Security hooks

588 tagged Security, measured the same way as everything else here.

Browse within: ai-security 62ai-governance 35AI Safety 30agent-security 28hooks 27devsecops 20Guardrails 18gemini-cli 17agent-governance 15bash 15plugin 14python 14gemini-cli-extension 13Orchestration 12

UserPromptExpansion

01

anthropics/claude-plugins-official

Hook

Runs to expand your prompt before the agent sees it for ^claude-security:claude-security$ tool calls, executing banner_hook.sh via sh. From anthropics/claude-plugins-official.

36k 3d ago A tokens not measured original Apache-2.0

PostToolUse

02

open-gsd/gsd-core

Hook

Runs after a tool call finishes for Bash, Edit, Write, MultiEdit, Agent, Task, Read, WebFetch and WebSearch tool calls, executing gsd-context-monitor.js and gsd-read-injection-scanner.js via node (2 commands). From open-gsd/gsd-core.

8.9k 2d ago A tokens not measured original MIT

PreToolUse

03

Galaxy-Dawn/claude-scholar

Hook

Runs before the agent uses a tool for Bash, Write and Edit tool calls, executing security-guard.js via node. From Galaxy-Dawn/claude-scholar.

5.3k 5d ago A tokens not measured original MIT

SessionStart

04

dmno-dev/varlock

Hook Claude Code

Runs when a session starts, executing worktree-deps.sh. From dmno-dev/varlock.

4.2k 2d ago A tokens not measured original MIT

PostToolUse

05

dmno-dev/varlock

Hook Claude Code

Runs after a tool call finishes for Bash tool calls, executing git-push-notice.sh. From dmno-dev/varlock.

4.2k 2d ago A tokens not measured original MIT

PreToolUse

06

parcadei/Continuous-Claude-v3

Hook Claude Code

Runs before the agent uses a tool for Read, Edit, Write, Read, Grep, Task and Edit tool calls, executing pre-tool-use-broadcast.mjs, path-rules.mjs, tldr-read-enforcer.mjs, smart-search-router.mjs, tldr-context-inject.mjs, arch-context-inject.mjs, file-claims.mjs, edit-context-inject.mjs and signature-helper.mjs via…

3.9k 7mo ago A tokens not measured original MIT

PreToolUse

07

rohitg00/pro-workflow

Hook

Runs before the agent uses a tool for tool == "Edit", tool == "Write", Read, Bash, tool == "Edit" and tool == "Write" tool calls, executing quality-gate.js, read-before-write.js, reread-tracker.js, tool-call-budget.js, git-blast-radius.js, pre-commit-check.js, commit-validate.js, pre-push-check.js and secret-scan.js…

2.8k 14d ago A tokens not measured

PreToolUse

08

sheeki03/tirith

Hook Claude Code

Runs before the agent uses a tool for Bash tool calls, executing tirith-check.py. From sheeki03/tirith.

2.7k 2d ago A tokens not measured AGPL-3.0

PreToolUse

09

aws/agent-toolkit-for-aws

Hook Claude Code

Runs before the agent uses a tool for Bash, use_aws, mcp__aws.* and mcp__plugin_.*aws-mcp.* tool calls, executing secret-safety.py via python3 (2 commands). From aws/agent-toolkit-for-aws.

2.5k 3d ago A tokens not measured original Apache-2.0

PostToolUse

10

stacklok/toolhive

Hook Claude Code

Runs after a tool call finishes for Edit and Write tool calls, running an inline shell check. From stacklok/toolhive.

2.1k +1 today A tokens not measured original Apache-2.0

PreToolUse

11

composio-community/awesome-claude-plugins

Hook

Runs before the agent uses a tool for Edit, Write and MultiEdit tool calls, executing security_reminder_hook.py via python3. From composio-community/awesome-claude-plugins.

1.9k +3 1mo ago A tokens not measured

PreToolUse

12

kenryu42/cc-safety-net

Hook

Runs before the agent uses a tool, executing cc-safety-net.js via node with --coding-cli. From kenryu42/cc-safety-net.

1.5k yesterday A tokens not measured original MIT

PreToolUse

13

CloudAI-X/claude-workflow-v2

Hook

Runs before the agent uses a tool for Edit, Write and Bash tool calls, executing protect-files.py, security-check.py, pre-commit-check.py, log-commands.sh and branch-protection.sh via python3 (5 commands). From CloudAI-X/claude-workflow-v2.

1.4k 6d ago A tokens not measured original MIT

PostToolUse

14

cloudposse/atmos

Hook Claude Code

Runs after a tool call finishes for Bash tool calls, executing security-remediate-trigger.sh. From cloudposse/atmos.

1.4k +2 today A tokens not measured copy · 39% Apache-2.0

UserPromptSubmit

15

first-fluke/oh-my-agent

Hook

Runs when you submit a prompt, before the agent sees it, executing keyword-detector.ts, state-boundary.ts and skill-injector.ts via bun (3 commands). From first-fluke/oh-my-agent.

1.3k 2d ago A tokens not measured original MIT

SubagentStop

16

H-mmer/pentest-agents

Hook Claude Code

Runs when a subagent finishes, executing cost_hook.py and chain_pressure_hook.py via uv (2 commands). From H-mmer/pentest-agents.

813 2mo ago A tokens not measured

SessionStart

17

H-mmer/pentest-agents

Hook Claude Code

Runs when a session starts, running an inline shell check. From H-mmer/pentest-agents.

813 2mo ago A tokens not measured

PreToolUse

18

H-mmer/pentest-agents

Hook Claude Code

Runs before the agent uses a tool for Bash, Write and Edit tool calls, executing scope_hook.py, file_path_guard.py, cvss_version_guard.py and validity_guard.py via uv (4 commands). From H-mmer/pentest-agents.

813 2mo ago A tokens not measured

PostToolUse

19

hoophq/hoop

Hook Claude Code

Runs after a tool call finishes for Edit and Write tool calls, executing gofmt.sh. From hoophq/hoop.

805 3d ago A tokens not measured copy · 42% MIT

PreToolUse

20

borghei/Claude-Skills

Hook Claude Code

Runs before the agent uses a tool for Bash tool calls, executing pre_tool_secret_scan.py via python3. From borghei/Claude-Skills.

654 19d ago A tokens not measured

PreToolUse

21

emiliaprotocol/emilia-protocol

Hook

Runs before the agent uses a tool for Bash, Write, Edit, MultiEdit and mcp__.* tool calls, executing guard.mjs via node. From emiliaprotocol/emilia-protocol.

653 yesterday A tokens not measured original Apache-2.0

PreToolUse

22

alibaba/anolisa

Hook

Runs before the agent uses a tool for Bash tool calls, executing code_scanner_hook.py, observability_hook.py and pii_checker_hook.py via python3 (3 commands). From alibaba/anolisa.

614 2d ago A tokens not measured original Apache-2.0

UserPromptSubmit

23

alibaba/anolisa

Hook

Runs when you submit a prompt, before the agent sees it, executing prompt_scanner_hook.py, pii_checker_hook.py, skill_ledger_hook.py and observability_hook.py via python3 (4 commands). From alibaba/anolisa.

614 2d ago A tokens not measured copy · 89% Apache-2.0

Stop

24

alibaba/anolisa

Hook

Runs when the agent finishes a response, executing observability_hook.py via python3. From alibaba/anolisa.

614 2d ago A tokens not measured original Apache-2.0