Claude Operator: Prompt to Autonomy · 22 min · 140 XP

Hooks are code you are choosing to run

Shell commands wired to events — powerful, and worth reading before enabling.

A hook is a shell command Claude Code runs when something happens: before a tool call, after an edit, when a session needs input. They're configured in settings with an event and a matcher deciding which tool calls they apply to.

Format every file after it's edited
{
  "hooks": {
    "PostToolUse": [
      {
        "matcher": "Edit|Write",
        "hooks": [
          { "type": "command", "command": "npx prettier --write $FILE" }
        ]
      }
    ]
  }
}

Read a hook before enabling it, especially one you didn't write. It's a shell command that will run automatically, on your machine, with your permissions. What does it execute, when does it fire, what does it touch, does it reach the network, and what happens when it fails? A hook in a repository you cloned is code you're agreeing to run.

The two useful shapes are a formatting hook (PostToolUse, tidy what was just edited) and a protective hook (PreToolUse, reject something unsafe). Protective hooks are strong: a PreToolUse hook that exits with code 2 stops the tool call before permission rules are evaluated, so it blocks even something an allow rule would have permitted. That makes it the right tool for "allow Bash generally, but never these specific commands".

They don't loosen anything, though. Hook decisions don't bypass permission rules — a matching deny rule still blocks the call, and a matching ask rule still prompts, even if the hook returned allow. Hooks can tighten; they can't override a deny.

Two failure modes to design out. Recursion: a formatting hook that edits a file can trigger the event that runs it again, so guard against re-entry or scope the matcher tightly. And noise: a hook that prints its whole output on every edit buries the one message that mattered. Reduce it to an actionable error and the minimum context — a concise failure with a next step is what makes a hook something you keep.

Practice. Inspect a sample hook's command, trigger, inputs, outputs and failure behaviour, and list every external side effect. Add a bounded formatting hook to a disposable project and confirm it touches only the intended files and surfaces failures. Add a protective hook that rejects one clearly defined unsafe action with a useful message, and check one unsafe test is blocked while a safe one passes. Verify your hook can't retrigger itself indefinitely, then cut its output down to an actionable error with a next step.

Loading your workspace…