Skip to main content

windbag

A pre-commit linter that catches comments narrating a change — a ticket number, what the code used to do, hedging about whether it works — instead of documenting why the current code is the way it is. Checks Python, JavaScript/TypeScript, Terraform/HCL, Rust, and SQL (including dbt and SQLMesh templates), plus the markup formats that carry comments: YAML, HTML, and Markdown.

What it detects

Rule Severity Flags
TICKET_ID error A ticket ID in a comment (SCA-533). Exempts TODO(SCA-600)-style tracked tasks and security-advisory IDs (CVE-, GHSA-, ...).
HISTORY_NARRATION error "was missing", "used to be", "no longer", "silently swallows", and similar.
HEDGE_LANGUAGE error "should work", "hopefully", "not sure why", "i believe", and similar.
CROSS_FILE_REF warn A pointer to another file/line (handler.py:147). Documentation URLs are exempt.
VERBOSE_COMMENT warn A comment that's long relative to what it documents. Markup files are exempt.
OBVIOUS_COMMENT warn A comment that just restates the line below it (// increment the counter above counter += 1).

error rules fail the check; warn rules are reported but don't block.

Markup files

YAML comments (#) come from the YAML grammar, so a # inside a quoted scalar stays data rather than becoming a comment. HTML and Markdown are checked through <!-- ... -->; in Markdown, anything inside a fenced code block is sample markup, not a comment, and is skipped.

The content rules — TICKET_ID, HISTORY_NARRATION, HEDGE_LANGUAGE, CROSS_FILE_REF — carry the weight here. VERBOSE_COMMENT does not apply: a few lines of explanation above a one-line config key is the idiomatic shape in a config file, not a comment outgrowing its code.

SQL files

.sql files are read as Jinja-templated SQL, which is what dbt and SQLMesh models are. --, /* */, and Jinja {# ... #} comments are all checked. A marker inside a 'string', a "quoted identifier", a $$ ... $$ body, or a {{ ... }} / {% ... %} tag is data the template emits, not a comment. The scanner is dialect-agnostic, so Snowflake, Postgres, BigQuery, and the rest all work; MySQL-style # line comments are the one form it does not read.

A comment is measured against the statement below it: the non-blank lines that follow, through the first one ending in ;.

Install

Needs a Rust toolchain. If you don't have one:

curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
. "$HOME/.cargo/env"    # and add this line to ~/.zshrc

Then, from a checkout:

cargo install --path .

That puts windbag in ~/.cargo/bin, which must be on your PATH.

Without wanting windbag on PATH permanently: this repo also builds as a Python package via maturin's bindings = "bin" mode, which just wraps the compiled binary in a wheel — there's no Python code here, and import windbag doesn't work. From a checkout with a Rust toolchain and uv:

uvx maturin build --release
uvx --from target/wheels/windbag-*.whl windbag check --all

No package is published yet, so this only works from a local build for now — uvx windbag (pulling from an index) isn't available.

Use

windbag init                  # write windbag.toml with generic defaults
windbag check --staged        # check what's about to be committed
windbag check --all           # check every git-tracked file in the repo
windbag check --json --staged # machine-readable output
windbag check --new-only f.py # only comments on lines the working tree adds over HEAD

Pre-commit:

- repo: local
  hooks:
    - id: windbag
      name: windbag
      entry: windbag check --staged
      language: system
      pass_filenames: false
      types_or: [python, javascript, jsx, ts, tsx, terraform, rust, yaml, markdown, html, sql]

(windbag needs to already be on PATH — language: system doesn't install it for you.)

Claude Code plugin

Pre-commit catches slop after it's written. The plugin catches it as it's written: a PostToolUse hook runs windbag on every file Claude edits and exits non-zero on a violation, so the findings go straight back to Claude as a blocking error and it rewrites the comment before moving on. A SessionStart hook states the rules up front so most edits never trip the linter at all.

/plugin marketplace add scale-venture-partners/windbag
/plugin install windbag@windbag

The binary has to be on PATH too — the plugin ships the hooks, not the linter, and they exit quietly when they can't find it. That means a Rust toolchain (see Install) plus:

cargo install --git https://github.com/scale-venture-partners/windbag

TODO: publish prebuilt macOS binaries from a tagged release so installing this doesn't require a Rust toolchain. Fine while it's a couple of people; not fine as a team-wide ask.

To turn it on for everyone working in a given repo, commit this to that repo's .claude/settings.json. Anyone who opens the repo is prompted to trust the marketplace, and the hooks apply from their next session:

{
  "extraKnownMarketplaces": {
    "windbag": {
      "source": { "source": "github", "repo": "scale-venture-partners/windbag" }
    }
  },
  "enabledPlugins": { "windbag@windbag": true }
}

Working on the plugin itself? /plugin marketplace add /path/to/windbag points at a local checkout instead. Either way the install copies plugin/ into ~/.claude/plugins/cache/ — keeping it out of the repo root is what keeps target/ out of the copy. That copy is a snapshot: after editing a hook, reinstall to pick up the change.

The hook needs windbag on PATH (or WINDBAG_BIN set) and jq installed; without either it exits quietly rather than breaking the session.

