hookify-rules
affaan-m/ecc
Create and manage Hookify rules to enforce patterns and guard against risky operations in Claude Code.
What is hookify-rules?
Hookify rules are YAML-frontmatter markdown files that watch for patterns in bash commands, file edits, prompts, and task completion, then display warnings or block operations. Use this skill when writing, configuring, or debugging Hookify rules for your project.
- Define regex patterns to match bash commands, file edits, user prompts, or task completion events
- Trigger warnings or block operations when patterns match using warn/block actions
- Use simple pattern matching or advanced multi-condition rules with field operators
- Store rules in `.claude/hookify.{name}.local.md` files with YAML frontmatter and markdown messages
- Test patterns with Python regex before deployment
- Manage rules with `/hookify`, `/hookify-list`, `/hookify-configure` commands
How to install hookify-rules
npx skills add null --skill hookify-rules- Project with `.claude/` directory in root
- Basic regex pattern knowledge (or use simple string matching)
- Understanding of which events (bash, file, prompt, stop) apply to your use case
How to use hookify-rules
- 1.Create a new `.claude/hookify.{rule-name}.local.md` file in your project root
- 2.Add YAML frontmatter with name, enabled, event, and pattern fields
- 3.Write the message to display when the rule triggers (supports markdown)
- 4.For complex rules, use conditions array instead of simple pattern field
- 5.Test your regex pattern with Python: `python3 -c "import re; print(re.search(r'pattern', 'test'))"
- 6.Run `/hookify-list` to verify the rule is loaded
- 7.Toggle rules on/off with `/hookify-configure` without deleting files
Use cases
- Prevent accidental `rm -rf` or destructive bash commands in a shared codebase
- Block commits of debug code like `console.log()` or `debugger` statements to production branches
- Warn when API keys or credentials are added to `.env` files without gitignore verification
- Enforce workflow steps by matching user prompts for required actions before task completion
- Catch security risks like `eval()` or `innerHTML` assignments in file edits
- Claude Code and Cursor users managing multi-file projects
- Teams enforcing code quality and security patterns
- Developers building safeguards against common mistakes
hookify-rules FAQ
warn (default) displays a message to Claude but allows the operation; block prevents the operation from completing.
Yes, use the conditions array with field, operator, and pattern for each condition. All conditions must match for the rule to trigger.
Use event: file with conditions matching file_path regex `\.env$` and new_text containing `API_KEY`.
Run `python3 -c "import re; print(re.search(r'your_pattern', 'test text'))"` to verify before adding to a rule.
No, add `.claude/*.local.md` to `.gitignore` to keep local rules private; share rules via non-local `.md` files if needed.
Full instructions (SKILL.md)
Source of truth, from affaan-m/ecc.
name: hookify-rules description: This skill should be used when the user asks to create a hookify rule, write a hook rule, configure hookify, add a hookify rule, or needs guidance on hookify rule syntax and patterns.
Writing Hookify Rules
Overview
Hookify rules are markdown files with YAML frontmatter that define patterns to watch for and messages to show when those patterns match. Rules are stored in .claude/hookify.{rule-name}.local.md files.
Rule File Format
Basic Structure
---
name: rule-identifier
enabled: true
event: bash|file|stop|prompt|all
pattern: regex-pattern-here
---
Message to show Claude when this rule triggers.
Can include markdown formatting, warnings, suggestions, etc.
Frontmatter Fields
| Field | Required | Values | Description |
|---|---|---|---|
| name | Yes | kebab-case string | Unique identifier (verb-first: warn-, block-, require-*) |
| enabled | Yes | true/false | Toggle without deleting |
| event | Yes | bash/file/stop/prompt/all | Which hook event triggers this |
| action | No | warn/block | warn (default) shows message; block prevents operation |
| pattern | Yes* | regex string | Pattern to match (*or use conditions for complex rules) |
Advanced Format (Multiple Conditions)
---
name: warn-env-api-keys
enabled: true
event: file
conditions:
- field: file_path
operator: regex_match
pattern: \.env$
- field: new_text
operator: contains
pattern: API_KEY
---
You're adding an API key to a .env file. Ensure this file is in .gitignore!
Condition fields by event:
- bash:
command - file:
file_path,new_text,old_text,content - prompt:
user_prompt
Operators: regex_match, contains, equals, not_contains, starts_with, ends_with
All conditions must match for rule to trigger.
Event Type Guide
bash Events
Match Bash command patterns:
- Dangerous commands:
rm\s+-rf,dd\s+if=,mkfs - Privilege escalation:
sudo\s+,su\s+ - Permission issues:
chmod\s+777
file Events
Match Edit/Write/MultiEdit operations:
- Debug code:
console\.log\(,debugger - Security risks:
eval\(,innerHTML\s*= - Sensitive files:
\.env$,credentials,\.pem$
stop Events
Completion checks and reminders. Pattern .* matches always.
prompt Events
Match user prompt content for workflow enforcement.
Pattern Writing Tips
Regex Basics
- Escape special chars:
.to\.,(to\( \swhitespace,\ddigit,\wword char+one or more,*zero or more,?optional|OR operator
Common Pitfalls
- Too broad:
logmatches "login", "dialog" — useconsole\.log\( - Too specific:
rm -rf /tmp— userm\s+-rf - YAML escaping: Use unquoted patterns; quoted strings need
\\s
Testing
python3 -c "import re; print(re.search(r'your_pattern', 'test text'))"
File Organization
- Location:
.claude/directory in project root - Naming:
.claude/hookify.{descriptive-name}.local.md - Gitignore: Add
.claude/*.local.mdto.gitignore
Commands
/hookify [description]- Create new rules (auto-analyzes conversation if no args)/hookify-list- View all rules in table format/hookify-configure- Toggle rules on/off interactively/hookify-help- Full documentation
Quick Reference
Minimum viable rule:
---
name: my-rule
enabled: true
event: bash
pattern: dangerous_command
---
Warning message here
Related skills
More from affaan-m/ecc and the wider catalog.
inherit-legacy-style
Agent skill from affaan-m/ecc.
intent-driven-development
Agent skill from affaan-m/ecc.
inventory-demand-planning
Demand forecasting, safety stock optimization, and replenishment planning for multi-location retailers.
investor-materials
Create consistent, credible investor materials—pitch decks, financial models, memos, and fundraising docs that align with a single source of truth.
investor-outreach
Draft personalized cold emails, warm intros, and investor updates for fundraising outreach.
ios-icon-gen
Generate iOS app icons from SF Symbols or 275k+ Iconify icons for Xcode asset catalogs.