SkillAgentSearch skills...

hook-inventory

Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the network or run arbitrary commands. Reads /api/cc-config/hooks and /api/cc-config/hook-scripts

Install / Use

npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

85/100

Category

Operations

Supported Platforms

Claude Code

Our assessment of hook-inventory

hook-inventory scores 85/100 on our quality scale, 485th of 736 Operations skills we index.

Its SKILL.md is 3.1 KB long, well organised into 8 sections and no code examples: a solid amount of guidance for an agent.

With 1,015 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
13/20
Description
15/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 12 days ago, so hook-inventory is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

hook-inventory compared with similar skills

All 4 of these similar skills score higher than hook-inventory; compare them before choosing.

SkillScoreStarsUpdatedFormat
hook-inventory (this skill)by hoangsonww851.0k12d agoSKILL.md
Agent-Reachby Panniantong10092.4k21d agoCLAUDE.md
headroomby headroomlabs-ai10074.5ktodayCLAUDE.md
Scraplingby D4Vinci10085.9ktodayMCP Server
crawl4aiby unclecode10084.8k1d agoMCP Server

Frequently asked questions

How do I install hook-inventory?
Run npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill hook-inventory. The install tabs above show the steps for each supported agent.
Which AI agents does hook-inventory work with?
It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
Is hook-inventory safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is hook-inventory still maintained?
The repository was last updated 12 days ago, so hook-inventory is actively maintained.

name: hook-inventory description: > Inventory hooks across the user, project, and project-local settings plus the ~/.claude/hooks scripts directory — read through the Agent Monitor Config Explorer API — and flag hooks that POST to the network or run arbitrary commands. Reads /api/cc-config/hooks and /api/cc-config/hook-scripts. Use when auditing hook safety.

Hook Inventory

Catalogue every Claude Code hook the user has configured and assess its safety — read through the Agent Monitor dashboard at http://localhost:4820.

Input

The user provides: $ARGUMENTS

This may be:

  • empty — inventory all hooks across every scope (default).
  • an event name (PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, Notification, PreCompact) — restrict to that event.
  • "scripts" — focus on the ~/.claude/hooks handler scripts dir.

Data Sources

| Endpoint | Returns | |----------|---------| | GET /api/cc-config/hooks | { items:[{ scope:"user"\|"project"\|"project-local", file, exists, hooks:{ <Event>:[{ matcher, type, command, timeout }] } }] } | | GET /api/cc-config/hook-scripts | { dir, items:[{ name, file, size, mtime }] } — the handler scripts under ~/.claude/hooks/ |

Report Sections

1. Configured hooks by scope

From /hooks, flatten each source into (scope, file, Event, matcher, type, command, timeout). Group by scope (user, project, project-local). Show the event, matcher, hook type, and the raw command. Note which file each came from so the user can edit the right one.

2. Hook scripts on disk

From /hook-scripts, list each file in ~/.claude/hooks/ with name, size (KB), and mtime. Cross-reference: flag scripts referenced by a hook command but missing from disk, and scripts on disk that no configured hook calls (orphaned).

3. Safety flags

For every type: "command" entry escalate:

  • Network egress (P0) — the command contains curl, wget, http, https, nc, or pipes output off-box. Print the destination if visible.
  • Arbitrary execution (P1) — pipes to sh/bash, evaluates downloaded content, or runs an unpinned interpreter on attacker-influenceable input.
  • No timeout (P2) — a command hook with timeout: null; it can hang a session indefinitely.
  • Broad matcher (P3) — matcher: "*" or empty on a destructive command.

Output

  • Section 1 as a table (Scope | Event | Matcher | Type | Command | Timeout).
  • Section 3 as a findings table (Hook | Risk | Severity | Detail) with a one-line verdict first (SAFE / REVIEW NEEDED / RISKY HOOKS).
  • Print raw commands verbatim — do not paraphrase a command you are flagging.
  • Cite only fields the API returned — never fabricate hooks or commands.
  • Note: hooks live inside settings.json and are read-only via the Config Explorer; edit them in the file named by the source, then reinstall with the dashboard's hook setup if needed.
  • If the dashboard is unreachable at http://localhost:4820, say so and tell the user to start it with npm start from the repo root.

Related Skills

View on GitHub
GitHub Stars1.0k
CategoryOperations
Updated12d ago
Forks238

Languages

JavaScript

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions