Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Git Hooks Automation

ASecurity

当需要在提交/推送前自动拦截代码质量问题(lint、格式化、类型检查、提交信息规范、密钥/大文件检测)时使用;用 Husky+lint-staged、pre-commit 框架或 core.hooksPath 搭建团队共享 Git 钩子并产出可执行配置;不适用于 CI 流水线编排或替代真实测试评审。触发词:git hooks、pre-commit、husky、lint-staged、commitlint、commit-msg、pre-push

3 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentspythonshellbashnodegitdevopsci/cd

Works with

cursorcli

Security Analysis

A92/100
mediumInstalls packages at runtime which could introduce malicious dependencies
mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned 9/19/2026

$npx -y skills add findscripter/everything-skills --skill git-hooks-automation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Git Hooks Automation?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Git Hooks Automation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/findscripter-git-hooks-automation/badge)](https://www.skillsdirectory.com/skills/findscripter-git-hooks-automation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: git-hooks-automation
title: Git Hooks 质量门禁
description: 当需要在提交/推送前自动拦截代码质量问题(lint、格式化、类型检查、提交信息规范、密钥/大文件检测)时使用;用 Husky+lint-staged、pre-commit 框架或 core.hooksPath 搭建团队共享 Git 钩子并产出可执行配置;不适用于 CI 流水线编排或替代真实测试评审。触发词:git hooks、pre-commit、husky、lint-staged、commitlint、commit-msg、pre-push
domain: 研发/devops
triggers: [设置 git hooks, 添加 pre-commit 钩子, husky, lint-staged, commitlint, commit-msg 校验, pre-push 钩子, 提交信息规范, Conventional Commits, core.hooksPath, Husky v4 升级 v9, 提交前自动 lint, core.hooksPath 共享钩子]
tags: [git, git-hooks, husky, lint-staged, pre-commit, commitlint, 代码质量, ci, 研发, misc]
level: 进阶
status: stable
agents: [claude-code, codex, cursor, gemini-cli]
tools: [Bash, Edit, Write, Read]
requires: []
related: []
combines_with: []
license: MIT
source: sickn33/agentic-awesome-skills
source_license: MIT
---
## 何时使用

在「问题进 CI 之前」于本地拦截:把 lint、格式化、类型检查、测试、提交信息校验、密钥/大文件扫描挂到 Git 生命周期,秒级反馈而非分钟级。

适用:
- 要求"配置 git hooks / 加 pre-commit 钩子"。
- 搭建 Husky、lint-staged、pre-commit 框架或 commitlint。
- 强制 Conventional Commits 提交规范。
- 提交前 lint/格式化/类型检查,推送前跑测试。
- 从 Husky v4 迁移到 v9+,或从零引入钩子。

不该用(负边界):
- 设计/编排 CI 流水线本身(钩子只是第一道防线,CI 才是事实来源)——这属于 CI 模板范畴。
- 把钩子当作替代真实测试、环境验证或人工评审的手段。
- 所需输入(技术栈、目标钩子、规范约束)不明时,先澄清再动手。

核心约束:`.git/hooks/` 是本地的、不随仓库共享,所以才需要 Husky 或 `core.hooksPath`。

## 步骤

1. 判断技术栈:Node/TS 选 Husky+lint-staged;Python/多语言选 pre-commit 框架;其他语言用 shell 脚本 + `core.hooksPath`。
2. 安装并初始化钩子目录。
3. 配置「仅对暂存文件」运行的命令(速度关键)。
4. 按需加 commit-msg(提交信息规范)与 pre-push(测试)。
5. 全量跑一次校验存量代码,再纳入团队共享(提交到仓库)。
6. 在 CI 中复跑同一套校验,兜住被 `--no-verify` 绕过的提交。

## 指令

Husky v9+(Node/TS):

```bash
npm install --save-dev husky lint-staged
npx husky init                       # 生成 .husky/ 目录与 pre-commit
echo "npx lint-staged" > .husky/pre-commit
```

`package.json` 中配置 lint-staged(只跑暂存文件):

```json
{
  "lint-staged": {
    "*.{js,jsx,ts,tsx}": ["eslint --fix --max-warnings=0", "prettier --write"],
    "*.{css,scss}": ["prettier --write", "stylelint --fix"],
    "*.{json,md,yml,yaml}": ["prettier --write"]
  }
}
```

