
Hookify Rules
- 4.1k installs
- 238k repo stars
- Updated August 5, 2026
- affaan-m/everything-claude-code
hookify-rules is an agent skill for implement automatic hookify event-driven rules that block or warn on risky claude code tool patterns.
About
The hookify-rules skill 自動フック実装、イベントドリブン実行、およびルール駆動ワークフロー。. Hookify rules are markdown files with YAML frontmatter that define patterns to watch for and messages to show when those patterns match. Rules are stored in .claude/hookify.{rule-name}.local.md files. ```markdown --- name: rule-identifier enabled: true event: bash file stop prompt all pattern: regex-pattern-here --- Message to show Claude when this rule triggers. Can include markdown formatting, warnings, suggestions, etc. ``` Field Required Values Description ------- ---------- -------- ------------- name Yes kebab-case string Unique identifier (verb-first: warn- , block- , require- ) enabled Yes true/false Toggle without deleting event Yes bash/file/stop/prompt/all Which hook event triggers this action No warn/block warn (default) shows message; block prevents operation pattern Yes regex string Pattern to match ( or use conditions for c Field Required Values Description ------- ---------- -------- ------------- name Yes kebab-case string Unique identifier (verb-first: warn- , block- , require- ) enabled Yes true/false Toggle without deleting event Yes bash/file/stop/prompt/all Which hook event triggers this action No wa.
- file: file_path, new_text, old_text, content
- prompt: user_prompt
- Dangerous commands: rm\s+-rf, dd\s+if=, mkfs
- Privilege escalation: sudo\s+, su\s+
- Permission issues: chmod\s+777
Hookify Rules by the numbers
- 4,055 all-time installs (skills.sh)
- +219 installs in the week ending Aug 5, 2026 (Skillselion tracking)
- Ranked #31 of 782 Skill Development skills by installs in the Skillselion catalog
- Security screen: LOW risk (skills.sh audit)
- Data as of Aug 5, 2026 (Skillselion catalog sync)
hookify-rules capabilities & compatibility
- Capabilities
- file: file_path, new_text, old_text, content · prompt: user_prompt · dangerous commands: rm\s+ rf, dd\s+if=, mkfs · privilege escalation: sudo\s+, su\s+ · permission issues: chmod\s+777
- Use cases
- orchestration · security audit
What hookify-rules says it does
Message to show Claude when this rule triggers.
Can include markdown formatting, warnings, suggestions, etc.
You're adding an API key to a .env file. Ensure this file is in .gitignore!
npx skills add https://github.com/affaan-m/everything-claude-code --skill hookify-rulesAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 4.1k |
|---|---|
| repo stars | ★ 238k |
| Security audit | 3 / 3 scanners passed |
| Last updated | August 5, 2026 |
| Repository | affaan-m/everything-claude-code ↗ |
How do I implement automatic hookify event-driven rules that block or warn on risky claude code tool patterns with documented agent guidance?
Implement automatic Hookify event-driven rules that block or warn on risky Claude Code tool patterns.
Who is it for?
Developers who need skill development help during build work.
Skip if: Skip when the task falls outside Skill Development scope described in SKILL.md.
When should I use this skill?
Implement automatic Hookify event-driven rules that block or warn on risky Claude Code tool patterns.
What you get
Completed skill development workflow aligned with SKILL.md steps and validation.
- .claude/hookify rule file
- regex session guardrail
By the numbers
- file: file_path, new_text, old_text, content
- prompt: user_prompt
- Dangerous commands: rm\s+-rf, dd\s+if=, mkfs
Files
Writing Hookify Rules
Overview
Hookify rules are markdown files with YAML frontmatter that define patterns to watch for and messages to show when those patterns match. Rules are stored in .claude/hookify.{rule-name}.local.md files.
Rule File Format
Basic Structure
---
name: rule-identifier
enabled: true
event: bash|file|stop|prompt|all
pattern: regex-pattern-here
---
Message to show Claude when this rule triggers.
Can include markdown formatting, warnings, suggestions, etc.Frontmatter Fields
| Field | Required | Values | Description |
|---|---|---|---|
| name | Yes | kebab-case string | Unique identifier (verb-first: warn-, block-, require-*) |
| enabled | Yes | true/false | Toggle without deleting |
| event | Yes | bash/file/stop/prompt/all | Which hook event triggers this |
| action | No | warn/block | warn (default) shows message; block prevents operation |
| pattern | Yes* | regex string | Pattern to match (*or use conditions for complex rules) |
Advanced Format (Multiple Conditions)
---
name: warn-env-api-keys
enabled: true
event: file
conditions:
- field: file_path
operator: regex_match
pattern: \.env$
- field: new_text
operator: contains
pattern: API_KEY
---
You're adding an API key to a .env file. Ensure this file is in .gitignore!Condition fields by event:
- bash:
command - file:
file_path,new_text,old_text,content - prompt:
user_prompt
Operators: regex_match, contains, equals, not_contains, starts_with, ends_with
All conditions must match for rule to trigger.
Event Type Guide
bash Events
Match Bash command patterns:
- Dangerous commands:
rm\s+-rf,dd\s+if=,mkfs - Privilege escalation:
sudo\s+,su\s+ - Permission issues:
chmod\s+777
file Events
Match Edit/Write/MultiEdit operations:
- Debug code:
console\.log\(,debugger - Security risks:
eval\(,innerHTML\s*= - Sensitive files:
\.env$,credentials,\.pem$
stop Events
Completion checks and reminders. Pattern .* matches always.
prompt Events
Match user prompt content for workflow enforcement.
Pattern Writing Tips
Regex Basics
- Escape special chars:
.to\.,(to\( \swhitespace,\ddigit,\wword char+one or more,*zero or more,?optional|OR operator
Common Pitfalls
- Too broad:
logmatches "login", "dialog" — useconsole\.log\( - Too specific:
rm -rf /tmp— userm\s+-rf - YAML escaping: Use unquoted patterns; quoted strings need
\\s
Testing
python3 -c "import re; print(re.search(r'your_pattern', 'test text'))"File Organization
- Location:
.claude/directory in project root - Naming:
.claude/hookify.{descriptive-name}.local.md - Gitignore: Add
.claude/*.local.mdto.gitignore
Commands
/hookify [description]- Create new rules (auto-analyzes conversation if no args)/hookify-list- View all rules in table format/hookify-configure- Toggle rules on/off interactively/hookify-help- Full documentation
Quick Reference
Minimum viable rule:
---
name: my-rule
enabled: true
event: bash
pattern: dangerous_command
---
Warning message hereRelated skills
Forks & variants (1)
Hookify Rules has 1 known copy in the catalog totaling 1.4k installs. They canonicalize to this original listing.
- affaan-m - 1.4k installs
How it compares
hookify-rules is an agent skill for implement automatic hookify event-driven rules that block or warn on risky claude code tool patterns, not a generic alternative.
FAQ
Who is hookify-rules for?
Developers using Skill Development workflows with agent-guided SKILL.md steps.
When should I use hookify-rules?
Implement automatic Hookify event-driven rules that block or warn on risky Claude Code tool patterns.
Is hookify-rules safe to install?
Review the Security Audits panel on this page before installing in production.