{"id":"4414a801-249d-4c6e-9315-71140cce395f","entityType":"agent","slug":"clawhub-athola-nm-abstract-hooks-eval","name":"hooks-eval","canonicalUrl":"https://www.xpersona.co/agent/clawhub-athola-nm-abstract-hooks-eval","canonicalPath":"/agent/clawhub-athola-nm-abstract-hooks-eval","generatedAt":"2026-10-10T07:02:06.858Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T23:35:28.120Z","emptyReason":null},"description":"Evaluate hook security, performance, and SDK compliance. Use for audits Skill: hooks-eval Owner: athola Summary: Evaluate hook security, performance, and SDK compliance. Use for audits Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:03:12.768Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:27:41.806Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:27:36.109Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:44:30.079Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:08.983Z | u","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-abstract-hooks-eval","sourceUrl":"https://clawhub.ai/athola/nm-abstract-hooks-eval","homepage":"https://clawhub.ai/athola/skills/nm-abstract-hooks-eval","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/athola/nm-abstract-hooks-eval","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/athola/skills/nm-abstract-hooks-eval","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":41,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Evaluate hook security, performance, and SDK compliance. Use for audits Skill: hooks-eval Owner: athola Summary: Evaluate hook security, performance, and SDK co"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:35:28.120Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:35:28.120Z","emptyReason":null},"stars":null,"forks":null,"downloads":1882,"packageName":null,"latestVersion":"1.9.19","tractionLabel":"1.9K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:35:28.120Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T23:35:28.120Z","lastCrawledAt":"2026-10-09T23:35:28.120Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T23:35:28.120Z","lastVerifiedAt":null,"highlights":[{"version":"1.9.19","createdAt":"2026-08-26T13:03:12.768Z","changelog":"Release v1.9.19","fileCount":5,"zipByteSize":10992},{"version":"1.9.18","createdAt":"2026-08-15T21:27:41.806Z","changelog":"Release v1.9.18","fileCount":5,"zipByteSize":11020},{"version":"1.9.17","createdAt":"2026-07-30T05:27:36.109Z","changelog":"Release v1.9.17","fileCount":5,"zipByteSize":11117},{"version":"1.9.16","createdAt":"2026-07-14T19:44:30.079Z","changelog":"Release v1.9.16","fileCount":5,"zipByteSize":11021},{"version":"1.9.15","createdAt":"2026-07-04T21:19:08.983Z","changelog":"Release v1.9.15","fileCount":5,"zipByteSize":11058},{"version":"1.9.14","createdAt":"2026-06-30T17:49:42.818Z","changelog":"Release v1.9.14","fileCount":5,"zipByteSize":11085},{"version":"1.9.13","createdAt":"2026-06-27T16:14:21.003Z","changelog":"Release v1.9.13","fileCount":5,"zipByteSize":11048},{"version":"1.9.12","createdAt":"2026-06-19T03:07:26.491Z","changelog":"Release v1.9.12","fileCount":5,"zipByteSize":11013}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-abstract-hooks-eval","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T07:02:06.854Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-hooks-eval/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T23:35:28.120Z","emptyReason":null},"readme":"Skill: hooks-eval\n\nOwner: athola\n\nSummary: Evaluate hook security, performance, and SDK compliance. Use for audits\n\nTags: latest:1.9.19\n\nVersion history:\n\nv1.9.19 | 2026-08-26T13:03:12.768Z | user\n\nRelease v1.9.19\n\nv1.9.18 | 2026-08-15T21:27:41.806Z | user\n\nRelease v1.9.18\n\nv1.9.17 | 2026-07-30T05:27:36.109Z | user\n\nRelease v1.9.17\n\nv1.9.16 | 2026-07-14T19:44:30.079Z | user\n\nRelease v1.9.16\n\nv1.9.15 | 2026-07-04T21:19:08.983Z | user\n\nRelease v1.9.15\n\nv1.9.14 | 2026-06-30T17:49:42.818Z | user\n\nRelease v1.9.14\n\nv1.9.13 | 2026-06-27T16:14:21.003Z | user\n\nRelease v1.9.13\n\nv1.9.12 | 2026-06-19T03:07:26.491Z | user\n\nRelease v1.9.12\n\nv1.8.6 | 2026-06-07T21:21:38.720Z | user\n\nRelease v1.9.11\n\nv1.8.5 | 2026-05-09T02:14:48.059Z | user\n\nRelease v1.9.5\n\nv1.8.4 | 2026-05-06T14:14:17.618Z | user\n\nRelease v1.9.4\n\nv1.8.3 | 2026-04-10T05:44:44.375Z | user\n\nRelease v1.8.3\n\nv1.8.2 | 2026-04-06T14:17:18.669Z | user\n\nRelease v1.8.2\n\nv1.0.0 | 2026-04-06T05:55:14.410Z | auto\n\nInitial release for hooks-eval auditing skill:\n\n- Provides a framework to evaluate hook security, performance, and SDK compliance in Claude Code plugins and projects.\n- Supports security analysis (vulnerability scanning, pattern detection), performance benchmarking, and structure/compliance checks.\n- Offers detailed references for hook event types, callback signatures, return values, and quality scoring.\n- Includes guidance for integrating with plugin-level `hooks.json` and the Python SDK.\n- Supplies command-line workflows for running evaluations, security-focused scans, and compliance reports.\n\nArchive index:\n\nArchive v1.9.19: 5 files, 10992 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (1830b), SKILL.md (6191b), _meta.json (142b)\n\nFile v1.9.19:SKILL.md\n\n---\nname: hooks-eval\ndescription: Evaluate hook security, performance, and SDK compliance. Use for audits\nversion: 1.9.8\ntriggers:\n  - hooks\n  - evaluation\n  - security\n  - performance\n  - claude-sdk\n  - agent-sdk\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.hook-scope-guide\"]}}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Key Capabilities](#key-capabilities)\n- [Core Components](#core-components)\n- [Quick Reference](#quick-reference)\n- [Hook Event Types](#hook-event-types)\n- [Hook Callback Signature](#hook-callback-signature)\n- [Return Values](#return-values)\n- [Quality Scoring (100 points)](#quality-scoring-(100-points))\n- [Detailed Resources](#detailed-resources)\n- [Basic Evaluation Workflow](#basic-evaluation-workflow)\n- [Integration with Other Tools](#integration-with-other-tools)\n- [Related Skills](#related-skills)\n\n\n# Hooks Evaluation Framework\n\n## Overview\n\nThis skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.\n\n### Key Capabilities\n\n- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention\n- **Performance Analysis**: Execution time benchmarking, resource usage, optimization\n- **Compliance Checking**: Structure validation, documentation requirements, best practices\n- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns\n\n### Core Components\n\n| Component | Purpose |\n|-----------|---------|\n| **Hook Types Reference** | Complete SDK hook event types and signatures |\n| **Evaluation Criteria** | Scoring system and quality gates |\n| **Security Patterns** | Common vulnerabilities and mitigations |\n| **Performance Benchmarks** | Thresholds and optimization guidance |\n\n## Quick Reference\n\n### Hook Event Types\n\n```python\nHookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via `hooks.json` using shell commands (e.g., leyline's `detect-git-platform.sh`).\n\n### Plugin-Level hooks.json\n\nPlugins can declare hooks via `\"hooks\": \"./hooks/hooks.json\"` in plugin.json. The evaluator validates:\n- Referenced hooks.json exists and is valid JSON\n- Shell commands referenced in hooks exist and are executable\n- Hook matchers use valid event types\n\n### Hook Callback Signature\n\n```python\nasync def my_hook(\n    input_data: dict[str, Any],    # Hook-specific input\n    tool_use_id: str | None,       # Tool ID (for tool hooks)\n    context: HookContext           # Additional context\n) -> dict[str, Any]:               # Return decision/messages\n    ...\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Return Values\n\n```python\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",       # Match hook type\n        \"permissionDecision\": \"deny\",        # Optional: block action\n        \"permissionDecisionReason\": \"...\",   # Reason for denial\n        \"additionalContext\": \"...\",          # Optional: context added\n    }\n}\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Quality Scoring (100 points)\n\n| Category | Points | Focus |\n|----------|--------|-------|\n| Security | 30 | Vulnerabilities, injection, validation |\n| Performance | 25 | Execution time, memory, I/O |\n| Compliance | 20 | Structure, documentation, error handling |\n| Reliability | 15 | Timeouts, idempotency, degradation |\n| Maintainability | 10 | Code structure, modularity |\n\n## Detailed Resources\n\n- **SDK Hook Types**: See `modules/sdk-hook-types.md` for complete Python SDK type definitions, patterns, and examples\n- **Evaluation Criteria**: See `modules/evaluation-criteria.md` for detailed scoring rubric and quality gates\n- **Security Patterns**: See `modules/sdk-hook-types.md` for vulnerability detection and mitigation\n- **Performance Guide**: See `modules/evaluation-criteria.md` for benchmarking and optimization\n\n## Basic Evaluation Workflow\n\n```bash\n# 1. Run detailed evaluation\n/hooks-eval --detailed\n\n# 2. Focus on security issues\n/hooks-eval --security-only --format sarif\n\n# 3. Benchmark performance\n/hooks-eval --performance-baseline\n\n# 4. Check compliance\n/hooks-eval --compliance-report\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Integration with Other Tools\n\n```bash\n# Complete plugin evaluation pipeline\n/hooks-eval --detailed          # Evaluate all hooks\n/analyze-hook hooks/specific.py      # Deep-dive on one hook\n/validate-plugin .                   # Validate overall structure\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Related Skills\n\n- `abstract:hook-scope-guide` - Decide where to place hooks (plugin/project/global)\n- `abstract:hook-authoring` - Write hook rules and patterns\n- `abstract:validate-plugin` - Validate complete plugin structure\n## Troubleshooting\n\n### Common Issues\n\n**Hook not firing**\nVerify hook pattern matches the event. Check hook logs for errors\n\n**Syntax errors**\nValidate JSON/Python syntax before deployment\n\n**Permission denied**\nCheck hook file permissions and ownership\n\nFile v1.9.19:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-hooks-eval\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787749392768\n}\n\nFile v1.9.19:modules/evaluation-criteria.md\n\n# Hook Evaluation Criteria\n\nDetailed scoring rubric and quality gates for hook evaluation.\n\n## Mathematical Foundation\n\nThis evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:\n\n- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))\n- **Weighting**: Security-first weights with stakeholder validation\n- **Aggregation**: Weighted sum with penalty-based security scoring\n- **Validation**: Sensitivity analysis on non-security weights\n\n**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.\n\n## Scoring System (100 points total)\n\n### Security Analysis (30 points)\n\n**Vulnerability Detection:**\n- Critical vulnerabilities: -15 points each\n- High-risk issues: -8 points each\n- Medium-risk issues: -4 points each\n- Low-risk issues: -1 point each\n\n**Security Checklist:**\n\n| Check | Severity | Points Lost |\n|-------|----------|-------------|\n| Dynamic code evaluation with user input | Critical | -15 |\n| Command injection vulnerability | Critical | -15 |\n| Unvalidated file path access | High | -8 |\n| Secrets/credentials in code | High | -8 |\n| Missing input validation | Medium | -4 |\n| Overly permissive patterns | Medium | -4 |\n| No rate limiting | Low | -1 |\n| Verbose error messages exposing internals | Low | -1 |\n\n### Performance Analysis (25 points)\n\n| Metric | Max Points | Criteria |\n|--------|------------|----------|\n| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |\n| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |\n| I/O operation efficiency | 4 | Minimal file/network operations |\n| Resource cleanup | 3 | Proper cleanup of handles, connections |\n\n**Performance Thresholds:**\n\n```yaml\npre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB\n```\n\n### Compliance Analysis (20 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Structure compliance | 8 | Valid JSON/Python, correct schema |\n| Documentation completeness | 6 | Purpose, parameters, return values documented |\n| Error handling | 4 | All exceptions caught, meaningful messages |\n| Best practices | 2 | Follows hook authoring guidelines |\n\n**Structure Requirements:**\n\n- JSON hooks: Valid JSON schema with required fields\n- Python hooks: Type hints, async/await patterns\n- Matcher patterns: Valid regex, appropriate scope\n\n### Reliability Analysis (15 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Error handling robustness | 6 | Graceful handling of all error conditions |\n| Timeout management | 4 | Appropriate timeouts configured |\n| Idempotency | 3 | Safe to retry without side effects |\n| Graceful degradation | 2 | Falls back safely on failure |\n\n**Reliability Checklist:**\n\n- [ ] Hook returns valid response on all code paths\n- [ ] Exceptions are caught and handled\n- [ ] Timeout is configured appropriately\n- [ ] Hook can be called multiple times safely\n- [ ] Failure doesn't break agent operation\n\n### Maintainability (10 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Code structure | 4 | Clear, modular, single responsibility |\n| Documentation clarity | 3 | Purpose and behavior well explained |\n| Modularity | 2 | Reusable components, no duplication |\n| Test coverage | 1 | Tests exist for key functionality |\n\n## Quality Levels\n\n| Score | Level | Description |\n|-------|-------|-------------|\n| 91-100 | Excellent | Production-ready, follows all best practices |\n| 76-90 | Good | Minor improvements suggested |\n| 51-75 | Acceptable | Some issues requiring attention |\n| 26-50 | Poor | Significant issues need addressing |\n| 0-25 | Critical | Major security or reliability issues |\n\n## Quality Gates\n\nDefault thresholds for CI/CD integration:\n\n```yaml\nquality_gates:\n  security_score: \">= 80\"\n  performance_score: \">= 70\"\n  compliance_score: \">= 85\"\n  reliability_score: \">= 85\"\n  overall_score: \">= 75\"\n  max_critical_issues: 0\n  max_high_issues: 2\n```\n\n### Sensitivity Analysis Requirements\n\nSecurity weights are non-negotiable, but other weights should be validated:\n\n```yaml\nsensitivity_analysis:\n  # Security weights are fixed (non-negotiable)\n  fixed_weights: [\"security_analysis\"]\n\n  # Other weights tested for sensitivity\n  test_weights: [\"performance\", \"compliance\", \"reliability\", \"maintainability\"]\n  variation: 0.20  # ±20% weight variation\n\n  requirements:\n    stable_rankings: true  # Rankings shouldn't change (except security)\n    critical_weights_identified: true  # Document sensitive weights\n```\n\nSee [Sensitivity Analysis](../../skills-eval/modules/multi-metric-evaluation-methodology.md#sensitivity-analysis) for implementation details.\n\n### Gate Behaviors\n\n| Gate | Failure Action |\n|------|----------------|\n| `security_score` | Block deployment, require review |\n| `performance_score` | Warn, suggest optimization |\n| `compliance_score` | Block until documentation complete |\n| `reliability_score` | Block deployment |\n| `max_critical_issues` | Immediate block |\n\n## Issue Classification\n\n### Critical Issues (Immediate Action Required)\n\n- Dynamic code evaluation with untrusted input\n- Command injection vulnerabilities\n- Credential exposure\n- Unhandled exceptions that break agent\n\n### High Issues (Address Before Release)\n\n- Missing input validation\n- Performance exceeds thresholds\n- Missing error handling\n- Insecure file operations\n\n### Medium Issues (Address Soon)\n\n- Missing documentation\n- Suboptimal patterns\n- Minor performance concerns\n- Code style violations\n\n### Low Issues (Nice to Fix)\n\n- Minor documentation gaps\n- Formatting inconsistencies\n- Optimization opportunities\n- Enhanced logging suggestions\n\n## Evaluation Report Format\n\n### Summary Format\n\n```\n=== Hooks Evaluation Report ===\nPlugin: {name} (v{version})\nScope: {scope}\nTotal hooks: {count} ({json_count} JSON, {python_count} Python)\n\n=== Scores ===\nSecurity:      {score}/100 ({level})\nPerformance:   {score}/100 ({level})\nCompliance:    {score}/100 ({level})\nReliability:   {score}/100 ({level})\nMaintainability: {score}/100 ({level})\n────────────────────────────────\nOverall:       {score}/100 ({level})\n\n=== Issues ===\nCritical: {count}\nHigh: {count}\nMedium: {count}\nLow: {count}\n```\n\n### Detailed Format\n\nIncludes per-hook breakdown:\n\n```\n=== Hook: {hook_path} ===\nType: {json|python}\nEvent: {PreToolUse|PostToolUse|...}\nMatcher: {pattern|universal}\n\nSecurity Issues:\n  [{severity}] Line {n}: {description}\n\nPerformance:\n  Estimated time: {ms}ms (threshold: {threshold}ms)\n  Memory usage: {mb}MB (threshold: {threshold}MB)\n\nRecommendations:\n  1. {recommendation}\n  2. {recommendation}\n```\n\n## Customization\n\n### Per-Plugin Configuration\n\nCreate `.hooks-eval.yaml` in plugin root:\n\n```yaml\nhooks_eval:\n  # Override security thresholds\n  security_thresholds:\n    critical_score: 80\n    high_score: 70\n\n  # Override performance thresholds\n  performance_thresholds:\n    pre_tool_use_max_ms: 100\n    post_tool_use_max_ms: 200\n    max_memory_mb: 50\n\n  # Compliance requirements\n  compliance_requirements:\n    require_documentation: true\n    require_error_handling: true\n    require_timeout_config: true\n\n  # Custom rules\n  custom_rules:\n    - name: \"no-hardcoded-secrets\"\n      pattern: \"password|secret|token\"\n      severity: \"high\"\n    - name: \"require-shebang\"\n      pattern: \"^#!\"\n      file_types: [\".sh\", \".py\"]\n      severity: \"medium\"\n\n  # Excluded paths\n  exclude_paths:\n    - \"hooks/experimental/*\"\n    - \"hooks/deprecated/*\"\n```\n\n### Severity Overrides\n\nOverride default severity for specific patterns:\n\n```yaml\nseverity_overrides:\n  - pattern: \"subprocess.run\"\n    default_severity: \"high\"\n    override_severity: \"medium\"\n    reason: \"Safe usage verified in review\"\n```\n\nFile v1.9.19:modules/sdk-hook-types.md\n\n# Python SDK Hook Types\n\nComplete reference for Claude Agent SDK hook types, callbacks,\nand matchers.\n\n## Hook Events\n\n### HookEvent\n\nSupported hook event types in the Python SDK.\n\n```python\nfrom typing import Literal\n\nHookEvent = Literal[\n    \"Setup\",             # Called when plugin installed/enabled\n    \"SessionStart\",      # Called when session begins\n    \"SessionEnd\",        # Called when session ends normally\n    \"UserPromptSubmit\",  # Called when user submits a prompt\n    \"PreToolUse\",        # Called before tool execution\n    \"PostToolUse\",       # Called after tool execution\n    \"PostToolUseFailure\",# Called when tool execution fails (2.1.20+)\n    \"PermissionRequest\", # Called when permission dialog would appear\n    \"Notification\",      # Called on system notification (2.1.20+)\n    \"SubagentStart\",     # Called when subagent spawns (2.1.20+)\n    \"SubagentStop\",      # Called when a subagent stops\n    \"Stop\",              # Called when stopping execution\n    \"TeammateIdle\",      # Called when teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",     # Called when a task finishes execution (2.1.33+)\n    \"ConfigChange\",      # Called when config is modified (2.1.49+)\n    \"InstructionsLoaded\",# Called when instructions are loaded (2.1.33+)\n    \"PreCompact\",        # Called before message compaction\n    \"PostCompact\",       # Called after compaction (2.1.76+)\n    \"WorktreeCreate\",    # Called when git worktree is created (2.1.50+)\n    \"WorktreeRemove\",    # Called when git worktree is removed (2.1.50+)\n    \"StopFailure\",       # Called on error (2.1.78+)\n    \"TaskCreated\",       # Called when task created (2.1.84+)\n    \"CwdChanged\",        # Called on working dir change (2.1.83+)\n    \"FileChanged\",       # Called on file change (2.1.83+)\n    \"Elicitation\",       # MCP elicitation request (2.1.76+)\n    \"ElicitationResult\", # MCP elicitation response (2.1.76+)\n]\n```\n\n**SDK vs CLI availability**: Most events work in both JSON\nhooks (CLI) and Python SDK hooks. `PermissionRequest` is\nCLI-only. `Setup`, `SessionStart`, `SessionEnd`, and\n`Notification` are CLI-only (JSON hooks).\n`WorktreeCreate` and `WorktreeRemove` are command-only\nhooks (no Python SDK callback). They do not support\nmatchers.\n\n### Event Summary\n\n| Event | Trigger | Blockable | Matcher |\n|-------|---------|-----------|---------|\n| `Setup` | Plugin installed/enabled | No | No |\n| `SessionStart` | Session begins | No | No |\n| `SessionEnd` | Session ends normally | No | No |\n| `UserPromptSubmit` | User submits input | No | No |\n| `PreToolUse` | Before any tool runs | Yes | Tool name |\n| `PostToolUse` | After tool completes | No | Tool name |\n| `PostToolUseFailure` | Tool execution fails | No | Tool name |\n| `PermissionRequest` | Permission dialog | Yes | Tool name |\n| `SubagentStart` | Subagent spawns | No | No |\n| `SubagentStop` | Subagent completes | No | No |\n| `Stop` | Agent stops | No | No |\n| `TeammateIdle` | Teammate idle | No | No |\n| `TaskCompleted` | Task finishes | No | No |\n| `ConfigChange` | Config modified | No | No |\n| `InstructionsLoaded` | Instructions loaded | No | No |\n| `PreCompact` | Before compaction | No | No |\n| `PostCompact` | After compaction | No | No |\n| `WorktreeCreate` | Worktree created | No | No |\n| `WorktreeRemove` | Worktree removed | No | No |\n| `StopFailure` | Error occurs | No | Error type |\n| `TaskCreated` | Task created | Yes | No |\n| `CwdChanged` | Directory changed | No | No |\n| `FileChanged` | File changed | No | Filename |\n| `Elicitation` | MCP elicitation | Yes | MCP server |\n| `ElicitationResult` | Elicitation response | Yes | MCP server |\n\n### Notable Version Changes\n\nAll hook events include `agent_id` and `agent_type` as\nof 2.1.69+.\n\n| Version | Change |\n|---------|--------|\n| 2.1.69 | `TeammateIdle`/`TaskCompleted` support `{\"continue\": false}` for graceful shutdown |\n| 2.1.69 | Plugin WorktreeCreate/WorktreeRemove hooks fire correctly (were silently ignored) |\n| 2.1.71 | New tools: `CronCreate`, `CronList`, `CronDelete` appear in PreToolUse/PostToolUse |\n| 2.1.72 | `ExitWorktree` tool added; `lsof`/`pgrep`/`tput`/`ss`/`fd`/`fdfind` auto-approved |\n| 2.1.72 | Skill hook double-fire fixed; `transcript_path` correct for resumed sessions |\n| 2.1.72 | Failed Read/WebFetch/Glob no longer cancel sibling tool calls (only Bash cascades) |\n| 2.1.73 | SessionStart no longer double-fires on `--resume`/`--continue` |\n| 2.1.73 | JSON-output hooks no longer inject spurious system-reminder messages |\n| 2.1.74 | SessionEnd hooks timeout now configurable via `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` |\n| 2.1.75 | Hook source displayed in permission prompts; async hook messages suppressed by default |\n| 2.1.76 | `Elicitation` and `ElicitationResult` events for MCP servers |\n| 2.1.76 | `PostCompact` event fires after context compaction |\n| 2.1.77 | PreToolUse \"allow\" no longer bypasses deny rules (security fix) |\n| 2.1.83 | `CwdChanged` and `FileChanged` events added |\n| 2.1.84 | `TaskCreated` event (blockable); HTTP hooks can return worktree path |\n| 2.1.85 | `if` field for conditional hook execution; PreToolUse can match `AskUserQuestion` |\n\n## Type Definitions\n\n### HookCallback\n\n```python\nfrom typing import Any, Awaitable, Callable\n\nHookCallback = Callable[\n    [dict[str, Any], str | None, HookContext],\n    Awaitable[dict[str, Any]]\n]\n```\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `input_data` | `dict[str, Any]` | Hook-specific input data (varies by event) |\n| `tool_use_id` | `str \\| None` | Tool use identifier (for tool-related hooks) |\n| `context` | `HookContext` | Additional context information |\n\n**Returns:** `dict[str, Any]` with optional fields:\n`decision` (\"block\"), `systemMessage` (str),\n`hookSpecificOutput` (dict).\n\n### HookMatcher\n\n```python\n@dataclass\nclass HookMatcher:\n    matcher: str | None = None\n    hooks: list[HookCallback] = field(default_factory=list)\n    timeout: float | None = None  # Default: 60s\n```\n\n| Pattern | Matches |\n|---------|---------|\n| `\"Bash\"` | Only Bash tool |\n| `\"Write\\|Edit\"` | Write OR Edit tools |\n| `None` | All tools (universal matcher) |\n\n## Complete Usage Example\n\n```python\nfrom claude_agent_sdk import query, ClaudeAgentOptions, HookMatcher, HookContext\nfrom typing import Any\n\nasync def validate_bash_command(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Block dangerous bash commands.\"\"\"\n    if input_data['tool_name'] == 'Bash':\n        command = input_data['tool_input'].get('command', '')\n        if 'rm -rf /' in command:\n            return {\n                'hookSpecificOutput': {\n                    'hookEventName': 'PreToolUse',\n                    'permissionDecision': 'deny',\n                    'permissionDecisionReason': 'Dangerous command blocked'\n                }\n            }\n    return {}\n\nasync def log_tool_use(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Log all tool usage for auditing.\"\"\"\n    print(f\"Tool used: {input_data.get('tool_name')}\")\n    return {}\n\noptions = ClaudeAgentOptions(\n    hooks={\n        'PreToolUse': [\n            HookMatcher(matcher='Bash', hooks=[validate_bash_command], timeout=120),\n            HookMatcher(hooks=[log_tool_use])\n        ],\n        'PostToolUse': [\n            HookMatcher(hooks=[log_tool_use])\n        ]\n    }\n)\n\nasync for message in query(prompt=\"Analyze this codebase\", options=options):\n    print(message)\n```\n\n## Input Data by Event Type\n\n### PreToolUse / PostToolUse\n\n```python\n# PreToolUse\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"}}\n\n# PostToolUse (adds result)\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"},\n \"tool_result\": \"file1.txt\\nfile2.txt\", \"error\": None}\n```\n\n### PermissionRequest (CLI only)\n\n```python\n# Input\n{\"session_id\": \"abc123\", \"tool_name\": \"Bash\",\n \"tool_input\": {\"command\": \"npm install\"},\n \"permission_mode\": \"default\", \"cwd\": \"/path/to/project\"}\n\n# Output: allow\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"allow\"}}}\n\n# Output: deny\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"deny\", \"message\": \"Reason\"}}}\n```\n\n### Other Events\n\n| Event | Key Fields |\n|-------|------------|\n| `UserPromptSubmit` | `prompt`, `conversation_id` |\n| `TeammateIdle` | `agent_id`, `session_id` |\n| `TaskCompleted` | `task_id`, `result`, `duration_ms`, `token_count` |\n| `Stop` / `SubagentStop` | `reason`, `final_message` |\n| `PreCompact` | `messages`, `token_count` |\n| `PostCompact` | `trigger` (\"manual\"/\"auto\"), `compact_summary` |\n| `WorktreeCreate` | `name` (must print worktree path to stdout) |\n| `WorktreeRemove` | `worktree_path` (cannot block removal) |\n\n## Hook Return Patterns\n\n```python\n# Allow (default)\nreturn {}\n\n# Block action\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",\n        \"permissionDecision\": \"deny\",\n        \"permissionDecisionReason\": \"Explanation\"\n    }\n}\n\n# Add system message\nreturn {\"systemMessage\": \"Important context added to conversation\"}\n```\n\n## Best Practices\n\n| Area | Guidance |\n|------|----------|\n| Performance | Keep hooks fast (<100ms PreToolUse, <200ms PostToolUse) |\n| Performance | Use appropriate timeouts; cache expensive computations |\n| Security | Validate all input; never use dynamic code eval with hook input |\n| Security | Use allowlists over blocklists; sanitize log data |\n| Reliability | Always return a dict (even empty `{}`); handle exceptions |\n| Reliability | Design hooks to be idempotent; include meaningful block reasons |\n| Testing | Test with various input patterns; verify timeout behavior |\n\nFile v1.9.19:skill-card.md\n\n## Description:\n\nEvaluate hook security, performance, and SDK compliance. Use for audits\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to audit Claude Code hooks for security, performance, SDK compliance, reliability, and maintainability before deployment.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad triggers may cause the skill to appear in general security or performance conversations where hook-specific audit guidance is not intended.\n\nMitigation: Invoke the skill deliberately for hook-related audits and verify that its guidance applies to the hook implementation under review.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-hooks-eval)\n- [ClawHub metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract)\n- [Hook evaluation criteria](modules/evaluation-criteria.md)\n- [Python SDK hook types](modules/sdk-hook-types.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with code blocks, scoring rubrics, and configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes hook event references, security and performance evaluation criteria, quality gates, and audit workflow examples.]\n\n## Skill Version(s):\n\n1.9.19 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.9.18: 5 files, 11020 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (1930b), SKILL.md (6191b), _meta.json (142b)\n\nFile v1.9.18:SKILL.md\n\n---\nname: hooks-eval\ndescription: Evaluate hook security, performance, and SDK compliance. Use for audits\nversion: 1.9.8\ntriggers:\n  - hooks\n  - evaluation\n  - security\n  - performance\n  - claude-sdk\n  - agent-sdk\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.hook-scope-guide\"]}}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Key Capabilities](#key-capabilities)\n- [Core Components](#core-components)\n- [Quick Reference](#quick-reference)\n- [Hook Event Types](#hook-event-types)\n- [Hook Callback Signature](#hook-callback-signature)\n- [Return Values](#return-values)\n- [Quality Scoring (100 points)](#quality-scoring-(100-points))\n- [Detailed Resources](#detailed-resources)\n- [Basic Evaluation Workflow](#basic-evaluation-workflow)\n- [Integration with Other Tools](#integration-with-other-tools)\n- [Related Skills](#related-skills)\n\n\n# Hooks Evaluation Framework\n\n## Overview\n\nThis skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.\n\n### Key Capabilities\n\n- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention\n- **Performance Analysis**: Execution time benchmarking, resource usage, optimization\n- **Compliance Checking**: Structure validation, documentation requirements, best practices\n- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns\n\n### Core Components\n\n| Component | Purpose |\n|-----------|---------|\n| **Hook Types Reference** | Complete SDK hook event types and signatures |\n| **Evaluation Criteria** | Scoring system and quality gates |\n| **Security Patterns** | Common vulnerabilities and mitigations |\n| **Performance Benchmarks** | Thresholds and optimization guidance |\n\n## Quick Reference\n\n### Hook Event Types\n\n```python\nHookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via `hooks.json` using shell commands (e.g., leyline's `detect-git-platform.sh`).\n\n### Plugin-Level hooks.json\n\nPlugins can declare hooks via `\"hooks\": \"./hooks/hooks.json\"` in plugin.json. The evaluator validates:\n- Referenced hooks.json exists and is valid JSON\n- Shell commands referenced in hooks exist and are executable\n- Hook matchers use valid event types\n\n### Hook Callback Signature\n\n```python\nasync def my_hook(\n    input_data: dict[str, Any],    # Hook-specific input\n    tool_use_id: str | None,       # Tool ID (for tool hooks)\n    context: HookContext           # Additional context\n) -> dict[str, Any]:               # Return decision/messages\n    ...\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Return Values\n\n```python\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",       # Match hook type\n        \"permissionDecision\": \"deny\",        # Optional: block action\n        \"permissionDecisionReason\": \"...\",   # Reason for denial\n        \"additionalContext\": \"...\",          # Optional: context added\n    }\n}\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Quality Scoring (100 points)\n\n| Category | Points | Focus |\n|----------|--------|-------|\n| Security | 30 | Vulnerabilities, injection, validation |\n| Performance | 25 | Execution time, memory, I/O |\n| Compliance | 20 | Structure, documentation, error handling |\n| Reliability | 15 | Timeouts, idempotency, degradation |\n| Maintainability | 10 | Code structure, modularity |\n\n## Detailed Resources\n\n- **SDK Hook Types**: See `modules/sdk-hook-types.md` for complete Python SDK type definitions, patterns, and examples\n- **Evaluation Criteria**: See `modules/evaluation-criteria.md` for detailed scoring rubric and quality gates\n- **Security Patterns**: See `modules/sdk-hook-types.md` for vulnerability detection and mitigation\n- **Performance Guide**: See `modules/evaluation-criteria.md` for benchmarking and optimization\n\n## Basic Evaluation Workflow\n\n```bash\n# 1. Run detailed evaluation\n/hooks-eval --detailed\n\n# 2. Focus on security issues\n/hooks-eval --security-only --format sarif\n\n# 3. Benchmark performance\n/hooks-eval --performance-baseline\n\n# 4. Check compliance\n/hooks-eval --compliance-report\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Integration with Other Tools\n\n```bash\n# Complete plugin evaluation pipeline\n/hooks-eval --detailed          # Evaluate all hooks\n/analyze-hook hooks/specific.py      # Deep-dive on one hook\n/validate-plugin .                   # Validate overall structure\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Related Skills\n\n- `abstract:hook-scope-guide` - Decide where to place hooks (plugin/project/global)\n- `abstract:hook-authoring` - Write hook rules and patterns\n- `abstract:validate-plugin` - Validate complete plugin structure\n## Troubleshooting\n\n### Common Issues\n\n**Hook not firing**\nVerify hook pattern matches the event. Check hook logs for errors\n\n**Syntax errors**\nValidate JSON/Python syntax before deployment\n\n**Permission denied**\nCheck hook file permissions and ownership\n\nFile v1.9.18:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-hooks-eval\",\n  \"version\": \"1.9.18\",\n  \"publishedAt\": 1786829261806\n}\n\nFile v1.9.18:modules/evaluation-criteria.md\n\n# Hook Evaluation Criteria\n\nDetailed scoring rubric and quality gates for hook evaluation.\n\n## Mathematical Foundation\n\nThis evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:\n\n- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))\n- **Weighting**: Security-first weights with stakeholder validation\n- **Aggregation**: Weighted sum with penalty-based security scoring\n- **Validation**: Sensitivity analysis on non-security weights\n\n**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.\n\n## Scoring System (100 points total)\n\n### Security Analysis (30 points)\n\n**Vulnerability Detection:**\n- Critical vulnerabilities: -15 points each\n- High-risk issues: -8 points each\n- Medium-risk issues: -4 points each\n- Low-risk issues: -1 point each\n\n**Security Checklist:**\n\n| Check | Severity | Points Lost |\n|-------|----------|-------------|\n| Dynamic code evaluation with user input | Critical | -15 |\n| Command injection vulnerability | Critical | -15 |\n| Unvalidated file path access | High | -8 |\n| Secrets/credentials in code | High | -8 |\n| Missing input validation | Medium | -4 |\n| Overly permissive patterns | Medium | -4 |\n| No rate limiting | Low | -1 |\n| Verbose error messages exposing internals | Low | -1 |\n\n### Performance Analysis (25 points)\n\n| Metric | Max Points | Criteria |\n|--------|------------|----------|\n| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |\n| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |\n| I/O operation efficiency | 4 | Minimal file/network operations |\n| Resource cleanup | 3 | Proper cleanup of handles, connections |\n\n**Performance Thresholds:**\n\n```yaml\npre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB\n```\n\n### Compliance Analysis (20 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Structure compliance | 8 | Valid JSON/Python, correct schema |\n| Documentation completeness | 6 | Purpose, parameters, return values documented |\n| Error handling | 4 | All exceptions caught, meaningful messages |\n| Best practices | 2 | Follows hook authoring guidelines |\n\n**Structure Requirements:**\n\n- JSON hooks: Valid JSON schema with required fields\n- Python hooks: Type hints, async/await patterns\n- Matcher patterns: Valid regex, appropriate scope\n\n### Reliability Analysis (15 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Error handling robustness | 6 | Graceful handling of all error conditions |\n| Timeout management | 4 | Appropriate timeouts configured |\n| Idempotency | 3 | Safe to retry without side effects |\n| Graceful degradation | 2 | Falls back safely on failure |\n\n**Reliability Checklist:**\n\n- [ ] Hook returns valid response on all code paths\n- [ ] Exceptions are caught and handled\n- [ ] Timeout is configured appropriately\n- [ ] Hook can be called multiple times safely\n- [ ] Failure doesn't break agent operation\n\n### Maintainability (10 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Code structure | 4 | Clear, modular, single responsibility |\n| Documentation clarity | 3 | Purpose and behavior well explained |\n| Modularity | 2 | Reusable components, no duplication |\n| Test coverage | 1 | Tests exist for key functionality |\n\n## Quality Levels\n\n| Score | Level | Description |\n|-------|-------|-------------|\n| 91-100 | Excellent | Production-ready, follows all best practices |\n| 76-90 | Good | Minor improvements suggested |\n| 51-75 | Acceptable | Some issues requiring attention |\n| 26-50 | Poor | Significant issues need addressing |\n| 0-25 | Critical | Major security or reliability issues |\n\n## Quality Gates\n\nDefault thresholds for CI/CD integration:\n\n```yaml\nquality_gates:\n  security_score: \">= 80\"\n  performance_score: \">= 70\"\n  compliance_score: \">= 85\"\n  reliability_score: \">= 85\"\n  overall_score: \">= 75\"\n  max_critical_issues: 0\n  max_high_issues: 2\n```\n\n### Sensitivity Analysis Requirements\n\nSecurity weights are non-negotiable, but other weights should be validated:\n\n```yaml\nsensitivity_analysis:\n  # Security weights are fixed (non-negotiable)\n  fixed_weights: [\"security_analysis\"]\n\n  # Other weights tested for sensitivity\n  test_weights: [\"performance\", \"compliance\", \"reliability\", \"maintainability\"]\n  variation: 0.20  # ±20% weight variation\n\n  requirements:\n    stable_rankings: true  # Rankings shouldn't change (except security)\n    critical_weights_identified: true  # Document sensitive weights\n```\n\nSee [Sensitivity Analysis](../../skills-eval/modules/multi-metric-evaluation-methodology.md#sensitivity-analysis) for implementation details.\n\n### Gate Behaviors\n\n| Gate | Failure Action |\n|------|----------------|\n| `security_score` | Block deployment, require review |\n| `performance_score` | Warn, suggest optimization |\n| `compliance_score` | Block until documentation complete |\n| `reliability_score` | Block deployment |\n| `max_critical_issues` | Immediate block |\n\n## Issue Classification\n\n### Critical Issues (Immediate Action Required)\n\n- Dynamic code evaluation with untrusted input\n- Command injection vulnerabilities\n- Credential exposure\n- Unhandled exceptions that break agent\n\n### High Issues (Address Before Release)\n\n- Missing input validation\n- Performance exceeds thresholds\n- Missing error handling\n- Insecure file operations\n\n### Medium Issues (Address Soon)\n\n- Missing documentation\n- Suboptimal patterns\n- Minor performance concerns\n- Code style violations\n\n### Low Issues (Nice to Fix)\n\n- Minor documentation gaps\n- Formatting inconsistencies\n- Optimization opportunities\n- Enhanced logging suggestions\n\n## Evaluation Report Format\n\n### Summary Format\n\n```\n=== Hooks Evaluation Report ===\nPlugin: {name} (v{version})\nScope: {scope}\nTotal hooks: {count} ({json_count} JSON, {python_count} Python)\n\n=== Scores ===\nSecurity:      {score}/100 ({level})\nPerformance:   {score}/100 ({level})\nCompliance:    {score}/100 ({level})\nReliability:   {score}/100 ({level})\nMaintainability: {score}/100 ({level})\n────────────────────────────────\nOverall:       {score}/100 ({level})\n\n=== Issues ===\nCritical: {count}\nHigh: {count}\nMedium: {count}\nLow: {count}\n```\n\n### Detailed Format\n\nIncludes per-hook breakdown:\n\n```\n=== Hook: {hook_path} ===\nType: {json|python}\nEvent: {PreToolUse|PostToolUse|...}\nMatcher: {pattern|universal}\n\nSecurity Issues:\n  [{severity}] Line {n}: {description}\n\nPerformance:\n  Estimated time: {ms}ms (threshold: {threshold}ms)\n  Memory usage: {mb}MB (threshold: {threshold}MB)\n\nRecommendations:\n  1. {recommendation}\n  2. {recommendation}\n```\n\n## Customization\n\n### Per-Plugin Configuration\n\nCreate `.hooks-eval.yaml` in plugin root:\n\n```yaml\nhooks_eval:\n  # Override security thresholds\n  security_thresholds:\n    critical_score: 80\n    high_score: 70\n\n  # Override performance thresholds\n  performance_thresholds:\n    pre_tool_use_max_ms: 100\n    post_tool_use_max_ms: 200\n    max_memory_mb: 50\n\n  # Compliance requirements\n  compliance_requirements:\n    require_documentation: true\n    require_error_handling: true\n    require_timeout_config: true\n\n  # Custom rules\n  custom_rules:\n    - name: \"no-hardcoded-secrets\"\n      pattern: \"password|secret|token\"\n      severity: \"high\"\n    - name: \"require-shebang\"\n      pattern: \"^#!\"\n      file_types: [\".sh\", \".py\"]\n      severity: \"medium\"\n\n  # Excluded paths\n  exclude_paths:\n    - \"hooks/experimental/*\"\n    - \"hooks/deprecated/*\"\n```\n\n### Severity Overrides\n\nOverride default severity for specific patterns:\n\n```yaml\nseverity_overrides:\n  - pattern: \"subprocess.run\"\n    default_severity: \"high\"\n    override_severity: \"medium\"\n    reason: \"Safe usage verified in review\"\n```\n\nFile v1.9.18:modules/sdk-hook-types.md\n\n# Python SDK Hook Types\n\nComplete reference for Claude Agent SDK hook types, callbacks,\nand matchers.\n\n## Hook Events\n\n### HookEvent\n\nSupported hook event types in the Python SDK.\n\n```python\nfrom typing import Literal\n\nHookEvent = Literal[\n    \"Setup\",             # Called when plugin installed/enabled\n    \"SessionStart\",      # Called when session begins\n    \"SessionEnd\",        # Called when session ends normally\n    \"UserPromptSubmit\",  # Called when user submits a prompt\n    \"PreToolUse\",        # Called before tool execution\n    \"PostToolUse\",       # Called after tool execution\n    \"PostToolUseFailure\",# Called when tool execution fails (2.1.20+)\n    \"PermissionRequest\", # Called when permission dialog would appear\n    \"Notification\",      # Called on system notification (2.1.20+)\n    \"SubagentStart\",     # Called when subagent spawns (2.1.20+)\n    \"SubagentStop\",      # Called when a subagent stops\n    \"Stop\",              # Called when stopping execution\n    \"TeammateIdle\",      # Called when teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",     # Called when a task finishes execution (2.1.33+)\n    \"ConfigChange\",      # Called when config is modified (2.1.49+)\n    \"InstructionsLoaded\",# Called when instructions are loaded (2.1.33+)\n    \"PreCompact\",        # Called before message compaction\n    \"PostCompact\",       # Called after compaction (2.1.76+)\n    \"WorktreeCreate\",    # Called when git worktree is created (2.1.50+)\n    \"WorktreeRemove\",    # Called when git worktree is removed (2.1.50+)\n    \"StopFailure\",       # Called on error (2.1.78+)\n    \"TaskCreated\",       # Called when task created (2.1.84+)\n    \"CwdChanged\",        # Called on working dir change (2.1.83+)\n    \"FileChanged\",       # Called on file change (2.1.83+)\n    \"Elicitation\",       # MCP elicitation request (2.1.76+)\n    \"ElicitationResult\", # MCP elicitation response (2.1.76+)\n]\n```\n\n**SDK vs CLI availability**: Most events work in both JSON\nhooks (CLI) and Python SDK hooks. `PermissionRequest` is\nCLI-only. `Setup`, `SessionStart`, `SessionEnd`, and\n`Notification` are CLI-only (JSON hooks).\n`WorktreeCreate` and `WorktreeRemove` are command-only\nhooks (no Python SDK callback). They do not support\nmatchers.\n\n### Event Summary\n\n| Event | Trigger | Blockable | Matcher |\n|-------|---------|-----------|---------|\n| `Setup` | Plugin installed/enabled | No | No |\n| `SessionStart` | Session begins | No | No |\n| `SessionEnd` | Session ends normally | No | No |\n| `UserPromptSubmit` | User submits input | No | No |\n| `PreToolUse` | Before any tool runs | Yes | Tool name |\n| `PostToolUse` | After tool completes | No | Tool name |\n| `PostToolUseFailure` | Tool execution fails | No | Tool name |\n| `PermissionRequest` | Permission dialog | Yes | Tool name |\n| `SubagentStart` | Subagent spawns | No | No |\n| `SubagentStop` | Subagent completes | No | No |\n| `Stop` | Agent stops | No | No |\n| `TeammateIdle` | Teammate idle | No | No |\n| `TaskCompleted` | Task finishes | No | No |\n| `ConfigChange` | Config modified | No | No |\n| `InstructionsLoaded` | Instructions loaded | No | No |\n| `PreCompact` | Before compaction | No | No |\n| `PostCompact` | After compaction | No | No |\n| `WorktreeCreate` | Worktree created | No | No |\n| `WorktreeRemove` | Worktree removed | No | No |\n| `StopFailure` | Error occurs | No | Error type |\n| `TaskCreated` | Task created | Yes | No |\n| `CwdChanged` | Directory changed | No | No |\n| `FileChanged` | File changed | No | Filename |\n| `Elicitation` | MCP elicitation | Yes | MCP server |\n| `ElicitationResult` | Elicitation response | Yes | MCP server |\n\n### Notable Version Changes\n\nAll hook events include `agent_id` and `agent_type` as\nof 2.1.69+.\n\n| Version | Change |\n|---------|--------|\n| 2.1.69 | `TeammateIdle`/`TaskCompleted` support `{\"continue\": false}` for graceful shutdown |\n| 2.1.69 | Plugin WorktreeCreate/WorktreeRemove hooks fire correctly (were silently ignored) |\n| 2.1.71 | New tools: `CronCreate`, `CronList`, `CronDelete` appear in PreToolUse/PostToolUse |\n| 2.1.72 | `ExitWorktree` tool added; `lsof`/`pgrep`/`tput`/`ss`/`fd`/`fdfind` auto-approved |\n| 2.1.72 | Skill hook double-fire fixed; `transcript_path` correct for resumed sessions |\n| 2.1.72 | Failed Read/WebFetch/Glob no longer cancel sibling tool calls (only Bash cascades) |\n| 2.1.73 | SessionStart no longer double-fires on `--resume`/`--continue` |\n| 2.1.73 | JSON-output hooks no longer inject spurious system-reminder messages |\n| 2.1.74 | SessionEnd hooks timeout now configurable via `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` |\n| 2.1.75 | Hook source displayed in permission prompts; async hook messages suppressed by default |\n| 2.1.76 | `Elicitation` and `ElicitationResult` events for MCP servers |\n| 2.1.76 | `PostCompact` event fires after context compaction |\n| 2.1.77 | PreToolUse \"allow\" no longer bypasses deny rules (security fix) |\n| 2.1.83 | `CwdChanged` and `FileChanged` events added |\n| 2.1.84 | `TaskCreated` event (blockable); HTTP hooks can return worktree path |\n| 2.1.85 | `if` field for conditional hook execution; PreToolUse can match `AskUserQuestion` |\n\n## Type Definitions\n\n### HookCallback\n\n```python\nfrom typing import Any, Awaitable, Callable\n\nHookCallback = Callable[\n    [dict[str, Any], str | None, HookContext],\n    Awaitable[dict[str, Any]]\n]\n```\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `input_data` | `dict[str, Any]` | Hook-specific input data (varies by event) |\n| `tool_use_id` | `str \\| None` | Tool use identifier (for tool-related hooks) |\n| `context` | `HookContext` | Additional context information |\n\n**Returns:** `dict[str, Any]` with optional fields:\n`decision` (\"block\"), `systemMessage` (str),\n`hookSpecificOutput` (dict).\n\n### HookMatcher\n\n```python\n@dataclass\nclass HookMatcher:\n    matcher: str | None = None\n    hooks: list[HookCallback] = field(default_factory=list)\n    timeout: float | None = None  # Default: 60s\n```\n\n| Pattern | Matches |\n|---------|---------|\n| `\"Bash\"` | Only Bash tool |\n| `\"Write\\|Edit\"` | Write OR Edit tools |\n| `None` | All tools (universal matcher) |\n\n## Complete Usage Example\n\n```python\nfrom claude_agent_sdk import query, ClaudeAgentOptions, HookMatcher, HookContext\nfrom typing import Any\n\nasync def validate_bash_command(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Block dangerous bash commands.\"\"\"\n    if input_data['tool_name'] == 'Bash':\n        command = input_data['tool_input'].get('command', '')\n        if 'rm -rf /' in command:\n            return {\n                'hookSpecificOutput': {\n                    'hookEventName': 'PreToolUse',\n                    'permissionDecision': 'deny',\n                    'permissionDecisionReason': 'Dangerous command blocked'\n                }\n            }\n    return {}\n\nasync def log_tool_use(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Log all tool usage for auditing.\"\"\"\n    print(f\"Tool used: {input_data.get('tool_name')}\")\n    return {}\n\noptions = ClaudeAgentOptions(\n    hooks={\n        'PreToolUse': [\n            HookMatcher(matcher='Bash', hooks=[validate_bash_command], timeout=120),\n            HookMatcher(hooks=[log_tool_use])\n        ],\n        'PostToolUse': [\n            HookMatcher(hooks=[log_tool_use])\n        ]\n    }\n)\n\nasync for message in query(prompt=\"Analyze this codebase\", options=options):\n    print(message)\n```\n\n## Input Data by Event Type\n\n### PreToolUse / PostToolUse\n\n```python\n# PreToolUse\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"}}\n\n# PostToolUse (adds result)\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"},\n \"tool_result\": \"file1.txt\\nfile2.txt\", \"error\": None}\n```\n\n### PermissionRequest (CLI only)\n\n```python\n# Input\n{\"session_id\": \"abc123\", \"tool_name\": \"Bash\",\n \"tool_input\": {\"command\": \"npm install\"},\n \"permission_mode\": \"default\", \"cwd\": \"/path/to/project\"}\n\n# Output: allow\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"allow\"}}}\n\n# Output: deny\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"deny\", \"message\": \"Reason\"}}}\n```\n\n### Other Events\n\n| Event | Key Fields |\n|-------|------------|\n| `UserPromptSubmit` | `prompt`, `conversation_id` |\n| `TeammateIdle` | `agent_id`, `session_id` |\n| `TaskCompleted` | `task_id`, `result`, `duration_ms`, `token_count` |\n| `Stop` / `SubagentStop` | `reason`, `final_message` |\n| `PreCompact` | `messages`, `token_count` |\n| `PostCompact` | `trigger` (\"manual\"/\"auto\"), `compact_summary` |\n| `WorktreeCreate` | `name` (must print worktree path to stdout) |\n| `WorktreeRemove` | `worktree_path` (cannot block removal) |\n\n## Hook Return Patterns\n\n```python\n# Allow (default)\nreturn {}\n\n# Block action\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",\n        \"permissionDecision\": \"deny\",\n        \"permissionDecisionReason\": \"Explanation\"\n    }\n}\n\n# Add system message\nreturn {\"systemMessage\": \"Important context added to conversation\"}\n```\n\n## Best Practices\n\n| Area | Guidance |\n|------|----------|\n| Performance | Keep hooks fast (<100ms PreToolUse, <200ms PostToolUse) |\n| Performance | Use appropriate timeouts; cache expensive computations |\n| Security | Validate all input; never use dynamic code eval with hook input |\n| Security | Use allowlists over blocklists; sanitize log data |\n| Reliability | Always return a dict (even empty `{}`); handle exceptions |\n| Reliability | Design hooks to be idempotent; include meaningful block reasons |\n| Testing | Test with various input patterns; verify timeout behavior |\n\nFile v1.9.18:skill-card.md\n\n## Description:\n\nEvaluate hook security, performance, and SDK compliance for audits.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to evaluate Claude Code hooks for security, performance, SDK compliance, reliability, and maintainability before deployment or audit review.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill may activate on broad hook, security, or performance wording outside a specific hook-audit task.\n\nMitigation: Confirm the audit scope before applying its guidance and ignore it for unrelated security or performance work.\n\nRisk: The artifact contains reference command examples, but the reviewed release is documentation-only and does not provide an executable scanner.\n\nMitigation: Treat command examples as workflow guidance and verify any available commands with their help output before use.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/athola/skills/nm-abstract-hooks-eval)\n- [Project Homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with tables, code examples, and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Documentation-only evaluation framework; it does not execute scans or install hooks by itself.]