Agent skill

Ad Hooks

by CorridorTech in CorridorTech/PoseCap

Scaffold deterministic quality gates per WORKFLOW.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration).

Apache-2.0Auto-check: notesTesting & QA

Install Ad Hooks

skills CLI
$ npx skills add CorridorTech/PoseCap --skill ad-hooks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CorridorTech/PoseCap ad-hooks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CorridorTech/PoseCap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/ad-hooks .claude/skills/ad-hooks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ad-hooks
GitHub stars
224
Token cost
~2.4k tokens
SKILL.md length
1,178 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scaffold deterministic quality gates per WORKFLOW.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration).

  • Works in 7 steps: Confirm the gates the user wants → Detect the runner → Recommend the per-stack commands → …
  • The user wants to wire hooks
  • SKILL.md covers Step 0 — Confirm the gates the…, Step 1 — Detect the runner, Step 2 — Recommend the… and Step 3 — Scaffold the runner…, plus 5 more sections
  • Calls npm, gitleaks and cargo

What it does

Ad Hooks is an agent skill from CorridorTech/PoseCap. Scaffold deterministic quality gates per WORKFLOW.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration). Detects the project's stack and recommends a hook runner (Husky / lefthook / pre-commit / native), scaffolds the runner config, and updates AGENTS.md Quality Gates. Use when the user wants to wire hooks, configure pre-commit / pre-push, set up quality gates, prevent --no-verify bypass, or close the WORKFLOW §11 advisory-vs-deterministic gap. Opt-in skill; not auto-installed in…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Quality gates, Project scaffolding and Agent instruction files. It works with npm. The licence is Apache-2.0.

When your agent uses it

  • The user wants to wire hooks
  • Configure pre-commit / pre-push
  • Set up quality gates
  • Prevent --no-verify bypass

Example prompts

  • “/ad-hooks”

Requirements

  • Python 3
  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, Glob, Bash

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Confirm the gates the user wants
  2. Detect the runner
  3. Recommend the per-stack commands
  4. Scaffold the runner config
  5. Update AGENTS.md Quality Gates section
  6. Mirror CI locally (drift check)
  7. Tell the user what to run

What it can do on your machine

Read from SKILL.md and the folder at commit 626701b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • gitleaks
    • cargo
    • npx
    • ruff
    • go
    • black
    • pytest
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ad Hooks loads about 2.4k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 1,178 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CorridorTech/PoseCap at commit 626701b, republished under its Apache-2.0 licence (© CorridorTech). 1,178 words, ~2,432 tokens.

Download SKILL.mdSave it as .claude/skills/ad-hooks/SKILL.md (or your agent's skills folder).
name
ad-hooks
description
Scaffold deterministic quality gates per WORKFLOW.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration). Detects the project's stack and recommends a hook runner (Husky / lefthook / pre-commit / native), scaffolds the runner config, and updates AGENTS.md Quality Gates. Use when the user wants to wire hooks, configure pre-commit / pre-push, set up quality gates, prevent --no-verify bypass, or close the WORKFLOW §11 advisory-vs-deterministic gap. Opt-in skill; not auto-installed in the universal set.
allowed-tools
Read, Write, Glob, Bash
summary
Scaffold deterministic quality gates per WORKFLOW §11 — pre-commit + pre-push, runner detected from stack signals.

/ad-hooks

Scaffolds the deterministic gates WORKFLOW.md §11 names. The skill writes config files for a hook runner and updates AGENTS.md Quality Gates; it does not execute install scripts. The user is responsible for the runner's one-time bootstrap (e.g., npx husky init, lefthook install, pre-commit install) — the skill says exactly which command to run.

Step 0 — Confirm the gates the user wants

WORKFLOW.md §11 names two tiers:

  • Pre-commit (fast): lint, format, secret-scan. Runs on every commit. Slow pre-commits push devs to --no-verify; keep it under ~5s.
  • Pre-push (thorough): build, unit tests, integration tests. Runs on every push. Acceptable to be slow; the cost is paid less often than commit.

Confirm both tiers are in scope for this project. If the user wants only one tier, scaffold only that tier — do not add gates the user did not ask for.

Visual / E2E for UI projects (Cypress, Playwright, Claude in Chrome) are mentioned by §11 but live in CI, not pre-push. Out of scope for this skill.

