hook-development
Guidance for creating Claude Code hooks (PreToolUse/PostToolUse/Stop, etc.) to validate tool use and automate events.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for hook-development, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Part of the plugin-dev plugin, this skill teaches creating Claude Code plugin hooks across all events (PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart/End, UserPromptSubmit, PreCompact, Notification), with emphasis on the prompt-based hooks API for validating tool use and blocking dangerous commands. It ships example hooks (validate-bash.sh, validate-write.sh, load-context.sh) and linter/test scripts run via bash.
Key features and capabilities
- All hook event types incl. prompt-based hooks
- Example validators: validate-bash.sh, validate-write.sh
- hook-linter.sh and test-hook.sh scripts
Use cases
- Block dangerous bash commands via a PreToolUse hook
- Auto-load context on SessionStart