Agent skill

Hook Inventory

by hoangsonww in hoangsonww/Claude-Code-Agent-Monitor

Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the…

MITAuto-check passed

Install Hook Inventory

skills CLI
$ npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hoangsonww/Claude-Code-Agent-Monitor hook-inventory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hoangsonww/Claude-Code-Agent-Monitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ccam-config/skills/hook-inventory .claude/skills/hook-inventory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hook-inventory
GitHub stars
1.1k
Token cost
~783 tokens
SKILL.md length
361 words
Files
2
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the…

  • Works in 3 steps: Configured hooks by scope → Hook scripts on disk → Safety flags
  • Auditing hook safety
  • SKILL.md covers Input, Data Sources, Report Sections and Output
  • Calls npm

What it does

Hook Inventory is an agent skill from hoangsonww/Claude-Code-Agent-Monitor. Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the network or run arbitrary commands. Reads /api/cc-config/hooks and /api/cc-config/hook-scripts. Use when auditing hook safety.

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

The repository describes itself as: 🚀 A real-time monitoring dashboard for Claude Code & Codex, built with SQLite3, Node.js, Express, React, Vite, TailwindCSS, & WebSockets. It tracks sessions, agent activity… The licence is MIT.

When your agent uses it

  • Auditing hook safety

Example prompts

  • “/hook-inventory”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Configured hooks by scope
  2. Hook scripts on disk
  3. Safety flags

What it can do on your machine

Read from SKILL.md and the folder at commit 1a10d68. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hook Inventory loads about 783 tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 361 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~783

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hoangsonww/Claude-Code-Agent-Monitor at commit 1a10d68, republished under its MIT licence (© hoangsonww). 361 words, ~783 tokens.

Download SKILL.mdSave it as .claude/skills/hook-inventory/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hook-inventory
description
Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the network or run arbitrary commands. Reads /api/cc-config/hooks and /api/cc-config/hook-scripts. Use when auditing hook safety.

Hook Inventory

Catalogue every Claude Code hook the user has configured and assess its safety — read through the Agent Monitor dashboard at http://localhost:4820.

Input

The user provides: $ARGUMENTS

This may be:

  • empty — inventory all hooks across every scope (default).
  • an event name (PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, Notification, PreCompact) — restrict to that event.
  • "scripts" — focus on the ~/.claude/hooks handler scripts dir.

Data Sources

EndpointReturns
GET /api/cc-config/hooks{ items:[{ scope:"user"|"project"|"project-local", file, exists, hooks:{ <Event>:[{ matcher, type, command, timeout }] } }] }
GET /api/cc-config/hook-scripts{ dir, items:[{ name, file, size, mtime }] } — the handler scripts under ~/.claude/hooks/

Report Sections

1. Configured hooks by scope

From /hooks, flatten each source into (scope, file, Event, matcher, type, command, timeout). Group by scope (user, project, project-local). Show the event, matcher, hook type, and the raw command. Note which file each came from so the user can edit the right one.

2. Hook scripts on disk

From /hook-scripts, list each file in ~/.claude/hooks/ with name, size (KB), and mtime. Cross-reference: flag scripts referenced by a hook command but missing from disk, and scripts on disk that no configured hook calls (orphaned).

Show full SKILL.md (179 more words)Show less
3. Safety flags

For every type: "command" entry escalate:

  • Network egress (P0) — the command contains curl, wget, http, https, nc, or pipes output off-box. Print the destination if visible.
  • Arbitrary execution (P1) — pipes to sh/bash, evaluates downloaded content, or runs an unpinned interpreter on attacker-influenceable input.
  • No timeout (P2) — a command hook with timeout: null; it can hang a session indefinitely.
  • Broad matcher (P3) — matcher: "*" or empty on a destructive command.

Output

  • Section 1 as a table (Scope | Event | Matcher | Type | Command | Timeout).
  • Section 3 as a findings table (Hook | Risk | Severity | Detail) with a one-line verdict first (SAFE / REVIEW NEEDED / RISKY HOOKS).
  • Print raw commands verbatim — do not paraphrase a command you are flagging.
  • Cite only fields the API returned — never fabricate hooks or commands.
  • Note: hooks live inside settings.json and are read-only via the Config Explorer; edit them in the file named by the source, then reinstall with the dashboard's hook setup if needed.
  • If the dashboard is unreachable at http://localhost:4820, say so and tell the user to start it with npm start from the repo root.

