This skill should be used when the user asks to "create a hook", "add a hook", "write a hook", or mentions Claude Code hooks. Also suggest this skill when the user asks to "automatically do X" or "run X before/after Y" as these are good candidates for hooks.
Create hooks that run shell commands on specific events to add guardrails, automations, and policy enforcement.
You MUST read the reference files for detailed schemas and examples:
| Code | Meaning | Behavior |
|---|---|---|
| 0 | Success | Action proceeds; stdout shown in verbose mode |
| 2 | Block | Action blocked; stderr fed to Claude |
| Other | Error | Non-blocking; stderr shown to user |
.claude/settings.json.claude/hooks/ (mark executable){
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": ".claude/hooks/my-script.sh",
"timeout": 60
}
]
}
]
}
}| Event | When | Can Block? |
|---|---|---|
| PreToolUse | Before tool executes | Yes (exit 2) |
| PostToolUse | After tool completes | Feedback only |
| PermissionRequest | User sees permission dialog | Yes |
| UserPromptSubmit | User submits prompt | Yes |
| Stop | Main agent finishes | Yes (continue) |
| SubagentStop | Subagent finishes | Yes (continue) |
| SessionStart | Session begins | Add context |
| SessionEnd | Session ends | Cleanup only |
| Notification | Notifications sent | No |
| PreCompact | Before compact | No |
For PreToolUse/PostToolUse/PermissionRequest:
Bash - Shell commandsEdit, Write, Read - File operationsGlob, Grep - Search operationsTask - Subagent tasksmcp__<server>__<tool> - MCP toolsUse wildcards for flexible matching patterns:
Bash(npm *) - Match any npm commandBash(*-h*) - Match commands containing -hBash(git:*) - Match any git subcommandThis reduces configuration overhead and avoids mismatched permissions blocking legitimate workflows.
#!/usr/bin/env bash
set -euo pipefail
# Read JSON input
input=$(cat)
tool_name=$(echo "$input" | jq -r '.tool_name // ""')
command=$(echo "$input" | jq -r '.tool_input.command // ""')
# Your validation logic here
if [[ "$command" =~ dangerous_pattern ]]; then
echo "Blocked: reason here" >&2
exit 2
fi
exit 0Hooks are snapshotted at startup. After creating or modifying hooks:
⚠️ Changes won't take effect until you either:
- Restart Claude Code (exit and re-run
claude), OR- Run
/hooksto review and apply the updated configurationThis is a security feature - it prevents malicious hook modifications from affecting your current session.
After restart, run /hooks to confirm your hook appears in the list. If it doesn't show up:
.claude/settings.json)disableAllHooks: true in any settings file/hooks or restart Claude Code/hooks output - Your hook should be listed with correct matchercat .claude/settings.json | jq . to check syntaxBash not bash)When creating hooks that block operations (like preventing push to main):
/hooks to confirm the updated hook is loadedUse claude --debug to see hook execution details, or add logging to your hook:
echo "[DEBUG] Hook triggered: $cmd" >> /tmp/hook-debug.logExamples adapted from Steve Kinney's Claude Code Hook Examples.
92f335c
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.