses a security vulnerability.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit simply renames a button label from 'Decline' to 'Cancel' on a shopping offer screen so the text matches what the button actually does (close the screen). There is no security relevance.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 16/100
This is a small code-quality cleanup in a Flutter screen that shows ticket attachment details. It stops passing a UI framework reference (WidgetRef) into helper methods and instead passes the actual service object directly. There is no direct security vulnerability visible in the diff, but the change removes a pattern that can make code harder to reason about and could theoretically hide lifecycle bugs.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100
This is a small bug-fix patch in a mobile wallet's shopping-support ticket screen. It stores a service reference when the screen first loads, then reuses that reference later, instead of asking the app's state-management system for the service again after the screen may have been destroyed. The change prevents a runtime crash ('provider read after dispose') but does not appear to be a security vulnerability.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 18/100
This is a one-line UI bug fix for opening attachment links on desktop versions of the Stack Wallet app. The change tells the app to use the root navigator on desktop when displaying an 'Opening attachment' progress indicator. There is no indication this fixes a security vulnerability; it appears to address a navigation/display issue specific to desktop layouts.
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit is a minor user-interface wording cleanup for a shopping feature. It changes two on-screen labels so that the heading now mentions VAT and the price line no longer repeats it. There is no security relevance in the code change itself.
Security candidateshorten and clarify concierge main request text fieldby julian · 90e9bb96 · Jul 8, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · julian
shorten and clarify concierge main request text field
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100
This commit only changes a user-visible label in a shopping concierge form from a longer description to a shorter one, and tweaks how a multi-line text field label is visually aligned. There is no security-relevant change.