\n\n## Skill Version(s):\n\n1.9.18 (source: release evidence; artifact frontmatter states 1.9.8)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.9.17: 5 files, 11117 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (2145b), SKILL.md (6191b), _meta.json (142b)\n\nFile v1.9.17:SKILL.md\n\n---\nname: hooks-eval\ndescription: Evaluate hook security, performance, and SDK compliance. Use for audits\nversion: 1.9.8\ntriggers:\n  - hooks\n  - evaluation\n  - security\n  - performance\n  - claude-sdk\n  - agent-sdk\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.hook-scope-guide\"]}}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Key Capabilities](#key-capabilities)\n- [Core Components](#core-components)\n- [Quick Reference](#quick-reference)\n- [Hook Event Types](#hook-event-types)\n- [Hook Callback Signature](#hook-callback-signature)\n- [Return Values](#return-values)\n- [Quality Scoring (100 points)](#quality-scoring-(100-points))\n- [Detailed Resources](#detailed-resources)\n- [Basic Evaluation Workflow](#basic-evaluation-workflow)\n- [Integration with Other Tools](#integration-with-other-tools)\n- [Related Skills](#related-skills)\n\n\n# Hooks Evaluation Framework\n\n## Overview\n\nThis skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.\n\n### Key Capabilities\n\n- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention\n- **Performance Analysis**: Execution time benchmarking, resource usage, optimization\n- **Compliance Checking**: Structure validation, documentation requirements, best practices\n- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns\n\n### Core Components\n\n| Component | Purpose |\n|-----------|---------|\n| **Hook Types Reference** | Complete SDK hook event types and signatures |\n| **Evaluation Criteria** | Scoring system and quality gates |\n| **Security Patterns** | Common vulnerabilities and mitigations |\n| **Performance Benchmarks** | Thresholds and optimization guidance |\n\n## Quick Reference\n\n### Hook Event Types\n\n```python\nHookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via `hooks.json` using shell commands (e.g., leyline's `detect-git-platform.sh`).\n\n### Plugin-Level hooks.json\n\nPlugins can declare hooks via `\"hooks\": \"./hooks/hooks.json\"` in plugin.json. The evaluator validates:\n- Referenced hooks.json exists and is valid JSON\n- Shell commands referenced in hooks exist and are executable\n- Hook matchers use valid event types\n\n### Hook Callback Signature\n\n```python\nasync def my_hook(\n    input_data: dict[str, Any],    # Hook-specific input\n    tool_use_id: str | None,       # Tool ID (for tool hooks)\n    context: HookContext           # Additional context\n) -> dict[str, Any]:               # Return decision/messages\n    ...\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Return Values\n\n```python\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",       # Match hook type\n        \"permissionDecision\": \"deny\",        # Optional: block action\n        \"permissionDecisionReason\": \"...\",   # Reason for denial\n        \"additionalContext\": \"...\",          # Optional: context added\n    }\n}\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Quality Scoring (100 points)\n\n| Category | Points | Focus |\n|----------|--------|-------|\n| Security | 30 | Vulnerabilities, injection, validation |\n| Performance | 25 | Execution time, memory, I/O |\n| Compliance | 20 | Structure, documentation, error handling |\n| Reliability | 15 | Timeouts, idempotency, degradation |\n| Maintainability | 10 | Code structure, modularity |\n\n## Detailed Resources\n\n- **SDK Hook Types**: See `modules/sdk-hook-types.md` for complete Python SDK type definitions, patterns, and examples\n- **Evaluation Criteria**: See `modules/evaluation-criteria.md` for detailed scoring rubric and quality gates\n- **Security Patterns**: See `modules/sdk-hook-types.md` for vulnerability detection and mitigation\n- **Performance Guide**: See `modules/evaluation-criteria.md` for benchmarking and optimization\n\n## Basic Evaluation Workflow\n\n```bash\n# 1. Run detailed evaluation\n/hooks-eval --detailed\n\n# 2. Focus on security issues\n/hooks-eval --security-only --format sarif\n\n# 3. Benchmark performance\n/hooks-eval --performance-baseline\n\n# 4. Check compliance\n/hooks-eval --compliance-report\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Integration with Other Tools\n\n```bash\n# Complete plugin evaluation pipeline\n/hooks-eval --detailed          # Evaluate all hooks\n/analyze-hook hooks/specific.py      # Deep-dive on one hook\n/validate-plugin .                   # Validate overall structure\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Related Skills\n\n- `abstract:hook-scope-guide` - Decide where to place hooks (plugin/project/global)\n- `abstract:hook-authoring` - Write hook rules and patterns\n- `abstract:validate-plugin` - Validate complete plugin structure\n## Troubleshooting\n\n### Common Issues\n\n**Hook not firing**\nVerify hook pattern matches the event. Check hook logs for errors\n\n**Syntax errors**\nValidate JSON/Python syntax before deployment\n\n**Permission denied**\nCheck hook file permissions and ownership\n\nFile v1.9.17:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-hooks-eval\",\n  \"version\": \"1.9.17\",\n  \"publishedAt\": 1785389256109\n}\n\nFile v1.9.17:modules/evaluation-criteria.md\n\n# Hook Evaluation Criteria\n\nDetailed scoring rubric and quality gates for hook evaluation.\n\n## Mathematical Foundation\n\nThis evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:\n\n- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))\n- **Weighting**: Security-first weights with stakeholder validation\n- **Aggregation**: Weighted sum with penalty-based security scoring\n- **Validation**: Sensitivity analysis on non-security weights\n\n**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.\n\n## Scoring System (100 points total)\n\n### Security Analysis (30 points)\n\n**Vulnerability Detection:**\n- Critical vulnerabilities: -15 points each\n- High-risk issues: -8 points each\n- Medium-risk issues: -4 points each\n- Low-risk issues: -1 point each\n\n**Security Checklist:**\n\n| Check | Severity | Points Lost |\n|-------|----------|-------------|\n| Dynamic code evaluation with user input | Critical | -15 |\n| Command injection vulnerability | Critical | -15 |\n| Unvalidated file path access | High | -8 |\n| Secrets/credentials in code | High | -8 |\n| Missing input validation | Medium | -4 |\n| Overly permissive patterns | Medium | -4 |\n| No rate limiting | Low | -1 |\n| Verbose error messages exposing internals | Low | -1 |\n\n### Performance Analysis (25 points)\n\n| Metric | Max Points | Criteria |\n|--------|------------|----------|\n| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |\n| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |\n| I/O operation efficiency | 4 | Minimal file/network operations |\n| Resource cleanup | 3 | Proper cleanup of handles, connections |\n\n**Performance Thresholds:**\n\n```yaml\npre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB\n```\n\n### Compliance Analysis (20 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Structure compliance | 8 | Valid JSON/Python, correct schema |\n| Documentation completeness | 6 | Purpose, parameters, return values documented |\n| Error handling | 4 | All exceptions caught, meaningful messages |\n| Best practices | 2 | Follows hook authoring guidelines |\n\n**Structure Requirements:**\n\n- JSON hooks: Valid JSON schema with required fields\n- Python hooks: Type hints, async/await patterns\n- Matcher patterns: Valid regex, appropriate scope\n\n### Reliability Analysis (15 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Error handling robustness | 6 | Graceful handling of all error conditions |\n| Timeout management | 4 | Appropriate timeouts configured |\n| Idempotency | 3 | Safe to retry without side effects |\n| Graceful degradation | 2 | Falls back safely on failure |\n\n**Reliability Checklist:**\n\n- [ ] Hook returns valid response on all code paths\n- [ ] Exceptions are caught and handled\n- [ ] Timeout is configured appropriately\n- [ ] Hook can be called multiple times safely\n- [ ] Failure doesn't break agent operation\n\n### Maintainability (10 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Code structure | 4 | Clear, modular, single responsibility |\n| Documentation clarity | 3 | Purpose and behavior well explained |\n| Modularity | 2 | Reusable components, no duplication |\n| Test coverage | 1 | Tests exist for key functionality |\n\n## Quality Levels\n\n| Score | Level | Description |\n|-------|-------|-------------|\n| 91-100 | Excellent | Production-ready, follows all best practices |\n| 76-90 | Good | Minor improvements suggested |\n| 51-75 | Acceptable | Some issues requiring attention |\n| 26-50 | Poor | Significant issues need addressing |\n| 0-25 | Critical | Major security or reliability issues |\n\n## Quality Gates\n\nDefault thresholds for CI/CD integration:\n\n```yaml\nquality_gates:\n  security_score: \">= 80\"\n  performance_score: \">= 70\"\n  compliance_score: \">= 85\"\n  reliability_score: \">= 85\"\n  overall_score: \">= 75\"\n  max_critical_issues: 0\n  max_high_issues: 2\n```\n\n### Sensitivity Analysis Requirements\n\nSecurity weights are non-negotiable, but other weights should be validated:\n\n```yaml\nsensitivity_analysis:\n  # Security weights are fixed (non-negotiable)\n  fixed_weights: [\"security_analysis\"]\n\n  # Other weights tested for sensitivity\n  test_weights: [\"performance\", \"compliance\", \"reliability\", \"maintainability\"]\n  variation: 0.20  # ±20% weight variation\n\n  requirements:\n    stable_rankings: true  # Rankings shouldn't change (except security)\n    critical_weights_identified: true  # Document sensitive weights\n```\n\nSee [Sensitivity Analysis](../../skills-eval/modules/multi-metric-evaluation-methodology.md#sensitivity-analysis) for implementation details.\n\n### Gate Behaviors\n\n| Gate | Failure Action |\n|------|----------------|\n| `security_score` | Block deployment, require review |\n| `performance_score` | Warn, suggest optimization |\n| `compliance_score` | Block until documentation complete |\n| `reliability_score` | Block deployment |\n| `max_critical_issues` | Immediate block |\n\n## Issue Classification\n\n### Critical Issues (Immediate Action Required)\n\n- Dynamic code evaluation with untrusted input\n- Command injection vulnerabilities\n- Credential exposure\n- Unhandled exceptions that break agent\n\n### High Issues (Address Before Release)\n\n- Missing input validation\n- Performance exceeds thresholds\n- Missing error handling\n- Insecure file operations\n\n### Medium Issues (Address Soon)\n\n- Missing documentation\n- Suboptimal patterns\n- Minor performance concerns\n- Code style violations\n\n### Low Issues (Nice to Fix)\n\n- Minor documentation gaps\n- Formatting inconsistencies\n- Optimization opportunities\n- Enhanced logging suggestions\n\n## Evaluation Report Format\n\n### Summary Format\n\n```\n=== Hooks Evaluation Report ===\nPlugin: {name} (v{version})\nScope: {scope}\nTotal hooks: {count} ({json_count} JSON, {python_count} Python)\n\n=== Scores ===\nSecurity:      {score}/100 ({level})\nPerformance:   {score}/100 ({level})\nCompliance:    {score}/100 ({level})\nReliability:   {score}/100 ({level})\nMaintainability: {score}/100 ({level})\n────────────────────────────────\nOverall:       {score}/100 ({level})\n\n=== Issues ===\nCritical: {count}\nHigh: {count}\nMedium: {count}\nLow: {count}\n```\n\n### Detailed Format\n\nIncludes per-hook breakdown:\n\n```\n=== Hook: {hook_path} ===\nType: {json|python}\nEvent: {PreToolUse|PostToolUse|...}\nMatcher: {pattern|universal}\n\nSecurity Issues:\n  [{severity}] Line {n}: {description}\n\nPerformance:\n  Estimated time: {ms}ms (threshold: {threshold}ms)\n  Memory usage: {mb}MB (threshold: {threshold}MB)\n\nRecommendations:\n  1. {recommendation}\n  2. {recommendation}\n```\n\n## Customization\n\n### Per-Plugin Configuration\n\nCreate `.hooks-eval.yaml` in plugin root:\n\n```yaml\nhooks_eval:\n  # Override security thresholds\n  security_thresholds:\n    critical_score: 80\n    high_score: 70\n\n  # Override performance thresholds\n  performance_thresholds:\n    pre_tool_use_max_ms: 100\n    post_tool_use_max_ms: 200\n    max_memory_mb: 50\n\n  # Compliance requirements\n  compliance_requirements:\n    require_documentation: true\n    require_error_handling: true\n    require_timeout_config: true\n\n  # Custom rules\n  custom_rules:\n    - name: \"no-hardcoded-secrets\"\n      pattern: \"password|secret|token\"\n      severity: \"high\"\n    - name: \"require-shebang\"\n      pattern: \"^#!\"\n      file_types: [\".sh\", \".py\"]\n      severity: \"medium\"\n\n  # Excluded paths\n  exclude_paths:\n    - \"hooks/experimental/*\"\n    - \"hooks/deprecated/*\"\n```\n\n### Severity Overrides\n\nOverride default severity for specific patterns:\n\n```yaml\nseverity_overrides:\n  - pattern: \"subprocess.run\"\n    default_severity: \"high\"\n    override_severity: \"medium\"\n    reason: \"Safe usage verified in review\"\n```\n\nFile v1.9.17:modules/sdk-hook-types.md\n\n# Python SDK Hook Types\n\nComplete reference for Claude Agent SDK hook types, callbacks,\nand matchers.\n\n## Hook Events\n\n### HookEvent\n\nSupported hook event types in the Python SDK.\n\n```python\nfrom typing import Literal\n\nHookEvent = Literal[\n    \"Setup\",             # Called when plugin installed/enabled\n    \"SessionStart\",      # Called when session begins\n    \"SessionEnd\",        # Called when session ends normally\n    \"UserPromptSubmit\",  # Called when user submits a prompt\n    \"PreToolUse\",        # Called before tool execution\n    \"PostToolUse\",       # Called after tool execution\n    \"PostToolUseFailure\",# Called when tool execution fails (2.1.20+)\n    \"PermissionRequest\", # Called when permission dialog would appear\n    \"Notification\",      # Called on system notification (2.1.20+)\n    \"SubagentStart\",     # Called when subagent spawns (2.1.20+)\n    \"SubagentStop\",      # Called when a subagent stops\n    \"Stop\",              # Called when stopping execution\n    \"TeammateIdle\",      # Called when teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",     # Called when a task finishes execution (2.1.33+)\n    \"ConfigChange\",      # Called when config is modified (2.1.49+)\n    \"InstructionsLoaded\",# Called when instructions are loaded (2.1.33+)\n    \"PreCompact\",        # Called before message compaction\n    \"PostCompact\",       # Called after compaction (2.1.76+)\n    \"WorktreeCreate\",    # Called when git worktree is created (2.1.50+)\n    \"WorktreeRemove\",    # Called when git worktree is removed (2.1.50+)\n    \"StopFailure\",       # Called on error (2.1.78+)\n    \"TaskCreated\",       # Called when task created (2.1.84+)\n    \"CwdChanged\",        # Called on working dir change (2.1.83+)\n    \"FileChanged\",       # Called on file change (2.1.83+)\n    \"Elicitation\",       # MCP elicitation request (2.1.76+)\n    \"ElicitationResult\", # MCP elicitation response (2.1.76+)\n]\n```\n\n**SDK vs CLI availability**: Most events work in both JSON\nhooks (CLI) and Python SDK hooks. `PermissionRequest` is\nCLI-only. `Setup`, `SessionStart`, `SessionEnd`, and\n`Notification` are CLI-only (JSON hooks).\n`WorktreeCreate` and `WorktreeRemove` are command-only\nhooks (no Python SDK callback). They do not support\nmatchers.\n\n### Event Summary\n\n| Event | Trigger | Blockable | Matcher |\n|-------|---------|-----------|---------|\n| `Setup` | Plugin installed/enabled | No | No |\n| `SessionStart` | Session begins | No | No |\n| `SessionEnd` | Session ends normally | No | No |\n| `UserPromptSubmit` | User submits input | No | No |\n| `PreToolUse` | Before any tool runs | Yes | Tool name |\n| `PostToolUse` | After tool completes | No | Tool name |\n| `PostToolUseFailure` | Tool execution fails | No | Tool name |\n| `PermissionRequest` | Permission dialog | Yes | Tool name |\n| `SubagentStart` | Subagent spawns | No | No |\n| `SubagentStop` | Subagent completes | No | No |\n| `Stop` | Agent stops | No | No |\n| `TeammateIdle` | Teammate idle | No | No |\n| `TaskCompleted` | Task finishes | No | No |\n| `ConfigChange` | Config modified | No | No |\n| `InstructionsLoaded` | Instructions loaded | No | No |\n| `PreCompact` | Before compaction | No | No |\n| `PostCompact` | After compaction | No | No |\n| `WorktreeCreate` | Worktree created | No | No |\n| `WorktreeRemove` | Worktree removed | No | No |\n| `StopFailure` | Error occurs | No | Error type |\n| `TaskCreated` | Task created | Yes | No |\n| `CwdChanged` | Directory changed | No | No |\n| `FileChanged` | File changed | No | Filename |\n| `Elicitation` | MCP elicitation | Yes | MCP server |\n| `ElicitationResult` | Elicitation response | Yes | MCP server |\n\n### Notable Version Changes\n\nAll hook events include `agent_id` and `agent_type` as\nof 2.1.69+.\n\n| Version | Change |\n|---------|--------|\n| 2.1.69 | `TeammateIdle`/`TaskCompleted` support `{\"continue\": false}` for graceful shutdown |\n| 2.1.69 | Plugin WorktreeCreate/WorktreeRemove hooks fire correctly (were silently ignored) |\n| 2.1.71 | New tools: `CronCreate`, `CronList`, `CronDelete` appear in PreToolUse/PostToolUse |\n| 2.1.72 | `ExitWorktree` tool added; `lsof`/`pgrep`/`tput`/`ss`/`fd`/`fdfind` auto-approved |\n| 2.1.72 | Skill hook double-fire fixed; `transcript_path` correct for resumed sessions |\n| 2.1.72 | Failed Read/WebFetch/Glob no longer cancel sibling tool calls (only Bash cascades) |\n| 2.1.73 | SessionStart no longer double-fires on `--resume`/`--continue` |\n| 2.1.73 | JSON-output hooks no longer inject spurious system-reminder messages |\n| 2.1.74 | SessionEnd hooks timeout now configurable via `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` |\n| 2.1.75 | Hook source displayed in permission prompts; async hook messages suppressed by default |\n| 2.1.76 | `Elicitation` and `ElicitationResult` events for MCP servers |\n| 2.1.76 | `PostCompact` event fires after context compaction |\n| 2.1.77 | PreToolUse \"allow\" no longer bypasses deny rules (security fix) |\n| 2.1.83 | `CwdChanged` and `FileChanged` events added |\n| 2.1.84 | `TaskCreated` event (blockable); HTTP hooks can return worktree path |\n| 2.1.85 | `if` field for conditional hook execution; PreToolUse can match `AskUserQuestion` |\n\n## Type Definitions\n\n### HookCallback\n\n```python\nfrom typing import Any, Awaitable, Callable\n\nHookCallback = Callable[\n    [dict[str, Any], str | None, HookContext],\n    Awaitable[dict[str, Any]]\n]\n```\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `input_data` | `dict[str, Any]` | Hook-specific input data (varies by event) |\n| `tool_use_id` | `str \\| None` | Tool use identifier (for tool-related hooks) |\n| `context` | `HookContext` | Additional context information |\n\n**Returns:** `dict[str, Any]` with optional fields:\n`decision` (\"block\"), `systemMessage` (str),\n`hookSpecificOutput` (dict).\n\n### HookMatcher\n\n```python\n@dataclass\nclass HookMatcher:\n    matcher: str | None = None\n    hooks: list[HookCallback] = field(default_factory=list)\n    timeout: float | None = None  # Default: 60s\n```\n\n| Pattern | Matches |\n|---------|---------|\n| `\"Bash\"` | Only Bash tool |\n| `\"Write\\|Edit\"` | Write OR Edit tools |\n| `None` | All tools (universal matcher) |\n\n## Complete Usage Example\n\n```python\nfrom claude_agent_sdk import query, ClaudeAgentOptions, HookMatcher, HookContext\nfrom typing import Any\n\nasync def validate_bash_command(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Block dangerous bash commands.\"\"\"\n    if input_data['tool_name'] == 'Bash':\n        command = input_data['tool_input'].get('command', '')\n        if 'rm -rf /' in command:\n            return {\n                'hookSpecificOutput': {\n                    'hookEventName': 'PreToolUse',\n                    'permissionDecision': 'deny',\n                    'permissionDecisionReason': 'Dangerous command blocked'\n                }\n            }\n    return {}\n\nasync def log_tool_use(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Log all tool usage for auditing.\"\"\"\n    print(f\"Tool used: {input_data.get('tool_name')}\")\n    return {}\n\noptions = ClaudeAgentOptions(\n    hooks={\n        'PreToolUse': [\n            HookMatcher(matcher='Bash', hooks=[validate_bash_command], timeout=120),\n            HookMatcher(hooks=[log_tool_use])\n        ],\n        'PostToolUse': [\n            HookMatcher(hooks=[log_tool_use])\n        ]\n    }\n)\n\nasync for message in query(prompt=\"Analyze this codebase\", options=options):\n    print(message)\n```\n\n## Input Data by Event Type\n\n### PreToolUse / PostToolUse\n\n```python\n# PreToolUse\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"}}\n\n# PostToolUse (adds result)\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"},\n \"tool_result\": \"file1.txt\\nfile2.txt\", \"error\": None}\n```\n\n### PermissionRequest (CLI only)\n\n```python\n# Input\n{\"session_id\": \"abc123\", \"tool_name\": \"Bash\",\n \"tool_input\": {\"command\": \"npm install\"},\n \"permission_mode\": \"default\", \"cwd\": \"/path/to/project\"}\n\n# Output: allow\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"allow\"}}}\n\n# Output: deny\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"deny\", \"message\": \"Reason\"}}}\n```\n\n### Other Events\n\n| Event | Key Fields |\n|-------|------------|\n| `UserPromptSubmit` | `prompt`, `conversation_id` |\n| `TeammateIdle` | `agent_id`, `session_id` |\n| `TaskCompleted` | `task_id`, `result`, `duration_ms`, `token_count` |\n| `Stop` / `SubagentStop` | `reason`, `final_message` |\n| `PreCompact` | `messages`, `token_count` |\n| `PostCompact` | `trigger` (\"manual\"/\"auto\"), `compact_summary` |\n| `WorktreeCreate` | `name` (must print worktree path to stdout) |\n| `WorktreeRemove` | `worktree_path` (cannot block removal) |\n\n## Hook Return Patterns\n\n```python\n# Allow (default)\nreturn {}\n\n# Block action\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",\n        \"permissionDecision\": \"deny\",\n        \"permissionDecisionReason\": \"Explanation\"\n    }\n}\n\n# Add system message\nreturn {\"systemMessage\": \"Important context added to conversation\"}\n```\n\n## Best Practices\n\n| Area | Guidance |\n|------|----------|\n| Performance | Keep hooks fast (<100ms PreToolUse, <200ms PostToolUse) |\n| Performance | Use appropriate timeouts; cache expensive computations |\n| Security | Validate all input; never use dynamic code eval with hook input |\n| Security | Use allowlists over blocklists; sanitize log data |\n| Reliability | Always return a dict (even empty `{}`); handle exceptions |\n| Reliability | Design hooks to be idempotent; include meaningful block reasons |\n| Testing | Test with various input patterns; verify timeout behavior |\n\nFile v1.9.17:skill-card.md\n\n## Description: <br>\nEvaluate hook security, performance, and SDK compliance. Use for audits <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to audit Claude Code hooks for security, performance, SDK compliance, reliability, and maintainability. It provides hook references, scoring criteria, quality gates, and example command workflows for reviewing hook implementations. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad trigger terms may surface this reference skill during general security or performance discussions. <br>\nMitigation: Confirm the task is specifically about hook evaluation before applying the guidance. <br>\nRisk: Hook examples or audit workflows could lead users to log sensitive prompts, paths, commands, or tool results. <br>\nMitigation: Require disclosure and redaction for any hook logging or reporting that captures user, project, command, or tool-result data. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/athola/skills/nm-abstract-hooks-eval) <br>\n- [OpenClaw Metadata Homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n- [Hook Evaluation Criteria](modules/evaluation-criteria.md) <br>\n- [Python SDK Hook Types](modules/sdk-hook-types.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance] <br>\n**Output Format:** [Markdown guidance with command examples and scoring rubrics] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only; no active code or hidden execution.] <br>\n\n## Skill Version(s): <br>\n1.9.17 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.16: 5 files, 11021 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (1947b), SKILL.md (6191b), _meta.json (142b)\n\nFile v1.9.16:SKILL.md\n\n---\nname: hooks-eval\ndescription: Evaluate hook security, performance, and SDK compliance. Use for audits\nversion: 1.9.8\ntriggers:\n  - hooks\n  - evaluation\n  - security\n  - performance\n  - claude-sdk\n  - agent-sdk\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.hook-scope-guide\"]}}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Key Capabilities](#key-capabilities)\n- [Core Components](#core-components)\n- [Quick Reference](#quick-reference)\n- [Hook Event Types](#hook-event-types)\n- [Hook Callback Signature](#hook-callback-signature)\n- [Return Values](#return-values)\n- [Quality Scoring (100 points)](#quality-scoring-(100-points))\n- [Detailed Resources](#detailed-resources)\n- [Basic Evaluation Workflow](#basic-evaluation-workflow)\n- [Integration with Other Tools](#integration-with-other-tools)\n- [Related Skills](#related-skills)\n\n\n# Hooks Evaluation Framework\n\n## Overview\n\nThis skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.\n\n### Key Capabilities\n\n- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention\n- **Performance Analysis**: Execution time benchmarking, resource usage, optimization\n- **Compliance Checking**: Structure validation, documentation requirements, best practices\n- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns\n\n### Core Components\n\n| Component | Purpose |\n|-----------|---------|\n| **Hook Types Reference** | Complete SDK hook event types and signatures |\n| **Evaluation Criteria** | Scoring system and quality gates |\n| **Security Patterns** | Common vulnerabilities and mitigations |\n| **Performance Benchmarks** | Thresholds and optimization guidance |\n\n## Quick Reference\n\n### Hook Event Types\n\n```python\nHookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via `hooks.json` using shell commands (e.g., leyline's `detect-git-platform.sh`).\n\n### Plugin-Level hooks.json\n\nPlugins can declare hooks via `\"hooks\": \"./hooks/hooks.json\"` in plugin.json. The evaluator validates:\n- Referenced hooks.json exists and is valid JSON\n- Shell commands referenced in hooks exist and are executable\n- Hook matchers use valid event types\n\n### Hook Callback Signature\n\n```python\nasync def my_hook(\n    input_data: dict[str, Any],    # Hook-specific input\n    tool_use_id: str | None,       # Tool ID (for tool hooks)\n    context: HookContext           # Additional context\n) -> dict[str, Any]:               # Return decision/messages\n    ...\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Return Values\n\n```python\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",       # Match hook type\n        \"permissionDecision\": \"deny\",        # Optional: block action\n        \"permissionDecisionReason\": \"...\",   # Reason for denial\n        \"additionalContext\": \"...\",          # Optional: context added\n    }\n}\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Quality Scoring (100 points)\n\n| Category | Points | Focus |\n|----------|--------|-------|\n| Security | 30 | Vulnerabilities, injection, validation |\n| Performance | 25 | Execution time, memory, I/O |\n| Compliance | 20 | Structure, documentation, error handling |\n| Reliability | 15 | Timeouts, idempotency, degradation |\n| Maintainability | 10 | Code structure, modularity |\n\n## Detailed Resources\n\n- **SDK Hook Types**: See `modules/sdk-hook-types.md` for complete Python SDK type definitions, patterns, and examples\n- **Evaluation Criteria**: See `modules/evaluation-criteria.md` for detailed scoring rubric and quality gates\n- **Security Patterns**: See `modules/sdk-hook-types.md` for vulnerability detection and mitigation\n- **Performance Guide**: See `modules/evaluation-criteria.md` for benchmarking and optimization\n\n## Basic Evaluation Workflow\n\n```bash\n# 1. Run detailed evaluation\n/hooks-eval --detailed\n\n# 2. Focus on security issues\n/hooks-eval --security-only --format sarif\n\n# 3. Benchmark performance\n/hooks-eval --performance-baseline\n\n# 4. Check compliance\n/hooks-eval --compliance-report\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Integration with Other Tools\n\n```bash\n# Complete plugin evaluation pipeline\n/hooks-eval --detailed          # Evaluate all hooks\n/analyze-hook hooks/specific.py      # Deep-dive on one hook\n/validate-plugin .                   # Validate overall structure\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Related Skills\n\n- `abstract:hook-scope-guide` - Decide where to place hooks (plugin/project/global)\n- `abstract:hook-authoring` - Write hook rules and patterns\n- `abstract:validate-plugin` - Validate complete plugin structure\n## Troubleshooting\n\n### Common Issues\n\n**Hook not firing**\nVerify hook pattern matches the event. Check hook logs for errors\n\n**Syntax errors**\nValidate JSON/Python syntax before deployment\n\n**Permission denied**\nCheck hook file permissions and ownership\n\nFile v1.9.16:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-hooks-eval\",\n  \"version\": \"1.9.16\",\n  \"publishedAt\": 1784058270079\n}\n\nFile v1.9.16:modules/evaluation-criteria.md\n\n# Hook Evaluation Criteria\n\nDetailed scoring rubric and quality gates for hook evaluation.\n\n## Mathematical Foundation\n\nThis evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:\n\n- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))\n- **Weighting**: Security-first weights with stakeholder validation\n- **Aggregation**: Weighted sum with penalty-based security scoring\n- **Validation**: Sensitivity analysis on non-security weights\n\n**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.\n\n## Scoring System (100 points total)\n\n### Security Analysis (30 points)\n\n**Vulnerability Detection:**\n- Critical vulnerabilities: -15 points each\n- High-risk issues: -8 points each\n- Medium-risk issues: -4 points each\n- Low-risk issues: -1 point each\n\n**Security Checklist:**\n\n| Check | Severity | Points Lost |\n|-------|----------|-------------|\n| Dynamic code evaluation with user input | Critical | -15 |\n| Command injection vulnerability | Critical | -15 |\n| Unvalidated file path access | High | -8 |\n| Secrets/credentials in code | High | -8 |\n| Missing input validation | Medium | -4 |\n| Overly permissive patterns | Medium | -4 |\n| No rate limiting | Low | -1 |\n| Verbose error messages exposing internals | Low | -1 |\n\n### Performance Analysis (25 points)\n\n| Metric | Max Points | Criteria |\n|--------|------------|----------|\n| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |\n| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |\n| I/O operation efficiency | 4 | Minimal file/network operations |\n| Resource cleanup | 3 | Proper cleanup of handles, connections |\n\n**Performance Thresholds:**\n\n```yaml\npre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB\n```\n\n### Compliance Analysis (20 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Structure compliance | 8 | Valid JSON/Python, correct schema |\n| Documentation completeness | 6 | Purpose, parameters, return values documented |\n| Error handling | 4 | All exceptions caught, meaningful messages |\n| Best practices | 2 | Follows hook authoring guidelines |\n\n**Structure Requirements:**\n\n- JSON hooks: Valid JSON schema with required fields\n- Python hooks: Type hints, async/await patterns\n- Matcher patterns: Valid regex, appropriate scope\n\n### Reliability Analysis (15 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Error handling robustness | 6 | Graceful handling of all error conditions |\n| Timeout management | 4 | Appropriate timeouts configured |\n| Idempotency | 3 | Safe to retry without side effects |\n| Graceful degradation | 2 | Falls back safely on failure |\n\n**Reliability Checklist:**\n\n- [ ] Hook returns valid response on all code paths\n- [ ] Exceptions are caught and handled\n- [ ] Timeout is configured appropriately\n- [ ] Hook can be called multiple times safely\n- [ ] Failure doesn't break agent operation\n\n### Maintainability (10 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Code structure | 4 | Clear, modular, single responsibility |\n| Documentation clarity | 3 | Purpose and behavior well explained |\n| Modularity | 2 | Reusable components, no duplication |\n| Test coverage | 1 | Tests exist for key functionality |\n\n## Quality Levels\n\n| Score | Level | Description |\n|-------|-------|-------------|\n| 91-100 | Excellent | Production-ready, follows all best practices |\n| 76-90 | Good | Minor improvements suggested |\n| 51-75 | Acceptable | Some issues requiring attention |\n| 26-50 | Poor | Significant issues need addressing |\n| 0-25 | Critical | Major security or reliability issues |\n\n## Quality Gates\n\nDefault thresholds for CI/CD integration:\n\n```yaml\nquality_gates:\n  security_score: \">= 80\"\n  performance_score: \">= 70\"\n  compliance_score: \">= 85\"\n  reliability_score: \">= 85\"\n  overall_score: \">= 75\"\n  max_critical_issues: 0\n  max_high_issues: 2\n```\n\n### Sensitivity Analysis Requirements\n\nSecurity weights are non-negotiable, but other weights should be validated:\n\n```yaml\nsensitivity_analysis:\n  # Security weights are fixed (non-negotiable)\n  fixed_weights: [\"security_analysis\"]\n\n  # Other weights tested for sensitivity\n  test_weights: [\"performance\", \"compliance\", \"reliability\", \"maintainability\"]\n  variation: 0.20  # ±20% weight variation\n\n  requirements:\n    stable_rankings: true  # Rankings shouldn't change (except security)\n    critical_weights_identified: true  # Document sensitive weights\n```\n\nSee [Sensitivity Analysis](../../skills-eval/modules/multi-metric-evaluation-methodology.md#sensitivity-analysis) for implementation details.\n\n### Gate Behaviors\n\n| Gate | Failure Action |\n|------|----------------|\n| `security_score` | Block deployment, require review |\n| `performance_score` | Warn, suggest optimization |\n| `compliance_score` | Block until documentation complete |\n| `reliability_score` | Block deployment |\n| `max_critical_issues` | Immediate block |\n\n## Issue Classification\n\n### Critical Issues (Immediate Action Required)\n\n- Dynamic code evaluation with untrusted input\n- Command injection vulnerabilities\n- Credential exposure\n- Unhandled exceptions that break agent\n\n### High Issues (Address Before Release)\n\n- Missing input validation\n- Performance exceeds thresholds\n- Missing error handling\n- Insecure file operations\n\n### Medium Issues (Address Soon)\n\n- Missing documentation\n- Suboptimal patterns\n- Minor performance concerns\n- Code style violations\n\n### Low Issues (Nice to Fix)\n\n- Minor documentation gaps\n- Formatting inconsistencies\n- Optimization opportunities\n- Enhanced logging suggestions\n\n## Evaluation Report Format\n\n### Summary Format\n\n```\n=== Hooks Evaluation Report ===\nPlugin: {name} (v{version})\nScope: {scope}\nTotal hooks: {count} ({json_count} JSON, {python_count} Python)\n\n=== Scores ===\nSecurity:      {score}/100 ({level})\nPerformance:   {score}/100 ({level})\nCompliance:    {score}/100 ({level})\nReliability:   {score}/100 ({level})\nMaintainability: {score}/100 ({level})\n────────────────────────────────\nOverall:       {score}/100 ({level})\n\n=== Issues ===\nCritical: {count}\nHigh: {count}\nMedium: {count}\nLow: {count}\n```\n\n### Detailed Format\n\nIncludes per-hook breakdown:\n\n```\n=== Hook: {hook_path} ===\nType: {json|python}\nEvent: {PreToolUse|PostToolUse|...}\nMatcher: {pattern|universal}\n\nSecurity Issues:\n  [{severity}] Line {n}: {description}\n\nPerformance:\n  Estimated time: {ms}ms (threshold: {threshold}ms)\n  Memory usage: {mb}MB (threshold: {threshold}MB)\n\nRecommendations:\n  1. {recommendation}\n  2. {recommendation}\n```\n\n## Customization\n\n### Per-Plugin Configuration\n\nCreate `.hooks-eval.yaml` in plugin root:\n\n```yaml\nhooks_eval:\n  # Override security thresholds\n  security_thresholds:\n    critical_score: 80\n    high_score: 70\n\n  # Override performance thresholds\n  performance_thresholds:\n    pre_tool_use_max_ms: 100\n    post_tool_use_max_ms: 200\n    max_memory_mb: 50\n\n  # Compliance requirements\n  compliance_requirements:\n    require_documentation: true\n    require_error_handling: true\n    require_timeout_config: true\n\n  # Custom rules\n  custom_rules:\n    - name: \"no-hardcoded-secrets\"\n      pattern: \"password|secret|token\"\n      severity: \"high\"\n    - name: \"require-shebang\"\n      pattern: \"^#!\"\n      file_types: [\".sh\", \".py\"]\n      severity: \"medium\"\n\n  # Excluded paths\n  exclude_paths:\n    - \"hooks/experimental/*\"\n    - \"hooks/deprecated/*\"\n```\n\n### Severity Overrides\n\nOverride default severity for specific patterns:\n\n```yaml\nseverity_overrides:\n  - pattern: \"subprocess.run\"\n    default_severity: \"high\"\n    override_severity: \"medium\"\n    reason: \"Safe usage verified in review\"\n```\n\nFile v1.9.16:modules/sdk-hook-types.md\n\n# Python SDK Hook Types\n\nComplete reference for Claude Agent SDK hook types, callbacks,\nand matchers.\n\n## Hook Events\n\n### HookEvent\n\nSupported hook event types in the Python SDK.\n\n```python\nfrom typing import Literal\n\nHookEvent = Literal[\n    \"Setup\",             # Called when plugin installed/enabled\n    \"SessionStart\",      # Called when session begins\n    \"SessionEnd\",        # Called when session ends normally\n    \"UserPromptSubmit\",  # Called when user submits a prompt\n    \"PreToolUse\",        # Called before tool execution\n    \"PostToolUse\",       # Called after tool execution\n    \"PostToolUseFailure\",# Called when tool execution fails (2.1.20+)\n    \"PermissionRequest\", # Called when permission dialog would appear\n    \"Notification\",      # Called on system notification (2.1.20+)\n    \"SubagentStart\",     # Called when subagent spawns (2.1.20+)\n    \"SubagentStop\",      # Called when a subagent stops\n    \"Stop\",              # Called when stopping execution\n    \"TeammateIdle\",      # Called when teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",     # Called when a task finishes execution (2.1.33+)\n    \"ConfigChange\",      # Called when config is modified (2.1.49+)\n    \"InstructionsLoaded\",# Called when instructions are loaded (2.1.33+)\n    \"PreCompact\",        # Called before message compaction\n    \"PostCompact\",       # Called after compaction (2.1.76+)\n    \"WorktreeCreate\",    # Called when git worktree is created (2.1.50+)\n    \"WorktreeRemove\",    # Called when git worktree is removed (2.1.50+)\n    \"StopFailure\",       # Called on error (2.1.78+)\n    \"TaskCreated\",       # Called when task created (2.1.84+)\n    \"CwdChanged\",        # Called on working dir change (2.1.83+)\n    \"FileChanged\",       # Called on file change (2.1.83+)\n    \"Elicitation\",       # MCP elicitation request (2.1.76+)\n    \"ElicitationResult\", # MCP elicitation response (2.1.76+)\n]\n```\n\n**SDK vs CLI availability**: Most events work in both JSON\nhooks (CLI) and Python SDK hooks. `PermissionRequest` is\nCLI-only. `Setup`, `SessionStart`, `SessionEnd`, and\n`Notification` are CLI-only (JSON hooks).\n`WorktreeCreate` and `WorktreeRemove` are command-only\nhooks (no Python SDK callback). They do not support\nmatchers.\n\n### Event Summary\n\n| Event | Trigger | Blockable | Matcher |\n|-------|---------|-----------|---------|\n| `Setup` | Plugin installed/enabled | No | No |\n| `SessionStart` | Session begins | No | No |\n| `SessionEnd` | Session ends normally | No | No |\n| `UserPromptSubmit` | User submits input | No | No |\n| `PreToolUse` | Before any tool runs | Yes | Tool name |\n| `PostToolUse` | After tool completes | No | Tool name |\n| `PostToolUseFailure` | Tool execution fails | No | Tool name |\n| `PermissionRequest` | Permission dialog | Yes | Tool name |\n| `SubagentStart` | Subagent spawns | No | No |\n| `SubagentStop` | Subagent completes | No | No |\n| `Stop` | Agent stops | No | No |\n| `TeammateIdle` | Teammate idle | No | No |\n| `TaskCompleted` | Task finishes | No | No |\n| `ConfigChange` | Config modified | No | No |\n| `InstructionsLoaded` | Instructions loaded | No | No |\n| `PreCompact` | Before compaction | No | No |\n| `PostCompact` | After compaction | No | No |\n| `WorktreeCreate` | Worktree created | No | No |\n| `WorktreeRemove` | Worktree removed | No | No |\n| `StopFailure` | Error occurs | No | Error type |\n| `TaskCreated` | Task created | Yes | No |\n| `CwdChanged` | Directory changed | No | No |\n| `FileChanged` | File changed | No | Filename |\n| `Elicitation` | MCP elicitation | Yes | MCP server |\n| `ElicitationResult` | Elicitation response | Yes | MCP server |\n\n### Notable Version Changes\n\nAll hook events include `agent_id` and `agent_type` as\nof 2.1.69+.\n\n| Version | Change |\n|---------|--------|\n| 2.1.69 | `TeammateIdle`/`TaskCompleted` support `{\"continue\": false}` for graceful shutdown |\n| 2.1.69 | Plugin WorktreeCreate/WorktreeRemove hooks fire correctly (were silently ignored) |\n| 2.1.71 | New tools: `CronCreate`, `CronList`, `CronDelete` appear in PreToolUse/PostToolUse |\n| 2.1.72 | `ExitWorktree` tool added; `lsof`/`pgrep`/`tput`/`ss`/`fd`/`fdfind` auto-approved |\n| 2.1.72 | Skill hook double-fire fixed; `transcript_path` correct for resumed sessions |\n| 2.1.72 | Failed Read/WebFetch/Glob no longer cancel sibling tool calls (only Bash cascades) |\n| 2.1.73 | SessionStart no longer double-fires on `--resume`/`--continue` |\n| 2.1.73 | JSON-output hooks no longer inject spurious system-reminder messages |\n| 2.1.74 | SessionEnd hooks timeout now configurable via `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` |\n| 2.1.75 | Hook source displayed in permission prompts; async hook messages suppressed by default |\n| 2.1.76 | `Elicitation` and `ElicitationResult` events for MCP servers |\n| 2.1.76 | `PostCompact` event fires after context compaction |\n| 2.1.77 | PreToolUse \"allow\" no longer bypasses deny rules (security fix) |\n| 2.1.83 | `CwdChanged` and `FileChanged` events added |\n| 2.1.84 | `TaskCreated` event (blockable); HTTP hooks can return worktree path |\n| 2.1.85 | `if` field for conditional hook execution; PreToolUse can match `AskUserQuestion` |\n\n## Type Definitions\n\n### HookCallback\n\n```python\nfrom typing import Any, Awaitable, Callable\n\nHookCallback = Callable[\n    [dict[str, Any], str | None, HookContext],\n    Awaitable[dict[str, Any]]\n]\n```\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `input_data` | `dict[str, Any]` | Hook-specific input data (varies by event) |\n| `tool_use_id` | `str \\| None` | Tool use identifier (for tool-related hooks) |\n| `context` | `HookContext` | Additional context information |\n\n**Returns:** `dict[str, Any]` with optional fields:\n`decision` (\"block\"), `systemMessage` (str),\n`hookSpecificOutput` (dict).\n\n### HookMatcher\n\n```python\n@dataclass\nclass HookMatcher:\n    matcher: str | None = None\n    hooks: list[HookCallback] = field(default_factory=list)\n    timeout: float | None = None  # Default: 60s\n```\n\n| Pattern | Matches |\n|---------|---------|\n| `\"Bash\"` | Only Bash tool |\n| `\"Write\\|Edit\"` | Write OR Edit tools |\n| `None` | All tools (universal matcher) |\n\n## Complete Usage Example\n\n```python\nfrom claude_agent_sdk import query, ClaudeAgentOptions, HookMatcher, HookContext\nfrom typing import Any\n\nasync def validate_bash_command(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Block dangerous bash commands.\"\"\"\n    if input_data['tool_name'] == 'Bash':\n        command = input_data['tool_input'].get('command', '')\n        if 'rm -rf /' in command:\n            return {\n                'hookSpecificOutput': {\n                    'hookEventName': 'PreToolUse',\n                    'permissionDecision': 'deny',\n                    'permissionDecisionReason': 'Dangerous command blocked'\n                }\n            }\n    return {}\n\nasync def log_tool_use(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Log all tool usage for auditing.\"\"\"\n    print(f\"Tool used: {input_data.get('tool_name')}\")\n    return {}\n\noptions = ClaudeAgentOptions(\n    hooks={\n        'PreToolUse': [\n            HookMatcher(matcher='Bash', hooks=[validate_bash_command], timeout=120),\n            HookMatcher(hooks=[log_tool_use])\n        ],\n        'PostToolUse': [\n            HookMatcher(hooks=[log_tool_use])\n        ]\n    }\n)\n\nasync for message in query(prompt=\"Analyze this codebase\", options=options):\n    print(message)\n```\n\n## Input Data by Event Type\n\n### PreToolUse / PostToolUse\n\n```python\n# PreToolUse\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"}}\n\n# PostToolUse (adds result)\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"},\n \"tool_result\": \"file1.txt\\nfile2.txt\", \"error\": None}\n```\n\n### PermissionRequest (CLI only)\n\n```python\n# Input\n{\"session_id\": \"abc123\", \"tool_name\": \"Bash\",\n \"tool_input\": {\"command\": \"npm install\"},\n \"permission_mode\": \"default\", \"cwd\": \"/path/to/project\"}\n\n# Output: allow\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"allow\"}}}\n\n# Output: deny\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"deny\", \"message\": \"Reason\"}}}\n```\n\n### Other Events\n\n| Event | Key Fields |\n|-------|------------|\n| `UserPromptSubmit` | `prompt`, `conversation_id` |\n| `TeammateIdle` | `agent_id`, `session_id` |\n| `TaskCompleted` | `task_id`, `result`, `duration_ms`, `token_count` |\n| `Stop` / `SubagentStop` | `reason`, `final_message` |\n| `PreCompact` | `messages`, `token_count` |\n| `PostCompact` | `trigger` (\"manual\"/\"auto\"), `compact_summary` |\n| `WorktreeCreate` | `name` (must print worktree path to stdout) |\n| `WorktreeRemove` | `worktree_path` (cannot block removal) |\n\n## Hook Return Patterns\n\n```python\n# Allow (default)\nreturn {}\n\n# Block action\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",\n        \"permissionDecision\": \"deny\",\n        \"permissionDecisionReason\": \"Explanation\"\n    }\n}\n\n# Add system message\nreturn {\"systemMessage\": \"Important context added to conversation\"}\n```\n\n## Best Practices\n\n| Area | Guidance |\n|------|----------|\n| Performance | Keep hooks fast (<100ms PreToolUse, <200ms PostToolUse) |\n| Performance | Use appropriate timeouts; cache expensive computations |\n| Security | Validate all input; never use dynamic code eval with hook input |\n| Security | Use allowlists over blocklists; sanitize log data |\n| Reliability | Always return a dict (even empty `{}`); handle exceptions |\n| Reliability | Design hooks to be idempotent; include meaningful block reasons |\n| Testing | Test with various input patterns; verify timeout behavior |\n\nFile v1.9.16:skill-card.md\n\n## Description: <br>\nEvaluate hook security, performance, and SDK compliance for Claude/OpenClaw hook audits. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent-tooling reviewers use this skill to audit Claude/OpenClaw hooks for security, performance, compliance, reliability, and maintainability before adopting or deploying hook behavior. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Example hook guidance may be adapted into real hooks that observe or influence agent actions. <br>\nMitigation: Review and scan any implemented hook code separately before deployment. <br>\nRisk: Broad trigger words may activate the skill during generic security or performance discussions. <br>\nMitigation: Use the guidance in contexts where hook auditing is relevant and confirm applicability before acting on recommendations. <br>\n\n\n## Reference(s): <br>\n- [Project homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n- [SDK Hook Types](modules/sdk-hook-types.md) <br>\n- [Hook Evaluation Criteria](modules/evaluation-criteria.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, shell commands] <br>\n**Output Format:** [Markdown guidance with command examples and scoring criteria] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only guidance; no installed executable behavior.] <br>\n\n## Skill Version(s): <br>\n1.9.16 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.15: 5 files, 11058 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (2050b), SKILL.md (6191b), _meta.json (142b)\n\nFile v1.9.15:SKILL.md\n\n---\nname: hooks-eval\ndescription: Evaluate hook security, performance, and SDK compliance. Use for audits\nversion: 1.9.8\ntriggers:\n  - hooks\n  - evaluation\n  - security\n  - performance\n  - claude-sdk\n  - agent-sdk\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.hook-scope-guide\"]}}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Key Capabilities](#key-capabilities)\n- [Core Components](#core-components)\n- [Quick Reference](#quick-reference)\n- [Hook Event Types](#hook-event-types)\n- [Hook Callback Signature](#hook-callback-signature)\n- [Return Values](#return-values)\n- [Quality Scoring (100 points)](#quality-scoring-(100-points))\n- [Detailed Resources](#detailed-resources)\n- [Basic Evaluation Workflow](#basic-evaluation-workflow)\n- [Integration with Other Tools](#integration-with-other-tools)\n- [Related Skills](#related-skills)\n\n\n# Hooks Evaluation Framework\n\n## Overview\n\nThis skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.\n\n### Key Capabilities\n\n- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention\n- **Performance Analysis**: Execution time benchmarking, resource usage, optimization\n- **Compliance Checking**: Structure validation, documentation requirements, best practices\n- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns\n\n### Core Components\n\n| Component | Purpose |\n|-----------|---------|\n| **Hook Types Reference** | Complete SDK hook event types and signatures |\n| **Evaluation Criteria** | Scoring system and quality gates |\n| **Security Patterns** | Common vulnerabilities and mitigations |\n| **Performance Benchmarks** | Thresholds and optimization guidance |\n\n## Quick Reference\n\n### Hook Event Types\n\n```python\nHookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via `hooks.json` using shell commands (e.g., leyline's `detect-git-platform.sh`).\n\n### Plugin-Level hooks.json\n\nPlugins can declare hooks via `\"hooks\": \"./hooks/hooks.json\"` in plugin.json. The evaluator validates:\n- Referenced hooks.json exists and is valid JSON\n- Shell commands referenced in hooks exist and are executable\n- Hook matchers use valid event types\n\n### Hook Callback Signature\n\n```python\nasync def my_hook(\n    input_data: dict[str, Any],    # Hook-specific input\n    tool_use_id: str | None,       # Tool ID (for tool hooks)\n    context: HookContext           # Additional context\n) -> dict[str, Any]:               # Return decision/messages\n    ...\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Return Values\n\n```python\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",       # Match hook type\n        \"permissionDecision\": \"deny\",        # Optional: block action\n        \"permissionDecisionReason\": \"...\",   # Reason for denial\n        \"additionalContext\": \"...\",          # Optional: context added\n    }\n}\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Quality Scoring (100 points)\n\n| Category | Points | Focus |\n|----------|--------|-------|\n| Security | 30 | Vulnerabilities, injection, validation |\n| Performance | 25 | Execution time, memory, I/O |\n| Compliance | 20 | Structure, documentation, error handling |\n| Reliability | 15 | Timeouts, idempotency, degradation |\n| Maintainability | 10 | Code structure, modularity |\n\n## Detailed Resources\n\n- **SDK Hook Types**: See `modules/sdk-hook-types.md` for complete Python SDK type definitions, patterns, and examples\n- **Evaluation Criteria**: See `modules/evaluation-criteria.md` for detailed scoring rubric and quality gates\n- **Security Patterns**: See `modules/sdk-hook-types.md` for vulnerability detection and mitigation\n- **Performance Guide**: See `modules/evaluation-criteria.md` for benchmarking and optimization\n\n## Basic Evaluation Workflow\n\n```bash\n# 1. Run detailed evaluation\n/hooks-eval --detailed\n\n# 2. Focus on security issues\n/hooks-eval --security-only --format sarif\n\n# 3. Benchmark performance\n/hooks-eval --performance-baseline\n\n# 4. Check compliance\n/hooks-eval --compliance-report\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Integration with Other Tools\n\n```bash\n# Complete plugin evaluation pipeline\n/hooks-eval --detailed          # Evaluate all hooks\n/analyze-hook hooks/specific.py      # Deep-dive on one hook\n/validate-plugin .                   # Validate overall structure\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Related Skills\n\n- `abstract:hook-scope-guide` - Decide where to place hooks (plugin/project/global)\n- `abstract:hook-authoring` - Write hook rules and patterns\n- `abstract:validate-plugin` - Validate complete plugin structure\n## Troubleshooting\n\n### Common Issues\n\n**Hook not firing**\nVerify hook pattern matches the event. Check hook logs for errors\n\n**Syntax errors**\nValidate JSON/Python syntax before deployment\n\n**Permission denied**\nCheck hook file permissions and ownership\n\nFile v1.9.15:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-hooks-eval\",\n  \"version\": \"1.9.15\",\n  \"publishedAt\": 1783199948983\n}\n\nFile v1.9.15:modules/evaluation-criteria.md\n\n# Hook Evaluation Criteria\n\nDetailed scoring rubric and quality gates for hook evaluation.