From git-flow
Configure safe git workflow hygiene: pre-commit/pre-push hooks, Gitleaks secret scanning, .gitignore rules, local git config, and guardrails. Use when setting up git hooks, gitleaks/git leaks, staged pre-commit checks, pre-push validation, core.hooksPath, .gitignore, or git config best practices. NOT for creating commits (use committing-code), cleaning branches/worktrees (use cleanup-git), or creating worktrees (use using-git-worktrees).
How this skill is triggered — by the user, by Claude, or both
Slash command
/git-flow:configuring-git-hygieneThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Set up project-local git hygiene. Keep hooks fast enough to stay enabled. Do not overwrite hooks, change global config, remove tracked files, or install tools without user approval.
Set up project-local git hygiene. Keep hooks fast enough to stay enabled. Do not overwrite hooks, change global config, remove tracked files, or install tools without user approval.
Use this skill for:
.gitignore rules and tracked-file cleanup.core.hooksPath, includeIf, signing, pull behavior, and pruning.Do not use this skill for:
committing-code.using-git-worktrees.cleanup-git.Run read-only checks first:
git rev-parse --show-toplevel
git status --short
git config --show-origin --get core.hooksPath || true
git config --show-origin --list | rg '^(file:.*\s+)?(user\.|commit\.|tag\.|pull\.|fetch\.|rerere\.|core\.hooksPath|includeIf\.)' || true
git ls-files .gitignore .pre-commit-config.yaml .gitleaks.toml 2>/dev/null || true
ls -la .git/hooks .githooks scripts/git-hooks 2>/dev/null || true
If a hook framework already exists, extend it. Do not replace it.
core.hooksPath changes: read hooks.md..gitignore or git rm --cached: read gitignore.md.State current facts, proposed files/config, verification, and risks. Ask before:
git config --local or any global config commandchmodgit rm --cachedRules:
pre-commit, then project-local core.hooksPath.git config --local core.hooksPath scripts/git-hooks..gitignore patterns derived from actual artifacts.Run the narrowest proof for the changed component:
git config --local --get core.hooksPath and direct hook execution with safe fixture input when possible.--redact when the tool is available..gitignore: git check-ignore -v <path> and git ls-files <path> for affected files.GIT HYGIENE CONFIG
==================
Scope: hooks | gitleaks | gitignore | config | guardrails
Status: PROPOSED | APPLIED | BLOCKED
Current state:
- <facts from git config/files>
Plan:
- <change and why>
Changes:
- <file/config edited>
Verification:
- <command> — pass/fail/not run
Next:
- <install tool, run hook, or push validation>
git status --short and ask before proceeding.--no-verify as the fix.npx claudepluginhub alexei-led/cc-thingz --plugin git-flowScans git repos for leaked secrets, rewrites history to remove them using git-filter-repo/BFG, and configures .gitignore and pre-commit hooks. Activate for security audits or scrubbing credentials.
Use when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo blocks secrets and internal files before commit. This is an installer and verifier, NOT a scanner (gitleaks does the actual scanning). Do NOT use for deep secret audits or RLS work.
Pre-push safety gate that runs gitleaks secret scanning, forbidden-file checks, divergence detection, and size warnings before every git push. Refuses on any secret hit and requires explicit confirmation.