Agent skill

Block No Verify Hook

by wshobson in wshobson/agents

Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags.

MITAuto-check: notesTesting & QA

Install Block No Verify Hook

skills CLI
$ npx skills add wshobson/agents --skill block-no-verify-hook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wshobson/agents block-no-verify-hook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/block-no-verify/skills/block-no-verify-hook .claude/skills/block-no-verify-hook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
block-no-verify-hook
GitHub stars
40k
Token cost
~1.9k tokens
SKILL.md length
601 words
Files
1
Skills in repo
142
Repo updated
First seen
Licence
MIT

At a glance

Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags.

  • Works in 5 steps: Matcher: The hook targets only Bash tool… → Inspection: Claude Code sends the tool… → Blocking: If a bypass flag is found in a… → …
  • Setting up Claude Code projects that enforce commit quality gates
  • SKILL.md covers Overview, Problem, Solution and Blocked Flags, plus 4 more sections
  • Calls git

What it does

Block No Verify Hook is an agent skill from wshobson/agents. Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags. Use when setting up Claude Code projects that enforce commit quality gates.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Quality gates. It works with Git. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.

When your agent uses it

  • Setting up Claude Code projects that enforce commit quality gates
  • Tasks that involve Quality gates

Example prompts

  • “/block-no-verify-hook”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Matcher: The hook targets only Bash tool calls, so it does not interfere with other tools (Read, Edit, Grep, etc.).
  2. Inspection: Claude Code sends the tool call to the hook as JSON on stdin and sets no $TOOL_INPUT variable. The hook searches the command…
  3. Blocking: If a bypass flag is found in a git command, the hook exits with code 2 and prints an error message. Exit code 2 signals Claude…
  4. Pass-through: If no bypass flag is found, the hook exits with code 0 and the command executes normally.
  5. Limits: The hook checks text, so it stops an agent that reaches for a bypass flag out of habit. It doesn't stop an agent that sets out to…

What it can do on your machine

Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Block No Verify Hook loads about 1.9k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 601 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:62
    `git`, so it also catches `if git ...`, `sudo git ...`, and `g=git; $g commit --no-verify`. A false match, such as a com

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 601 words, ~1,877 tokens.

Download SKILL.mdSave it as .claude/skills/block-no-verify-hook/SKILL.md (or your agent's skills folder).
name
block-no-verify-hook
description
Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags. Use when setting up Claude Code projects that enforce commit quality gates.

Block No-Verify Hook

PreToolUse hook configuration that intercepts and blocks bypass-flag usage before execution, ensuring AI agents cannot skip pre-commit hooks, GPG signing, or other git safety mechanisms.

Overview

AI coding agents (Claude Code, Codex, etc.) can run shell commands with flags like --no-verify that bypass pre-commit hooks. This defeats the purpose of linting, formatting, testing, and security checks configured in pre-commit hooks. The block-no-verify hook adds a PreToolUse guard that rejects any tool call containing bypass flags before execution.

Problem

When AI agents commit code, they may use bypass flags to avoid hook failures:

bash
# These commands skip pre-commit hooks entirely
git commit --no-verify -m "quick fix"
git push --no-verify
git commit --no-gpg-sign -m "unsigned commit"
git merge --no-verify feature-branch

This allows:

  • Unformatted code to enter the repository
  • Linting errors to bypass checks
  • Security scanning to be skipped
  • Unsigned commits to bypass signing policies
  • Test suites to be circumvented

Solution

Add a PreToolUse hook to .claude/settings.json that inspects every Bash tool call and blocks commands containing bypass flags.

Configuration

Add the following to your project's .claude/settings.json:

json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi"
          }
        ]
      }
    ]
  }
}
How It Works
  1. Matcher: The hook targets only Bash tool calls, so it does not interfere with other tools (Read, Edit, Grep, etc.).
  2. Inspection: Claude Code sends the tool call to the hook as JSON on stdin and sets no $TOOL_INPUT variable. The hook searches the command value in that JSON with grep -E, so it needs no jq or node, and text in other fields, such as cwd or the tool call's description, can't trigger it. It blocks --no-verify, --no-gpg-sign, and any shorter prefix of them that git accepts, e.g., --no-veri. It also blocks a short option group with n that follows commit in the same command, e.g., -n or -nm, because -n is the short form of --no-verify. The hook doesn't look for the word git, so it also catches if git ..., sudo git ..., and g=git; $g commit --no-verify. A false match, such as a commit message that mentions a flag, blocks the call, which is the safe way to fail.
  3. Blocking: If a bypass flag is found in a git command, the hook exits with code 2 and prints an error message. Exit code 2 signals Claude Code to reject the tool call entirely.
  4. Pass-through: If no bypass flag is found, the hook exits with code 0 and the command executes normally.
  5. Limits: The hook checks text, so it stops an agent that reaches for a bypass flag out of habit. It doesn't stop an agent that sets out to evade it, e.g., by building the flag from pieces or by running git -c core.hooksPath=/dev/null commit.
Show full SKILL.md (186 more words)Show less
Exit Codes
CodeMeaning
0Allow the tool call to proceed
1Error (tool call still proceeds, warning shown)
2Block the tool call entirely

Blocked Flags

FlagPurposeWhy Blocked
--no-verifySkips pre-commit and commit-msg hooksBypasses linting, formatting, testing, security checks
--no-gpg-signSkips GPG commit signingBypasses commit signing policy

Installation

Per-Project Setup

Create or update .claude/settings.json in your project root:

bash
mkdir -p .claude
cat > .claude/settings.json << 'EOF'
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi"
          }
        ]
      }
    ]
  }
}
EOF
Global Setup

To enforce across all projects, add to ~/.claude/settings.json:

bash
mkdir -p ~/.claude
cat > ~/.claude/settings.json << 'EOF'
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: --no-verify and --no-gpg-sign flags are not allowed. Run the commit without bypass flags so that pre-commit hooks execute properly.' >&2; exit 2; fi"
          }
        ]
      }
    ]
  }
}
EOF

Verification

Test that the hook blocks bypass flags:

bash
# This should be blocked by the hook:
git commit --no-verify -m "test"

# This should succeed normally:
git commit -m "test"

Extending the Hook

Adding More Blocked Flags

To block additional flags (e.g., --force), extend the grep pattern:

json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n|git([[:space:]]|\\\\t)([^\"\\\\]|\\\\.)*--force)'; then echo 'BLOCKED: Bypass flags are not allowed.' >&2; exit 2; fi"
          }
        ]
      }
    ]
  }
}
Combining with Other Hooks

The block-no-verify hook works alongside other PreToolUse hooks:

json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "if grep -qE '\"command\"[[:space:]]*:[[:space:]]*\"([^\"\\\\]|\\\\.)*(--no-(ver|g)|commit([^\"\\\\]|\\\\.)*([[:space:]]|\\\\[tn])-[a-zA-Z]*n)'; then echo 'BLOCKED: Bypass flags not allowed.' >&2; exit 2; fi"
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "if grep -qE 'rm[[:space:]]+-rf[[:space:]]+/'; then echo 'BLOCKED: Dangerous rm command.' >&2; exit 2; fi"
          }
        ]
      }
    ]
  }
}

Best Practices

  1. Commit the settings file -- Add .claude/settings.json to version control so all team members benefit from the hook.
  2. Document in onboarding -- Mention the hook in your project's contributing guide so developers understand why bypass flags are blocked.
  3. Pair with pre-commit hooks -- The block-no-verify hook ensures pre-commit hooks run; make sure you have meaningful pre-commit hooks configured.
  4. Test after setup -- Verify the hook works by intentionally triggering it in a test commit.

© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/block-no-verify/skills/block-no-verify-hook of wshobson/agents.

