Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add hooks/pluto2060/ctx/setupgit clone --depth 1 https://github.com/pluto2060/CTXGrade A, and why
Setup scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the commands this hook runs, not an audit. A hook is shell that executes on your machine at the event it names, which is why every command in it is printed with what was found.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
"command": "bash -c 'set -e; VD=$HOME/.local/share/claude-vault; mkdir -p $VD; PY=python3; if $PY -m venv $VD/venv 2>/dev/null || true; then VPY=$VD/venv/bin/python; $VPY -m ensurepip --upgrade 2>/dev/null || curl -sS ht What it actually says
{
"Setup": [
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "bash -c 'set -e; VD=$HOME/.local/share/claude-vault; mkdir -p $VD; PY=python3; if $PY -m venv $VD/venv 2>/dev/null || true; then VPY=$VD/venv/bin/python; $VPY -m ensurepip --upgrade 2>/dev/null || curl -sS https://bootstrap.pypa.io/get-pip.py | $VPY 2>/dev/null || true; $VPY -m pip install --quiet ctx-retriever rank_bm25 numpy sqlite-vec 2>/dev/null; $VPY -m pip install --quiet sentence-transformers 2>/dev/null || true; $VPY -m ctx_retriever.cli.install 2>/dev/null; echo \"[CTX] setup complete (venv=$VD/venv)\"; fi'",
"timeout": 180
}
]
}
]
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 14 lines scan A 1124e84bba16
Setup is a hook published in the GitHub repository pluto2060/CTX (9 stars, last pushed 3mo ago), licensed MIT. Its token cost is not measured: a hook is shell that never enters the context. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other hooks, from other repositories
PreToolUse
Runs before the agent uses a tool for Write, Edit, MultiEdit and TodoWrite tool calls, running npx tdd-guard@latest. From nizos/tdd-guard.
UserPromptSubmit
Runs when you submit a prompt, before the agent sees it, running npx tdd-guard@latest. From nizos/tdd-guard.
SessionStart
Runs when a session starts on startup, resume and clear, running npx tdd-guard@latest. From nizos/tdd-guard.
SessionStart
Runs when a session starts, executing load-memory.py via python3. From ReScienceLab/opc-skills.
PreToolUse
Runs before the agent uses a tool for Edit, Write, NotebookEdit, Read, Skill, Agent and Task tool calls, executing hook-launcher.mjs and pre-agent-inject.sh via node (3 commands). From sdsrss/claude-mem-lite.
UserPromptSubmit
Runs when you submit a prompt, before the agent sees it, executing silence-nudge.js via node. From V-Songbird/hush.