Official agent skill

Writing Hookify Rules

by anthropics in anthropics/claude-plugins-official

Explains the hookify rule file format: markdown with YAML frontmatter that watches bash commands, file edits, prompts or stop events and warns or blocks.

OfficialApache-2.0Auto-check: notesAgent Workflows

Install Writing Hookify Rules

skills CLI
$ npx skills add anthropics/claude-plugins-official --skill writing-hookify-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-plugins-official writing-hookify-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-plugins-official.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/hookify/skills/writing-rules .claude/skills/writing-hookify-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
writing-hookify-rules
GitHub stars
38k
Used in
6 other repos
Token cost
~2.1k tokens
SKILL.md length
639 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Explains the hookify rule file format: markdown with YAML frontmatter that watches bash commands, file edits, prompts or stop events and warns or blocks.

  • Works in 6 steps: Identify unwanted behavior → Determine which tool is involved (Bash,… → Choose event type (bash, file, stop, etc.) → …
  • Creating a rule that warns before dangerous rm commands
  • SKILL.md covers Overview, Rule File Format, Message Body and Event Type Guide, plus 5 more sections
  • Calls python3; needs API_KEY

What it does

Hookify rules are markdown files with YAML frontmatter, kept in `.claude/` as files named `hookify.` plus the rule name and `.local.md`. The frontmatter has a kebab-case `name` that starts with a verb such as warn or block, an `enabled` flag, an `event` (`bash`, `file`, `stop`, `prompt` or `all`) and an optional `action` that is either `warn`, the default, or `block`. A simple rule adds one `pattern`, a Python regex matched against the command for bash events or the new text for file events.

More complex rules list several conditions, each with a field (such as `command`, `file_path`, `new_text`, `old_text` or `content`), an operator (`regex_match`, `contains`, `equals`, `not_contains`, `starts_with` or `ends_with`) and a pattern, and all of them must match for the rule to trigger. The markdown body after the frontmatter is the message shown to Claude, and a good one says what was detected, why it is a problem and what to do instead. The excerpt ends in the event type guide, so later sections are not described.

When your agent uses it

  • Creating a rule that warns before dangerous rm commands
  • Blocking console.log or other patterns from being written into code
  • Toggling or editing an existing hookify rule
  • Looking up hookify frontmatter fields and operators

Example prompts

  • “Create a hookify rule that warns when a command contains rm -rf.”
  • “Write a hookify rule that blocks edits to .env files.”
  • “Add a hookify rule that stops console.log from being added to production code.”

Requirements

  • The hookify plugin for Claude Code

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify unwanted behavior
  2. Determine which tool is involved (Bash, Edit, etc.)
  3. Choose event type (bash, file, stop, etc.)
  4. Write regex pattern
  5. Create .claude/hookify.{name}.local.md file in project root
  6. Test immediately - rules are read dynamically on next tool use

What it can do on your machine

Read from SKILL.md and the folder at commit b78ac49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Writing Hookify Rules loads about 2.1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 639 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:82
    You're adding an API key to a .env file. Ensure this file is in .gitignore!
  • NoteMentions a .env fileSKILL.md:327
    s-warning.local.md` - Warn about editing .env files

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-plugins-official at commit b78ac49, republished under its Apache-2.0 licence (© anthropics). 639 words, ~2,104 tokens.

Download SKILL.mdSave it as .claude/skills/writing-hookify-rules/SKILL.md (or your agent's skills folder).
name
writing-hookify-rules
description
This skill should be used when the user asks to "create a hookify rule", "write a hook rule", "configure hookify", "add a hookify rule", or needs guidance on hookify rule syntax and patterns.
version
0.1.0

Writing Hookify Rules

Overview

Hookify rules are markdown files with YAML frontmatter that define patterns to watch for and messages to show when those patterns match. Rules are stored in .claude/hookify.{rule-name}.local.md files.

