ASD

Block No Verify Hook

Configura un hook PreToolUse para impedir que los agentes de IA salten los pre-commit hooks de git con --no-verify y otros flags de bypass.

Estrellas
38.8k

en todo el repo

Actividad
38

0–100, la ruta de este skill

Actualizado
hace 4 meses

último commit aquí

Commits
0

últimos 90 días

Contexto
1.6k tok

50 tok en reposo

Paquete
1 archivo

6 KB

Instalar

Funciona con cualquier agente que lea SKILL.md

npx -y skills add wshobson/agents --skill block-no-verify-hook --agent claude-code

Se instala solo en este repositorio.

Este skill reads environment config.

Qué hace

  • Añade un hook PreToolUse en .claude/settings.json que inspecciona cada llamada Bash antes de ejecutarse
  • Bloquea comandos git que contengan --no-verify o --no-gpg-sign devolviendo exit code 2
  • Permite extender el patrón grep para bloquear flags adicionales como --force
  • Deja pasar sin bloqueo cualquier comando que no contenga flags de bypass

Úsalo cuando

  • Configurar proyectos Claude Code que deben forzar quality gates en los commits
  • Evitar que agentes de IA salten pre-commit hooks, firma GPG u otros mecanismos de seguridad de git

No lo uses cuando

    Qué lo activa

    Di cualquiera de estas frases y el agente debería cargar este skill.

    • Configura un hook que bloquee git commit --no-verify en este proyecto
    • Impide que el agente use --no-gpg-sign al hacer commits
    • Añade una regla PreToolUse para bloquear flags de bypass en git

    SKILL.md

    En inglés

    Block No-Verify Hook

    PreToolUse hook configuration that intercepts and blocks bypass-flag usage before execution, ensuring AI agents cannot skip pre-commit hooks, GPG signing, or other git safety mechanisms.

    Overview

    AI coding agents (Claude Code, Codex, etc.) can run shell commands with flags like --no-verify that bypass pre-commit hooks. This defeats the purpose of linting, formatting, testing, and security checks configured in pre-commit hooks. The block-no-verify hook adds a PreToolUse guard that rejects any tool call containing bypass flags before execution.

    Problem

    When AI agents commit code, they may use bypass flags to avoid hook failures:

    # These commands skip pre-commit hooks entirely
    git commit --no-verify -m "quick fix"
    git push --no-verify
    git commit --no-gpg-sign -m "unsigned commit"
    git merge --no-verify feature-branch
    

    This allows:

    • Unformatted code to enter the repository
    • Linting errors to bypass checks
    • Security scanning to be skipped
    • Unsigned commits to bypass signing policies
    • Test suites to be circumvented

    Solution

    Add a PreToolUse hook to .claude/settings.json that inspects every Bash tool call and blocks commands containing bypass flags.

    Configuration

    Add the following to your project's .claude/settings.json:

    {
      "hooks": {
        "PreToolUse": [
          {
            "matcher": "Bash",
            "hook": {
              "type": "command",
              "command": "if printf '%s' \"$TOOL_INPUT\" | grep -qE '(^|&&|;|\\|)\\s*git\\s+.*--(no-verify|no-gpg-sign)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi"
            }
          }
        ]
      }
    }
    

    How It Works

    1. Matcher: The hook targets only Bash tool calls, so it does not interfere with other tools (Read, Edit, Grep, etc.).
    2. Inspection: The $TOOL_INPUT environment variable contains the full command the agent is about to execute. The hook uses printf to safely pass input (avoiding echo pitfalls with special characters) and checks for --no-verify or --no-gpg-sign flags only when preceded by a git command.
    3. Blocking: If a bypass flag is found in a git command, the hook exits with code 2 and prints an error message. Exit code 2 signals Claude Code to reject the tool call entirely.
    4. Pass-through: If no bypass flag is found, the hook exits with code 0 and the command executes normally.

    Exit Codes

    Code Meaning
    0 Allow the tool call to proceed
    1 Error (tool call still proceeds, warning shown)
    2 Block the tool call entirely

    Blocked Flags

    Flag Purpose Why Blocked
    --no-verify Skips pre-commit and commit-msg hooks Bypasses linting, formatting, testing, security checks
    --no-gpg-sign Skips GPG commit signing Bypasses commit signing policy

    Installation

    Per-Project Setup

    Create or update .claude/settings.json in your project root:

    mkdir -p .claude
    cat > .claude/settings.json << 'EOF'
    {
      "hooks": {
        "PreToolUse": [
          {
            "matcher": "Bash",
            "hook": {
              "type": "command",
              "command": "if printf '%s' \"$TOOL_INPUT\" | grep -qE '(^|&&|;|\\|)\\s*git\\s+.*--(no-verify|no-gpg-sign)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi"
            }
          }
        ]
      }
    }
    EOF
    

    Global Setup

    To enforce across all projects, add to ~/.claude/settings.json:

    mkdir -p ~/.claude
    cat > ~/.claude/settings.json << 'EOF'
    {
      "hooks": {
        "PreToolUse": [
          {
            "matcher": "Bash",
            "hook": {
              "type": "command",
              "command": "if printf '%s' \"$TOOL_INPUT\" | grep -qE '(^|&&|;|\\|)\\s*git\\s+.*--(no-verify|no-gpg-sign)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi"
            }
          }
        ]
      }
    }
    EOF
    

    Verification

    Test that the hook blocks bypass flags:

