Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add spinningrachel/career-engine/plugin install career-engineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/hooks/spinningrachel/career-engine/stop)<a href="https://agentmods.dev/hooks/spinningrachel/career-engine/stop"><img src="https://agentmods.dev/badge/hooks/spinningrachel/career-engine/stop.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
Stop scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the commands this hook runs, not an audit. A hook is shell that executes on your machine at the event it names, which is why every command in it is printed with what was found.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 16 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"Stop": [
{
"hooks": [
{
"type": "command",
"command": "bash \"${CLAUDE_PLUGIN_ROOT}/scripts/log-token-usage.sh\""
},
{
"type": "prompt",
"prompt": "You are checking a just-finished Claude Code turn for one specific, narrow failure mode documented in the career-engine plugin's CLAUDE.md as the 'mid-run scope-check anti-pattern': a career-engine pipeline run (orchestrator, intake, or edit) pausing or stopping mid-run to ask about scope, cost, run length, or call volume, instead of continuing to process its queue. Read last_assistant_message. Only flag a violation if BOTH hold: (1) the message shows clear evidence a pipeline run is actually EXECUTING in this session — it reports real pipeline tool activity from this run, such as a fetched Notion role queue, spawned career-coach/cv-writer/letter-writer/gatekeeper subagents, gatekeeper rounds on a specific role's draft, or writes to a run-scoped `_pipeline`/`_intake_pipeline` directory, `state.json`, or `halted-roles.json`. Merely MENTIONING the plugin, its files, its agents, or its pipeline steps is NOT evidence of a run, and neither is run output the USER pasted into chat for discussion: a session that is editing the plugin's markdown, debugging its doctrine, running QA, answering questions about how the pipeline works, or discussing its design is a development conversation, and a developer's question awaiting the user's answer in such a session is always legitimate — never auto-continue past it. AND (2) instead of calling a tool to advance the queue, or reporting one specific hard blocker (a real error, a missing required config key, or a role hitting its documented revision cap and being flagged to halted-roles.json per the flag-and-deliver policy), the message pauses, hedges, asks how to proceed, or narrates a rationale for stopping early because the run feels large, long, or expensive. If both hold, respond {\"ok\": false, \"reason\": \"What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 16 lines scan A cf2143f05660
Stop is a hook published in the GitHub repository spinningrachel/career-engine (4 stars, last pushed 22d ago), licensed MIT. Its token cost is not measured: a hook is shell that never enters the context. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other hooks, from other repositories
PostToolUse
Runs after a tool call finishes for Write and Edit tool calls, executing format_and_lint.sh. From supabase/supabase.
SessionStart
Runs when a session starts, executing on-start.js via node. From google-gemini/gemini-cli.
SessionStart
Runs when a session starts on startup, executing install_pkgs.sh. From supabase/supabase.
PreToolUse
Runs before the agent uses a tool for Bash tool calls, running an inline shell check. From apache/superset.
PreToolUse
Runs before the agent uses a tool, executing pre-write.sh and pre-bash.sh (2 commands). From anthropics/claude-cookbooks.
SessionStart
Runs when a session starts, executing session-start.sh. From anthropics/claude-cookbooks.