# Block No Verify Hook > Configura un hook PreToolUse para impedir que los agentes de IA salten los pre-commit hooks de git con --no-verify y otros flags de bypass. Fuente: https://skillsagentes.com/skills/wshobson/agents/block-no-verify-hook Markdown: https://skillsagentes.com/skills/wshobson/agents/block-no-verify-hook.md Repositorio: https://github.com/wshobson/agents Autor: wshobson Licencia: MIT Actualizado: hace 5 meses Coste de contexto: 50 tok instalada, 1.6k tok al activarse, 1.6k tok con todos los archivos del bundle Bundle: 1 archivo, 6 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add wshobson/agents --skill block-no-verify-hook --agent claude-code # Cursor npx -y skills add wshobson/agents --skill block-no-verify-hook --agent cursor # Codex npx -y skills add wshobson/agents --skill block-no-verify-hook --agent codex # Gemini CLI npx -y skills add wshobson/agents --skill block-no-verify-hook --agent gemini # Windsurf npx -y skills add wshobson/agents --skill block-no-verify-hook --agent windsurf # Cline npx -y skills add wshobson/agents --skill block-no-verify-hook --agent cline ``` ## Qué hace - Añade un hook PreToolUse en .claude/settings.json que inspecciona cada llamada Bash antes de ejecutarse - Bloquea comandos git que contengan --no-verify o --no-gpg-sign devolviendo exit code 2 - Permite extender el patrón grep para bloquear flags adicionales como --force - Deja pasar sin bloqueo cualquier comando que no contenga flags de bypass ## Cuándo usarla - Configurar proyectos Claude Code que deben forzar quality gates en los commits - Evitar que agentes de IA salten pre-commit hooks, firma GPG u otros mecanismos de seguridad de git ## Qué la activa - "Configura un hook que bloquee git commit --no-verify en este proyecto" - "Impide que el agente use --no-gpg-sign al hacer commits" - "Añade una regla PreToolUse para bloquear flags de bypass en git" ## Antes de instalar - Requiere Claude Code con soporte de hooks PreToolUse y acceso para editar .claude/settings.json (local o global). - Necesita en el PATH: git - Variables de entorno: TOOL_INPUT - reads environment config ## Archivos - SKILL.md — 6 KB ## SKILL.md Reproducido tal cual desde wshobson/agents bajo MIT. Esta sección es el documento original y está en inglés. # Block No-Verify Hook PreToolUse hook configuration that intercepts and blocks bypass-flag usage before execution, ensuring AI agents cannot skip pre-commit hooks, GPG signing, or other git safety mechanisms. ## Overview AI coding agents (Claude Code, Codex, etc.) can run shell commands with flags like `--no-verify` that bypass pre-commit hooks. This defeats the purpose of linting, formatting, testing, and security checks configured in pre-commit hooks. The block-no-verify hook adds a PreToolUse guard that rejects any tool call containing bypass flags before execution. ## Problem When AI agents commit code, they may use bypass flags to avoid hook failures: ```bash # These commands skip pre-commit hooks entirely git commit --no-verify -m "quick fix" git push --no-verify git commit --no-gpg-sign -m "unsigned commit" git merge --no-verify feature-branch ``` This allows: - Unformatted code to enter the repository - Linting errors to bypass checks - Security scanning to be skipped - Unsigned commits to bypass signing policies - Test suites to be circumvented ## Solution Add a `PreToolUse` hook to `.claude/settings.json` that inspects every Bash tool call and blocks commands containing bypass flags. ### Configuration Add the following to your project's `.claude/settings.json`: ```json { "hooks": { "PreToolUse": [ { "matcher": "Bash", "hooks": [ { "type": "command", "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi" } ] } ] } } ``` ### How It Works 1. **Matcher**: The hook targets only `Bash` tool calls, so it does not interfere with other tools (Read, Edit, Grep, etc.). 2. **Inspection**: Claude Code sends the tool call to the hook as JSON on stdin and sets no `$TOOL_INPUT` variable. The hook searches the `command` value in that JSON with `grep -E`, so it needs no `jq` or `node`, and text in other fields, such as `cwd` or the tool call's description, can't trigger it. It blocks `--no-verify`, `--no-gpg-sign`, and any shorter prefix of them that git accepts, e.g., `--no-veri`. It also blocks a short option group with `n` that follows `commit` in the same command, e.g., `-n` or `-nm`, because `-n` is the short form of `--no-verify`. The hook doesn't look for the word `git`, so it also catches `if git ...`, `sudo git ...`, and `g=git; $g commit --no-verify`. A false match, such as a commit message that mentions a flag, blocks the call, which is the safe way to fail. 3. **Blocking**: If a bypass flag is found in a git command, the hook exits with code 2 and prints an error message. Exit code 2 signals Claude Code to reject the tool call entirely. 4. **Pass-through**: If no bypass flag is found, the hook exits with code 0 and the command executes normally. 