Step 1 — Detect the runner

Read the repo signals in this order:

  1. Existing runner. .husky/ → Husky present. lefthook.yml or .lefthook.yml → lefthook present. .pre-commit-config.yaml → pre-commit present. .git/hooks/ with non-sample scripts → native hooks present.
  2. Stack signals (if no runner present). package.json → Node-rooted; recommend Husky (most common in Node ecosystem) or lefthook (cross-language fit). pyproject.toml → Python-rooted; recommend pre-commit. go.mod → Go-rooted; recommend lefthook. Cargo.toml → Rust-rooted; recommend lefthook. Multiple stacks → recommend lefthook (cross-language by default).
  3. No signals. Recommend native .git/hooks/ only as fallback. Warn the user that native hooks are not portable across clones (every contributor has to run a setup script).

If multiple runners are present, surface the conflict and ask the user before scaffolding. Never silently pick.

Step 2 — Recommend the per-stack commands

For the chosen runner, propose the per-tier command set:

  • Node (package.json present): lint = npm run lint (fall back to npx eslint . if no lint script); format check = npm run format:check (fall back to npx prettier --check .); secret-scan = gitleaks detect --no-banner (cite the install instruction); build = npm run build (skip if no script); test = npm test.
  • Python (pyproject.toml present): lint = ruff check .; format check = ruff format --check . or black --check .; secret-scan = gitleaks detect --no-banner; test = pytest -q.
  • Go (go.mod present): lint = golangci-lint run; format check = gofmt -d .; secret-scan = gitleaks detect --no-banner; build = go build ./...; test = go test ./....
  • Rust (Cargo.toml present): lint = cargo clippy -- -D warnings; format check = cargo fmt --check; secret-scan = gitleaks detect --no-banner; build = cargo build; test = cargo test.
  • Mixed / other: ask the user for the per-tier command list. Do not invent.

Offer to swap any default. Confirm before writing.

Step 3 — Scaffold the runner config

Write the runner-specific config file. Below are the canonical shapes; adapt to the user's tier choices.

Husky — .husky/pre-commit and .husky/pre-push (shell scripts). Plus a prepare script in package.json ("prepare": "husky"). User runs npm install once to bootstrap.

lefthook — lefthook.yml at the repo root with pre-commit and pre-push commands keyed by stage. User runs lefthook install once.

pre-commit (pre-commit.com) — .pre-commit-config.yaml referencing the canonical hooks for the stack (e.g., pre-commit/mirrors-eslint, psf/black, astral-sh/ruff-pre-commit). User runs pre-commit install and pre-commit install --hook-type pre-push.

Native .git/hooks/ — .git/hooks/pre-commit and .git/hooks/pre-push plus a setup-hooks.sh script the user runs after every clone (since .git/ is not committed). Document the setup-script invocation in AGENTS.md.

Step 4 — Update AGENTS.md Quality Gates section

Append (or refresh, if a Quality Gates section already exists) the following content:

## Quality Gates

Deterministic enforcement — agent cannot skip.

- Pre-commit hook (fast): <stack-specific lint, format, secret-scan commands>
- Pre-push hook (thorough): <stack-specific build, unit, integration commands>
- Hook runner: <Husky | lefthook | pre-commit | native>; config at <path>
- Bootstrap: <one-line setup command>
- CI blocks on: <list — skip if CI not yet wired>
- Never bypass: no `--no-verify`, no skipped hooks, no deleted failing tests. WORKFLOW §11 is binding.

Honor the existing managed-skills / managed-quality-gates markers if ad-bootstrap already wrote a Quality Gates section. The skill refreshes the section in place; user content outside the markers is preserved.

Show full SKILL.md (592 more words)Show less

Step 5 — Mirror CI locally (drift check)

Local gates must mirror what CI runs — same commands, same matrix. WORKFLOW §11: "CI failure is a local gate gap." Read the CI config and compare.

