claude-code-hooks
A marketplace of 22 hook plugins for Claude Code: safety, cost control, observability and automation
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- The plugins run shell scripts and read files and session transcripts
- Hooks intercept tool calls and can block or modify the agent's actions
Install
Manual install
/plugin marketplace add karanb192/claude-code-hooks
/plugin install block-dangerous-commands@claude-code-hooksSwap the plugin name for any from the marketplace list in the README.
This is third-party code. Review the repository files before installing.
What it does
The repository is an installable Claude Code plugin marketplace where each hook installs with one command. Hooks intercept the agent's tool calls through PreToolUse and PostToolUse events and allow, deny or modify the action, feeding the reason back to the model. Because they run as separate processes outside the model, prompt injection cannot talk its way past them. The safety set blocks reading .env and secret exfiltration, curl-piped-to-shell patterns, rm -rf, force pushes to main and edits to the hook config itself; the rest handle automation, session logs, notifications and cost tracking. Every hook is mapped against the OWASP LLM Top 10.
Who it is for. For developers and devops engineers who give the agent autonomy and want to bound it with process-level rules.
Good fit when
- You need to block dangerous commands and secret reads by the agent
- You want a log of what the agent did in a session and cost tracking
- You want to automate actions on Claude Code events without writing hook code
Not a fit when
- Your agent is not Claude Code and does not support its plugin and hook format
- You need an application skill or MCP server rather than action guards
Example request
Add a hook that blocks reading .env and dangerous commands in this projectLimitations
The plugins target Claude Code and its event and hook model. Some run shell scripts in JavaScript and Python and read files and session transcripts. Hooks reduce risk but do not replace real sandboxing. They need no keys or paid accounts.
How to disable. Remove the plugin via /plugin, or drop its hook from settings.json if you wired the script in by hand.
Security check
- The plugins run shell scripts and read files and session transcripts
- Hooks intercept tool calls and can block or modify the agent's actions
README in short
The README presents ready-made Claude Code hooks as a 22-plugin marketplace: safety, automation, notifications. Every tool call passes through a hook that allows, denies or modifies the action and returns a reason to the agent. Hooks run outside the model as separate processes, so prompt injection cannot bypass them. The safety set covers secret exfiltration, dangerous commands, force pushes and hook-config tampering. Each plugin installs with one /plugin command, and its script can also be wired into settings.json by hand. MIT licensed.
FAQ
Can I skip the plugin format?
Yes. Each plugin's script also works standalone: copy plugins/<name>/<name>.js and wire it into settings.json yourself.
Why are hooks stronger than instructions?
Hooks run as separate processes outside the model, so prompt text cannot talk them into skipping an action.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents