---
title: "security-key-git-signing"
description: "Checks a hardware security key is plugged in before git signs a commit or tag with GPG, and asks for it if not"
canonical: https://agentpluginsdirectory.com/plugins/security-key-git-signing
last-updated: 2026-09-28
---

# security-key-git-signing
Checks a hardware security key is plugged in before git signs a commit or tag with GPG, and asks for it if not
- Slug: security-key-git-signing
- Publisher: wmxscott
- Repository: https://github.com/wmxscott/ai-toolkit
- Manifest: plugins/security-key-git-signing/plugin.json
- License: MIT
- Category (editorial): other
- Skills: 1 (security-key-git-signing)
- MCP servers: 0
- Stars: 0
- Repository created: 2026-09-13
- Repository last pushed: 2026-09-27
- Publisher type: User
- Listing: https://agentpluginsdirectory.com/plugins/security-key-git-signing
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What security-key-git-signing does, in the publisher's words

Stops the agent from running a signed git operation while your GPG signing key's hardware security key (a YubiKey or other OpenPGP smart card) is unplugged.

Without it, the agent runs git commit, gpg can't reach the card, and git fails with gpg failed to sign the data, sometimes halfway through a rebase or merge. The security-key-git-signing skill checks first and asks you to insert the key.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/wmxscott/ai-toolkit/HEAD/plugins/security-key-git-signing/README.md

## Skills

- security-key-git-signing: Use when about to run git commit, git tag -s, or any other GPG-signed git operation where commit.gpgsign or tag.gpgsign may be enabled and the signing key may be on a hardware security key (YubiKey, OpenPGP smart card). Checks the key is plugged in first, so signing doesn't fail halfway.

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
