signing-preflight
SkillDev toolsChecks before your agent's first git commit that code signing works so commits aren't left unsigned.
Use signing-preflight in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add signing-preflight and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the signing-preflight skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
About this skill
Before the first commit of a session, check that commit signing will work, the key is loaded and unlocked, and ask the operator to unlock it once, up front, instead of discovering it after a hundred unsigned commits. Never disables signing silently, never re-signs history without asking. Use at th
What this skill tells your AI
The instructions your AI receives, as published by avelikiy/great_cto in skills/signing-preflight/SKILL.md and read by Ahel’s review.
On real projects: an agent committed unsigned without asking to unlock the key; a signing call on a locked SSH key hung the session; 121 commits had to be re-signed after the fact — and the key turned out to have no passphrase at all. Each was a two-second question at the start of the session.
Check (read-only, bounded)
git config --get commit.gpgsign # true → signing is expected
git config --get gpg.format # ssh | openpgp (empty = openpgp)
git config --get user.signingkey
SSH signing — does a test signature finish? (user.signingkey may be a key file or a
literal key::ssh-…; the test signature is the check that works for both.)
K="$(git config --get user.signingkey)"; case "$K" in key::*) printf '%s\n' "${K#key::}" > /tmp/sigpre.pub; K=/tmp/sigpre.pub ;; esac
echo preflight | perl -e 'alarm 5; exec @ARGV' ssh-keygen -Y sign -n git -f "$K" >/dev/null 2>&1 && echo signs || echo CANNOT-SIGN
OpenPGP — a batch signature that refuses to prompt:
echo preflight | perl -e 'alarm 5; exec @ARGV' gpg --batch --pinentry-mode error --clearsign -u "$(git config --get user.signingkey)" >/dev/null 2>&1 && echo signs || echo CANNOT-SIGN
Always bound the test with a timeout: an unbounded signing call on a locked key waits for a passphrase nobody will type, and the session stalls.
Then
- signs → proceed; nothing to say.
- CANNOT-SIGN → one question to the operator, before any work:
"Commit signing is on and the key is locked / not loaded. Unlock it (
ssh-add/ gpg-agent) and I will continue — or tell me to commit unsigned for this session." Wait for the answer. This is the one question worth stopping for at the start.
Never, without being told
git -c commit.gpgsign=false commit …or--no-gpg-sign— an unsigned commit on a branch that requires signatures is a push that will be refused, or worse, accepted.- Re-signing history (
rebase --exec 'git commit --amend -S') — it rewrites every hash after the first commit it touches; on a pushed branch that is a force-push.
Report unsigned work
If commits were made unsigned anyway, say so with the list:
git log --format='%h %G? %s' @{upstream}..HEAD | awk '$2!="G"'
Signals
- GitHub stars
- 102
- Forks
- 13
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
signing-preflight- Source
- github.com/avelikiy/great_cto