mcpbeat Sign in

Hook Inventory Skill for Claude

> Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the network or run arbitrary commands. Reads /api/cc-config/hooks and /api/cc-config/hook-scripts. Use when auditing hook safety.

783 tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
867
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory

The instruction itself

8 sections, as written by the author

Hook Inventory

Catalogue every Claude Code hook the user has configured and assess its safety —

read through the Agent Monitor dashboard at http://localhost:4820.

Input

The user provides: $ARGUMENTS

This may be:

  • empty — inventory all hooks across every scope (default).
  • an event name (PreToolUse, PostToolUse, Stop, SubagentStop,

SessionStart, SessionEnd, UserPromptSubmit, Notification,

PreCompact) — restrict to that event.

  • "scripts" — focus on the ~/.claude/hooks handler scripts dir.

Data Sources

| Endpoint | Returns |

|----------|---------|

| GET /api/cc-config/hooks | { items:[{ scope:"user"\|"project"\|"project-local", file, exists, hooks:{ <Event>:[{ matcher, type, command, timeout }] } }] } |

| GET /api/cc-config/hook-scripts | { dir, items:[{ name, file, size, mtime }] } — the handler scripts under ~/.claude/hooks/ |

Report Sections

1. Configured hooks by scope

From /hooks, flatten each source into `(scope, file, Event, matcher, type,

command, timeout). Group by scope` (user, project, project-local). Show the

event, matcher, hook type, and the raw command. Note which file each came

from so the user can edit the right one.

2. Hook scripts on disk

From /hook-scripts, list each file in ~/.claude/hooks/ with name, size

(KB), and mtime. Cross-reference: flag scripts referenced by a hook command

but missing from disk, and scripts on disk that no configured hook calls

(orphaned).

3. Safety flags

For every type: "command" entry escalate:

  • Network egress (P0) — the command contains curl, wget, http,

https, nc, or pipes output off-box. Print the destination if visible.

  • Arbitrary execution (P1) — pipes to sh/bash, evaluates downloaded

content, or runs an unpinned interpreter on attacker-influenceable input.

  • No timeout (P2) — a command hook with timeout: null; it can hang a

session indefinitely.

  • Broad matcher (P3)matcher: "*" or empty on a destructive command.

Output

  • Section 1 as a table (Scope | Event | Matcher | Type | Command | Timeout).
  • Section 3 as a findings table (Hook | Risk | Severity | Detail) with a

one-line verdict first (SAFE / REVIEW NEEDED / RISKY HOOKS).

  • Print raw commands verbatim — do not paraphrase a command you are flagging.
  • Cite only fields the API returned — never fabricate hooks or commands.
  • Note: hooks live inside settings.json and are read-only via the Config

Explorer; edit them in the file named by the source, then reinstall with

the dashboard's hook setup if needed.

  • If the dashboard is unreachable at http://localhost:4820, say so and tell

the user to start it with npm start from the repo root.

Other skills for the same job

different authors, same section of the catalogue
Hook Development
by anthropics
vendor ×2

This skill should be used when the user asks to "create a hook", "add a PreToolUse/PostToolUse/Stop hook", "validate tool use", "implement prompt-based hooks", "use ${CLAUDE_PLUGIN_ROOT}", "set up event-driven automation", "block dangerous commands", or mentions hook events (PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, PreCompact, Notification). Provides comprehensive guidance for creating and implementing Claude Code plugin hooks with focus on advanced prompt-based hooks API.

16k tokens scripts
Hook Development
by anthropics
vendor ×2

This skill should be used when the user asks to "create a hook", "add a PreToolUse/PostToolUse/Stop hook", "validate tool use", "implement prompt-based hooks", "use ${CLAUDE_PLUGIN_ROOT}", "set up event-driven automation", "block dangerous commands", or mentions hook events (PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, PreCompact, Notification). Provides comprehensive guidance for creating and implementing Claude Code plugin hooks with focus on advanced prompt-based hooks API.

16k tokens scripts
Copilot SDK
by christophacham
×2

Build agentic applications with GitHub Copilot SDK. Use when embedding AI agents in apps, creating custom tools, implementing streaming responses, managing sessions, connecting to MCP servers, or creating custom agents. Triggers on Copilot SDK, GitHub SDK, agentic app, embed Copilot, programmable agent, MCP server, custom agent.

6k tokens
Cass
by Dicklesworthstone
×2

Coding Agent Session Search - unified CLI/TUI to index and search local coding agent history from Claude Code, Codex, Gemini, Cursor, Aider, ChatGPT, Pi-Agent, Factory, and more. Purpose-built for AI agent consumption with robot mode.

6k tokens
Dcg
by Dicklesworthstone
×2

Destructive Command Guard - High-performance Rust hook for Claude Code that blocks dangerous commands before execution. SIMD-accelerated, modular pack system, whitelist-first architecture. Essential safety layer for agent workflows.

4k tokens
Makepad Skills
by ComeOnOliver
×2

Makepad UI development skills for Rust apps: setup, patterns, shaders, packaging, and troubleshooting.

2k tokens
Varlock Claude Skill
by ComeOnOliver
×2

Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits

3k tokens
Create Agentsmd
by github
vendor ×1

Prompt for generating an AGENTS.md file for a repository

2k tokens

How to use it

Copy the folder

Take hoangsonww/hook-inventory from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.