> Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the network or run arbitrary commands. Reads /api/cc-config/hooks and /api/cc-config/hook-scripts. Use when auditing hook safety.
npx skills add https://github.com/hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory
Catalogue every Claude Code hook the user has configured and assess its safety —
read through the Agent Monitor dashboard at http://localhost:4820.
The user provides: $ARGUMENTS
This may be:
PreToolUse, PostToolUse, Stop, SubagentStop,SessionStart, SessionEnd, UserPromptSubmit, Notification,
PreCompact) — restrict to that event.
~/.claude/hooks handler scripts dir.| Endpoint | Returns |
|----------|---------|
| GET /api/cc-config/hooks | { items:[{ scope:"user"\|"project"\|"project-local", file, exists, hooks:{ <Event>:[{ matcher, type, command, timeout }] } }] } |
| GET /api/cc-config/hook-scripts | { dir, items:[{ name, file, size, mtime }] } — the handler scripts under ~/.claude/hooks/ |
From /hooks, flatten each source into `(scope, file, Event, matcher, type,
command, timeout). Group by scope` (user, project, project-local). Show the
event, matcher, hook type, and the raw command. Note which file each came
from so the user can edit the right one.
From /hook-scripts, list each file in ~/.claude/hooks/ with name, size
(KB), and mtime. Cross-reference: flag scripts referenced by a hook command
but missing from disk, and scripts on disk that no configured hook calls
(orphaned).
For every type: "command" entry escalate:
curl, wget, http,https, nc, or pipes output off-box. Print the destination if visible.
sh/bash, evaluates downloadedcontent, or runs an unpinned interpreter on attacker-influenceable input.
command hook with timeout: null; it can hang asession indefinitely.
matcher: "*" or empty on a destructive command.Scope | Event | Matcher | Type | Command | Timeout).Hook | Risk | Severity | Detail) with aone-line verdict first (SAFE / REVIEW NEEDED / RISKY HOOKS).
Explorer; edit them in the file named by the source, then reinstall with
the dashboard's hook setup if needed.
http://localhost:4820, say so and tellthe user to start it with npm start from the repo root.
This skill should be used when the user asks to "create a hook", "add a PreToolUse/PostToolUse/Stop hook", "validate tool use", "implement prompt-based hooks", "use ${CLAUDE_PLUGIN_ROOT}", "set up event-driven automation", "block dangerous commands", or mentions hook events (PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, PreCompact, Notification). Provides comprehensive guidance for creating and implementing Claude Code plugin hooks with focus on advanced prompt-based hooks API.
This skill should be used when the user asks to "create a hook", "add a PreToolUse/PostToolUse/Stop hook", "validate tool use", "implement prompt-based hooks", "use ${CLAUDE_PLUGIN_ROOT}", "set up event-driven automation", "block dangerous commands", or mentions hook events (PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, PreCompact, Notification). Provides comprehensive guidance for creating and implementing Claude Code plugin hooks with focus on advanced prompt-based hooks API.
Build agentic applications with GitHub Copilot SDK. Use when embedding AI agents in apps, creating custom tools, implementing streaming responses, managing sessions, connecting to MCP servers, or creating custom agents. Triggers on Copilot SDK, GitHub SDK, agentic app, embed Copilot, programmable agent, MCP server, custom agent.
Coding Agent Session Search - unified CLI/TUI to index and search local coding agent history from Claude Code, Codex, Gemini, Cursor, Aider, ChatGPT, Pi-Agent, Factory, and more. Purpose-built for AI agent consumption with robot mode.
Destructive Command Guard - High-performance Rust hook for Claude Code that blocks dangerous commands before execution. SIMD-accelerated, modular pack system, whitelist-first architecture. Essential safety layer for agent workflows.
Makepad UI development skills for Rust apps: setup, patterns, shaders, packaging, and troubleshooting.
Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits
Prompt for generating an AGENTS.md file for a repository
Take hoangsonww/hook-inventory from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.