Safety gate that must run before any git commit or push. Scans the pending change for leaked API keys and credentials, repository waste (node_modules, build output, oversized binaries), merge-conflict markers, syntax errors, elided or unimplemented AI-generated code, risky patterns, and an unrun test suite. Use whenever the user asks to commit, push, publish, ship, or "put this on GitHub", and before running git commit or git push for any reason.