hooks-eval
Evaluate hook security, performance, and SDK compliance. Use for audits Skill: hooks-eval Owner: athola Summary: Evaluate hook security, performance, and SDK compliance. Use for audits Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:03:12.768Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:27:41.806Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:27:36.109Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:44:30.079Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:08.983Z | u
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
1.9.19
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.9.19release · observed Aug 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-abstract-hooks-eval- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/snapshot"
Documentation
CLAWHUB
144,348 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: hooks-eval
description: Evaluate hook security, performance, and SDK compliance. Use for audits
version: 1.9.8
triggers:
- hooks
- evaluation
- security
- performance
- claude-sdk
- agent-sdk
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/abstract", "emoji": "\ud83e\udd9e", "requires": {"config": ["night-market.hook-scope-guide"]}}}
source: claude-night-market
source_plugin: abstract
---
> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.
## Table of Contents
- [Overview](#overview)
- [Key Capabilities](#key-capabilities)
- [Core Components](#core-components)
- [Quick Reference](#quick-reference)
- [Hook Event Types](#hook-event-types)
- [Hook Callback Signature](#hook-callback-signature)
- [Return Values](#return-values)
- [Quality Scoring (100 points)](#quality-scoring-(100-points))
- [Detailed Resources](#detailed-resources)
- [Basic Evaluation Workflow](#basic-evaluation-workflow)
- [Integration with Other Tools](#integration-with-other-tools)
- [Related Skills](#related-skills)
# Hooks Evaluation Framework
## Overview
This skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.
### Key Capabilities
- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention
- **Performance Analysis**: Execution time benchmarking, resource usage, optimization
- **Compliance Checking**: Structure validation, documentation requirements, best practices
- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns
### Core Components
| Component | Purpose |
|-----------|---------|
| **Hook Types Reference** | Complete SDK hook event types and signatures |
| **Evaluation Criteria** | Scoring system and quality gates |
| **Security Patterns** | Common vulnerabilities and mitigations |
| **Performance Benchmarks** | Thresholds and optimization guidance |
## Quick Reference
### Hook Event Types
```python
HookEvent = Literal[
"PreToolUse", # Before tool execution
"PostToolUse", # After tool execution
"UserPromptSubmit", # When user submits prompt
"Stop", # When stopping execution
"SubagentStop", # When a subagent stops
"TeammateIdle", # When teammate agent becomes idle (2.1.33+)
"TaskCompleted", # When a task finishes execution (2.1.33+)
"PreCompact" # Before message compaction
]
```
**Verification:** Run the command with `--help` flag to verify availability.
**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via _meta.json
{
"ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
"slug": "nm-abstract-hooks-eval",
"version": "1.9.19",
"publishedAt": 1787749392768
}modules/evaluation-criteria.md
# Hook Evaluation Criteria Detailed scoring rubric and quality gates for hook evaluation. ## Mathematical Foundation This evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices: - **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md)) - **Weighting**: Security-first weights with stakeholder validation - **Aggregation**: Weighted sum with penalty-based security scoring - **Validation**: Sensitivity analysis on non-security weights **Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation. ## Scoring System (100 points total) ### Security Analysis (30 points) **Vulnerability Detection:** - Critical vulnerabilities: -15 points each - High-risk issues: -8 points each - Medium-risk issues: -4 points each - Low-risk issues: -1 point each **Security Checklist:** | Check | Severity | Points Lost | |-------|----------|-------------| | Dynamic code evaluation with user input | Critical | -15 | | Command injection vulnerability | Critical | -15 | | Unvalidated file path access | High | -8 | | Secrets/credentials in code | High | -8 | | Missing input validation | Medium | -4 | | Overly permissive patterns | Medium | -4 | | No rate limiting | Low | -1 | | Verbose error messages exposing internals | Low | -1 | ### Performance Analysis (25 points) | Metric | Max Points | Criteria | |--------|------------|----------| | Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms | | Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex | | I/O operation efficiency | 4 | Minimal file/network operations | | Resource cleanup | 3 | Proper cleanup of handles, connections | **Performance Thresholds:** ```yaml pre_tool_use: excellent: <50ms good: <100ms acceptable: <200ms poor: >200ms post_tool_use: excellent: <100ms good: <200ms acceptable: <500ms poor: >500ms memory: excellent: <25MB good: <50MB acceptable: <100MB poor: >100MB ``` ### Compliance Analysis (20 points) | Aspect | Max Points | Requirements | |--------|------------|--------------| | Structure compliance | 8 | Valid JSON/Python, correct schema | | Documentation completeness | 6 | Purpose, parameters, return values documented | | Error handling | 4 | All exceptions caught, meaningful messages | | Best practices | 2 | Follows hook authoring guidelines | **Structure Requirements:** - JSON hooks: Valid JSON schema with required fields - Python hooks: Type hints, async/await patterns - Matcher patterns: Valid regex, appropriate scope ### Reliability Analysis (15 points) | Aspect | Max Points | Requirements | |--------|------------|--------------| | Error handling robustness | 6 | Graceful handling of all error conditions | | Timeout management | 4 | Appropriate timeouts configured | | Idempotency | 3 | Safe to r
modules/sdk-hook-types.md
# Python SDK Hook Types
Complete reference for Claude Agent SDK hook types, callbacks,
and matchers.
## Hook Events
### HookEvent
Supported hook event types in the Python SDK.
```python
from typing import Literal
HookEvent = Literal[
"Setup", # Called when plugin installed/enabled
"SessionStart", # Called when session begins
"SessionEnd", # Called when session ends normally
"UserPromptSubmit", # Called when user submits a prompt
"PreToolUse", # Called before tool execution
"PostToolUse", # Called after tool execution
"PostToolUseFailure",# Called when tool execution fails (2.1.20+)
"PermissionRequest", # Called when permission dialog would appear
"Notification", # Called on system notification (2.1.20+)
"SubagentStart", # Called when subagent spawns (2.1.20+)
"SubagentStop", # Called when a subagent stops
"Stop", # Called when stopping execution
"TeammateIdle", # Called when teammate agent becomes idle (2.1.33+)
"TaskCompleted", # Called when a task finishes execution (2.1.33+)
"ConfigChange", # Called when config is modified (2.1.49+)
"InstructionsLoaded",# Called when instructions are loaded (2.1.33+)
"PreCompact", # Called before message compaction
"PostCompact", # Called after compaction (2.1.76+)
"WorktreeCreate", # Called when git worktree is created (2.1.50+)
"WorktreeRemove", # Called when git worktree is removed (2.1.50+)
"StopFailure", # Called on error (2.1.78+)
"TaskCreated", # Called when task created (2.1.84+)
"CwdChanged", # Called on working dir change (2.1.83+)
"FileChanged", # Called on file change (2.1.83+)
"Elicitation", # MCP elicitation request (2.1.76+)
"ElicitationResult", # MCP elicitation response (2.1.76+)
]
```
**SDK vs CLI availability**: Most events work in both JSON
hooks (CLI) and Python SDK hooks. `PermissionRequest` is
CLI-only. `Setup`, `SessionStart`, `SessionEnd`, and
`Notification` are CLI-only (JSON hooks).
`WorktreeCreate` and `WorktreeRemove` are command-only
hooks (no Python SDK callback). They do not support
matchers.
### Event Summary
| Event | Trigger | Blockable | Matcher |
|-------|---------|-----------|---------|
| `Setup` | Plugin installed/enabled | No | No |
| `SessionStart` | Session begins | No | No |
| `SessionEnd` | Session ends normally | No | No |
| `UserPromptSubmit` | User submits input | No | No |
| `PreToolUse` | Before any tool runs | Yes | Tool name |
| `PostToolUse` | After tool completes | No | Tool name |
| `PostToolUseFailure` | Tool execution fails | No | Tool name |
| `PermissionRequest` | Permission dialog | Yes | Tool name |
| `SubagentStart` | Subagent spawns | No | No |
| `SubagentStop` | Subagent completes | No | No |
| `Stop` | Agent stops | No | No |
| `TeammateIdle` | Teammate idle | No | No |
| `TaskCompleted` | Task finishes | No |skill-card.md
## Description: Evaluate hook security, performance, and SDK compliance. Use for audits This skill is ready for commercial/non-commercial use. ## Publisher: [athola](https://clawhub.ai/user/athola) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use this skill to audit Claude Code hooks for security, performance, SDK compliance, reliability, and maintainability before deployment. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Broad triggers may cause the skill to appear in general security or performance conversations where hook-specific audit guidance is not intended. Mitigation: Invoke the skill deliberately for hook-related audits and verify that its guidance applies to the hook implementation under review. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-hooks-eval) - [ClawHub metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) - [Hook evaluation criteria](modules/evaluation-criteria.md) - [Python SDK hook types](modules/sdk-hook-types.md) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, configuration, guidance] **Output Format:** [Markdown guidance with code blocks, scoring rubrics, and configuration examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Includes hook event references, security and performance evaluation criteria, quality gates, and audit workflow examples.] ## Skill Version(s): 1.9.19 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/athola/skills/nm-abstract-hooks-eval",
"sourceUrl": "https://clawhub.ai/athola/skills/nm-abstract-hooks-eval",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:35:28.120Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T23:35:28.120Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
"sourceUrl": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:35:28.120Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.19",
"href": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
"sourceUrl": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:03:12.768Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.19",
"description": "Release v1.9.19",
"href": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
"sourceUrl": "https://clawhub.ai/athola/nm-abstract-hooks-eval",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:03:12.768Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