提交信息校验(commitlint):

```bash
npm install --save-dev @commitlint/cli @commitlint/config-conventional
# commitlint.config.js: extends ['@commitlint/config-conventional'],可加 subject-max-length=72 等规则
echo "npx --no -- commitlint --edit \$1" > .husky/commit-msg
echo "npm test" > .husky/pre-push   # 推送前跑测试
```

pre-commit 框架(Python/多语言)—— `.pre-commit-config.yaml` 用 YAML 声明、隔离环境运行:

```bash
pip install pre-commit
# 配置 repos:pre-commit-hooks(trailing-whitespace/check-yaml/check-added-large-files --maxkb=500/detect-private-key)、black、ruff(--fix)+ruff-format、shellcheck、conventional-pre-commit(stages:[commit-msg])
pre-commit install
pre-commit install --hook-type commit-msg
pre-commit run --all-files          # 首次全量
```

常用命令:`pre-commit autoupdate`(更新版本)、`pre-commit run <hook-id>`、`pre-commit clean`(清缓存)。

任意语言 —— 共享自定义 shell 钩子:

```bash
git config core.hooksPath .githooks   # 指向仓库内目录,随仓库共享
chmod +x .githooks/*
```

绕过钩子(应稀少):`git commit --no-verify`、`git push --no-verify`、`SKIP=eslint git commit ...`。

## 示例

`.githooks/pre-commit` 便携脚本(任意语言,关键逻辑):

```bash
#!/bin/sh
set -e
# 1. 禁止直接提交到 main/master
BRANCH=$(git symbolic-ref --short HEAD 2>/dev/null || echo detached)
[ "$BRANCH" = "main" ] || [ "$BRANCH" = "master" ] && { echo "禁止直接提交到 $BRANCH,请用特性分支"; exit 1; }
# 2. 调试残留:console.log / debugger / binding.pry / import pdb -> 命中即 exit 1
# 3. 大文件 >1MB -> exit 1
# 4. 密钥模式 AKIA[0-9A-Z]{16} / sk-... / ghp_... / password=... -> 命中即 exit 1
echo "✅ 全部 pre-commit 校验通过"
```

CI 复跑(GitHub Actions,兜底被绕过的钩子):

```yaml
# pre-commit/action@v3.0.1 或:npm ci && npx eslint . --max-warnings=0 && npx prettier --check .
```

## 注意事项

- 只跑暂存文件:绝不在每次提交时 lint 整个代码库(用 lint-staged,而非 `eslint src/`)。
- 能自动修就自动修:多用 `--fix` 降低开发摩擦。
- 钩子要快:pre-commit 目标 < 5 秒;频繁被 `--no-verify` 绕过说明钩子太慢或太严,应修钩子而非纵容绕过。
- 失败要响亮:错误信息附带可执行的修复指引。
- 团队共享:用 Husky 或 `core.hooksPath` 让钩子纳入版本控制;纯 `.git/hooks/` 改动无法分享。
- CI 是事实来源:钩子是便利,CI 才是强制执行者,两者校验保持一致。
- 渐进引入:先只做格式化(低摩擦),1-2 周后加 lint,再加提交信息校验、pre-push 测试,避免团队抵触。

常见排错:钩子静默跳过→未安装,跑 `npx husky init` / `pre-commit install`;"Permission denied"→`chmod +x`;本地通过 CI 失败→在 CI 固定 Node/Python 版本。Husky v4→v9 迁移:卸载旧版并删 `.husky`、删 `package.json` 里 `husky.hooks` 配置,再 `npx husky init` 重建钩子(新版用 `.husky/` 目录里的纯脚本)。

## 互见

- `codebase-audit-pre-push` —— 推送前的深度审计。
- `bash-pro` —— 自定义钩子的进阶 shell 脚本。
- `github-actions-templates` —— CI/CD 工作流模板。
- `verification-before-completion` —— 声明完成前的验证。

---

采编自 sickn33/antigravity-awesome-skills(MIT 许可)。

Attribution

findscripterfindscripter
View sourceSee grades on GitHubMore from findscripter →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →