Block No-Verify Hook
PreToolUse hook configuration that intercepts and blocks bypass-flag usage before execution, ensuring AI agents cannot skip pre-commit hooks, GPG signing, or other git safety mechanisms.
Overview
AI coding agents (Claude Code, Codex, etc.) can run shell commands with flags like --no-verify that bypass pre-commit hooks. This defeats the purpose of linting, formatting, testing, and security checks configured in pre-commit hooks. The block-no-verify hook adds a PreToolUse guard that rejects any tool call containing bypass flags before execution.
Problem
When AI agents commit code, they may use bypass flags to avoid hook failures:
This allows:
- Unformatted code to enter the repository
- Linting errors to bypass checks
- Security scanning to be skipped
- Unsigned commits to bypass signing policies
- Test suites to be circumvented
Solution
Add a PreToolUse hook to .claude/settings.json that inspects every Bash tool call and blocks commands containing bypass flags.
Configuration
Add the following to your project's .claude/settings.json:
How It Works
- Matcher: The hook targets only
Bashtool calls, so it does not interfere with other tools (Read, Edit, Grep, etc.). - Inspection: Claude Code sends the tool call to the hook as JSON on stdin and sets no
$TOOL_INPUTvariable. The hook searches thecommandvalue in that JSON withgrep -E, so it needs nojqornode, and text in other fields, such ascwdor the tool call's description, can't trigger it. It blocks--no-verify,--no-gpg-sign, and any shorter prefix of them that git accepts, e.g.,--no-veri. It also blocks a short option group withnthat followscommitin the same command, e.g.,-nor-nm, because-nis the short form of--no-verify. The hook doesn't look for the wordgit, so it also catchesif git ...,sudo git ..., andg=git; $g commit --no-verify. A false match, such as a commit message that mentions a flag, blocks the call, which is the safe way to fail. - Blocking: If a bypass flag is found in a git command, the hook exits with code 2 and prints an error message. Exit code 2 signals Claude Code to reject the tool call entirely.
- Pass-through: If no bypass flag is found, the hook exits with code 0 and the command executes normally.
- Limits: The hook checks text, so it stops an agent that reaches for a bypass flag out of habit. It doesn't stop an agent that sets out to evade it, e.g., by building the flag from pieces or by running
git -c core.hooksPath=/dev/null commit.
Exit Codes
Blocked Flags
Installation
Per-Project Setup
Create or update .claude/settings.json in your project root:
Global Setup
To enforce across all projects, add to ~/.claude/settings.json:
Verification
Test that the hook blocks bypass flags:
Extending the Hook
Adding More Blocked Flags
To block additional flags (e.g., --force), extend the grep pattern:
Combining with Other Hooks
The block-no-verify hook works alongside other PreToolUse hooks:
Best Practices
- Commit the settings file -- Add
.claude/settings.jsonto version control so all team members benefit from the hook. - Document in onboarding -- Mention the hook in your project's contributing guide so developers understand why bypass flags are blocked.
- Pair with pre-commit hooks -- The block-no-verify hook ensures pre-commit hooks run; make sure you have meaningful pre-commit hooks configured.
- Test after setup -- Verify the hook works by intentionally triggering it in a test commit.


