Create Plugin
ruvnet/ruflo
Scaffold a new Claude Code plugin with proper directory structure, plugin.json, skills, commands, and agents
Expert guidance for writing secure, reliable, and performant Claude Code hooks - validates design decisions, enforces best practices, and prevents common pitfalls.
$ npx skills add secondsky/claude-skills --skill claude-hook-writer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install secondsky/claude-skills claude-hook-writer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/claude-hook-writer/skills/claude-hook-writer .claude/skills/claude-hook-writer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "claude-hook-writer" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/claude-hook-writer/skills/claude-hook-writer into .claude/skills/claude-hook-writer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "claude-hook-writer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/secondsky/claude-skills/tree/main/plugins/claude-hook-writer/skills/claude-hook-writerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add secondsky/claude-skills --skill claude-hook-writer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install secondsky/claude-skills claude-hook-writer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/claude-hook-writer/skills/claude-hook-writer .agents/skills/claude-hook-writer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "claude-hook-writer" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/claude-hook-writer/skills/claude-hook-writer into .agents/skills/claude-hook-writer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "claude-hook-writer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add secondsky/claude-skills --skill claude-hook-writer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install secondsky/claude-skills claude-hook-writer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/claude-hook-writer/skills/claude-hook-writer .cursor/skills/claude-hook-writer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "claude-hook-writer" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/claude-hook-writer/skills/claude-hook-writer into .cursor/skills/claude-hook-writer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "claude-hook-writer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/secondsky/claude-skills.git --path plugins/claude-hook-writer/skills/claude-hook-writer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add secondsky/claude-skills --skill claude-hook-writer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install secondsky/claude-skills claude-hook-writer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/claude-hook-writer/skills/claude-hook-writer .gemini/skills/claude-hook-writer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "claude-hook-writer" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/claude-hook-writer/skills/claude-hook-writer into .gemini/skills/claude-hook-writer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "claude-hook-writer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install secondsky/claude-skills claude-hook-writerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add secondsky/claude-skills --skill claude-hook-writer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/claude-hook-writer/skills/claude-hook-writer .github/skills/claude-hook-writer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "claude-hook-writer" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/claude-hook-writer/skills/claude-hook-writer into .github/skills/claude-hook-writer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "claude-hook-writer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add secondsky/claude-skills --skill claude-hook-writer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install secondsky/claude-skills claude-hook-writer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/claude-hook-writer/skills/claude-hook-writer .opencode/skills/claude-hook-writer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "claude-hook-writer" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/claude-hook-writer/skills/claude-hook-writer into .opencode/skills/claude-hook-writer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "claude-hook-writer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
claude-hook-writerExpert guidance for writing secure, reliable, and performant Claude Code hooks - validates design decisions, enforces best practices, and prevents common pitfalls.
Claude Hook Writer is an agent skill from secondsky/claude-skills. Expert guidance for writing secure, reliable, and performant Claude Code hooks - validates design decisions, enforces best practices, and prevents common pitfalls. Use when creating, reviewing, or debugging Claude Code hooks.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/code-templates.md`, `references/publishing-guide.md` and `references/quick-reference.md`).
It sits in Agent Workflows, covering Hooks and plugins and Architecture decision records. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqprettiernpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.claude.comprpm.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Hook Writer loads about 3.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 1,254 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
if [[ $FILE == ".env" ]]; thenecho "Don't edit .env" >&2if [[ $FILE == ".env" ]]; thenecho "Blocked: .env is protected" >&2✅ Block sensitive files (`.env`, `*.key`, credentials)- Blocking sensitive files (`.env`, keys, credentials)- [ ] Blocks sensitive files (`.env`, `*.key`, etc.)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 1,254 words, ~3,148 tokens.
.claude/skills/claude-hook-writer/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Status: Production Ready Version: 2.0.0 (Optimized with progressive disclosure) Last Updated: 2025-12-17
Expert guidance for writing secure, reliable, and performant Claude Code hooks. This skill validates design decisions, enforces best practices, and prevents common pitfalls.
Hooks execute automatically with user permissions and can read, modify, or delete any file the user can access.
ALWAYS validate and sanitize all input. Hooks receive JSON via stdin—never trust it blindly.
For complete security patterns: Load references/security-requirements.md when implementing validation or securing hooks.
A hook that works 99% of the time is a broken hook. Edge cases (Unicode filenames, spaces in paths, missing tools) will happen.
Test with edge cases before deploying.
For reliability patterns: Load references/reliability-performance.md when handling errors or edge cases.
Hooks block operations. A 5-second hook means Claude waits 5 seconds before continuing.
Keep hooks fast. Run heavy operations in background.
For performance optimization: Load references/reliability-performance.md when optimizing hook speed.
Missing dependencies, malformed input, and disk errors will occur.
Handle errors explicitly. Log failures. Return meaningful exit codes.