Rule File Format

Basic Structure
markdown
---
name: rule-identifier
enabled: true
event: bash|file|stop|prompt|all
pattern: regex-pattern-here
---

Message to show Claude when this rule triggers.
Can include markdown formatting, warnings, suggestions, etc.
Frontmatter Fields

name (required): Unique identifier for the rule

  • Use kebab-case: warn-dangerous-rm, block-console-log
  • Be descriptive and action-oriented
  • Start with verb: warn, prevent, block, require, check

enabled (required): Boolean to activate/deactivate

  • true: Rule is active
  • false: Rule is disabled (won't trigger)
  • Can toggle without deleting rule

event (required): Which hook event to trigger on

  • bash: Bash tool commands
  • file: Edit, Write, MultiEdit tools
  • stop: When agent wants to stop
  • prompt: When user submits a prompt
  • all: All events

action (optional): What to do when rule matches

  • warn: Show message but allow operation (default)
  • block: Prevent operation (PreToolUse) or stop session (Stop events)
  • If omitted, defaults to warn

pattern (simple format): Regex pattern to match

  • Used for simple single-condition rules
  • Matches against command (bash) or new_text (file)
  • Python regex syntax

Example:

yaml
event: bash
pattern: rm\s+-rf
Advanced Format (Multiple Conditions)

For complex rules with multiple conditions:

markdown
---
name: warn-env-file-edits
enabled: true
event: file
conditions:
  - field: file_path
    operator: regex_match
    pattern: \.env$
  - field: new_text
    operator: contains
    pattern: API_KEY
---

You're adding an API key to a .env file. Ensure this file is in .gitignore!

Condition fields:

  • field: Which field to check
    • For bash: command
    • For file: file_path, new_text, old_text, content
  • operator: How to match
    • regex_match: Regex pattern matching
    • contains: Substring check
    • equals: Exact match
    • not_contains: Substring must NOT be present
    • starts_with: Prefix check
    • ends_with: Suffix check
  • pattern: Pattern or string to match

All conditions must match for rule to trigger.

Message Body

The markdown content after frontmatter is shown to Claude when the rule triggers.

Good messages:

  • Explain what was detected
  • Explain why it's problematic
  • Suggest alternatives or best practices
  • Use formatting for clarity (bold, lists, etc.)

Example:

markdown
⚠️ **Console.log detected!**

You're adding console.log to production code.

**Why this matters:**
- Debug logs shouldn't ship to production
- Console.log can expose sensitive data
- Impacts browser performance

**Alternatives:**
- Use a proper logging library
- Remove before committing
- Use conditional debug builds

Event Type Guide

bash Events

Match Bash command patterns:

markdown
---
event: bash
pattern: sudo\s+|rm\s+-rf|chmod\s+777
---

Dangerous command detected!

Common patterns:

  • Dangerous commands: rm\s+-rf, dd\s+if=, mkfs
  • Privilege escalation: sudo\s+, su\s+
  • Permission issues: chmod\s+777, chown\s+root
file Events

Match Edit/Write/MultiEdit operations:

markdown
---
event: file
pattern: console\.log\(|eval\(|innerHTML\s*=
---

Potentially problematic code pattern detected!

Match on different fields:

markdown
---
event: file
conditions:
  - field: file_path
    operator: regex_match
    pattern: \.tsx?$
  - field: new_text
    operator: regex_match
    pattern: console\.log\(
---

Console.log in TypeScript file!

Common patterns:

  • Debug code: console\.log\(, debugger, print\(
  • Security risks: eval\(, innerHTML\s*=, dangerouslySetInnerHTML
  • Sensitive files: \.env$, credentials, \.pem$
  • Generated files: node_modules/, dist/, build/
stop Events

Match when agent wants to stop (completion checks):

markdown
---
event: stop
pattern: .*
---

Before stopping, verify:
- [ ] Tests were run
- [ ] Build succeeded
- [ ] Documentation updated

Use for:

  • Reminders about required steps
  • Completion checklists
  • Process enforcement
prompt Events

Match user prompt content (advanced):

markdown
---
event: prompt
conditions:
  - field: user_prompt
    operator: contains
    pattern: deploy to production
---

Production deployment checklist:
- [ ] Tests passing?
- [ ] Reviewed by team?
- [ ] Monitoring ready?

