agentCLAWHUBUnverified

hooks-eval

Evaluate hook security, performance, and SDK compliance. Use for audits Skill: hooks-eval Owner: athola Summary: Evaluate hook security, performance, and SDK compliance. Use for audits Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:03:12.768Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:27:41.806Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:27:36.109Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:44:30.079Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:08.983Z | u

OpenClaw

Rank

62

Safety

84

Downloads

1.9k

Updated

Oct 9, 2026

Version

1.9.19

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
1.9K downloadsadoption · observed Oct 9, 2026
Latest release
1.9.19release · observed Aug 26, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-abstract-hooks-eval
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/snapshot"

Documentation

CLAWHUB

144,348 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: hooks-eval
description: Evaluate hook security, performance, and SDK compliance. Use for audits
version: 1.9.8
triggers:
  - hooks
  - evaluation
  - security
  - performance
  - claude-sdk
  - agent-sdk
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/abstract", "emoji": "\ud83e\udd9e", "requires": {"config": ["night-market.hook-scope-guide"]}}}
source: claude-night-market
source_plugin: abstract
---

> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.


## Table of Contents

- [Overview](#overview)
- [Key Capabilities](#key-capabilities)
- [Core Components](#core-components)
- [Quick Reference](#quick-reference)
- [Hook Event Types](#hook-event-types)
- [Hook Callback Signature](#hook-callback-signature)
- [Return Values](#return-values)
- [Quality Scoring (100 points)](#quality-scoring-(100-points))
- [Detailed Resources](#detailed-resources)
- [Basic Evaluation Workflow](#basic-evaluation-workflow)
- [Integration with Other Tools](#integration-with-other-tools)
- [Related Skills](#related-skills)


# Hooks Evaluation Framework

## Overview

This skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.

### Key Capabilities

- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention
- **Performance Analysis**: Execution time benchmarking, resource usage, optimization
- **Compliance Checking**: Structure validation, documentation requirements, best practices
- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns

### Core Components

| Component | Purpose |
|-----------|---------|
| **Hook Types Reference** | Complete SDK hook event types and signatures |
| **Evaluation Criteria** | Scoring system and quality gates |
| **Security Patterns** | Common vulnerabilities and mitigations |
| **Performance Benchmarks** | Thresholds and optimization guidance |

## Quick Reference

### Hook Event Types

```python
HookEvent = Literal[
    "PreToolUse",       # Before tool execution
    "PostToolUse",      # After tool execution
    "UserPromptSubmit", # When user submits prompt
    "Stop",             # When stopping execution
    "SubagentStop",     # When a subagent stops
    "TeammateIdle",     # When teammate agent becomes idle (2.1.33+)
    "TaskCompleted",    # When a task finishes execution (2.1.33+)
    "PreCompact"        # Before message compaction
]
```
**Verification:** Run the command with `--help` flag to verify availability.

**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via 

_meta.json

{
  "ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
  "slug": "nm-abstract-hooks-eval",
  "version": "1.9.19",
  "publishedAt": 1787749392768
}

modules/evaluation-criteria.md

# Hook Evaluation Criteria

Detailed scoring rubric and quality gates for hook evaluation.

## Mathematical Foundation

This evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:

- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))
- **Weighting**: Security-first weights with stakeholder validation
- **Aggregation**: Weighted sum with penalty-based security scoring
- **Validation**: Sensitivity analysis on non-security weights

**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.

## Scoring System (100 points total)

### Security Analysis (30 points)

**Vulnerability Detection:**
- Critical vulnerabilities: -15 points each
- High-risk issues: -8 points each
- Medium-risk issues: -4 points each
- Low-risk issues: -1 point each

**Security Checklist:**

| Check | Severity | Points Lost |
|-------|----------|-------------|
| Dynamic code evaluation with user input | Critical | -15 |
| Command injection vulnerability | Critical | -15 |
| Unvalidated file path access | High | -8 |
| Secrets/credentials in code | High | -8 |
| Missing input validation | Medium | -4 |
| Overly permissive patterns | Medium | -4 |
| No rate limiting | Low | -1 |
| Verbose error messages exposing internals | Low | -1 |

### Performance Analysis (25 points)

| Metric | Max Points | Criteria |
|--------|------------|----------|
| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |
| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |
| I/O operation efficiency | 4 | Minimal file/network operations |
| Resource cleanup | 3 | Proper cleanup of handles, connections |

**Performance Thresholds:**

```yaml
pre_tool_use:
  excellent: <50ms
  good: <100ms
  acceptable: <200ms
  poor: >200ms

post_tool_use:
  excellent: <100ms
  good: <200ms
  acceptable: <500ms
  poor: >500ms

memory:
  excellent: <25MB
  good: <50MB
  acceptable: <100MB
  poor: >100MB
```

### Compliance Analysis (20 points)

| Aspect | Max Points | Requirements |
|--------|------------|--------------|
| Structure compliance | 8 | Valid JSON/Python, correct schema |
| Documentation completeness | 6 | Purpose, parameters, return values documented |
| Error handling | 4 | All exceptions caught, meaningful messages |
| Best practices | 2 | Follows hook authoring guidelines |

**Structure Requirements:**

- JSON hooks: Valid JSON schema with required fields
- Python hooks: Type hints, async/await patterns
- Matcher patterns: Valid regex, appropriate scope

### Reliability Analysis (15 points)

| Aspect | Max Points | Requirements |
|--------|------------|--------------|
| Error handling robustness | 6 | Graceful handling of all error conditions |
| Timeout management | 4 | Appropriate timeouts configured |
| Idempotency | 3 | Safe to r

modules/sdk-hook-types.md

# Python SDK Hook Types

Complete reference for Claude Agent SDK hook types, callbacks,
and matchers.

