Block no-verify hook — stop agents skipping git pre-commit hooks
A Claude Code PreToolUse hook that intercepts --no-verify/--no-gpg-sign bypass flags in Bash commands before they execute — with installation, extension and verification recipes
- What
- A Claude Code PreToolUse hook that intercepts --no-verify/--no-gpg-sign bypass flags in Bash commands before they execute — with installation, extension and verification recipes
- Cost
- Free
- Needs
- a Claude Code project (hooks are Claude Code-specific); meaningful pre-commit hooks already configured — this skill blocks bypassing them, it doesn't create them
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @wshobson practical skill for keeping AI coding agents honest at commit time. Agents habitually reach for `git commit --no-verify` to dodge hook failures; this skill configures a Claude Code `PreToolUse` hook on Bash that inspects each tool call's JSON with a dependency-free grep pattern and rejects (exit code 2) any command containing `--no-verify`, `--no-gpg-sign`, their short prefixes (git accepts `--no-veri`), or a short-option group containing `-n` after `commit`. It covers per-project and global installation (`.claude/settings.json`), is explicit about its limits (it stops habitual bypasses, not a determined evader who builds the flag from pieces or swaps `core.hooksPath`), notes that commit messages mentioning a flag are blocked too (failing safe), and shows how to extend the pattern to other flags like `--force` and combine it with sibling hooks. MIT-licensed. Honest caveats: Claude Code-specific — other agent harnesses need their own hook mechanism; it only works if the settings file is actually installed and the agent doesn't tamper with hooks; pair it with meaningful pre-commit hooks, because blocking bypasses is pointless if there is nothing to run. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a Claude Code project (hooks are Claude Code-specific); meaningful pre-commit hooks already configured — this skill blocks bypassing them, it doesn't create them Install "Block no-verify hook — stop agents skipping git pre-commit hooks" for me. It gives my agent @wshobson's skill: a Claude Code PreToolUse hook on Bash that inspects each tool call with a dependency-free grep pattern and rejects --no-verify, --no-gpg-sign, their short prefixes, and short-option -n groups after commit — with per-project and global installation recipes, documented limits, extension to other flags (--force), and combination with sibling hooks. MIT-licensed. Repository: https://github.com/wshobson/agents/blob/main/plugins/block-no-verify/skills/block-no-verify-hook/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "block-no-verify-hook". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. actually add the PreToolUse hook to my project's .claude/settings.json and test it with a dummy commit — installing the skill alone doesn't enforce anything). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.