<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Roei </title>
    <description>The latest articles on DEV Community by Roei  (@shoustak).</description>
    <link>https://dev.to/shoustak</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4170446%2F9de01419-956a-4811-88bf-ca51f8e01b9f.png</url>
      <title>DEV Community: Roei </title>
      <link>https://dev.to/shoustak</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/shoustak"/>
    <language>en</language>
    <item>
      <title>Claude Code hooks: a practical guide with examples</title>
      <dc:creator>Roei </dc:creator>
      <pubDate>Thu, 08 Oct 2026 12:00:00 +0000</pubDate>
      <link>https://dev.to/shoustak/claude-code-hooks-a-practical-guide-with-examples-3hlj</link>
      <guid>https://dev.to/shoustak/claude-code-hooks-a-practical-guide-with-examples-3hlj</guid>
      <description>&lt;p&gt;Claude Code hooks are commands that run at fixed points in a session: before a tool runs, after a file is edited, when a prompt is submitted, when Claude stops. Unlike a line in &lt;code&gt;CLAUDE.md&lt;/code&gt;, a hook is not advice. It always runs, and a &lt;code&gt;PreToolUse&lt;/code&gt; hook can block the action outright by exiting with code 2.&lt;/p&gt;

&lt;p&gt;Checked against &lt;a href="https://code.claude.com/docs/en/hooks-guide" rel="noopener noreferrer"&gt;the hooks guide&lt;/a&gt; and &lt;a href="https://code.claude.com/docs/en/hooks" rel="noopener noreferrer"&gt;reference&lt;/a&gt; on 2026-10-05 (Claude Code 2.1.289). The event list has grown to 33; the handful below are the ones most teams use. Three things changed in the fortnight before that date: sessions now start in auto mode, mods arrived and can overrule a hook, and Cursor runs Claude Code's hooks too. Each has a section below.&lt;/p&gt;

&lt;h2&gt;
  
  
  What are Claude Code hooks?
&lt;/h2&gt;

&lt;p&gt;Anthropic's &lt;a href="https://code.claude.com/docs/en/best-practices" rel="noopener noreferrer"&gt;best practices&lt;/a&gt; put it in one line: unlike &lt;code&gt;CLAUDE.md&lt;/code&gt; instructions, which are advisory, hooks are deterministic and guarantee the action happens. A rule asks the model. A hook does not ask anyone. That is why the answer to "Claude keeps ignoring my rule" is so often "make it a hook", and why the causes behind the ignoring, covered in &lt;a href="https://gethrbr.com/blog/why-claude-ignores-claude-md" rel="noopener noreferrer"&gt;why Claude ignores CLAUDE.md&lt;/a&gt;, do not apply to one.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which hook events should you know?
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;th&gt;Fires&lt;/th&gt;
&lt;th&gt;Typical use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;PreToolUse&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Before a tool call runs. Can block it&lt;/td&gt;
&lt;td&gt;Refuse dangerous commands, protect files&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;PostToolUse&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;After a tool call succeeds&lt;/td&gt;
&lt;td&gt;Format or lint the file that was just edited&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;UserPromptSubmit&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;When you submit a prompt, before Claude sees it&lt;/td&gt;
&lt;td&gt;Add context to the prompt, such as branch state&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;SessionStart&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;When a session begins, resumes, clears or compacts&lt;/td&gt;
&lt;td&gt;Load context the session should start with&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;Stop&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;When Claude finishes responding&lt;/td&gt;
&lt;td&gt;Run the tests and refuse to stop until they pass&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;PreCompact&lt;/code&gt; / &lt;code&gt;PostCompact&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Around context compaction&lt;/td&gt;
&lt;td&gt;Re-inject what must survive a summary&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;SessionEnd&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;When the session terminates&lt;/td&gt;
&lt;td&gt;Write logs, clean up&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;Notification&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;When Claude Code sends a notification&lt;/td&gt;
&lt;td&gt;Desktop alert when Claude is waiting for you&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  How do you configure a hook?
&lt;/h2&gt;