Pattern Writing Tips

Regex Basics

Literal characters: Most characters match themselves

  • rm matches "rm"
  • console.log matches "console.log"

Special characters need escaping:

  • . (any char) → \. (literal dot)
  • ( ) → \( \) (literal parens)
  • [ ] → \[ \] (literal brackets)

Common metacharacters:

  • \s - whitespace (space, tab, newline)
  • \d - digit (0-9)
  • \w - word character (a-z, A-Z, 0-9, _)
  • . - any character
  • + - one or more
  • * - zero or more
  • ? - zero or one
  • | - OR

Examples:

rm\s+-rf         Matches: rm -rf, rm  -rf
console\.log\(   Matches: console.log(
(eval|exec)\(    Matches: eval( or exec(
chmod\s+777      Matches: chmod 777, chmod  777
API_KEY\s*=      Matches: API_KEY=, API_KEY =
Show full SKILL.md (229 more words)Show less
Testing Patterns

Test regex patterns before using:

bash
python3 -c "import re; print(re.search(r'your_pattern', 'test text'))"

Or use online regex testers (regex101.com with Python flavor).

Common Pitfalls

Too broad:

yaml
pattern: log    # Matches "log", "login", "dialog", "catalog"

Better: console\.log\(|logger\.

Too specific:

yaml
pattern: rm -rf /tmp  # Only matches exact path

Better: rm\s+-rf

Escaping issues:

  • YAML quoted strings: "pattern" requires double backslashes \\s
  • YAML unquoted: pattern: \s works as-is
  • Recommendation: Use unquoted patterns in YAML

File Organization

Location: All rules in .claude/ directory Naming: .claude/hookify.{descriptive-name}.local.md Gitignore: Add .claude/*.local.md to .gitignore

Good names:

  • hookify.dangerous-rm.local.md
  • hookify.console-log.local.md
  • hookify.require-tests.local.md
  • hookify.sensitive-files.local.md

Bad names:

  • hookify.rule1.local.md (not descriptive)
  • hookify.md (missing .local)
  • danger.local.md (missing hookify prefix)

Workflow

Creating a Rule
  1. Identify unwanted behavior
  2. Determine which tool is involved (Bash, Edit, etc.)
  3. Choose event type (bash, file, stop, etc.)
  4. Write regex pattern
  5. Create .claude/hookify.{name}.local.md file in project root
  6. Test immediately - rules are read dynamically on next tool use
Refining a Rule
  1. Edit the .local.md file
  2. Adjust pattern or message
  3. Test immediately - changes take effect on next tool use
Disabling a Rule

Temporary: Set enabled: false in frontmatter Permanent: Delete the .local.md file

Examples

See ${CLAUDE_PLUGIN_ROOT}/examples/ for complete examples:

  • dangerous-rm.local.md - Block dangerous rm commands
  • console-log-warning.local.md - Warn about console.log
  • sensitive-files-warning.local.md - Warn about editing .env files

Quick Reference

Minimum viable rule:

markdown
---
name: my-rule
enabled: true
event: bash
pattern: dangerous_command
---

Warning message here

Rule with conditions:

markdown
---
name: my-rule
enabled: true
event: file
conditions:
  - field: file_path
    operator: regex_match
    pattern: \.ts$
  - field: new_text
    operator: contains
    pattern: any
---

Warning message

Event types:

  • bash - Bash commands
  • file - File edits
  • stop - Completion checks
  • prompt - User input
  • all - All events

Field options:

  • Bash: command
  • File: file_path, new_text, old_text, content
  • Prompt: user_prompt

Operators:

  • regex_match, contains, equals, not_contains, starts_with, ends_with

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/hookify/skills/writing-rules of anthropics/claude-plugins-official.

Open the folder on GitHubat commit b78ac49

Used in 6 other repositories

We found 24 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 6 other GitHub owners. This page covers the copy in anthropics/claude-plugins-official, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Writing Hookify Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Writing Hookify Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Writing Hookify Rules this skillanthropics/claude-plugins-official38k6 repos~2.1kAutomated safety check: NotesApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Plate Plugin Creatorudecode/plate17k—~2.3kAutomated safety check: PassCustom licence
AgentSys Cross-Platform Maintenanceagent-sh/agentsys994—~1.2kAutomated safety check: PassMIT
Readyprekuter/dryforge4101 repos~6.8kAutomated safety check: PassApache-2.0
Agent Setup Health Audittw93/Waza7.2k—~5.2kAutomated safety check: NotesMIT

Similar skills

  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Build new Plate plugins with Slate-first architecture, sane typing, and explicit React/Plate wrapper boundaries.

