AIToday
Large Language ModelsAI Coding AssistantsAI Safety & AlignmentZenn AI/MLPublished: Oct 3, 2026, 22:00 JST

Claude Code hooks turn prompt requests into hard rules

Claude Code hooks turn prompt requests into hard rules

3 Key Points

  1. What happened

    A hands-on guide shows three Claude Code hooks — PostToolUse auto-formats edited files with prettier, ruff, or gofmt, PreToolUse blocks commands like 'rm -rf' with exit code 2, and Stop runs lint when the agent finishes.

  2. Why it matters

    Unlike asking the model in a prompt to 'always run prettier after edits', which may or may not be followed, a hook fires every time the specified event occurs, so the rule no longer depends on the AI's judgment.

  3. What to watch

    Hooks run shell commands with the user's own permissions, so the guide warns against using an unreviewed repository's .claude/settings.json, and notes that hook specifications can change between versions.

WHO IT HITSDevelopers and platform teams running Claude Code on shared codebases are the ones who can turn formatting, guardrails, and end-of-task checks into enforced rules rather than hopes.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The article frames hooks as a shift in how rules are enforced when working with an AI coding agent. Asking in a prompt for the agent to run a formatter after every edit is a request; the guide's point is that it may or may not be honored. A hook instead runs a user-defined command whenever a specified event occurs, so the behavior is no longer left to the model's judgment.

The three hands-on examples map to three different moments. PostToolUse fires right after a tool runs, so editing a file can trigger a formatter such as prettier for JavaScript and TypeScript, ruff for Python, or gofmt for Go, keeping the diff aligned with the formatter. PreToolUse fires just before a tool runs and is the one that can block: the sample script greps the incoming command and rejects destructive or irreversible patterns, exiting with code 2, which sends its stderr message back to Claude so the agent knows why it was stopped and may try another approach. Stop fires when the agent finishes responding and carries no matcher, making it a place for lightweight checks like lint or a type check.

The guide is candid about what comes with this power. Hooks execute shell commands with the user's own permissions, so it warns against using an untrusted repository's .claude/settings.json without reviewing it. It also notes that a hook can hang and stall the session, that a PostToolUse formatter rewriting files can create loops if the hook itself calls the agent's tools, and that hook specifications may change by version. Whether these hooks pay off in practice is likely to hinge on how carefully teams keep them fast, scoped, and reviewed — and on whether the enforcement they buy is worth the shell access they grant.

FAQ
How does a hook actually stop a dangerous command?
A PreToolUse hook fires before the tool runs. If it exits with code 2, the command is blocked, and whatever it wrote to stderr is fed back to Claude so the agent understands why.
Where do I put the hook settings?
Settings go in .claude/settings.json. ~/.claude/settings.json applies to the whole user, <repo>/.claude/settings.json applies to a project and can be committed for teams, and <repo>/.claude/settings.local.json is for personal settings kept out of git.
What do I need installed to run the examples?
Claude Code (CLI) plus macOS, Linux, or WSL, and jq to handle the JSON that is passed to the hook. You also restart Claude Code after editing settings so they reload.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleKaran Joshi extracts Muse files on everyone you know