&lt;p&gt;Hooks live in a settings file under a &lt;code&gt;hooks&lt;/code&gt; key. Each event takes matchers (a tool name or a regex such as &lt;code&gt;Edit|Write&lt;/code&gt;) and the commands to run. This formats every file Claude edits:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="err"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;.claude/settings.json&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"hooks"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"PostToolUse"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"matcher"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Edit|Write"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"hooks"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"jq -r '.tool_input.file_path' | xargs npx prettier --write"&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Where the block goes decides who it applies to:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Location&lt;/th&gt;
&lt;th&gt;Scope&lt;/th&gt;
&lt;th&gt;Shared&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;~/.claude/settings.json&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;All your projects&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;.claude/settings.json&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;This project&lt;/td&gt;
&lt;td&gt;Yes, commit it&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;.claude/settings.local.json&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;This project&lt;/td&gt;
&lt;td&gt;No, gitignored&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Managed policy settings&lt;/td&gt;
&lt;td&gt;The whole organization&lt;/td&gt;
&lt;td&gt;Admin controlled&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Plugin, skill or subagent&lt;/td&gt;
&lt;td&gt;While that is enabled or running&lt;/td&gt;
&lt;td&gt;Yes, ships with it&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Run &lt;code&gt;/hooks&lt;/code&gt; inside Claude Code to see everything configured. Since 2.1.286 it opens on one list grouped by event, each hook labelled with where it comes from; select one to see the full command and the file that defines it. The menu is read-only, so to change a hook you edit that file.&lt;/p&gt;

&lt;h2&gt;
  
  
  How do you block a command with a PreToolUse hook?
&lt;/h2&gt;

&lt;p&gt;The hook receives the tool call as JSON on stdin. Exit 0 lets it through. Exit 2 blocks it, and what you write to stderr goes back to Claude as the reason, so it can change course. This is the pattern from Anthropic's guide, protecting files:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;#!/bin/bash&lt;/span&gt;
&lt;span class="c"&gt;# .claude/hooks/protect-files.sh&lt;/span&gt;
&lt;span class="nv"&gt;INPUT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;cat&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;
&lt;span class="nv"&gt;FILE_PATH&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$INPUT&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; | jq &lt;span class="nt"&gt;-r&lt;/span&gt; &lt;span class="s1"&gt;'.tool_input.file_path // empty'&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;

&lt;span class="k"&gt;for &lt;/span&gt;pattern &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="s2"&gt;".env"&lt;/span&gt; &lt;span class="s2"&gt;"package-lock.json"&lt;/span&gt; &lt;span class="s2"&gt;".git/"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;do
  if&lt;/span&gt; &lt;span class="o"&gt;[[&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$FILE_PATH&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$pattern&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt; &lt;span class="o"&gt;]]&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="k"&gt;then
    &lt;/span&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"Blocked: &lt;/span&gt;&lt;span class="nv"&gt;$FILE_PATH&lt;/span&gt;&lt;span class="s2"&gt; matches protected pattern '&lt;/span&gt;&lt;span class="nv"&gt;$pattern&lt;/span&gt;&lt;span class="s2"&gt;'"&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&amp;amp;2
    &lt;span class="nb"&gt;exit &lt;/span&gt;2
  &lt;span class="k"&gt;fi
done
&lt;/span&gt;&lt;span class="nb"&gt;exit &lt;/span&gt;0
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Register it on &lt;code&gt;PreToolUse&lt;/code&gt; with the matcher &lt;code&gt;Edit|Write&lt;/code&gt;, make it executable, and ask Claude to edit &lt;code&gt;.env&lt;/code&gt; to test it. For structured control, exit 0 and print JSON with &lt;code&gt;permissionDecision&lt;/code&gt; set to &lt;code&gt;deny&lt;/code&gt;, &lt;code&gt;ask&lt;/code&gt; or &lt;code&gt;allow&lt;/code&gt;. When several hooks answer, the most restrictive wins.&lt;/p&gt;

