Recover from missing DCO sign-off on commits. An agent skill from linuxfoundation/insights.

MITAuto-check: notesDevelopment

Install Dco

skills CLI
$ npx skills add linuxfoundation/insights --skill dco -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install linuxfoundation/insights dco --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/linuxfoundation/insights.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dco .claude/skills/dco && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dco
GitHub stars
280
Token cost
~696 tokens
SKILL.md length
253 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Recover from missing DCO sign-off on commits. An agent skill from linuxfoundation/insights.

  • A PR fails the DCO check
  • SKILL.md covers Case 1: Last commit only, Case 2: Older commit on the…, Case 3: Cherry-pick / merge… and Verifying the whole branch, plus 1 more section
  • Calls git
  • A commit needs a Signed-off-by trailer added retroactively

What it does

Dco is an agent skill from linuxfoundation/insights. Recover from missing DCO sign-off on commits. Handles the single-commit amend, older-commit recovery via interactive rebase or cherry-pick, and explains the Probot DCO check that blocks PRs without sign-off. Use when a PR fails the DCO check, when a commit needs a Signed-off-by trailer added retroactively, or when sign-off was forgotten during rebase / cherry-pick / amend.

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: Insights into the world's most critical open source software. The licence is MIT.

When your agent uses it

  • A PR fails the DCO check
  • A commit needs a Signed-off-by trailer added retroactively
  • Sign-off was forgotten during rebase / cherry-pick / amend

Example prompts

  • “/dco”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Edit

What it can do on your machine

Read from SKILL.md and the folder at commit 3df53b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dco loads about 696 tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 253 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~696

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Edit

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from linuxfoundation/insights at commit 3df53b5, republished under its MIT licence (© linuxfoundation). 253 words, ~696 tokens.

Download SKILL.mdSave it as .claude/skills/dco/SKILL.md (or your agent's skills folder).
name
dco
description
Recover from missing DCO sign-off on commits. Handles the single-commit amend, older-commit recovery via interactive rebase or cherry-pick, and explains the Probot DCO check that blocks PRs without sign-off. Use when a PR fails the DCO check, when a commit needs a Signed-off-by trailer added retroactively, or when sign-off was forgotten during rebase / cherry-pick / amend.
allowed-tools
Bash, Read, Edit

DCO Sign-off Recovery

All commits in this repo must carry a Signed-off-by: trailer (Developer Certificate of Origin). The Probot DCO check on PRs blocks merge until every commit is signed.

The standard way to add it is with --signoff at commit time. This skill handles the cases where that was missed.

Case 1: Last commit only

bash
git commit --amend --signoff -S --no-edit
git push --force-with-lease

--force-with-lease is preferred over plain --force — it refuses if someone else has pushed to the branch since you last fetched.

Case 2: Older commit on the same branch

Find the commit hash of the oldest unsigned commit:

bash
git log --pretty='%h %s %(trailers:key=Signed-off-by,valueonly)' origin/main..HEAD
# Any line with an empty trailing field is unsigned

Then interactively rebase from one commit before that:

bash
git rebase -i <parent-of-unsigned-commit>
# In the editor, change `pick` to `edit` for each unsigned commit
# Save and exit; the rebase stops at each `edit` line so you can amend

For each commit in the rebase, replace it with a signed version:

bash
git commit --amend --signoff -S --no-edit
git rebase --continue

When done, force-push:

bash
git push --force-with-lease

Case 3: Cherry-pick / merge brought in unsigned commits

Cherry-pick with sign-off baked in:

bash
git cherry-pick --signoff <sha>

If you already cherry-picked without it, fall back to Case 1 or Case 2 above.

Verifying the whole branch

Before pushing, verify every commit ahead of origin/main has both DCO and GPG:

bash
git log --format='%G? %(trailers:key=Signed-off-by,valueonly,separator=%x20) %h %s' origin/main..HEAD

Each line must start with G or U (good GPG signature) AND carry a non-empty Signed-off-by value before the SHA. Codes N / B / E need investigation. See .claude/rules/commit-workflow.md for the canonical signing policy.

What the Probot DCO check looks for

The check passes when every commit message includes a Signed-off-by: Name <email> trailer matching the commit author's email. The --signoff (or -s) flag adds this trailer automatically using your user.name and user.email git config.

A failing DCO check on a PR will show a "Details" link explaining which commits are missing sign-off.

© linuxfoundation, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dco of linuxfoundation/insights.

Open the folder on GitHubat commit 3df53b5

Compare with similar skills

Dco next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dco compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dco this skilllinuxfoundation/insights280—~696Automated safety check: NotesMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k24 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 24 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed

More from linuxfoundation/insights

All 9 skills in this repo
  • Event Tracking

    linuxfoundation/insights

    Add event tracking calls to Vue/Nuxt components in the Insights app using the useTrackEvent composable.

    280 GitHub stars~1.9k tokensUpdated 6 days ago
    Auto-check passed
  • Review PR

    linuxfoundation/insights

    Review a pull request against Insights architecture standards — fetches PR diff, verifies previous comments are addressed, validates PR metadata (title, branch, JIRA, size), runs a code-standards…

    280 GitHub stars~2.7k tokensUpdated 6 days ago
    Auto-check: notes
  • Adr

    linuxfoundation/insights

    Record an architecture decision as an ADR in api/docs/arch/adr/.

    280 GitHub stars~1k tokensUpdated 6 days ago
    Auto-check passed
  • Fix Vulns

    linuxfoundation/insights

    Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).

    280 GitHub stars~3.8k tokensUpdated 6 days ago
    Auto-check: notes
  • Setup

    linuxfoundation/insights

    Full development environment setup from scratch — prerequisites, dependencies, .env file, optional local PostgreSQL database (for auth/collections/chat work), and dev server.

    280 GitHub stars~1.9k tokensUpdated 6 days ago
    Auto-check: notes
  • Setup Docs

    linuxfoundation/insights

    Run the docs site, blog, or Storybook locally. An agent skill from linuxfoundation/insights.

    280 GitHub stars~383 tokensUpdated 6 days ago
    Auto-check: notes

Categories

Questions about Dco

What does Dco do?

Recover from missing DCO sign-off on commits. An agent skill from linuxfoundation/insights. Dco is an agent skill from linuxfoundation/insights. Recover from missing DCO sign-off on commits.

When should I use Dco?

Dco fits situations like: A PR fails the DCO check; A commit needs a Signed-off-by trailer added retroactively; sign-off was forgotten during rebase / cherry-pick / amend.

How do I install Dco in Claude Code?

Run `npx skills add linuxfoundation/insights --skill dco -a claude-code`. Or copy the skill folder (.claude/skills/dco in linuxfoundation/insights) into .claude/skills/dco in your project. Claude Code loads it when a task matches its description.

How do I install Dco in Codex?

Run `npx skills add linuxfoundation/insights --skill dco -a codex`. Or copy the skill folder (.claude/skills/dco in linuxfoundation/insights) into .agents/skills/dco in your project. Codex loads it when a task matches its description.

Can I use Dco in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add linuxfoundation/insights --skill dco -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dco, .gemini/skills/dco, .github/skills/dco and .opencode/skills/dco in your project.

What does Dco need to run?

Going by SKILL.md and its folder, Dco needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Bash, Read, Edit.

Does Dco access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dco safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dco use?

Dco is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dco use?

About 696 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dco?

Skills that share tags, products or a category with Dco: Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dco?

linuxfoundation (a GitHub organization) maintains it in linuxfoundation/insights, which has 280 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 1, 2026.

Source: linuxfoundation/insights on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.