PluginBench
Skill
Pass
Audit score 90

hookify-rules

affaan-m/ecc

Create and manage Hookify rules to enforce patterns and guard against risky operations in Claude Code.

What is hookify-rules?

Hookify rules are YAML-frontmatter markdown files that watch for patterns in bash commands, file edits, prompts, and task completion, then display warnings or block operations. Use this skill when writing, configuring, or debugging Hookify rules for your project.

  • Define regex patterns to match bash commands, file edits, user prompts, or task completion events
  • Trigger warnings or block operations when patterns match using warn/block actions
  • Use simple pattern matching or advanced multi-condition rules with field operators
  • Store rules in `.claude/hookify.{name}.local.md` files with YAML frontmatter and markdown messages
  • Test patterns with Python regex before deployment
  • Manage rules with `/hookify`, `/hookify-list`, `/hookify-configure` commands

How to install hookify-rules

npx skills add null --skill hookify-rules
Prerequisites
  • Project with `.claude/` directory in root
  • Basic regex pattern knowledge (or use simple string matching)
  • Understanding of which events (bash, file, prompt, stop) apply to your use case
Claude Code
Cursor
Windsurf
Cline

How to use hookify-rules

  1. 1.Create a new `.claude/hookify.{rule-name}.local.md` file in your project root
  2. 2.Add YAML frontmatter with name, enabled, event, and pattern fields
  3. 3.Write the message to display when the rule triggers (supports markdown)
  4. 4.For complex rules, use conditions array instead of simple pattern field
  5. 5.Test your regex pattern with Python: `python3 -c "import re; print(re.search(r'pattern', 'test'))"
  6. 6.Run `/hookify-list` to verify the rule is loaded
  7. 7.Toggle rules on/off with `/hookify-configure` without deleting files

Use cases

Good for
  • Prevent accidental `rm -rf` or destructive bash commands in a shared codebase
  • Block commits of debug code like `console.log()` or `debugger` statements to production branches
  • Warn when API keys or credentials are added to `.env` files without gitignore verification
  • Enforce workflow steps by matching user prompts for required actions before task completion
  • Catch security risks like `eval()` or `innerHTML` assignments in file edits
Who it's for
  • Claude Code and Cursor users managing multi-file projects
  • Teams enforcing code quality and security patterns
  • Developers building safeguards against common mistakes

hookify-rules FAQ

What's the difference between warn and block actions?

warn (default) displays a message to Claude but allows the operation; block prevents the operation from completing.

Can I match multiple conditions in one rule?

Yes, use the conditions array with field, operator, and pattern for each condition. All conditions must match for the rule to trigger.

Which event type should I use for detecting API keys in .env files?

Use event: file with conditions matching file_path regex `\.env$` and new_text containing `API_KEY`.

How do I test if my regex pattern works?

Run `python3 -c "import re; print(re.search(r'your_pattern', 'test text'))"` to verify before adding to a rule.

Should I commit .local.md rule files to git?

No, add `.claude/*.local.md` to `.gitignore` to keep local rules private; share rules via non-local `.md` files if needed.

Full instructions (SKILL.md)

Source of truth, from affaan-m/ecc.


name: hookify-rules description: This skill should be used when the user asks to create a hookify rule, write a hook rule, configure hookify, add a hookify rule, or needs guidance on hookify rule syntax and patterns.

Writing Hookify Rules

Overview

Hookify rules are markdown files with YAML frontmatter that define patterns to watch for and messages to show when those patterns match. Rules are stored in .claude/hookify.{rule-name}.local.md files.

Rule File Format

Basic Structure

---
name: rule-identifier
enabled: true
event: bash|file|stop|prompt|all
pattern: regex-pattern-here
---

Message to show Claude when this rule triggers.
Can include markdown formatting, warnings, suggestions, etc.

Frontmatter Fields

FieldRequiredValuesDescription
nameYeskebab-case stringUnique identifier (verb-first: warn-, block-, require-*)
enabledYestrue/falseToggle without deleting
eventYesbash/file/stop/prompt/allWhich hook event triggers this
actionNowarn/blockwarn (default) shows message; block prevents operation
patternYes*regex stringPattern to match (*or use conditions for complex rules)

Advanced Format (Multiple Conditions)

---
name: warn-env-api-keys
enabled: true
event: file
conditions:
  - field: file_path
    operator: regex_match
    pattern: \.env$
  - field: new_text
    operator: contains
    pattern: API_KEY
---

You're adding an API key to a .env file. Ensure this file is in .gitignore!

Condition fields by event:

  • bash: command
  • file: file_path, new_text, old_text, content
  • prompt: user_prompt

Operators: regex_match, contains, equals, not_contains, starts_with, ends_with

All conditions must match for rule to trigger.

Event Type Guide

bash Events

Match Bash command patterns:

  • Dangerous commands: rm\s+-rf, dd\s+if=, mkfs
  • Privilege escalation: sudo\s+, su\s+
  • Permission issues: chmod\s+777

file Events

Match Edit/Write/MultiEdit operations:

  • Debug code: console\.log\(, debugger
  • Security risks: eval\(, innerHTML\s*=
  • Sensitive files: \.env$, credentials, \.pem$

stop Events

Completion checks and reminders. Pattern .* matches always.

prompt Events

Match user prompt content for workflow enforcement.

Pattern Writing Tips

Regex Basics

  • Escape special chars: . to \., ( to \(
  • \s whitespace, \d digit, \w word char
  • + one or more, * zero or more, ? optional
  • | OR operator

Common Pitfalls

  • Too broad: log matches "login", "dialog" — use console\.log\(
  • Too specific: rm -rf /tmp — use rm\s+-rf
  • YAML escaping: Use unquoted patterns; quoted strings need \\s

Testing

python3 -c "import re; print(re.search(r'your_pattern', 'test text'))"

File Organization

  • Location: .claude/ directory in project root
  • Naming: .claude/hookify.{descriptive-name}.local.md
  • Gitignore: Add .claude/*.local.md to .gitignore

Commands

  • /hookify [description] - Create new rules (auto-analyzes conversation if no args)
  • /hookify-list - View all rules in table format
  • /hookify-configure - Toggle rules on/off interactively
  • /hookify-help - Full documentation

Quick Reference

Minimum viable rule:

---
name: my-rule
enabled: true
event: bash
pattern: dangerous_command
---
Warning message here