About
This skill checks if your Git commit signing key is ready before your first commit, preventing unsigned commits. It proactively prompts you to unlock the key once per session instead of failing mid-workflow. Use it at the start of work in repos requiring signed commits to avoid common GPG or SSH signing errors.
Quick Install
Claude Code
Recommendednpx skills add avelikiy/great_cto -a claude-code/plugin add https://github.com/avelikiy/great_ctogit clone https://github.com/avelikiy/great_cto.git ~/.claude/skills/signing-preflightCopy and paste this command in Claude Code to install this skill
Documentation
signing-preflight — find the locked key before the first commit, not after the hundredth
On real projects: an agent committed unsigned without asking to unlock the key; a signing call on a locked SSH key hung the session; 121 commits had to be re-signed after the fact — and the key turned out to have no passphrase at all. Each was a two-second question at the start of the session.
Check (read-only, bounded)
git config --get commit.gpgsign # true → signing is expected
git config --get gpg.format # ssh | openpgp (empty = openpgp)
git config --get user.signingkey
SSH signing — does a test signature finish? (user.signingkey may be a key file or a
literal key::ssh-…; the test signature is the check that works for both.)
K="$(git config --get user.signingkey)"; case "$K" in key::*) printf '%s\n' "${K#key::}" > /tmp/sigpre.pub; K=/tmp/sigpre.pub ;; esac
echo preflight | perl -e 'alarm 5; exec @ARGV' ssh-keygen -Y sign -n git -f "$K" >/dev/null 2>&1 && echo signs || echo CANNOT-SIGN
OpenPGP — a batch signature that refuses to prompt:
echo preflight | perl -e 'alarm 5; exec @ARGV' gpg --batch --pinentry-mode error --clearsign -u "$(git config --get user.signingkey)" >/dev/null 2>&1 && echo signs || echo CANNOT-SIGN
Always bound the test with a timeout: an unbounded signing call on a locked key waits for a passphrase nobody will type, and the session stalls.
Then
- signs → proceed; nothing to say.
- CANNOT-SIGN → one question to the operator, before any work:
"Commit signing is on and the key is locked / not loaded. Unlock it (
ssh-add/ gpg-agent) and I will continue — or tell me to commit unsigned for this session." Wait for the answer. This is the one question worth stopping for at the start.
Never, without being told
git -c commit.gpgsign=false commit …or--no-gpg-sign— an unsigned commit on a branch that requires signatures is a push that will be refused, or worse, accepted.- Re-signing history (
rebase --exec 'git commit --amend -S') — it rewrites every hash after the first commit it touches; on a pushed branch that is a force-push.
Report unsigned work
If commits were made unsigned anyway, say so with the list:
git log --format='%h %G? %s' @{upstream}..HEAD | awk '$2!="G"'
GitHub Repository
Frequently asked questions
What is the signing-preflight skill?
signing-preflight is a Claude Skill by avelikiy. Skills package instructions and resources that Claude loads on demand, so Claude can perform signing-preflight-related tasks without extra prompting.
How do I install signing-preflight?
Use the install commands on this page: add signing-preflight to Claude Code as a plugin, or clone its repository into your skills directory, then restart Claude so it picks up the skill.
What category does signing-preflight belong to?
signing-preflight is in the Design category.
Is signing-preflight free to use?
Yes. signing-preflight is listed on AIMCP and free to install.
Related Skills
Use the executing-plans skill when you have a complete implementation plan to execute in controlled batches with review checkpoints. It loads and critically reviews the plan, then executes tasks in small batches (default 3 tasks) while reporting progress between each batch for architect review. This ensures systematic implementation with built-in quality control checkpoints.
This skill dispatches a code-reviewer subagent to analyze code changes against requirements before proceeding. It should be used after completing tasks, implementing major features, or before merging to main. The review helps catch issues early by comparing the current implementation with the original plan.
This skill provides a comprehensive guide for developers to connect MCP servers to Claude Code using HTTP, stdio, or SSE transports. It covers installation, configuration, authentication, and security for integrating external services like GitHub, Notion, and custom APIs. Use it when setting up MCP integrations, configuring external tools, or working with Claude's Model Context Protocol.
This skill helps developers choose between Claude Code Web and CLI interfaces based on task analysis, then enables seamless session teleportation between these environments. It optimizes workflow by managing session state and context when switching between web, CLI, or mobile. Use it for complex projects requiring different tools at various stages.
