Is UserPromptSubmit safe to install?

Yes — UserPromptSubmit is safe to install, on this review. Fable 5.1 read every file UserPromptSubmit ships from shanraisshan/claude-code-best-practice on 7 September 2026 and found nothing that acts against the person installing it; the static scan of its 26 rules grades it A.

Reviewed by Fable 5.1 on 7 September 2026 · a grade is what a scan and a reading found, not a guarantee · how this works

What the reviewer found

UserPromptSubmit: runs .claude/hooks/scripts/hooks.py, which plays a sound file from .claude/hooks/sounds and appends the full hook input (including the prompt text) to .claude/hooks/logs/hooks-log.jsonl inside the project. Local only, exits 0 always, nothing leaves the machine.

What was read

The hook definition and the script it runs, fetched from shanraisshan/claude-code-best-practice:

What the static scan said

The 26-rule scan found nothing in this file; the review read it anyway.

How this review was made

Fable 5.1 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.

Produced by agentmods.dev · Fable 5.1 · 7 September 2026

← Back to UserPromptSubmit