CtrlK
BlogDocsLog inGet started
Tessl Logo

block-no-verify-hook

Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags. Use when setting up Claude Code projects that enforce commit quality gates.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/block-no-verify/skills/block-no-verify-hook/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with copy-paste-ready config and install commands, a clear configure-then-verify workflow, and good section organization. Its chief weakness is conciseness: the identical hook configuration is repeated verbatim across multiple sections where one canonical block plus path variations would suffice.

Suggestions

Show the full settings.json hook block once, then in Per-Project and Global Setup reference it with only the differing path (`.claude/settings.json` vs `~/.claude/settings.json`) instead of repeating the entire JSON verbatim.

Add a short feedback loop to the Verification section describing what to check if the hook does not block (e.g., confirm matcher is Bash, confirm settings file is the one Claude Code loads).

Consider moving the Extending/Combining-with-Other-Hooks variants into a separate reference file to reduce inline repetition and body length.

DimensionReasoningScore

Conciseness

Prose is direct and free of basic-concept padding, but the full settings.json hook block is repeated verbatim three times (Configuration, Per-Project Setup, Global Setup) and again in the extending sections, which is unnecessary padding that could be tightened to one block plus a path note, placing it at the 3-anchor rather than 4.

3 / 5

Actionability

It provides fully copy-paste-ready JSON config, executable heredoc install commands, a concrete grep pattern, and worked verification/extension examples that cover the common cases.

5 / 5

Workflow Clarity

The configure-then-verify sequence is clear with an explicit Verification section and a Best Practices test step, but the verification lacks a feedback loop for what to do if the block fails to trigger, so it stops at 4 rather than 5.

4 / 5

Progressive Disclosure

The single SKILL.md is well-organized with clear section headers and no nested references, but at ~190 lines the repeated config blocks are candidates for a separate reference file, leaving minor organization gaps versus the 5-anchor.

4 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, third-person, and supplies both a clear what and an explicit when, with a distinct niche and low conflict risk. Its main limitation is that the action list is a single configured action elaborated with detail rather than multiple distinct capabilities, and a few natural trigger synonyms are missing.

Suggestions

Broaden the action list in the description to name multiple distinct capabilities (e.g., block --no-verify and --no-gpg-sign, extend to custom bypass flags) rather than one elaborated action.

Add more natural trigger synonyms users might say, such as "git hooks", "GPG signing", or "commit signing policy", to the Use-when clause.

DimensionReasoningScore

Specificity

"Configure a PreToolUse hook to prevent AI agents from skipping git pre-commit hooks with --no-verify and other bypass flags" names the domain plus several concrete specifics (PreToolUse hook, git pre-commit hooks, --no-verify, bypass flags), but coverage is essentially one action elaborated rather than a comprehensive action list, so it sits above the 3-anchor and below 5.

4 / 5

Completeness

It states a clear what ("Configure a PreToolUse hook to prevent...") and an explicit when ("Use when setting up Claude Code projects that enforce commit quality gates"), but the when could be more specific with concrete trigger phrasing, matching the 4-anchor rather than 5.

4 / 5

Trigger Term Quality

Natural phrases like "git pre-commit hooks", "--no-verify", "Claude Code projects", and "commit quality gates" give good keyword coverage a user would say, though a few natural synonyms (e.g. GPG signing, git hooks) referenced in the body are absent from the description.

4 / 5

Distinctiveness Conflict Risk

It targets a narrow niche (blocking --no-verify/--no-gpg-sign bypass flags via a PreToolUse hook) with distinct triggers and minimal realistic overlap with other skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
wshobson/agents
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.