Skip to content

fix(.cursor/hooks): route block-no-verify through local hook to fix message-body false positives (#2107) - #2177

Merged
affaan-m merged 1 commit into
affaan-m:mainfrom
gaurav0107:fix/2107-cursor-block-no-verify-use-local-hook
Jun 7, 2026
Merged

affaan-m merged 1 commit into
affaan-m:mainfrom
gaurav0107:fix/2107-cursor-block-no-verify-use-local-hook

Conversation

@gaurav0107

@gaurav0107 gaurav0107 commented Jun 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Cursor hooks were still wired to npx block-no-verify@1.1.2, the
    external package whose matcher over-matches: it blocks legitimate
    git commit whenever the literal string --no-verify (or no-verify)
    appears anywhere in the command — including inside the commit message
    body. See #2107 for the
    reproduction.
  • The Claude Code surface (hooks/hooks.json) already routes through
    the local scripts/hooks/block-no-verify.js, which uses
    flag-position-aware tokenisation (-m/-F/-am "..." / -tn etc.)
    and already passes 25 regression tests covering every false-positive
    case described in block-no-verify over-matches: blocks commits when the flag appears in the commit message body #2107. Cursor users were missing out.
  • Add a thin Cursor wrapper, .cursor/hooks/before-shell-execution-block-no-verify.js,
    that reads Cursor stdin, transforms to the Claude Code
    tool_input.command shape, delegates to the local hook's exported
    run(), and forwards exit code and stderr. Update .cursor/hooks.json
    to call the wrapper instead of the npx package.
  • The wrapper honours the standard ECC_HOOK_PROFILE and
    ECC_DISABLED_HOOKS=pre:bash:block-no-verify runtime gating via
    adapter.hookEnabled, matching the rest of the Cursor hook surface.

Verification

  • node tests/hooks/cursor-block-no-verify.test.js — 14/14 pass (new
    file; pins each false-positive case from block-no-verify over-matches: blocks commits when the flag appears in the commit message body #2107 plus the still-blocked
    real bypass attempts and the disable-via-env path).
  • node tests/hooks/block-no-verify.test.js — 25/25 pass (existing
    local-hook tests stay green).
  • node tests/run-all.js — 2633/2633 pass.
  • node scripts/ci/validate-no-personal-paths.js — clean.
  • node scripts/ci/check-unicode-safety.js — clean.
  • node scripts/ci/validate-hooks.js — 28 hook matchers validated.
  • npx eslint tests/hooks/cursor-block-no-verify.test.js — clean
    (.cursor/** is intentionally ignored by eslint.config.js).

Fixes #2107


Summary by cubic

Route Cursor’s block-no-verify hook through the local, flag-aware implementation to stop false blocks when --no-verify appears in commit messages, while still blocking real bypass attempts. Fixes #2107.

  • Bug Fixes
    • Replaced npx block-no-verify@1.1.2 with node .cursor/hooks/before-shell-execution-block-no-verify.js, which delegates to scripts/hooks/block-no-verify.js for position-aware parsing and consistent behavior with Claude Code.
    • Added tests/hooks/cursor-block-no-verify.test.js (14 cases) to pin false-positive regressions and blocking paths; wrapper respects ECC_HOOK_PROFILE and ECC_DISABLED_HOOKS.

Written for commit 484b6d5. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Tests

    • Added comprehensive test suite for hook wrapper behavior, validating bypass prevention across multiple commit/push scenarios, malformed input handling, and configuration-based disabling.
  • Chores

    • Migrated pre-execution hook implementation from external npm package to local wrapper script, improving system reliability and operational consistency.

…essage-body false positives (affaan-m#2107)

Cursor hooks still called `npx block-no-verify@1.1.2`, the broken external
package whose matcher over-matches: it blocks legitimate `git commit`
whenever `--no-verify` (or `no-verify`) appears anywhere in the command
string, including inside the commit message body. The Claude Code surface
already routes through the in-repo `scripts/hooks/block-no-verify.js`,
which performs flag-position-aware tokenisation and passes 25 regression
tests covering every false-positive case from affaan-m#2107.

Add a thin Cursor wrapper (`before-shell-execution-block-no-verify.js`)
that reads Cursor stdin, transforms to the Claude Code `tool_input.command`
shape, delegates to the local hook's exported `run()`, and forwards exit
code and stderr. Update `.cursor/hooks.json` to call the wrapper instead
of the npx package. New 14-case test file pins the false-positive cases
from the issue plus the still-blocked real bypass attempts.