&lt;p&gt;A hook and your permission rules stack. A hook that exits 2 blocks the call even when an allow rule would let it through, and a deny rule still blocks a call the hook allowed. Since 2.1.288, if Claude Code cannot match a &lt;code&gt;PreToolUse&lt;/code&gt; hook or cannot serialize the tool's input for it, the call is blocked rather than waved through. That fix is narrow: a guard that exits 1, or times out, still lets the call run, so a guard should exit 2 on anything it does not understand.&lt;/p&gt;

&lt;h2&gt;
  
  
  Do hooks still run in auto mode?
&lt;/h2&gt;

&lt;p&gt;Yes, and they matter more there. Since 2.1.284, published 2026-09-28, interactive sessions start in auto mode when no permission mode is configured, on every plan and provider. Most tool calls are then approved by a classifier instead of by you. &lt;code&gt;PreToolUse&lt;/code&gt; hooks still run before that: a hook that denies, or exits 2, blocks the call, and a hook that returns &lt;code&gt;ask&lt;/code&gt; forces a prompt the classifier cannot approve on its own.&lt;/p&gt;

&lt;p&gt;Auto mode adds one event of its own. &lt;code&gt;PermissionDenied&lt;/code&gt; fires when the classifier refuses a call, which is the place to log what it stopped. And a &lt;code&gt;PostToolUse&lt;/code&gt; hook can return &lt;code&gt;classifierContext&lt;/code&gt;, a note the classifier reads before it judges the next action, since it never sees tool results themselves. Details are in the &lt;a href="https://code.claude.com/docs/en/permission-modes" rel="noopener noreferrer"&gt;permission modes docs&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Mods vs hooks: can a mod overrule a hook?
&lt;/h2&gt;

&lt;p&gt;Yes. Mods arrived in 2.1.287 on 2026-10-01. A mod is a plugin whose handlers are JavaScript or TypeScript functions running inside Claude Code rather than shell commands, so it can draw panes, add commands and step into a tool call. The &lt;a href="https://code.claude.com/docs/en/plugins/mods/overview" rel="noopener noreferrer"&gt;mods docs&lt;/a&gt; now call the hooks on this page "settings hooks" to tell them apart.&lt;/p&gt;

&lt;p&gt;The part that matters for a guard: per the &lt;a href="https://code.claude.com/docs/en/permissions#extend-permissions-with-hooks" rel="noopener noreferrer"&gt;permissions docs&lt;/a&gt;, a mod that handles &lt;code&gt;tool.check&lt;/code&gt; answers after your rules and your &lt;code&gt;PreToolUse&lt;/code&gt; hooks, and its answer can replace theirs.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Your control&lt;/th&gt;
&lt;th&gt;Can an installed mod approve past it?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A &lt;code&gt;PreToolUse&lt;/code&gt; hook that blocks&lt;/td&gt;
&lt;td&gt;Yes, unless the hook is in managed settings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;An ask rule&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;The auto mode classifier&lt;/td&gt;
&lt;td&gt;Yes. A call the mod approves is not checked&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A deny rule&lt;/td&gt;
&lt;td&gt;Not on a machine with managed settings or a Team or Enterprise sign-in, by default. Anywhere else, yes&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;So a guard the whole team relies on belongs in managed settings, and a mod deserves the review you would give any dependency that runs with your permissions. If a shell script does the job, a settings hook is still the simpler choice.&lt;/p&gt;

&lt;h2&gt;
  
  
  Do Codex and Cursor have hooks too?
&lt;/h2&gt;