5. **Limits**: The hook checks text, so it stops an agent that reaches for a bypass flag out of habit. It doesn't stop an agent that sets out to evade it, e.g., by building the flag from pieces or by running `git -c core.hooksPath=/dev/null commit`. ### Exit Codes | Code | Meaning | |------|---------| | 0 | Allow the tool call to proceed | | 1 | Error (tool call still proceeds, warning shown) | | 2 | Block the tool call entirely | ## Blocked Flags | Flag | Purpose | Why Blocked | |------|---------|-------------| | `--no-verify` | Skips pre-commit and commit-msg hooks | Bypasses linting, formatting, testing, security checks | | `--no-gpg-sign` | Skips GPG commit signing | Bypasses commit signing policy | ## Installation ### Per-Project Setup Create or update `.claude/settings.json` in your project root: ```bash mkdir -p .claude cat > .claude/settings.json << 'EOF' { "hooks": { "PreToolUse": [ { "matcher": "Bash", "hooks": [ { "type": "command", "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi" } ] } ] } } EOF ``` ### Global Setup To enforce across all projects, add to `~/.claude/settings.json`: ```bash mkdir -p ~/.claude cat > ~/.claude/settings.json << 'EOF' { "hooks": { "PreToolUse": [ { "matcher": "Bash", "hooks": [ { "type": "command", "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi" } ] } ] } } EOF ``` ## Verification Test that the hook blocks bypass flags: ```bash # This should be blocked by the hook: git commit --no-verify -m "test" # This should succeed normally: git commit -m "test" ``` ## Extending the Hook ### Adding More Blocked Flags To block additional flags (e.g., `--force`), extend the grep pattern: ```json { "hooks": { "PreToolUse": [ { "matcher": "Bash", "hooks": [ { "type": "command", "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n|git([[:space:]]|\\\\t)([^\"\\\\]|\\\\.)*--force)'; then echo 'BLOCKED: Bypass flags are not allowed.' >&2; exit 2; fi" } ] } ] } } ``` ### Combining with Other Hooks The block-no-verify hook works alongside other PreToolUse hooks: ```json { "hooks": { "PreToolUse": [ { "matcher": "Bash", "hooks": [ { "type": "command", "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: Bypass flags not allowed.' >&2; exit 2; fi" } ] }, { "matcher": "Bash", "hooks": [ { "type": "command", "command": "if grep -qE 'rm[[:space:]]+-rf[[:space:]]+/'; then echo 'BLOCKED: Dangerous rm command.' >&2; exit 2; fi" } ] } ] } } ``` ## Best Practices 1. **Commit the settings file** -- Add `.claude/settings.json` to version control so all team members benefit from the hook. 2. **Document in onboarding** -- Mention the hook in your project's contributing guide so developers understand why bypass flags are blocked. 3. **Pair with pre-commit hooks** -- The block-no-verify hook ensures pre-commit hooks run; make sure you have meaningful pre-commit hooks configured. 4. **Test after setup** -- Verify the hook works by intentionally triggering it in a test commit. ## Dónde encaja - Categoría: [DevOps e infraestructura](https://skillsagentes.com/categorias/devops-infraestructura.md) — Despliegues, contenedores, IaC y flujos de gestión de incidentes. - Creador: [wshobson](https://skillsagentes.com/creators/wshobson.md) — 183 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) ## Otras skills del mismo repositorio - [Hermes Tweet](https://skillsagentes.com/skills/wshobson/agents/hermes-tweet.md): Instala y opera Hermes Tweet, un plugin de Hermes Agent para investigar X/Twitter, leer timelines, analizar tweets y ejecutar operaciones privadas o de cambio de estado con aprobación previa. - [Grounded Vault](https://skillsagentes.com/skills/wshobson/agents/grounded-vault.md): Úsalo para mantener un almacén Markdown de conocimiento donde cada afirmación compilada se rastrea hasta una fuente inmutable y el drift se detecta con git diff sin gastar tokens. - [Postgresql Table Design](https://skillsagentes.com/skills/wshobson/agents/postgresql-table-design.md): Úsalo al diseñar o revisar un esquema específico de PostgreSQL: buenas prácticas, tipos de datos, indexación, restricciones, patrones de rendimiento y funciones avanzadas. - [Superself](https://skillsagentes.com/skills/wshobson/agents/superself.md): Úsalo cuando un proyecto guarda su estado en Superself: lee `self context` al iniciar sesión, vincula el trabajo a una work unit, reporta con evidencia y registra decisiones confirmadas. - [Prompt Engineering Patterns](https://skillsagentes.com/skills/wshobson/agents/prompt-engineering-patterns.md): Úsalo cuando pidan optimizar un prompt, mejorar su rendimiento, diseñar una plantilla, aplicar chain-of-thought, few-shot prompting o técnicas avanzadas de prompt engineering para producción. ## Skills relacionadas - [Airflow Dag Patterns](https://skillsagentes.com/skills/wshobson/agents/airflow-dag-patterns.md): Construye DAGs de Apache Airflow listos para producción con buenas prácticas para operadores, sensores, testing y despliegue. - [Bash Defensive Patterns](https://skillsagentes.com/skills/wshobson/agents/bash-defensive-patterns.md): Domina técnicas de programación defensiva en Bash para scripts de nivel producción: úsalo al escribir shell scripts robustos, pipelines CI/CD o utilidades de sistema que requieran tolerancia a fallos. - [Bazel Build Optimization](https://skillsagentes.com/skills/wshobson/agents/bazel-build-optimization.md): Optimiza builds de Bazel en monorepos a gran escala. Úsalo al configurar Bazel, implementar ejecución remota u optimizar el rendimiento de builds en codebases empresariales. - [Cost Optimization](https://skillsagentes.com/skills/wshobson/agents/cost-optimization.md): Optimiza costos en la nube en AWS, Azure, GCP y OCI mediante rightsizing, tagging, instancias reservadas y análisis de gasto; para reducir gastos o implementar gobernanza de costos. - [Deployment Pipeline Design](https://skillsagentes.com/skills/wshobson/agents/deployment-pipeline-design.md): Diseña pipelines CI/CD multi-etapa con gates de aprobación, verificaciones de seguridad y orquestación de despliegues, incluyendo canary, rollback y depuración de gates fallidos. --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)