block-no-verify

PackSecurity

block-no-verify is a plugin that adds a PreToolUse hook to an AI agent's tooling. It stops the agent from running git commands with flags like --no-verify or --no-gpg-sign that skip safety checks such as signature verification. This keeps commits and other git operations going through the hooks that would otherwise be bypassed.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have an agent setup that supports plugins and PreToolUse hooks.

What your AI can do with it

  • Blocks use of the --no-verify flag before a git command runs
  • Blocks use of the --no-gpg-sign flag
  • Blocks other bypass flags that skip git hooks
  • Runs as a PreToolUse hook, checking commands before execution

Getting started

  1. Have an agent setup that supports plugins and PreToolUse hooks.
  2. Install the block-no-verify plugin.
  3. Run git commands through the agent as usual; bypass flags are now blocked.

Signals

GitHub stars
40k
Forks
4k
Last commit
Sep 2026

Questions

What does block-no-verify do?
It is a plugin with a PreToolUse hook that prevents AI agents from using --no-verify, --no-gpg-sign, and other bypass flags that skip git hooks.
Why block these flags?
Flags like --no-verify and --no-gpg-sign let git commands such as commit skip safety checks like signature verification. Blocking them keeps those checks in place when an agent runs git.
Does it affect git commands without bypass flags?
No. It only blocks commands that use flags which skip git hooks; normal git commands run as usual.
Advanced
Item type
plugin
Key
wshobson-agents-block-no-verify
Source
github.com/wshobson/agents