Before writing code, answer these questions:
PreToolUse - Before tool execution (modify input, validate, block)PostToolUse - After tool completes (format, log, cleanup)UserPromptSubmit - Before user input processes (validate, enhance)SessionStart - When Claude Code starts (setup, env check)SessionEnd - When Claude Code exits (cleanup, persist state)Notification - During alerts (desktop notifications, logging)Stop / SubagentStop - When responses finish (cleanup, summary)PreCompact - Before context compaction (save important context)Common mistake: Using PostToolUse for validation (too late—tool already ran). Use PreToolUse to block operations.
Be specific. matcher: "*" runs on every tool call.
Good matchers:
"Write" - Only file writes"Edit|Write" - File modifications"Bash" - Shell commands"mcp__github__*" - All GitHub MCP toolsBad matchers:
"*" - Everything (use only for logging/metrics)Different tools provide different input. Check what's available:
# PreToolUse / PostToolUse
{
"input": {
"file_path": "/path/to/file.ts", // Read, Write, Edit
"command": "npm test", // Bash
"old_string": "...", // Edit
"new_string": "..." // Edit
}
}Validate fields exist before using them:
FILE=$(echo "$INPUT" | jq -r '.input.file_path // empty')
if [[ -z "$FILE" ]]; then
echo "No file path provided" >&2
exit 1
fiCommand hooks (type: "command"):
Prompt hooks (type: "prompt"):
Rule of thumb: Use command hooks unless you need LLM reasoning.
exit 0 - Success (continue operation)exit 2 - Block operation (show error to Claude)exit 1 or other - Non-blocking error (log but continue)For PreToolUse hooks:
For PostToolUse hooks:
Error: Hooks break on filenames with spaces or special characters
Why: Unquoted variables split on whitespace
Example:
# ❌ WRONG - breaks on "my file.txt"
cat $FILE
prettier --write $FILE
rm $FILE
# ✅ RIGHT - handles spaces and special chars
cat "$FILE"
prettier --write "$FILE"
rm "$FILE"Why this matters: Files with spaces ("my file.txt"), Unicode ("文件.txt"), or special chars ("file (1).txt") are common.
For quoting best practices: Load references/security-requirements.md for comprehensive input handling patterns.
Error: Hook executes on malicious or malformed input
Why: Not validating JSON fields before using them
Example:
# ❌ DANGEROUS - no validation
FILE=$(jq -r '.input.file_path')
rm "$FILE" # Could delete ../../../etc/passwd
# ✅ SAFE - validate first
FILE=$(jq -r '.input.file_path // empty')
[[ -n "$FILE" ]] || exit 1
[[ "$FILE" == "$CLAUDE_PROJECT_DIR"* ]] || exit 2
[[ "$FILE" != *".."* ]] || exit 2
rm "$FILE"Why this matters: Prevents path traversal attacks, protects files outside project, prevents malformed input crashes.
For complete security patterns: Load references/security-requirements.md.
Error: Hook takes 30+ seconds, blocking Claude
Why: Running expensive operations (tests, builds) synchronously in hook
Example:
# ❌ BLOCKS Claude for 30 seconds
npm test
npm run build
# ✅ RUN IN BACKGROUND - returns immediately
(npm test > /tmp/test-results.log 2>&1 &)
(npm run build > /tmp/build.log 2>&1 &)
exit 0Why this matters: Slow hooks create bad user experience. Target < 100ms for PreToolUse, < 500ms for PostToolUse.
For performance optimization: Load references/reliability-performance.md.
Error: PreToolUse hook doesn't actually block the operation
Why: Using exit 1 instead of exit 2
Example:
# ❌ WRONG - logs error but doesn't block
if [[ $FILE == ".env" ]]; then
echo "Don't edit .env" >&2
exit 1 # Tool still runs!
fi
# ✅ RIGHT - actually blocks
if [[ $FILE == ".env" ]]; then
echo "Blocked: .env is protected" >&2
exit 2 # Tool is blocked
fiWhy this matters: Exit 1 only logs errors. Exit 2 is required to block in PreToolUse hooks.
For exit code patterns: Load references/hook-templates.md for complete hook response patterns.
Error: Hook crashes when dependency is missing
Why: Not checking if tool is installed before using
Example:
# ❌ BREAKS if prettier not installed
prettier --write "$FILE"
# ✅ SAFE - check first
if command -v prettier &>/dev/null; then
prettier --write "$FILE"
else
echo "prettier not installed, skipping" >&2
exit 0 # Success exit, just skip
fiWhy this matters: Users may not have all tools installed. Hooks should degrade gracefully.
For reliability patterns: Load references/reliability-performance.md.
✅ Validate all JSON input before using (jq -r '... // empty')
✅ Quote all variables containing paths or user input
✅ Use absolute paths for scripts (${CLAUDE_PLUGIN_ROOT}/...)
✅ Block sensitive files (.env, *.key, credentials)
✅ Check if required tools exist (command -v toolname)
✅ Set reasonable timeouts (< 5s for PreToolUse)
✅ Run heavy operations in background
✅ Test with edge cases (spaces, Unicode, special chars)
✅ Use exit 2 to block in PreToolUse hooks
✅ Log errors to stderr or file, not stdout
❌ Trust JSON input without validation
❌ Use unquoted variables ($FILE instead of "$FILE")
❌ Use relative paths for scripts
❌ Skip path sanitization (check for .., validate in project)
❌ Assume tools are installed
❌ Block for > 1 second in PreToolUse hooks
❌ Use exit 1 when you mean to block (use exit 2)
❌ Log sensitive data to stdout or files
❌ Use matcher: "*" unless truly necessary
Load reference files when working on specific hook aspects:
references/security-requirements.md)Load when:
.env, keys, credentials)references/reliability-performance.md)Load when:
references/code-templates.md)Load when:
references/testing-debugging.md)Load when:
references/publishing-guide.md)Load when:
continue, stopReason, suppressOutput, systemMessagereferences/quick-reference.md)Load when:
Before publishing a hook:
.env, *.key, etc.)This skill includes 6 reference files for on-demand loading:
Security & Reliability (2 files):
security-requirements.md - Input validation, path sanitization, blocking sensitive filesreliability-performance.md - Error handling, timeouts, performance optimizationImplementation (2 files):
code-templates.md - Working hook examples (format-on-save, block-sensitive, logger, etc.)quick-reference.md - Fast syntax lookup (exit codes, jq patterns, environment vars)Testing & Publishing (2 files):
testing-debugging.md - Test patterns, edge cases, debugging techniquespublishing-guide.md - PRPM packaging, advanced configuration, README templateLoad references on-demand when specific knowledge is needed. See "When to Load References" section for triggers.
Last verified: 2025-12-17 | Version: 2.0.0
© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in plugins/claude-hook-writer/skills/claude-hook-writer of secondsky/claude-skills.
Open the folder on GitHubat commit 8837836
Claude Hook Writer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Claude Hook Writer this skillsecondsky/claude-skills | 227 | — | ~3.1k | Automated safety check: Notes | MIT | |
| Create Pluginruvnet/ruflo | 74k | — | ~1.4k | Automated safety check: Notes | MIT | |
| Claude Hook Writerpr-pm/prpm | 122 | — | ~5k | Automated safety check: Notes | MIT | |
| Claude Code Plugin Structureanthropics/claude-plugins-official | 38k | 10 repos | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Crush Configurationcharmbracelet/crush | 29k | — | ~3.7k | Automated safety check: Pass | Custom licence | |
| Plate Plugin Creatorudecode/plate | 17k | — | ~2.3k | Automated safety check: Pass | Custom licence |
ruvnet/ruflo
Scaffold a new Claude Code plugin with proper directory structure, plugin.json, skills, commands, and agents
pr-pm/prpm
Expert guidance for writing secure, reliable, and performant Claude Code hooks - validates design decisions, enforces best practices, and prevents common pitfalls
anthropics/claude-plugins-official
Explains the directory layout, plugin.json manifest and component organization of a Claude Code plugin, including auto-discovery and portable paths.
charmbracelet/crush
Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.
udecode/plate
Build new Plate plugins with Slate-first architecture, sane typing, and explicit React/Plate wrapper boundaries.
agent-sh/agentsys
Maintainer guide to where AgentSys keeps its marketplace, installer, transforms and adapters, and what to run when preparing a release or fixing a platform bug.
secondsky/claude-skills
TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.
secondsky/claude-skills
AutoAnimate (@formkit/auto-animate) zero-config animations for React.
secondsky/claude-skills
MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.
secondsky/claude-skills
This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…
secondsky/claude-skills
Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).
secondsky/claude-skills
Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.
Categories
Expert guidance for writing secure, reliable, and performant Claude Code hooks - validates design decisions, enforces best practices, and prevents common pitfalls. Claude Hook Writer is an agent skill from secondsky/claude-skills. Expert guidance for writing secure, reliable, and performant Claude Code hooks - validates design decisions, enforces best practices, and prevents common pitfalls.
Claude Hook Writer fits situations like: debugging Claude Code hooks; tasks that involve Hooks and plugins; tasks that involve Architecture decision records.
Run `npx skills add secondsky/claude-skills --skill claude-hook-writer -a claude-code`. Or copy the skill folder (plugins/claude-hook-writer/skills/claude-hook-writer in secondsky/claude-skills) into .claude/skills/claude-hook-writer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add secondsky/claude-skills --skill claude-hook-writer -a codex`. Or copy the skill folder (plugins/claude-hook-writer/skills/claude-hook-writer in secondsky/claude-skills) into .agents/skills/claude-hook-writer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill claude-hook-writer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/claude-hook-writer, .gemini/skills/claude-hook-writer, .github/skills/claude-hook-writer and .opencode/skills/claude-hook-writer in your project.
Going by SKILL.md and its folder, Claude Hook Writer needs the command-line tools its instructions call (jq, prettier and npm).
SKILL.md names 2 domains. As links in the text: docs.claude.com and prpm.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Claude Hook Writer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Claude Hook Writer: Create Plugin (ruvnet/ruflo, 74k stars), Claude Hook Writer (pr-pm/prpm, 122 stars), Claude Code Plugin Structure (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.
Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.