Env var Effect
WINDBAG_HOOK=off Disable both hooks without uninstalling.
WINDBAG_HOOK_LEVEL=error Block only on error rules; ignore warnings.
WINDBAG_BIN Explicit path to the binary.

Only comments on lines the working tree adds over HEAD are reported, so editing a file doesn't re-litigate comments that were already there. Claude is told not to silence a rule with windbag: ignore on its own — a false positive should surface to you, not get suppressed.

/windbag sweeps the whole repo and fixes what it finds.

Suppress a false positive inline:

# Was missing until v2 (LEGACY-1) — kept for the changelog.  windbag: ignore[TICKET_ID]

Config lives in windbag.toml; see examples/scalevp.toml for narrowing TICKET_ID to a real tracker prefix instead of the generic default.

Examples

main.tf:218  error TICKET_ID          comment references a ticket ID (SCA-533) — that
                                       context belongs in the commit message or PR
                                       description, not the code
main.tf:218  error HISTORY_NARRATION  comment narrates the change ("was missing")
                                       instead of the current state — describe the
                                       constraint, not the history
main.tf:218  warn  VERBOSE_COMMENT    comment block is long relative to what it
                                       documents (7 comment lines, 7.0x the 1 attached
                                       code line(s))
# Was missing entirely (SCA-533): this used to silently no-op.  <- TICKET_ID, HISTORY_NARRATION
value = fetch_value()

# This should work but I'm not sure why it fails sometimes.       <- HEDGE_LANGUAGE
retry(fetch_value)

# increment the counter                                           <- OBVIOUS_COMMENT
counter += 1

# TODO(SCA-600): revisit after Q3 pricing model ships              <- clean, exempt
schedule_followup()

# Sorted DESC because the caller assumes the first row is newest.  <- clean, real WHY
return sorted(items, reverse=True)
# Was missing (SCA-533): the deploy no longer fails.  <- TICKET_ID, HISTORY_NARRATION
steps:
  - checkout

# Pinned because the orb syntax below requires 2.1.   <- clean, real WHY
version: 2.1

In Markdown, a comment shown as sample markup inside a fence is content:

<!-- Was missing (SCA-533): renders wrong without it. -->   <- TICKET_ID, HISTORY_NARRATION

```html
<!-- Was missing (SCA-901): this one is an example. -->     <- clean, inside a fence
```

License

MIT

Metadata

Release files for windbag 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for windbag 0.1.0
File Size Uploaded
windbag-0.1.0.tar.gz 38.5 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for windbag 0.1.0
File
windbag-0.1.0-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
windbag-0.1.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
windbag-0.1.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
windbag-0.1.0-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
windbag-0.1.0-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 8.6 MB

Release files / windbag-0.1.0.tar.gz

Download URL windbag-0.1.0.tar.gz
Size 38.5 kB
Tags Source
SHA-256 checksum
How to use checksums
c62f292f8bb33ac7006f22b90406eed771067ad74dd144b4406763808818e0f0
BLAKE2b-256 checksum
How to use checksums
47083d36e59ed5259d989265c79387cee2160d67c97916701bdb73d94e9dbe22
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / windbag-0.1.0-py3-none-win_amd64.whl

Download URL windbag-0.1.0-py3-none-win_amd64.whl
Size 1.7 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
b5366fcca6ea5abd252b5d7fefdf3b6239be75afcc851c54d7feac0570ffd191
BLAKE2b-256 checksum
How to use checksums
2c81997b4df8acc5540666886062023938ef678ce301f49f3d60aa1a2854d260
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / windbag-0.1.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL windbag-0.1.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 1.8 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
10ecb18adb5bb892532f15efe3a0c9506b9f72f915bd4d91cefac3543e4a19c9
BLAKE2b-256 checksum
How to use checksums
4787b19ee414038c544ba630cd5577f53221a569fb6ebf1e52efecf06f421c61
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / windbag-0.1.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL windbag-0.1.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 1.7 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
02af06307c94b5317af015812b131bcf2e13582e663b2fc3bd83001d766fc8c8
BLAKE2b-256 checksum
How to use checksums
407d2c521c5a5fb8c21bbb89e4bb4b700cd5d8337400e3f8f6d8a766c7dd1e58
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / windbag-0.1.0-py3-none-macosx_11_0_arm64.whl

Download URL windbag-0.1.0-py3-none-macosx_11_0_arm64.whl
Size 1.7 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
82d6a162b023cf2f039ea47c36f53685f7666ac28ee6858f0af93002b859c450
BLAKE2b-256 checksum
How to use checksums
e9444a98e458a1dbc94c85a95882ea9df270c368659a4f78fa19728a4a874a80
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / windbag-0.1.0-py3-none-macosx_10_12_x86_64.whl

Download URL windbag-0.1.0-py3-none-macosx_10_12_x86_64.whl
Size 1.7 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
008c922bf0d4598d18cbb1ebc0fdbf814a204953fea5bcdbe8fb158c042fdd63
BLAKE2b-256 checksum
How to use checksums
bb20c2851d51cae9ba1be4f1a5003356859b40fe35a0976841168f7a9c3eba74
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.0

6 release files

0.1.1

6 release files

This release

0.1.0 This release

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page