## Hook Events

### HookEvent

Supported hook event types in the Python SDK.

```python
from typing import Literal

HookEvent = Literal[
    "Setup",             # Called when plugin installed/enabled
    "SessionStart",      # Called when session begins
    "SessionEnd",        # Called when session ends normally
    "UserPromptSubmit",  # Called when user submits a prompt
    "PreToolUse",        # Called before tool execution
    "PostToolUse",       # Called after tool execution
    "PostToolUseFailure",# Called when tool execution fails (2.1.20+)
    "PermissionRequest", # Called when permission dialog would appear
    "Notification",      # Called on system notification (2.1.20+)
    "SubagentStart",     # Called when subagent spawns (2.1.20+)
    "SubagentStop",      # Called when a subagent stops
    "Stop",              # Called when stopping execution
    "TeammateIdle",      # Called when teammate agent becomes idle (2.1.33+)
    "TaskCompleted",     # Called when a task finishes execution (2.1.33+)
    "ConfigChange",      # Called when config is modified (2.1.49+)
    "InstructionsLoaded",# Called when instructions are loaded (2.1.33+)
    "PreCompact",        # Called before message compaction
    "PostCompact",       # Called after compaction (2.1.76+)
    "WorktreeCreate",    # Called when git worktree is created (2.1.50+)
    "WorktreeRemove",    # Called when git worktree is removed (2.1.50+)
    "StopFailure",       # Called on error (2.1.78+)
    "TaskCreated",       # Called when task created (2.1.84+)
    "CwdChanged",        # Called on working dir change (2.1.83+)
    "FileChanged",       # Called on file change (2.1.83+)
    "Elicitation",       # MCP elicitation request (2.1.76+)
    "ElicitationResult", # MCP elicitation response (2.1.76+)
]
```

**SDK vs CLI availability**: Most events work in both JSON
hooks (CLI) and Python SDK hooks. `PermissionRequest` is
CLI-only. `Setup`, `SessionStart`, `SessionEnd`, and
`Notification` are CLI-only (JSON hooks).
`WorktreeCreate` and `WorktreeRemove` are command-only
hooks (no Python SDK callback). They do not support
matchers.

### Event Summary

| Event | Trigger | Blockable | Matcher |
|-------|---------|-----------|---------|
| `Setup` | Plugin installed/enabled | No | No |
| `SessionStart` | Session begins | No | No |
| `SessionEnd` | Session ends normally | No | No |
| `UserPromptSubmit` | User submits input | No | No |
| `PreToolUse` | Before any tool runs | Yes | Tool name |
| `PostToolUse` | After tool completes | No | Tool name |
| `PostToolUseFailure` | Tool execution fails | No | Tool name |
| `PermissionRequest` | Permission dialog | Yes | Tool name |
| `SubagentStart` | Subagent spawns | No | No |
| `SubagentStop` | Subagent completes | No | No |
| `Stop` | Agent stops | No | No |
| `TeammateIdle` | Teammate idle | No | No |
| `TaskCompleted` | Task finishes | No |

skill-card.md

## Description:

Evaluate hook security, performance, and SDK compliance. Use for audits

This skill is ready for commercial/non-commercial use.

## Publisher:

[athola](https://clawhub.ai/user/athola)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and engineers use this skill to audit Claude Code hooks for security, performance, SDK compliance, reliability, and maintainability before deployment.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Broad triggers may cause the skill to appear in general security or performance conversations where hook-specific audit guidance is not intended.

Mitigation: Invoke the skill deliberately for hook-related audits and verify that its guidance applies to the hook implementation under review.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-hooks-eval)
- [ClawHub metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract)
- [Hook evaluation criteria](modules/evaluation-criteria.md)
- [Python SDK hook types](modules/sdk-hook-types.md)

## Skill Output:

**Output Type(s):** [text, markdown, shell commands, configuration, guidance]

**Output Format:** [Markdown guidance with code blocks, scoring rubrics, and configuration examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Includes hook event references, security and performance evaluation criteria, quality gates, and audit workflow examples.]

## Skill Version(s):

1.9.19 (source: server release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 6h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/athola/skills/nm-abstract-hooks-eval",
      "sourceUrl": "https://clawhub.ai/athola/skills/nm-abstract-hooks-eval",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:35:28.120Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:35:28.120Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.9K downloads",
      "href": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
      "sourceUrl": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:35:28.120Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.9.19",
      "href": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
      "sourceUrl": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:03:12.768Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.9.19",
      "description": "Release v1.9.19",
      "href": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
      "sourceUrl": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:03:12.768Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to hooks-eval and adjacent AI workflows.