    17k GitHub stars~2.3k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Maintainer guide to where AgentSys keeps its marketplace, installer, transforms and adapters, and what to run when preparing a release or fixing a platform bug.

    994 GitHub stars~1.2k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Ready

    prekuter/dryforge

    Understand what you mean before anything is built. An agent skill from prekuter/dryforge.

    410 GitHub starsUsed in 1 repo~6.8k tokens
    Agent WorkflowsAuto-check passed
  • Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

    7.2k GitHub stars~5.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Writing Plugins

    nukeop/nuclear

    A skill your agent uses when writing, scaffolding, or modifying Nuclear plugins.

    19k GitHub stars~825 tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed

More from anthropics/claude-plugins-official

All 29 skills in this repo
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 11 repos~4.1k tokens
    Auto-check: notes
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 8 repos~2.8k tokens
    Auto-check passed
  • Plugin Settings Pattern

    anthropics/claude-plugins-official

    Official

    Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.

    38k GitHub starsUsed in 7 repos~3k tokens
    Auto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Auto-check passed
  • Claude Code Command Development

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code slash commands: Markdown files with YAML frontmatter, arguments, file references, bash context and interactive prompts.

    38k GitHub starsUsed in 10 repos~4.8k tokens
    Auto-check passed
  • Claude Code Plugin Structure

    anthropics/claude-plugins-official

    Official

    Explains the directory layout, plugin.json manifest and component organization of a Claude Code plugin, including auto-discovery and portable paths.

    38k GitHub starsUsed in 10 repos~3.4k tokens
    Auto-check passed

Questions about Writing Hookify Rules

What does Writing Hookify Rules do?

Explains the hookify rule file format: markdown with YAML frontmatter that watches bash commands, file edits, prompts or stop events and warns or blocks. md`. The frontmatter has a kebab-case `name` that starts with a verb such as warn or block, an `enabled` flag, an `event` (`bash`, `file`, `stop`, `prompt` or `all`) and an optional `action` that is either `warn`, the default, or `block`.

When should I use Writing Hookify Rules?

Writing Hookify Rules fits situations like: creating a rule that warns before dangerous rm commands; blocking console.log or other patterns from being written into code; toggling or editing an existing hookify rule; looking up hookify frontmatter fields and operators.

How do I install Writing Hookify Rules in Claude Code?

Run `npx skills add anthropics/claude-plugins-official --skill writing-hookify-rules -a claude-code`. Or copy the skill folder (plugins/hookify/skills/writing-rules in anthropics/claude-plugins-official) into .claude/skills/writing-hookify-rules in your project. Claude Code loads it when a task matches its description.

How do I install Writing Hookify Rules in Codex?

Run `npx skills add anthropics/claude-plugins-official --skill writing-hookify-rules -a codex`. Or copy the skill folder (plugins/hookify/skills/writing-rules in anthropics/claude-plugins-official) into .agents/skills/writing-hookify-rules in your project. Codex loads it when a task matches its description.

Can I use Writing Hookify Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-plugins-official --skill writing-hookify-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/writing-hookify-rules, .gemini/skills/writing-hookify-rules, .github/skills/writing-hookify-rules and .opencode/skills/writing-hookify-rules in your project.

What does Writing Hookify Rules need to run?

Going by SKILL.md and its folder, Writing Hookify Rules needs the command-line tools its instructions call (python3) and credentials named API_KEY. Our summary lists: The hookify plugin for Claude Code.

Does Writing Hookify Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Writing Hookify Rules safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Writing Hookify Rules use?

Writing Hookify Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Writing Hookify Rules use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Writing Hookify Rules?

Skills that share tags, products or a category with Writing Hookify Rules: Crush Configuration (charmbracelet/crush, 29k stars), Plate Plugin Creator (udecode/plate, 17k stars), AgentSys Cross-Platform Maintenance (agent-sh/agentsys, 994 stars) and Ready (prekuter/dryforge, 410 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Writing Hookify Rules?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-plugins-official, which has 37,509 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 8, 2026.

Source: anthropics/claude-plugins-official on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.