Fixes affaan-m#2107
@coderabbitai

coderabbitai Bot commented Jun 6, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9bbebfa4-5b0d-4d0d-9e97-027b0ab12b50

📥 Commits

Reviewing files that changed from the base of the PR and between 7113b5b and 484b6d5.

📒 Files selected for processing (3)
  • .cursor/hooks.json
  • .cursor/hooks/before-shell-execution-block-no-verify.js
  • tests/hooks/cursor-block-no-verify.test.js

📝 Walkthrough

Walkthrough

This PR replaces the npm-based block-no-verify@1.1.2 Cursor hook with a local Node.js wrapper that delegates to the in-repo implementation, fixing false positives (Issue #2107) where --no-verify appears in commit message bodies rather than as an actual flag.

Changes

Hook Wiring and Wrapper Implementation

Layer / File(s) Summary
Hook configuration and wrapper bridge
.cursor/hooks.json, .cursor/hooks/before-shell-execution-block-no-verify.js
Cursor hook command now invokes a local wrapper script instead of the npm package. The wrapper reads Cursor stdin, conditionally enables the hook based on profile settings (minimal/standard/strict), normalizes input to Claude Code's tool_input.command JSON shape, delegates to the in-repo run() function, forwards stderr and exit code 2 when blocked, and passes stdin through otherwise with graceful error handling.

Hook Wrapper Validation Tests

Layer / File(s) Summary
Comprehensive test suite
tests/hooks/cursor-block-no-verify.test.js
Test infrastructure validates the wrapper against Cursor input shapes (command and args.command fields), confirms Issue #2107 false positives are resolved (message bodies containing --no-verify no longer trigger blocks), verifies real bypass attempts remain blocked (git commit --no-verify, git commit -n, core.hooksPath overrides, git push --no-verify), confirms robustness to non-git commands and malformed JSON, and validates hook disabling via ECC_DISABLED_HOOKS.

🎯 2 (Simple) | ⏱️ ~10 minutes

🐰 A wrapper script so clever and true,
Delegates the bash-hook work it must do,
No more false alarms from messages that say
"Don't use --no-verify" in a docs-file way,
The real blocks stay firm—hooray, hooray! 🎉

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: routing the block-no-verify hook through a local implementation to fix false positives from the external package.
Linked Issues check ✅ Passed The PR successfully addresses issue #2107 by implementing a flag-position-aware block-no-verify check that eliminates false positives when the flag appears in commit message bodies.
Out of Scope Changes check ✅ Passed All changes are directly scoped to fixing the block-no-verify false-positive issue: updating the Cursor hook configuration, adding a wrapper script, and adding corresponding tests.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed. For unrecoverable errors, disable the tool in CodeRabbit configuration.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@ecc-tools

ecc-tools Bot commented Jun 6, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@gaurav0107
gaurav0107 marked this pull request as ready for review June 6, 2026 13:34
@gaurav0107
gaurav0107 requested a review from affaan-m as a code owner June 6, 2026 13:34
@gaurav0107

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 6, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Re-trigger cubic

@affaan-m
affaan-m merged commit d8a84b5 into affaan-m:main Jun 7, 2026
40 checks passed
syarfandi pushed a commit to syarfandi/ECC that referenced this pull request Jun 9, 2026
…essage-body false positives (affaan-m#2107) (affaan-m#2177)

Cursor hooks still called `npx block-no-verify@1.1.2`, the broken external
package whose matcher over-matches: it blocks legitimate `git commit`
whenever `--no-verify` (or `no-verify`) appears anywhere in the command
string, including inside the commit message body. The Claude Code surface
already routes through the in-repo `scripts/hooks/block-no-verify.js`,
which performs flag-position-aware tokenisation and passes 25 regression
tests covering every false-positive case from affaan-m#2107.

Add a thin Cursor wrapper (`before-shell-execution-block-no-verify.js`)
that reads Cursor stdin, transforms to the Claude Code `tool_input.command`
shape, delegates to the local hook's exported `run()`, and forwards exit
code and stderr. Update `.cursor/hooks.json` to call the wrapper instead
of the npx package. New 14-case test file pins the false-positive cases
from the issue plus the still-blocked real bypass attempts.

Fixes affaan-m#2107
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

block-no-verify over-matches: blocks commits when the flag appears in the commit message body

2 participants