Install
$ agentstack add skill-product-on-purpose-agent-skills-toolkit-askit-build-hook ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
askit-build-hook
Purpose
Author a plugin's hooks: event-driven enforcement or context injection (Standard sec 3.5). Hooks are an Advanced-tier capability. Two modes: create scaffolds a hook and its registration; improve raises an existing hook toward the bar (documentation, idempotency, actionable block messages). The hook SKILL is portable; what it authors is primarily a Claude capability (31 events) with a smaller Codex event set. Authoring depth is in [references/authoring-hooks.md](references/authoring-hooks.md). Follows the shared builder contract ([../../docs/reference/builder-pattern.md](../../docs/reference/builder-pattern.md)).
When to use
When the user asks to add, scaffold, author, or improve a hook (a PreToolUse / PostToolUse / Stop / SessionStart guard, a context injector, or any event-driven automation) for a plugin.
create mode
- Brief interview: the event (for example PreToolUse), the trigger or matcher, the hook type (
command/http/mcp_tool/prompt/agent), the scope (what it guards or injects), and the failure behavior (fail-safe block vs warn). Skip the interview if these are in context. - Author the hook and its registration. A plugin registers hooks in
hooks/hooks.jsonusing${CLAUDE_PLUGIN_ROOT}; copytemplates/hooks.jsonif none exists. Document the event, trigger, scope, and failure behavior (Standard sec 3.5 MUST). - For a blocking hook (for example a PreToolUse deny), write an ACTIONABLE message that states what was blocked and how to proceed. Make the hook idempotent where the event can repeat.
- Register the hook in
library.jsoncomponents.hooksas{ name, version, tier, status }. - Targets: Claude supports 31 events. Codex supports a smaller set (PreToolUse, PostToolUse, Pre/PostCompact, SessionStart, SubagentStart/Stop, UserPromptSubmit, Stop, PermissionRequest). Verify current Codex plugin-hook ingestion at build time (a known caveat) and scope
agent-targetsaccordingly. - Assess with
node scripts/evaluate.mjs . --json. Hook documentation and idempotency are graded at the Advanced tier; the deterministic hook check lands with Gold self-hosting (Phase 5).
improve mode
- Run
node scripts/evaluate.mjs . --jsonand read the report. - Fix what it flags. For hooks specifically, confirm the event / trigger / scope / failure are documented (sec 3.5), the block message is actionable, and the hook is idempotent.
- Re-run to confirm.
Scope
Hooks are Advanced-tier and the most agent-specific component: Claude's event set is the richest, Codex covers a subset, and the wider ecosystem does not support hooks. A hook MUST document its event, trigger, scope, and failure behavior, and a blocking hook MUST emit an actionable message (Standard sec 3.5). Least privilege applies (sec 9): a hook's command runs with the narrowest scope needed.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: product-on-purpose
- Source: product-on-purpose/agent-skills-toolkit
- License: Apache-2.0
- Homepage: https://product-on-purpose.github.io/agent-skills-toolkit
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.