    # This should be blocked by the hook:
    git commit --no-verify -m "test"
    
    # This should succeed normally:
    git commit -m "test"
    

    Extending the Hook

    Adding More Blocked Flags

    To block additional flags (e.g., --force), extend the grep pattern:

    {
      "hooks": {
        "PreToolUse": [
          {
            "matcher": "Bash",
            "hook": {
              "type": "command",
              "command": "if printf '%s' \"$TOOL_INPUT\" | grep -qE '(^|&&|;|\\|)\\s*git\\s+.*--(no-verify|no-gpg-sign|force-with-lease|force)'; then echo 'BLOCKED: Bypass flags are not allowed.' >&2; exit 2; fi"
            }
          }
        ]
      }
    }
    

    Combining with Other Hooks

    The block-no-verify hook works alongside other PreToolUse hooks:

    {
      "hooks": {
        "PreToolUse": [
          {
            "matcher": "Bash",
            "hook": {
              "type": "command",
              "command": "if printf '%s' \"$TOOL_INPUT\" | grep -qE '(^|&&|;|\\|)\\s*git\\s+.*--(no-verify|no-gpg-sign)'; then echo 'BLOCKED: Bypass flags not allowed.' >&2; exit 2; fi"
            }
          },
          {
            "matcher": "Bash",
            "hook": {
              "type": "command",
              "command": "if printf '%s' \"$TOOL_INPUT\" | grep -qE 'rm\\s+-rf\\s+/'; then echo 'BLOCKED: Dangerous rm command.' >&2; exit 2; fi"
            }
          }
        ]
      }
    }
    

    Best Practices

    1. Commit the settings file -- Add .claude/settings.json to version control so all team members benefit from the hook.
    2. Document in onboarding -- Mention the hook in your project's contributing guide so developers understand why bypass flags are blocked.
    3. Pair with pre-commit hooks -- The block-no-verify hook ensures pre-commit hooks run; make sure you have meaningful pre-commit hooks configured.
    4. Test after setup -- Verify the hook works by intentionally triggering it in a test commit.

    Reproducido de wshobson/agents bajo licencia MIT. Leer esta página en markdown.

    Archivos

    1 archivo en el paquete. Solo se lee SKILL.md al activarse — las referencias se cargan si el skill decide que las necesita.

    Antes de instalar

    Requiere Claude Code con soporte de hooks PreToolUse y acceso para editar .claude/settings.json (local o global).

    Necesita en el PATH:git

    Variables de entorno:TOOL_INPUT

    Detalles

    Creador
    wshobson
    Licencia
    MIT
    Recursos incluidos
    Solo SKILL.md
    Repositorio
    wshobson/agents
    Código fuente
    Ver SKILL.md

    Etiquetas

    Más de wshobson/agents

    Este repo incluye 180 skills. Si instalas uno, normalmente ya tienes los demás.

    Úsalo al seleccionar y colocar iconos, imágenes, SVGs, diagramas o infografías de apoyo aprobados en un PPTX editable.

    Costo de contexto al activarse
    344 tok
    Tamaño del paquete
    2 archivos
    Última actualización
    hace 26 días
    documentos

    Úsalo cuando pidan optimizar un prompt, mejorar su rendimiento, diseñar una plantilla, aplicar chain-of-thought, few-shot prompting o técnicas avanzadas de prompt engineering para producción.

    Costo de contexto al activarse
    1.3k tok
    Tamaño del paquete
    10 archivos
    Última actualización
    el mes pasado
    herramientas desarrollo

    Úsalo al redactar o reparar una especificación JSON con coordenadas explícitas para un PPTX editable.

    Costo de contexto al activarse
    489 tok
    Tamaño del paquete
    2 archivos
    Última actualización
    hace 26 días
    documentos

    Úsalo para validar o reparar un PPTX editable en cuanto a geometría, accesibilidad, editabilidad nativa, linaje de fuente e integridad del paquete OOXML.

    Costo de contexto al activarse
    409 tok
    Tamaño del paquete
    2 archivos
    Última actualización
    hace 26 días
    documentos

    Úsalo para analizar un PPTX de referencia en modo solo lectura: estructura, tema, tipografía, ritmo de layout, diagnósticos, catálogos de plantillas derivados o inspección segura del paquete OOXML.

    Costo de contexto al activarse
    689 tok
    Tamaño del paquete
    8 archivos
    Última actualización
    hace 26 días
    documentos

    Úsalo al preparar la narrativa, las fuentes y el contexto de diseño para un nuevo deck PPTX editable.

    Costo de contexto al activarse
    415 tok
    Tamaño del paquete
    2 archivos
    Última actualización
    hace 26 días
    documentos

    Skills relacionados

    Configura Turborepo para builds de monorepo eficientes con caché local y remota. Útil al configurar Turborepo, optimizar pipelines de build o implementar caching distribuido.

    Costo de contexto al activarse
    2k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 5 meses
    devops infraestructura

    Implementa observabilidad integral para service meshes, incluyendo tracing distribuido, métricas y visualización. Útil para monitoreo de mesh, depuración de latencia y SLOs.

    Costo de contexto al activarse
    708 tok
    Tamaño del paquete
    2 archivos
    Última actualización
    hace 2 meses
    devops infraestructura

    Define e implementa Indicadores (SLI) y Objetivos (SLO) de nivel de servicio con error budgets y alertas, para establecer metas de fiabilidad y prácticas SRE.

    Costo de contexto al activarse
    1.8k tok
    Tamaño del paquete
    2 archivos
    Última actualización
    hace 2 meses
    devops infraestructura