&lt;p&gt;Both do, and both borrowed Claude Code's shape, so one guard script can serve all three.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Cursor&lt;/th&gt;
&lt;th&gt;OpenAI Codex&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Where&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;.cursor/hooks.json&lt;/code&gt;, &lt;code&gt;~/.cursor/hooks.json&lt;/code&gt;, and enterprise paths&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;.codex/hooks.json&lt;/code&gt; or &lt;code&gt;[hooks]&lt;/code&gt; in &lt;code&gt;.codex/config.toml&lt;/code&gt;, and the same under &lt;code&gt;~/.codex&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reads Claude Code's hooks&lt;/td&gt;
&lt;td&gt;Yes, by default, from &lt;code&gt;.claude/settings.json&lt;/code&gt;, &lt;code&gt;.claude/settings.local.json&lt;/code&gt; and &lt;code&gt;~/.claude/settings.json&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Blocking&lt;/td&gt;
&lt;td&gt;Exit 2, or Claude Code's &lt;code&gt;permissionDecision&lt;/code&gt; JSON. Any other non-zero exit lets the action through&lt;/td&gt;
&lt;td&gt;Exit 2, or &lt;code&gt;permissionDecision: "deny"&lt;/code&gt;. Matching hooks start at once, so one cannot stop another&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Before a hook runs&lt;/td&gt;
&lt;td&gt;Nothing extra&lt;/td&gt;
&lt;td&gt;You review and trust each hook in /hooks; a changed hook is skipped until trusted again. Project hooks load only in trusted projects&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Cursor maps the names for you: &lt;code&gt;Bash&lt;/code&gt; becomes &lt;code&gt;Shell&lt;/code&gt;, &lt;code&gt;Edit&lt;/code&gt; becomes &lt;code&gt;Write&lt;/code&gt;, and &lt;code&gt;UserPromptSubmit&lt;/code&gt; becomes &lt;code&gt;beforeSubmitPrompt&lt;/code&gt;. It does not map &lt;code&gt;Notification&lt;/code&gt; or &lt;code&gt;PermissionRequest&lt;/code&gt;. Codex calls a file edit &lt;code&gt;apply_patch&lt;/code&gt;, so an &lt;code&gt;Edit|Write&lt;/code&gt; matcher needs that name added there. Because Cursor fails open on a crash, write a guard to exit 2 when it cannot parse its own input. Sources: &lt;a href="https://cursor.com/docs/reference/third-party-hooks" rel="noopener noreferrer"&gt;Cursor third-party hooks&lt;/a&gt;, &lt;a href="https://developers.openai.com/codex/hooks" rel="noopener noreferrer"&gt;Codex hooks&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which commands are worth blocking?
&lt;/h2&gt;

&lt;p&gt;The ones your agents actually run, not the ones that sound scariest. A guard written from imagination can sit for months without matching anything. The costly commands are often ordinary: &lt;code&gt;rm -r&lt;/code&gt; on a source directory, &lt;code&gt;git checkout -- &amp;lt;paths&amp;gt;&lt;/code&gt; or &lt;code&gt;git reset --hard&lt;/code&gt; throwing away uncommitted work. Read your agents' command history before you decide which guard comes first.&lt;/p&gt;

&lt;p&gt;Start a new guard in log-only mode for a week, count what it would have blocked, then switch it to blocking. A guard that fires on legitimate work gets disabled by the second person it annoys.&lt;/p&gt;

&lt;h2&gt;
  
  
  Can a hook add context for Claude?
&lt;/h2&gt;

&lt;p&gt;Yes. On &lt;code&gt;UserPromptSubmit&lt;/code&gt;, return JSON with &lt;code&gt;hookSpecificOutput.additionalContext&lt;/code&gt; and the text is added to Claude's context for that prompt. The guide's example adds the branch and a deploy freeze. Put the field inside &lt;code&gt;hookSpecificOutput&lt;/code&gt;; at the top level it is silently ignored. &lt;code&gt;SessionStart&lt;/code&gt; with the &lt;code&gt;compact&lt;/code&gt; matcher is the documented way to re-inject what must survive a compaction.&lt;/p&gt;

&lt;p&gt;This is the part of hooks that is easiest to overdo. Every line a hook injects is in the prompt, with the same cost and the same &lt;a href="https://gethrbr.com/blog/context-rot-stale-rules" rel="noopener noreferrer"&gt;context rot&lt;/a&gt; as a line in &lt;code&gt;CLAUDE.md&lt;/code&gt;. Inject what applies to this prompt, not everything that might.&lt;/p&gt;

&lt;h2&gt;
  
  
  How do you debug a hook that is not running?
&lt;/h2&gt;

