Claude Code hooks can make selected checks automatic: block a defined risky action, run a formatter after an edit, or verify work when a turn ends. They do not prove code is correct or make every action safe. The useful goal is narrower: make specific failures harder to overlook, with results a person can inspect.
What hooks can—and cannot—guarantee
A hook is a command or handler attached to an event in Claude Code’s lifecycle. Depending on the event, it can inspect a planned tool call, respond after a call, run at turn completion, or react to configuration changes. Anthropic documents the events and configuration in its hooks guide and hooks reference.
Use hooks to enforce explicit policies and gather evidence, not to certify an entire coding session. A formatter checks formatting; a linter checks its configured rules; tests cover only the behavior they exercise. Anthropic’s power-user guidance calls verification the most impactful tip for checking Claude’s output. That is advice, not a measured success rate.
Five hook patterns worth considering
These are practical patterns assembled from documented capabilities, not a preset Anthropic configuration or a proven five-hook package. Choose one that addresses a real workflow failure, then expand only if its output is useful.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Pattern | When it runs | Coverage and effect | Failure it addresses |
|---|---|---|---|
| Block dangerous shell actions | PreToolUse | Match Bash, and PowerShell if used; can deny a selected call before execution. | A clearly defined high-risk command being run. |
| Protect sensitive paths | PreToolUse | Match Edit and Write; compare target paths with project policy and deny prohibited edits. | Changes to files the project intends to protect. |
| Run formatting or lint feedback | PostToolUse | Match relevant tools such as Edit and Write; report findings after the tool succeeds. | Mechanical issues introduced by an edit. |
| Validate at turn completion | Stop | Run a defined test or validation command; expose its actual result. | A turn ending without the intended verification. |
| Audit policy changes | ConfigChange | Record or block changes to settings or policy-related configuration. | Unexpected drift in the guardrails themselves. |
1. PreToolUse: block explicitly dangerous shell actions
Inspect a planned command before it runs and deny only cases your team has explicitly defined as dangerous. Anthropic’s hook guide demonstrates using PreToolUse to block destructive shell commands. Keep the matcher and command checks narrow: broad patterns can interrupt ordinary work while still missing a dangerous variation.
Where the project uses PowerShell, account for it deliberately rather than assuming a Bash-only rule covers it. Make the denial reason specific enough that Claude and the developer can understand what policy was triggered.
2. PreToolUse: protect sensitive paths
Use a separate check for Edit and Write targets that violate the project’s protected-file policy. Depending on the repository, that might include secret-bearing files or generated and lock files that should only change through a particular workflow. The official guide demonstrates blocking edits to protected files and returning a reason.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Normalize paths before comparing them with the policy, and test both a permitted path and a denied one. A filename-only check can be fooled by path variations or miss a file in an unexpected location, so define the path rules to match the repository’s layout.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →3. PostToolUse: run a fast formatter or linter
After successful Edit or Write calls, run a deterministic, focused formatter or linter and make its output visible. This gives fast feedback close to the change, without asking the model to remember a style rule.
This is post-action feedback, not a pre-write block: the edit has already happened. Also, matching Edit and Write does not observe every possible file change. A shell command can modify files without using either tool, so do not treat this hook as comprehensive write monitoring.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
4. Stop: run a deterministic completion check
At turn completion, run the project’s chosen fast test or validation command. For workflows where uncommitted changes matter, include an appropriate working-tree check. Anthropic’s power-user guidance recommends a Stop hook pattern for auditable workflows; the important part is to report the command that ran and its actual outcome.
A model’s statement that tests passed is not test evidence. Conversely, a passing suite establishes only that the included tests passed under the conditions in which they ran; it cannot establish correctness beyond their coverage.
5. ConfigChange: watch the policy surface
Use ConfigChange to record or block unexpected changes to settings, skills, or other policy files during a session. The hook reference documents this event and the ability to prevent a configuration change from taking effect. This makes changes to the guardrails more visible; it does not remove the need to review trusted hook code or control filesystem access.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Optional: restore concise context after compaction
For long sessions, a SessionStart hook with a compact matcher can re-inject a short set of critical conventions after context compaction. Anthropic documents this pattern in the hooks guide. Treat it as context restoration, not enforcement: use deterministic checks for blocking actions and verifying results.
How to implement hooks without creating false confidence
- Choose one observed failure. Identify a concrete problem, such as a forbidden file being edited or a turn ending without a test run. Avoid adding a hook just because an event exists.
- Pick the event and scope. Decide when the check must run and which tools or paths it actually covers. A file-edit matcher will not catch shell-based file changes.
- Test both outcomes. Exercise a safe or allowed case and the case that should trigger the hook. Confirm the result is understandable and that the intended block or report occurs.
- Make decisions inspectable. Log enough to explain why a hook allowed, denied, or reported an action, without unnecessarily exposing secrets.
- Review executable hook code. Hooks run commands in the local environment and can act with the user’s permissions. Inspect changes to hook scripts as privileged-code changes.
- Expand only when useful. Add another hook when it covers a distinct failure mode and its outcome can be checked by a human.
Do not auto-approve every permission prompt for convenience. Anthropic warns that broad matching can approve all permission prompts, including shell commands and writes. Hook matching also matters for side effects: matching hooks may run concurrently, so one hook’s denial does not guarantee that another handler will not run.
Security limits to account for
- Hooks inherit local authority. Treat their scripts as privileged code; validate and quote inputs, prefer explicit paths, and avoid sending secrets to processes that do not need them.
- A hook can fail unsafely. A rule that approves a risky operation or silently ignores errors can weaken rather than strengthen the workflow. Make error handling and failure behavior deliberate.
- Coverage is never universal by default. Each matcher sees only its configured events and tools. State what the check covers, and do not imply it monitors every way the environment can change.
- Checks provide bounded evidence. A formatter, linter, or test command supports only the claim its function and coverage justify.
Anthropic’s December 11, 2025 hook-configuration article also discusses hook customization. No published statistic or controlled result establishes an effectiveness percentage for this particular five-pattern selection, so treat it as a set of design options rather than a guaranteed safety configuration.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