© hoangsonww, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/ccam-config/skills/hook-inventory of hoangsonww/Claude-Code-Agent-Monitor.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 1a10d68

Compare with similar skills

Hook Inventory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hook Inventory compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hook Inventory this skillhoangsonww/Claude-Code-Agent-Monitor1.1k—~783Automated safety check: PassMIT
Manage Settingsasgeirtj/system_prompts_leaks69k—~3.1kAutomated safety check: PassCC0-1.0
Agent Runtime Lifecycle Hookslobehub/lobehub83k—~2.8kAutomated safety check: PassCustom licence
Plugin Settings Patternanthropics/claude-plugins-official38k7 repos~3kAutomated safety check: PassApache-2.0
Agentmemory Capture Hooksrohitg00/agentmemory29k—~444Automated safety check: PassApache-2.0
Crush Hook Writercharmbracelet/crush29k—~1.8kAutomated safety check: PassCustom licence

Similar skills

  • Manage Settings

    asgeirtj/system_prompts_leaks

    Any explicit Muse Code setting question or change (model, reasoning effort, /settings) requires a silent readskill call for bundled:manage-settings as FIRST ACTION—no assistant text or other tool…

    69k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Registers lifecycle hooks on an agent run to observe, mock or intervene at each step, dispatching them in the order they were registered.

    83k GitHub stars~2.8k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Plugin Settings Pattern

    anthropics/claude-plugins-official

    Official

    Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.

    38k GitHub starsUsed in 7 repos~3k tokens
    Agent WorkflowsAuto-check passed
  • Agentmemory Capture Hooks

    rohitg00/agentmemory

    Describes the lifecycle hooks in the agentmemory Claude Code plugin that record observations automatically, and what to check when observations go missing.

    29k GitHub stars~444 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Crush Hook Writer

    charmbracelet/crush

    Helps write, debug and configure Crush hooks in crush.json that block, approve or rewrite tool calls before they run.

    29k GitHub stars~1.8k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes

More from hoangsonww/Claude-Code-Agent-Monitor

All 78 skills in this repo
  • Budget Set

    hoangsonww/Claude-Code-Agent-Monitor

    Define a spend budget for Claude Code and, optionally, create a cost alert rule that fires when usage crosses the limit, via POST /api/alerts/rules on the Agent Monitor dashboard.

    1.1k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Version Release

    hoangsonww/Claude-Code-Agent-Monitor

    Choose and apply the correct semantic version bump for this repository.

    1.1k GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Cost Breakdown

    hoangsonww/Claude-Code-Agent-Monitor

    Break down Claude Code costs using the Agent Monitor pricing engine.

    1.1k GitHub starsUsed in 1 repo~845 tokens
    Auto-check passed
  • File Headers

    hoangsonww/Claude-Code-Agent-Monitor

    MANDATORY for every coding agent (Claude Code, Codex, or any other) on every change-set — every applicable source file the agent creates or updates MUST start with the project's copyright/authorship…

    1.1k GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Hook Diagnostics

    hoangsonww/Claude-Code-Agent-Monitor

    Diagnose Claude Code hook installation, delivery, and ingestion issues.

    1.1k GitHub starsUsed in 1 repo~676 tokens
    Auto-check passed
  • Memory Review

    hoangsonww/Claude-Code-Agent-Monitor

    Review the file-based memory store via the Agent Monitor Config Explorer API: the user and project CLAUDE.md plus per-project auto-memory files under ~/.claude/projects/<slug/memory/.md.

    1.1k GitHub starsUsed in 1 repo~970 tokens
    Auto-check passed

Questions about Hook Inventory

What does Hook Inventory do?

Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the…. Hook Inventory is an agent skill from hoangsonww/Claude-Code-Agent-Monitor.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the network or run arbitrary commands.

When should I use Hook Inventory?

Hook Inventory fits situations like: auditing hook safety.

How do I install Hook Inventory in Claude Code?

Run `npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory -a claude-code`. Or copy the skill folder (plugins/ccam-config/skills/hook-inventory in hoangsonww/Claude-Code-Agent-Monitor) into .claude/skills/hook-inventory in your project. Claude Code loads it when a task matches its description.

How do I install Hook Inventory in Codex?

Run `npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory -a codex`. Or copy the skill folder (plugins/ccam-config/skills/hook-inventory in hoangsonww/Claude-Code-Agent-Monitor) into .agents/skills/hook-inventory in your project. Codex loads it when a task matches its description.

Can I use Hook Inventory in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hook-inventory, .gemini/skills/hook-inventory, .github/skills/hook-inventory and .opencode/skills/hook-inventory in your project.

What does Hook Inventory need to run?

Going by SKILL.md and its folder, Hook Inventory needs the command-line tools its instructions call (npm).

Does Hook Inventory access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Hook Inventory safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hook Inventory use?

Hook Inventory is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hook Inventory use?

About 783 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hook Inventory?

Skills that share tags, products or a category with Hook Inventory: Manage Settings (asgeirtj/system_prompts_leaks, 69k stars), Agent Runtime Lifecycle Hooks (lobehub/lobehub, 83k stars), Plugin Settings Pattern (anthropics/claude-plugins-official, 38k stars) and Agentmemory Capture Hooks (rohitg00/agentmemory, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hook Inventory?

hoangsonww (a GitHub user) maintains it in hoangsonww/Claude-Code-Agent-Monitor, which has 1,054 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 8, 2026.

Source: hoangsonww/Claude-Code-Agent-Monitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.