Open the folder on GitHubat commit 46891e7

Compare with similar skills

Block No Verify Hook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Block No Verify Hook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Block No Verify Hook this skillwshobson/agents40k—~1.9kAutomated safety check: NotesMIT
Land The Planedralgorhythm/claude-agentic-framework125—~1.2kAutomated safety check: PassNone
CI Triageandymai/brepjs115—~3.7kAutomated safety check: PassApache-2.0
Doc Updatesathola/claude-night-market341—~3.8kAutomated safety check: PassMIT
Requesting Code ReviewHezaoHezao/poirot2495 repos~1.6kAutomated safety check: PassMIT
Commithyperlane-xyz/hyperlane-explorer102—~726Automated safety check: NotesCustom licence

Similar skills

  • Land The Plane

    dralgorhythm/claude-agentic-framework

    Lands in-flight work: quality gates, atomic commit, rebase, push, verified remote sync, then handoff — a user-invoked finish-line workflow.

    125 GitHub stars~1.2k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • CI Triage

    andymai/brepjs

    This skill should be used when a brepjs GitHub Actions job is red or behaving oddly on github.com (a remote CI run, not a local pre-commit/pre-push hook) — "CI failed", "ci-pass is failing", "npm ci…

    115 GitHub stars~3.7k tokensUpdated today
    Testing & QAAuto-check passed
  • Doc Updates

    athola/claude-night-market

    Updates documentation after code changes with quality gates, slop detection, and accuracy checks.

    341 GitHub stars~3.8k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Requesting Code Review

    HezaoHezao/poirot

    Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

    249 GitHub starsUsed in 5 repos~1.6k tokens
    DevelopmentAuto-check passed
  • Commit

    hyperlane-xyz/hyperlane-explorer

    Commit changes following project quality gates and best practices.

    102 GitHub stars~726 tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Official

    Confirms that newly added tests actually fail without the fix, auto-detecting UI, device, unit or XAML tests and running the matching runner.

    23k GitHub stars~2.7k tokensUpdated today
    Testing & QAAuto-check passed

More from wshobson/agents

All 142 skills in this repo
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    Auto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Auto-check passed
  • Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.

    40k GitHub starsUsed in 13 repos~814 tokens
    Auto-check passed
  • Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.

    40k GitHub starsUsed in 12 repos~1.3k tokens
    Auto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    Auto-check passed
  • Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.

    40k GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about Block No Verify Hook

What does Block No Verify Hook do?

Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags. Block No Verify Hook is an agent skill from wshobson/agents. Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags.

When should I use Block No Verify Hook?

Block No Verify Hook fits situations like: setting up Claude Code projects that enforce commit quality gates; tasks that involve Quality gates.

How do I install Block No Verify Hook in Claude Code?

Run `npx skills add wshobson/agents --skill block-no-verify-hook -a claude-code`. Or copy the skill folder (plugins/block-no-verify/skills/block-no-verify-hook in wshobson/agents) into .claude/skills/block-no-verify-hook in your project. Claude Code loads it when a task matches its description.

How do I install Block No Verify Hook in Codex?

Run `npx skills add wshobson/agents --skill block-no-verify-hook -a codex`. Or copy the skill folder (plugins/block-no-verify/skills/block-no-verify-hook in wshobson/agents) into .agents/skills/block-no-verify-hook in your project. Codex loads it when a task matches its description.

Can I use Block No Verify Hook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill block-no-verify-hook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/block-no-verify-hook, .gemini/skills/block-no-verify-hook, .github/skills/block-no-verify-hook and .opencode/skills/block-no-verify-hook in your project.

What does Block No Verify Hook need to run?

Going by SKILL.md and its folder, Block No Verify Hook needs the command-line tools its instructions call (git).

Does Block No Verify Hook access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Block No Verify Hook safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Block No Verify Hook use?

Block No Verify Hook is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Block No Verify Hook use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Block No Verify Hook?

Skills that share tags, products or a category with Block No Verify Hook: Land The Plane (dralgorhythm/claude-agentic-framework, 125 stars), CI Triage (andymai/brepjs, 115 stars), Doc Updates (athola/claude-night-market, 341 stars) and Requesting Code Review (HezaoHezao/poirot, 249 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Block No Verify Hook?

wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,305 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.

Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.