signing-preflight

SkillDev tools

Checks before your first commit that git commit signing is set up and unlocked, so you don't end up with unsigned commits.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the signing-preflight skill

About this skill

Before the first commit of a session, check that commit signing will work, the key is loaded and unlocked, and ask the operator to unlock it once, up front, instead of discovering it after a hundred unsigned commits. Never disables signing silently, never re-signs history without asking. Use at th

What this skill tells your AI

The instructions your AI receives, as published by avelikiy/great_cto in skills/signing-preflight/SKILL.md and read by ahel’s review.

On real projects: an agent committed unsigned without asking to unlock the key; a signing call on a locked SSH key hung the session; 121 commits had to be re-signed after the fact — and the key turned out to have no passphrase at all. Each was a two-second question at the start of the session.

Check (read-only, bounded)

git config --get commit.gpgsign          # true → signing is expected
git config --get gpg.format              # ssh | openpgp (empty = openpgp)
git config --get user.signingkey

SSH signing — does a test signature finish? (user.signingkey may be a key file or a literal key::ssh-…; the test signature is the check that works for both.)

K="$(git config --get user.signingkey)"; case "$K" in key::*) printf '%s\n' "${K#key::}" > /tmp/sigpre.pub; K=/tmp/sigpre.pub ;; esac
echo preflight | perl -e 'alarm 5; exec @ARGV' ssh-keygen -Y sign -n git -f "$K" >/dev/null 2>&1 && echo signs || echo CANNOT-SIGN

OpenPGP — a batch signature that refuses to prompt:

echo preflight | perl -e 'alarm 5; exec @ARGV' gpg --batch --pinentry-mode error --clearsign -u "$(git config --get user.signingkey)" >/dev/null 2>&1 && echo signs || echo CANNOT-SIGN

Always bound the test with a timeout: an unbounded signing call on a locked key waits for a passphrase nobody will type, and the session stalls.

Then

  • signs → proceed; nothing to say.
  • CANNOT-SIGN → one question to the operator, before any work: "Commit signing is on and the key is locked / not loaded. Unlock it (ssh-add / gpg-agent) and I will continue — or tell me to commit unsigned for this session." Wait for the answer. This is the one question worth stopping for at the start.

Never, without being told

  • git -c commit.gpgsign=false commit … or --no-gpg-sign — an unsigned commit on a branch that requires signatures is a push that will be refused, or worse, accepted.
  • Re-signing history (rebase --exec 'git commit --amend -S') — it rewrites every hash after the first commit it touches; on a pushed branch that is a force-push.

Report unsigned work

If commits were made unsigned anyway, say so with the list:

git log --format='%h %G? %s' @{upstream}..HEAD | awk '$2!="G"'

Signals

GitHub stars
97
Forks
13
Last commit
Sep 2026
Advanced
Item type
skill
Key
signing-preflight
Source
github.com/avelikiy/great_cto