  1. Detect the CI surface. In order: .github/workflows/*.yml (GitHub Actions), .gitlab-ci.yml (GitLab CI), .circleci/config.yml (Circle), azure-pipelines.yml (Azure), .buildkite/pipeline.yml (Buildkite). If none, note the gap and stop this step — the mirror check has no target.
  2. Extract CI commands. Parse the run: / script: steps from the CI config. Focus on test / lint / typecheck / build invocations; ignore checkout, setup, cache, publish steps.
  3. Extract CI matrix. Language versions (Node 20 / 22, Python 3.11 / 3.12, Go 1.22, etc.), OS runners (ubuntu-latest, macos-latest), feature flags. These become the pre-push matrix requirement when they change the failure surface.
  4. Diff against the pre-push tier. For each CI command not covered by pre-push, warn: CI runs <cmd> — pre-push does not. Add to pre-push or CI will catch what local won't. For each matrix dimension CI covers that pre-push does not (e.g., pre-push runs Node 22 only, CI runs 20 + 22), warn: CI matrix <dim>=<values>, pre-push runs <value>. Failures under <missing-value> will only surface in CI.
  5. Offer to close the gap. If gaps exist, propose specific edits to the runner config (extra commands, matrix loop via Node --version iteration, feature-flag pass). Ask the user before writing — matrix mirroring can be expensive; the user picks.

The mirror check runs after Step 4 wrote the config, so gap edits layer on top of a working scaffold. If the CI surface is absent, note: "No CI config detected — pre-push is the only gate. Add CI so contributors cannot bypass via --no-verify and re-run this skill to re-mirror."

Step 6 — Tell the user what to run

After writing the config, output exactly the bootstrap command the user must run (e.g., npm install for Husky, lefthook install for lefthook, pre-commit install for pre-commit). The skill does not execute the bootstrap — that is the user's call.

If the user is wiring CI alongside hooks (GitHub Actions / GitLab CI / Circle), point them at the existing .github/workflows/, .gitlab-ci.yml, or .circleci/ directory. CI scaffolding is a separate skill's responsibility (deferred — not this one).

Output contract

Filesystem changes:

  • The runner's config file (e.g., .husky/pre-commit, lefthook.yml, .pre-commit-config.yaml).
  • An updated AGENTS.md Quality Gates section (or appended if absent), naming the runner, the gates wired, the bootstrap command, and the no-bypass policy.
  • For the native-hooks fallback only: a setup-hooks.sh script the user runs after every clone.

The skill does not execute the runner's install command. The skill does not write CI config. The skill does not configure agent-side hooks (.claude/settings.json Stop / PreToolUse / PostToolUse) — that is a different surface; future ADR may cover it.

A narrative document, so the documentation discipline rules apply at write time:

  • No emoji anywhere in the scaffolded config or in the AGENTS.md update.
  • No version stamps or DRAFT markers.
  • The Quality Gates section opens with the operational rule (gates are deterministic) before listing the gates themselves.
  • One scope: Quality Gates. Do not duplicate ARCHITECTURE.md or ADR rationale here.
  • No commented-out scripts. No orphan TODO / FIXME — every deferred command references a tracked task or GitHub Issue.

Next

  • Run the runner's bootstrap command (cited in Step 6 — e.g., npm install, lefthook install, pre-commit install).
  • Verify a deliberately-failing edit (e.g., a known lint violation) gets blocked at commit. The gate is real only when it actually fires.
  • Add a redundant CI gate (.github/workflows/, GitLab CI, or equivalent) so contributors cannot bypass via --no-verify. WORKFLOW §11 binding.
  • /ad-drift periodically to confirm hooks stay wired as the project evolves.

© CorridorTech, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/ad-hooks of CorridorTech/PoseCap.

Open the folder on GitHubat commit 626701b

Compare with similar skills

Ad Hooks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ad Hooks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ad Hooks this skillCorridorTech/PoseCap224—~2.4kAutomated safety check: NotesApache-2.0
Quality Gatesandymai/brepjs114—~3.2kAutomated safety check: PassApache-2.0
Django Verification Loopaffaan-m/ECC275k7 repos~2.9kAutomated safety check: PassMIT
Npx CLIjwynia/agent-skills166—~2.4kAutomated safety check: PassNone
Create Saleor Packagesaleor/apps162—~608Automated safety check: PassCustom licence
Deno Runtime and Package Managerdenoland/skills100—~2.7kAutomated safety check: PassMIT

Similar skills

  • Quality Gates

    andymai/brepjs

    This skill should be used when a local brepjs quality gate or npm run validate step fails and the specific rule's fix or escape hatch is needed — ESLint errors like "no-explicit-any" or "Direct .oc…

    114 GitHub stars~3.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review.

    275k GitHub starsUsed in 7 repos~2.9k tokens
    DevelopmentAuto-check passed
  • Npx CLI

    jwynia/agent-skills

    Build and publish npx-executable CLI tools using Bun as the primary toolchain with npm-compatible output.

    166 GitHub stars~2.4k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Scaffold a new shared package in the saleor-apps monorepo under ./packages/.

    162 GitHub stars~608 tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Guides writing, running and configuring Deno 2.9+ projects: installing npm and JSR dependencies, permissions, config file precedence and the built-in fmt, lint, test and compile toolchain.

    100 GitHub stars~2.7k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Keep the repository's linted Markdown passing npm run lint:markdown.

    214 GitHub stars~832 tokensUpdated 8 days ago
    DevelopmentAuto-check passed

More from CorridorTech/PoseCap

All 15 skills in this repo
  • Ad Adr

    CorridorTech/PoseCap

    Draft a new ADR (Architecture Decision Record) at doc/adr/NNNN-<short-title.md, using Michael Nygard's Context/Decision/Consequences/Alternatives pattern.

    224 GitHub stars~1k tokensUpdated today
    Auto-check: notes
  • Ad Architecture

    CorridorTech/PoseCap

    Generate ARCHITECTURE.md at the repo root by scanning the code first, pre-filling layers/patterns/observability/deployment from observed signals, then asking only the genuine gaps.

    224 GitHub stars~1.5k tokensUpdated today
    Auto-check: notes
  • Ad Archive

    CorridorTech/PoseCap

    Hard-delete completed plan files (tasks Status:done, specs Status:shipped, PRDs Status:superseded, ADRs Status:superseded or deprecated) via git rm, leaving git history as the only ledger.

    224 GitHub stars~1.9k tokensUpdated today
    Auto-check: notes
  • Ad Drift

    CorridorTech/PoseCap

    Read-only drift audit — compare AGENTS.md, ARCHITECTURE.md, ADR statuses, feature specs in doc/specs/, and documentation discipline against what the code actually does.

    224 GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • Ad Next

    CorridorTech/PoseCap

    Survey the project's state across the six-layer artifact stack and recommend prioritized next actions, modeled on flutter doctor.

    224 GitHub stars~3.3k tokensUpdated today
    Auto-check: notes
  • Ad Bootstrap

    CorridorTech/PoseCap

    Generate AGENTS.md at the repo root by scanning the codebase first, pre-filling placeholders from observed signals, and asking only the genuine gaps.

    224 GitHub stars~2.4k tokensUpdated today
    Auto-check: warnings

Works with

Categories

Questions about Ad Hooks

What does Ad Hooks do?

Scaffold deterministic quality gates per WORKFLOW.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration). Ad Hooks is an agent skill from CorridorTech/PoseCap.md §11 — pre-commit (lint, format, secret-scan), pre-push (build, unit, integration).

When should I use Ad Hooks?

Ad Hooks fits situations like: the user wants to wire hooks; configure pre-commit / pre-push; set up quality gates; prevent --no-verify bypass.

How do I install Ad Hooks in Claude Code?

Run `npx skills add CorridorTech/PoseCap --skill ad-hooks -a claude-code`. Or copy the skill folder (.claude/skills/ad-hooks in CorridorTech/PoseCap) into .claude/skills/ad-hooks in your project. Claude Code loads it when a task matches its description.

How do I install Ad Hooks in Codex?

Run `npx skills add CorridorTech/PoseCap --skill ad-hooks -a codex`. Or copy the skill folder (.claude/skills/ad-hooks in CorridorTech/PoseCap) into .agents/skills/ad-hooks in your project. Codex loads it when a task matches its description.

Can I use Ad Hooks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CorridorTech/PoseCap --skill ad-hooks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ad-hooks, .gemini/skills/ad-hooks, .github/skills/ad-hooks and .opencode/skills/ad-hooks in your project.

What does Ad Hooks need to run?

Going by SKILL.md and its folder, Ad Hooks needs the command-line tools its instructions call (npm, gitleaks, cargo, npx, ruff and go). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Write, Glob, Bash.

Does Ad Hooks access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ad Hooks safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ad Hooks use?

Ad Hooks is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ad Hooks use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ad Hooks?

Skills that share tags, products or a category with Ad Hooks: Quality Gates (andymai/brepjs, 114 stars), Django Verification Loop (affaan-m/ECC, 275k stars), Npx CLI (jwynia/agent-skills, 166 stars) and Create Saleor Package (saleor/apps, 162 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ad Hooks?

CorridorTech (a GitHub organization) maintains it in CorridorTech/PoseCap, which has 224 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: CorridorTech/PoseCap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.