&lt;p&gt;Press &lt;code&gt;Ctrl+O&lt;/code&gt; for the transcript view. A successful hook shows nothing; a block shows its reason; a failing hook shows a &lt;em&gt;hook error&lt;/em&gt; notice. For the full picture, start with &lt;code&gt;claude --debug-file /tmp/claude.log&lt;/code&gt; and tail the log, or run &lt;code&gt;/debug&lt;/code&gt; mid-session. The usual culprits: the script is not executable, &lt;code&gt;jq&lt;/code&gt; is missing, the matcher does not match the tool name, or a project setting set &lt;code&gt;disableAllHooks&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Harbor fits
&lt;/h2&gt;

&lt;p&gt;Harbor is itself delivered through hooks. &lt;code&gt;harbor init&lt;/code&gt; installs hooks in Claude Code, Codex and Cursor, and they serve each session the team's approved facts that apply to the repo and the task, so the agent starts with the decision from last month's review instead of rediscovering it. What a session learns is written back through review, not straight into the next prompt.&lt;/p&gt;

&lt;p&gt;Harbor's &lt;a href="https://gethrbr.com/docs/guardrails" rel="noopener noreferrer"&gt;guardrails&lt;/a&gt; run on these same hooks, in Claude Code, Codex and Cursor, and since 2026-10-04 they cover MCP tool calls as well as shell commands, so the GitHub MCP server's &lt;code&gt;merge_pull_request&lt;/code&gt; can be stopped the way &lt;code&gt;gh pr merge&lt;/code&gt; is. The ready-made ones are off, and record nothing, until your team turns one on. A guardrail you write starts in observe, the log-only week above, and one you add from the library blocks from the start. Either can be switched, and Claude Code tells each developer when one is turned on. &lt;code&gt;harbor off&lt;/code&gt; pauses the whole thing for one repo, and &lt;code&gt;harbor doctor&lt;/code&gt; checks that the hooks are installed and reaching the agents you think they reach.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;See what is installed where.&lt;/strong&gt; &lt;a href="https://gethrbr.com/docs/agents" rel="noopener noreferrer"&gt;Agents and MCP&lt;/a&gt; lists every hook event Harbor uses per agent, and the &lt;a href="https://gethrbr.com/docs/quickstart" rel="noopener noreferrer"&gt;quickstart&lt;/a&gt; takes about ten minutes.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What are hooks in Claude Code?
&lt;/h3&gt;

&lt;p&gt;Hooks are commands Claude Code runs at fixed points in a session, such as before a tool call, after a file edit, or when Claude stops. Unlike CLAUDE.md instructions, they always run.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I block a command in Claude Code?
&lt;/h3&gt;

&lt;p&gt;Add a PreToolUse hook with a matcher such as Bash or Edit|Write. The script reads the tool call as JSON on stdin and exits with code 2 to block it; what it writes to stderr is passed back to Claude as the reason.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where are Claude Code hooks configured?
&lt;/h3&gt;

&lt;p&gt;In a settings file under a hooks key: ~/.claude/settings.json for all your projects, .claude/settings.json to share with the team, .claude/settings.local.json for yourself, or managed settings for the organization. Run /hooks to see them all.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do hooks run in Claude Code auto mode?
&lt;/h3&gt;

&lt;p&gt;Yes. PreToolUse hooks run before the auto mode classifier: a hook that denies or exits 2 blocks the call, and one that returns ask forces a prompt the classifier cannot approve on its own. Since 2.1.284, sessions start in auto mode when no permission mode is configured.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does Cursor run Claude Code hooks?
&lt;/h3&gt;

&lt;p&gt;Yes, by default. Cursor loads hooks from .claude/settings.json, .claude/settings.local.json and ~/.claude/settings.json, maps Bash to Shell and Edit to Write, and honours exit code 2 and Claude Code's permissionDecision JSON. Codex does not read them; it uses .codex/hooks.json.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Disclosure: I work on Harbor, which published this note.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>claudecode</category>
      <category>ai</category>
      <category>devtools</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