\n\n## Mathematical Foundation\n\nThis evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:\n\n- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))\n- **Weighting**: Security-first weights with stakeholder validation\n- **Aggregation**: Weighted sum with penalty-based security scoring\n- **Validation**: Sensitivity analysis on non-security weights\n\n**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.\n\n## Scoring System (100 points total)\n\n### Security Analysis (30 points)\n\n**Vulnerability Detection:**\n- Critical vulnerabilities: -15 points each\n- High-risk issues: -8 points each\n- Medium-risk issues: -4 points each\n- Low-risk issues: -1 point each\n\n**Security Checklist:**\n\n| Check | Severity | Points Lost |\n|-------|----------|-------------|\n| Dynamic code evaluation with user input | Critical | -15 |\n| Command injection vulnerability | Critical | -15 |\n| Unvalidated file path access | High | -8 |\n| Secrets/credentials in code | High | -8 |\n| Missing input validation | Medium | -4 |\n| Overly permissive patterns | Medium | -4 |\n| No rate limiting | Low | -1 |\n| Verbose error messages exposing internals | Low | -1 |\n\n### Performance Analysis (25 points)\n\n| Metric | Max Points | Criteria |\n|--------|------------|----------|\n| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |\n| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |\n| I/O operation efficiency | 4 | Minimal file/network operations |\n| Resource cleanup | 3 | Proper cleanup of handles, connections |\n\n**Performance Thresholds:**\n\n```yaml\npre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB\n```\n\n### Compliance Analysis (20 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Structure compliance | 8 | Valid JSON/Python, correct schema |\n| Documentation completeness | 6 | Purpose, parameters, return values documented |\n| Error handling | 4 | All exceptions caught, meaningful messages |\n| Best practices | 2 | Follows hook authoring guidelines |\n\n**Structure Requirements:**\n\n- JSON hooks: Valid JSON schema with required fields\n- Python hooks: Type hints, async/await patterns\n- Matcher patterns: Valid regex, appropriate scope\n\n### Reliability Analysis (15 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Error handling robustness | 6 | Graceful handling of all error conditions |\n| Timeout management | 4 | Appropriate timeouts configured |\n| Idempotency | 3 | Safe to retry without side effects |\n| Graceful degradation | 2 | Falls back safely on failure |\n\n**Reliability Checklist:**\n\n- [ ] Hook returns valid response on all code paths\n- [ ] Exceptions are caught and handled\n- [ ] Timeout is configured appropriately\n- [ ] Hook can be called multiple times safely\n- [ ] Failure doesn't break agent operation\n\n### Maintainability (10 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Code structure | 4 | Clear, modular, single responsibility |\n| Documentation clarity | 3 | Purpose and behavior well explained |\n| Modularity | 2 | Reusable components, no duplication |\n| Test coverage | 1 | Tests exist for key functionality |\n\n## Quality Levels\n\n| Score | Level | Description |\n|-------|-------|-------------|\n| 91-100 | Excellent | Production-ready, follows all best practices |\n| 76-90 | Good | Minor improvements suggested |\n| 51-75 | Acceptable | Some issues requiring attention |\n| 26-50 | Poor | Significant issues need addressing |\n| 0-25 | Critical | Major security or reliability issues |\n\n## Quality Gates\n\nDefault thresholds for CI/CD integration:\n\n```yaml\nquality_gates:\n  security_score: \">= 80\"\n  performance_score: \">= 70\"\n  compliance_score: \">= 85\"\n  reliability_score: \">= 85\"\n  overall_score: \">= 75\"\n  max_critical_issues: 0\n  max_high_issues: 2\n```\n\n### Sensitivity Analysis Requirements\n\nSecurity weights are non-negotiable, but other weights should be validated:\n\n```yaml\nsensitivity_analysis:\n  # Security weights are fixed (non-negotiable)\n  fixed_weights: [\"security_analysis\"]\n\n  # Other weights tested for sensitivity\n  test_weights: [\"performance\", \"compliance\", \"reliability\", \"maintainability\"]\n  variation: 0.20  # ±20% weight variation\n\n  requirements:\n    stable_rankings: true  # Rankings shouldn't change (except security)\n    critical_weights_identified: true  # Document sensitive weights\n```\n\nSee [Sensitivity Analysis](../../skills-eval/modules/multi-metric-evaluation-methodology.md#sensitivity-analysis) for implementation details.\n\n### Gate Behaviors\n\n| Gate | Failure Action |\n|------|----------------|\n| `security_score` | Block deployment, require review |\n| `performance_score` | Warn, suggest optimization |\n| `compliance_score` | Block until documentation complete |\n| `reliability_score` | Block deployment |\n| `max_critical_issues` | Immediate block |\n\n## Issue Classification\n\n### Critical Issues (Immediate Action Required)\n\n- Dynamic code evaluation with untrusted input\n- Command injection vulnerabilities\n- Credential exposure\n- Unhandled exceptions that break agent\n\n### High Issues (Address Before Release)\n\n- Missing input validation\n- Performance exceeds thresholds\n- Missing error handling\n- Insecure file operations\n\n### Medium Issues (Address Soon)\n\n- Missing documentation\n- Suboptimal patterns\n- Minor performance concerns\n- Code style violations\n\n### Low Issues (Nice to Fix)\n\n- Minor documentation gaps\n- Formatting inconsistencies\n- Optimization opportunities\n- Enhanced logging suggestions\n\n## Evaluation Report Format\n\n### Summary Format\n\n```\n=== Hooks Evaluation Report ===\nPlugin: {name} (v{version})\nScope: {scope}\nTotal hooks: {count} ({json_count} JSON, {python_count} Python)\n\n=== Scores ===\nSecurity:      {score}/100 ({level})\nPerformance:   {score}/100 ({level})\nCompliance:    {score}/100 ({level})\nReliability:   {score}/100 ({level})\nMaintainability: {score}/100 ({level})\n────────────────────────────────\nOverall:       {score}/100 ({level})\n\n=== Issues ===\nCritical: {count}\nHigh: {count}\nMedium: {count}\nLow: {count}\n```\n\n### Detailed Format\n\nIncludes per-hook breakdown:\n\n```\n=== Hook: {hook_path} ===\nType: {json|python}\nEvent: {PreToolUse|PostToolUse|...}\nMatcher: {pattern|universal}\n\nSecurity Issues:\n  [{severity}] Line {n}: {description}\n\nPerformance:\n  Estimated time: {ms}ms (threshold: {threshold}ms)\n  Memory usage: {mb}MB (threshold: {threshold}MB)\n\nRecommendations:\n  1. {recommendation}\n  2. {recommendation}\n```\n\n## Customization\n\n### Per-Plugin Configuration\n\nCreate `.hooks-eval.yaml` in plugin root:\n\n```yaml\nhooks_eval:\n  # Override security thresholds\n  security_thresholds:\n    critical_score: 80\n    high_score: 70\n\n  # Override performance thresholds\n  performance_thresholds:\n    pre_tool_use_max_ms: 100\n    post_tool_use_max_ms: 200\n    max_memory_mb: 50\n\n  # Compliance requirements\n  compliance_requirements:\n    require_documentation: true\n    require_error_handling: true\n    require_timeout_config: true\n\n  # Custom rules\n  custom_rules:\n    - name: \"no-hardcoded-secrets\"\n      pattern: \"password|secret|token\"\n      severity: \"high\"\n    - name: \"require-shebang\"\n      pattern: \"^#!\"\n      file_types: [\".sh\", \".py\"]\n      severity: \"medium\"\n\n  # Excluded paths\n  exclude_paths:\n    - \"hooks/experimental/*\"\n    - \"hooks/deprecated/*\"\n```\n\n### Severity Overrides\n\nOverride default severity for specific patterns:\n\n```yaml\nseverity_overrides:\n  - pattern: \"subprocess.run\"\n    default_severity: \"high\"\n    override_severity: \"medium\"\n    reason: \"Safe usage verified in review\"\n```\n\nFile v1.9.15:modules/sdk-hook-types.md\n\n# Python SDK Hook Types\n\nComplete reference for Claude Agent SDK hook types, callbacks,\nand matchers.\n\n## Hook Events\n\n### HookEvent\n\nSupported hook event types in the Python SDK.\n\n```python\nfrom typing import Literal\n\nHookEvent = Literal[\n    \"Setup\",             # Called when plugin installed/enabled\n    \"SessionStart\",      # Called when session begins\n    \"SessionEnd\",        # Called when session ends normally\n    \"UserPromptSubmit\",  # Called when user submits a prompt\n    \"PreToolUse\",        # Called before tool execution\n    \"PostToolUse\",       # Called after tool execution\n    \"PostToolUseFailure\",# Called when tool execution fails (2.1.20+)\n    \"PermissionRequest\", # Called when permission dialog would appear\n    \"Notification\",      # Called on system notification (2.1.20+)\n    \"SubagentStart\",     # Called when subagent spawns (2.1.20+)\n    \"SubagentStop\",      # Called when a subagent stops\n    \"Stop\",              # Called when stopping execution\n    \"TeammateIdle\",      # Called when teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",     # Called when a task finishes execution (2.1.33+)\n    \"ConfigChange\",      # Called when config is modified (2.1.49+)\n    \"InstructionsLoaded\",# Called when instructions are loaded (2.1.33+)\n    \"PreCompact\",        # Called before message compaction\n    \"PostCompact\",       # Called after compaction (2.1.76+)\n    \"WorktreeCreate\",    # Called when git worktree is created (2.1.50+)\n    \"WorktreeRemove\",    # Called when git worktree is removed (2.1.50+)\n    \"StopFailure\",       # Called on error (2.1.78+)\n    \"TaskCreated\",       # Called when task created (2.1.84+)\n    \"CwdChanged\",        # Called on working dir change (2.1.83+)\n    \"FileChanged\",       # Called on file change (2.1.83+)\n    \"Elicitation\",       # MCP elicitation request (2.1.76+)\n    \"ElicitationResult\", # MCP elicitation response (2.1.76+)\n]\n```\n\n**SDK vs CLI availability**: Most events work in both JSON\nhooks (CLI) and Python SDK hooks. `PermissionRequest` is\nCLI-only. `Setup`, `SessionStart`, `SessionEnd`, and\n`Notification` are CLI-only (JSON hooks).\n`WorktreeCreate` and `WorktreeRemove` are command-only\nhooks (no Python SDK callback). They do not support\nmatchers.\n\n### Event Summary\n\n| Event | Trigger | Blockable | Matcher |\n|-------|---------|-----------|---------|\n| `Setup` | Plugin installed/enabled | No | No |\n| `SessionStart` | Session begins | No | No |\n| `SessionEnd` | Session ends normally | No | No |\n| `UserPromptSubmit` | User submits input | No | No |\n| `PreToolUse` | Before any tool runs | Yes | Tool name |\n| `PostToolUse` | After tool completes | No | Tool name |\n| `PostToolUseFailure` | Tool execution fails | No | Tool name |\n| `PermissionRequest` | Permission dialog | Yes | Tool name |\n| `SubagentStart` | Subagent spawns | No | No |\n| `SubagentStop` | Subagent completes | No | No |\n| `Stop` | Agent stops | No | No |\n| `TeammateIdle` | Teammate idle | No | No |\n| `TaskCompleted` | Task finishes | No | No |\n| `ConfigChange` | Config modified | No | No |\n| `InstructionsLoaded` | Instructions loaded | No | No |\n| `PreCompact` | Before compaction | No | No |\n| `PostCompact` | After compaction | No | No |\n| `WorktreeCreate` | Worktree created | No | No |\n| `WorktreeRemove` | Worktree removed | No | No |\n| `StopFailure` | Error occurs | No | Error type |\n| `TaskCreated` | Task created | Yes | No |\n| `CwdChanged` | Directory changed | No | No |\n| `FileChanged` | File changed | No | Filename |\n| `Elicitation` | MCP elicitation | Yes | MCP server |\n| `ElicitationResult` | Elicitation response | Yes | MCP server |\n\n### Notable Version Changes\n\nAll hook events include `agent_id` and `agent_type` as\nof 2.1.69+.\n\n| Version | Change |\n|---------|--------|\n| 2.1.69 | `TeammateIdle`/`TaskCompleted` support `{\"continue\": false}` for graceful shutdown |\n| 2.1.69 | Plugin WorktreeCreate/WorktreeRemove hooks fire correctly (were silently ignored) |\n| 2.1.71 | New tools: `CronCreate`, `CronList`, `CronDelete` appear in PreToolUse/PostToolUse |\n| 2.1.72 | `ExitWorktree` tool added; `lsof`/`pgrep`/`tput`/`ss`/`fd`/`fdfind` auto-approved |\n| 2.1.72 | Skill hook double-fire fixed; `transcript_path` correct for resumed sessions |\n| 2.1.72 | Failed Read/WebFetch/Glob no longer cancel sibling tool calls (only Bash cascades) |\n| 2.1.73 | SessionStart no longer double-fires on `--resume`/`--continue` |\n| 2.1.73 | JSON-output hooks no longer inject spurious system-reminder messages |\n| 2.1.74 | SessionEnd hooks timeout now configurable via `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` |\n| 2.1.75 | Hook source displayed in permission prompts; async hook messages suppressed by default |\n| 2.1.76 | `Elicitation` and `ElicitationResult` events for MCP servers |\n| 2.1.76 | `PostCompact` event fires after context compaction |\n| 2.1.77 | PreToolUse \"allow\" no longer bypasses deny rules (security fix) |\n| 2.1.83 | `CwdChanged` and `FileChanged` events added |\n| 2.1.84 | `TaskCreated` event (blockable); HTTP hooks can return worktree path |\n| 2.1.85 | `if` field for conditional hook execution; PreToolUse can match `AskUserQuestion` |\n\n## Type Definitions\n\n### HookCallback\n\n```python\nfrom typing import Any, Awaitable, Callable\n\nHookCallback = Callable[\n    [dict[str, Any], str | None, HookContext],\n    Awaitable[dict[str, Any]]\n]\n```\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `input_data` | `dict[str, Any]` | Hook-specific input data (varies by event) |\n| `tool_use_id` | `str \\| None` | Tool use identifier (for tool-related hooks) |\n| `context` | `HookContext` | Additional context information |\n\n**Returns:** `dict[str, Any]` with optional fields:\n`decision` (\"block\"), `systemMessage` (str),\n`hookSpecificOutput` (dict).\n\n### HookMatcher\n\n```python\n@dataclass\nclass HookMatcher:\n    matcher: str | None = None\n    hooks: list[HookCallback] = field(default_factory=list)\n    timeout: float | None = None  # Default: 60s\n```\n\n| Pattern | Matches |\n|---------|---------|\n| `\"Bash\"` | Only Bash tool |\n| `\"Write\\|Edit\"` | Write OR Edit tools |\n| `None` | All tools (universal matcher) |\n\n## Complete Usage Example\n\n```python\nfrom claude_agent_sdk import query, ClaudeAgentOptions, HookMatcher, HookContext\nfrom typing import Any\n\nasync def validate_bash_command(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Block dangerous bash commands.\"\"\"\n    if input_data['tool_name'] == 'Bash':\n        command = input_data['tool_input'].get('command', '')\n        if 'rm -rf /' in command:\n            return {\n                'hookSpecificOutput': {\n                    'hookEventName': 'PreToolUse',\n                    'permissionDecision': 'deny',\n                    'permissionDecisionReason': 'Dangerous command blocked'\n                }\n            }\n    return {}\n\nasync def log_tool_use(\n    input_data: dict[str, Any],\n    tool_use_id: str | None,\n    context: HookContext\n) -> dict[str, Any]:\n    \"\"\"Log all tool usage for auditing.\"\"\"\n    print(f\"Tool used: {input_data.get('tool_name')}\")\n    return {}\n\noptions = ClaudeAgentOptions(\n    hooks={\n        'PreToolUse': [\n            HookMatcher(matcher='Bash', hooks=[validate_bash_command], timeout=120),\n            HookMatcher(hooks=[log_tool_use])\n        ],\n        'PostToolUse': [\n            HookMatcher(hooks=[log_tool_use])\n        ]\n    }\n)\n\nasync for message in query(prompt=\"Analyze this codebase\", options=options):\n    print(message)\n```\n\n## Input Data by Event Type\n\n### PreToolUse / PostToolUse\n\n```python\n# PreToolUse\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"}}\n\n# PostToolUse (adds result)\n{\"tool_name\": \"Bash\", \"tool_input\": {\"command\": \"ls -la\"},\n \"tool_result\": \"file1.txt\\nfile2.txt\", \"error\": None}\n```\n\n### PermissionRequest (CLI only)\n\n```python\n# Input\n{\"session_id\": \"abc123\", \"tool_name\": \"Bash\",\n \"tool_input\": {\"command\": \"npm install\"},\n \"permission_mode\": \"default\", \"cwd\": \"/path/to/project\"}\n\n# Output: allow\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"allow\"}}}\n\n# Output: deny\n{\"hookSpecificOutput\": {\"hookEventName\": \"PermissionRequest\",\n \"decision\": {\"behavior\": \"deny\", \"message\": \"Reason\"}}}\n```\n\n### Other Events\n\n| Event | Key Fields |\n|-------|------------|\n| `UserPromptSubmit` | `prompt`, `conversation_id` |\n| `TeammateIdle` | `agent_id`, `session_id` |\n| `TaskCompleted` | `task_id`, `result`, `duration_ms`, `token_count` |\n| `Stop` / `SubagentStop` | `reason`, `final_message` |\n| `PreCompact` | `messages`, `token_count` |\n| `PostCompact` | `trigger` (\"manual\"/\"auto\"), `compact_summary` |\n| `WorktreeCreate` | `name` (must print worktree path to stdout) |\n| `WorktreeRemove` | `worktree_path` (cannot block removal) |\n\n## Hook Return Patterns\n\n```python\n# Allow (default)\nreturn {}\n\n# Block action\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",\n        \"permissionDecision\": \"deny\",\n        \"permissionDecisionReason\": \"Explanation\"\n    }\n}\n\n# Add system message\nreturn {\"systemMessage\": \"Important context added to conversation\"}\n```\n\n## Best Practices\n\n| Area | Guidance |\n|------|----------|\n| Performance | Keep hooks fast (<100ms PreToolUse, <200ms PostToolUse) |\n| Performance | Use appropriate timeouts; cache expensive computations |\n| Security | Validate all input; never use dynamic code eval with hook input |\n| Security | Use allowlists over blocklists; sanitize log data |\n| Reliability | Always return a dict (even empty `{}`); handle exceptions |\n| Reliability | Design hooks to be idempotent; include meaningful block reasons |\n| Testing | Test with various input patterns; verify timeout behavior |\n\nFile v1.9.15:skill-card.md\n\n## Description: <br>\nEvaluate hook security, performance, and SDK compliance for audits. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to audit Claude Code hooks for security, performance, SDK compatibility, reliability, and documentation quality. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad triggers may activate the skill for general security or performance questions outside hook-audit work. <br>\nMitigation: Confirm the task is specifically about hook evaluation before applying the skill's rubric or recommendations. <br>\nRisk: Audit guidance can be incomplete if used without inspecting the actual hook implementation and runtime context. <br>\nMitigation: Validate recommendations against the target hook files, configuration, and runtime behavior before deployment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-hooks-eval) <br>\n- [Metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n- [Python SDK Hook Types](modules/sdk-hook-types.md) <br>\n- [Hook Evaluation Criteria](modules/evaluation-criteria.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown guidance with code and shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only output; no files or commands are executed by the skill itself.] <br>\n\n## Skill Version(s): <br>\n1.9.15 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.14: 5 files, 11085 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (2135b), SKILL.md (6191b), _meta.json (142b)\n\nFile v1.9.14:SKILL.md\n\n---\nname: hooks-eval\ndescription: Evaluate hook security, performance, and SDK compliance. Use for audits\nversion: 1.9.8\ntriggers:\n  - hooks\n  - evaluation\n  - security\n  - performance\n  - claude-sdk\n  - agent-sdk\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.hook-scope-guide\"]}}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Key Capabilities](#key-capabilities)\n- [Core Components](#core-components)\n- [Quick Reference](#quick-reference)\n- [Hook Event Types](#hook-event-types)\n- [Hook Callback Signature](#hook-callback-signature)\n- [Return Values](#return-values)\n- [Quality Scoring (100 points)](#quality-scoring-(100-points))\n- [Detailed Resources](#detailed-resources)\n- [Basic Evaluation Workflow](#basic-evaluation-workflow)\n- [Integration with Other Tools](#integration-with-other-tools)\n- [Related Skills](#related-skills)\n\n\n# Hooks Evaluation Framework\n\n## Overview\n\nThis skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.\n\n### Key Capabilities\n\n- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention\n- **Performance Analysis**: Execution time benchmarking, resource usage, optimization\n- **Compliance Checking**: Structure validation, documentation requirements, best practices\n- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns\n\n### Core Components\n\n| Component | Purpose |\n|-----------|---------|\n| **Hook Types Reference** | Complete SDK hook event types and signatures |\n| **Evaluation Criteria** | Scoring system and quality gates |\n| **Security Patterns** | Common vulnerabilities and mitigations |\n| **Performance Benchmarks** | Thresholds and optimization guidance |\n\n## Quick Reference\n\n### Hook Event Types\n\n```python\nHookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via `hooks.json` using shell commands (e.g., leyline's `detect-git-platform.sh`).\n\n### Plugin-Level hooks.json\n\nPlugins can declare hooks via `\"hooks\": \"./hooks/hooks.json\"` in plugin.json. The evaluator validates:\n- Referenced hooks.json exists and is valid JSON\n- Shell commands referenced in hooks exist and are executable\n- Hook matchers use valid event types\n\n### Hook Callback Signature\n\n```python\nasync def my_hook(\n    input_data: dict[str, Any],    # Hook-specific input\n    tool_use_id: str | None,       # Tool ID (for tool hooks)\n    context: HookContext           # Additional context\n) -> dict[str, Any]:               # Return decision/messages\n    ...\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Return Values\n\n```python\nreturn {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",       # Match hook type\n        \"permissionDecision\": \"deny\",        # Optional: block action\n        \"permissionDecisionReason\": \"...\",   # Reason for denial\n        \"additionalContext\": \"...\",          # Optional: context added\n    }\n}\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n### Quality Scoring (100 points)\n\n| Category | Points | Focus |\n|----------|--------|-------|\n| Security | 30 | Vulnerabilities, injection, validation |\n| Performance | 25 | Execution time, memory, I/O |\n| Compliance | 20 | Structure, documentation, error handling |\n| Reliability | 15 | Timeouts, idempotency, degradation |\n| Maintainability | 10 | Code structure, modularity |\n\n## Detailed Resources\n\n- **SDK Hook Types**: See `modules/sdk-hook-types.md` for complete Python SDK type definitions, patterns, and examples\n- **Evaluation Criteria**: See `modules/evaluation-criteria.md` for detailed scoring rubric and quality gates\n- **Security Patterns**: See `modules/sdk-hook-types.md` for vulnerability detection and mitigation\n- **Performance Guide**: See `modules/evaluation-criteria.md` for benchmarking and optimization\n\n## Basic Evaluation Workflow\n\n```bash\n# 1. Run detailed evaluation\n/hooks-eval --detailed\n\n# 2. Focus on security issues\n/hooks-eval --security-only --format sarif\n\n# 3. Benchmark performance\n/hooks-eval --performance-baseline\n\n# 4. Check compliance\n/hooks-eval --compliance-report\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Integration with Other Tools\n\n```bash\n# Complete plugin evaluation pipeline\n/hooks-eval --detailed          # Evaluate all hooks\n/analyze-hook hooks/specific.py      # Deep-dive on one hook\n/validate-plugin .                   # Validate overall structure\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n## Related Skills\n\n- `abstract:hook-scope-guide` - Decide where to place hooks (plugin/project/global)\n- `abstract:hook-authoring` - Write hook rules and patterns\n- `abstract:validate-plugin` - Validate complete plugin structure\n## Troubleshooting\n\n### Common Issues\n\n**Hook not firing**\nVerify hook pattern matches the event. Check hook logs for errors\n\n**Syntax errors**\nValidate JSON/Python syntax before deployment\n\n**Permission denied**\nCheck hook file permissions and ownership\n\nFile v1.9.14:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-hooks-eval\",\n  \"version\": \"1.9.14\",\n  \"publishedAt\": 1782841782818\n}\n\nFile v1.9.14:modules/evaluation-criteria.md\n\n# Hook Evaluation Criteria\n\nDetailed scoring rubric and quality gates for hook evaluation.\n\n## Mathematical Foundation\n\nThis evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:\n\n- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))\n- **Weighting**: Security-first weights with stakeholder validation\n- **Aggregation**: Weighted sum with penalty-based security scoring\n- **Validation**: Sensitivity analysis on non-security weights\n\n**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.\n\n## Scoring System (100 points total)\n\n### Security Analysis (30 points)\n\n**Vulnerability Detection:**\n- Critical vulnerabilities: -15 points each\n- High-risk issues: -8 points each\n- Medium-risk issues: -4 points each\n- Low-risk issues: -1 point each\n\n**Security Checklist:**\n\n| Check | Severity | Points Lost |\n|-------|----------|-------------|\n| Dynamic code evaluation with user input | Critical | -15 |\n| Command injection vulnerability | Critical | -15 |\n| Unvalidated file path access | High | -8 |\n| Secrets/credentials in code | High | -8 |\n| Missing input validation | Medium | -4 |\n| Overly permissive patterns | Medium | -4 |\n| No rate limiting | Low | -1 |\n| Verbose error messages exposing internals | Low | -1 |\n\n### Performance Analysis (25 points)\n\n| Metric | Max Points | Criteria |\n|--------|------------|----------|\n| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |\n| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |\n| I/O operation efficiency | 4 | Minimal file/network operations |\n| Resource cleanup | 3 | Proper cleanup of handles, connections |\n\n**Performance Thresholds:**\n\n```yaml\npre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB\n```\n\n### Compliance Analysis (20 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Structure compliance | 8 | Valid JSON/Python, correct schema |\n| Documentation completeness | 6 | Purpose, parameters, return values documented |\n| Error handling | 4 | All exceptions caught, meaningful messages |\n| Best practices | 2 | Follows hook authoring guidelines |\n\n**Structure Requirements:**\n\n- JSON hooks: Valid JSON schema with required fields\n- Python hooks: Type hints, async/await patterns\n- Matcher patterns: Valid regex, appropriate scope\n\n### Reliability Analysis (15 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Error handling robustness | 6 | Graceful handling of all error conditions |\n| Timeout management | 4 | Appropriate timeouts configured |\n| Idempotency | 3 | Safe to retry without side effects |\n| Graceful degradation | 2 | Falls back safely on failure |\n\n**Reliability Checklist:**\n\n- [ ] Hook returns valid response on all code paths\n- [ ] Exceptions are caught and ha\n\nArchive v1.9.13: 5 files, 11048 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (2014b), SKILL.md (6191b), _meta.json (142b)\n\nArchive v1.9.12: 5 files, 11013 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (1950b), SKILL.md (6191b), _meta.json (142b)\n\nArchive v1.8.6: 5 files, 11037 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (9713b), skill-card.md (2051b), SKILL.md (6191b), _meta.json (141b)\n\nArchive v1.8.5: 5 files, 15451 bytes\n\nFiles: modules/evaluation-criteria.md (8138b), modules/sdk-hook-types.md (22607b), skill-card.md (2103b), SKILL.md (6191b), _meta.json (141b)","readmeExcerpt":"Skill: hooks-eval Owner: athola Summary: Evaluate hook security, performance, and SDK compliance. Use for audits Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:03:12.768Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:27:41.806Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:27:36.109Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:44:30.079Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:08.983Z | u","codeSnippets":[],"executableExamples":[{"language":"python","snippet":"HookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]"},{"language":"python","snippet":"async def my_hook(\n    input_data: dict[str, Any],    # Hook-specific input\n    tool_use_id: str | None,       # Tool ID (for tool hooks)\n    context: HookContext           # Additional context\n) -> dict[str, Any]:               # Return decision/messages\n    ..."},{"language":"python","snippet":"return {\n    \"hookSpecificOutput\": {\n        \"hookEventName\": \"PreToolUse\",       # Match hook type\n        \"permissionDecision\": \"deny\",        # Optional: block action\n        \"permissionDecisionReason\": \"...\",   # Reason for denial\n        \"additionalContext\": \"...\",          # Optional: context added\n    }\n}"},{"language":"bash","snippet":"# 1. Run detailed evaluation\n/hooks-eval --detailed\n\n# 2. Focus on security issues\n/hooks-eval --security-only --format sarif\n\n# 3. Benchmark performance\n/hooks-eval --performance-baseline\n\n# 4. Check compliance\n/hooks-eval --compliance-report"},{"language":"bash","snippet":"# Complete plugin evaluation pipeline\n/hooks-eval --detailed          # Evaluate all hooks\n/analyze-hook hooks/specific.py      # Deep-dive on one hook\n/validate-plugin .                   # Validate overall structure"},{"language":"yaml","snippet":"pre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: hooks-eval\ndescription: Evaluate hook security, performance, and SDK compliance. Use for audits\nversion: 1.9.8\ntriggers:\n  - hooks\n  - evaluation\n  - security\n  - performance\n  - claude-sdk\n  - agent-sdk\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\", \"requires\": {\"config\": [\"night-market.hook-scope-guide\"]}}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Key Capabilities](#key-capabilities)\n- [Core Components](#core-components)\n- [Quick Reference](#quick-reference)\n- [Hook Event Types](#hook-event-types)\n- [Hook Callback Signature](#hook-callback-signature)\n- [Return Values](#return-values)\n- [Quality Scoring (100 points)](#quality-scoring-(100-points))\n- [Detailed Resources](#detailed-resources)\n- [Basic Evaluation Workflow](#basic-evaluation-workflow)\n- [Integration with Other Tools](#integration-with-other-tools)\n- [Related Skills](#related-skills)\n\n\n# Hooks Evaluation Framework\n\n## Overview\n\nThis skill provides a detailed framework for evaluating, auditing, and implementing Claude Code hooks across all scopes (plugin, project, global) and both JSON-based and programmatic (Python SDK) hooks.\n\n### Key Capabilities\n\n- **Security Analysis**: Vulnerability scanning, dangerous pattern detection, injection prevention\n- **Performance Analysis**: Execution time benchmarking, resource usage, optimization\n- **Compliance Checking**: Structure validation, documentation requirements, best practices\n- **SDK Integration**: Python SDK hook types, callbacks, matchers, and patterns\n\n### Core Components\n\n| Component | Purpose |\n|-----------|---------|\n| **Hook Types Reference** | Complete SDK hook event types and signatures |\n| **Evaluation Criteria** | Scoring system and quality gates |\n| **Security Patterns** | Common vulnerabilities and mitigations |\n| **Performance Benchmarks** | Thresholds and optimization guidance |\n\n## Quick Reference\n\n### Hook Event Types\n\n```python\nHookEvent = Literal[\n    \"PreToolUse\",       # Before tool execution\n    \"PostToolUse\",      # After tool execution\n    \"UserPromptSubmit\", # When user submits prompt\n    \"Stop\",             # When stopping execution\n    \"SubagentStop\",     # When a subagent stops\n    \"TeammateIdle\",     # When teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",    # When a task finishes execution (2.1.33+)\n    \"PreCompact\"        # Before message compaction\n]\n```\n**Verification:** Run the command with `--help` flag to verify availability.\n\n**Note**: Python SDK does not support `SessionStart`, `SessionEnd`, or `Notification` hooks due to setup limitations. However, plugins can define `SessionStart` hooks via "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-hooks-eval\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787749392768\n}"},{"path":"modules/evaluation-criteria.md","content":"# Hook Evaluation Criteria\n\nDetailed scoring rubric and quality gates for hook evaluation.\n\n## Mathematical Foundation\n\nThis evaluation framework follows Multi-Criteria Decision Analysis (MCDA) best practices:\n\n- **Normalization**: Vector normalization for scale invariance ([full methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md))\n- **Weighting**: Security-first weights with stakeholder validation\n- **Aggregation**: Weighted sum with penalty-based security scoring\n- **Validation**: Sensitivity analysis on non-security weights\n\n**Documentation**: See [Multi-Metric Evaluation Methodology](../../skills-eval/modules/multi-metric-evaluation-methodology.md) for complete mathematical foundation.\n\n## Scoring System (100 points total)\n\n### Security Analysis (30 points)\n\n**Vulnerability Detection:**\n- Critical vulnerabilities: -15 points each\n- High-risk issues: -8 points each\n- Medium-risk issues: -4 points each\n- Low-risk issues: -1 point each\n\n**Security Checklist:**\n\n| Check | Severity | Points Lost |\n|-------|----------|-------------|\n| Dynamic code evaluation with user input | Critical | -15 |\n| Command injection vulnerability | Critical | -15 |\n| Unvalidated file path access | High | -8 |\n| Secrets/credentials in code | High | -8 |\n| Missing input validation | Medium | -4 |\n| Overly permissive patterns | Medium | -4 |\n| No rate limiting | Low | -1 |\n| Verbose error messages exposing internals | Low | -1 |\n\n### Performance Analysis (25 points)\n\n| Metric | Max Points | Criteria |\n|--------|------------|----------|\n| Execution time efficiency | 10 | PreToolUse <100ms, PostToolUse <200ms |\n| Memory usage optimization | 8 | <50MB for simple hooks, <100MB for complex |\n| I/O operation efficiency | 4 | Minimal file/network operations |\n| Resource cleanup | 3 | Proper cleanup of handles, connections |\n\n**Performance Thresholds:**\n\n```yaml\npre_tool_use:\n  excellent: <50ms\n  good: <100ms\n  acceptable: <200ms\n  poor: >200ms\n\npost_tool_use:\n  excellent: <100ms\n  good: <200ms\n  acceptable: <500ms\n  poor: >500ms\n\nmemory:\n  excellent: <25MB\n  good: <50MB\n  acceptable: <100MB\n  poor: >100MB\n```\n\n### Compliance Analysis (20 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Structure compliance | 8 | Valid JSON/Python, correct schema |\n| Documentation completeness | 6 | Purpose, parameters, return values documented |\n| Error handling | 4 | All exceptions caught, meaningful messages |\n| Best practices | 2 | Follows hook authoring guidelines |\n\n**Structure Requirements:**\n\n- JSON hooks: Valid JSON schema with required fields\n- Python hooks: Type hints, async/await patterns\n- Matcher patterns: Valid regex, appropriate scope\n\n### Reliability Analysis (15 points)\n\n| Aspect | Max Points | Requirements |\n|--------|------------|--------------|\n| Error handling robustness | 6 | Graceful handling of all error conditions |\n| Timeout management | 4 | Appropriate timeouts configured |\n| Idempotency | 3 | Safe to r"},{"path":"modules/sdk-hook-types.md","content":"# Python SDK Hook Types\n\nComplete reference for Claude Agent SDK hook types, callbacks,\nand matchers.\n\n## Hook Events\n\n### HookEvent\n\nSupported hook event types in the Python SDK.\n\n```python\nfrom typing import Literal\n\nHookEvent = Literal[\n    \"Setup\",             # Called when plugin installed/enabled\n    \"SessionStart\",      # Called when session begins\n    \"SessionEnd\",        # Called when session ends normally\n    \"UserPromptSubmit\",  # Called when user submits a prompt\n    \"PreToolUse\",        # Called before tool execution\n    \"PostToolUse\",       # Called after tool execution\n    \"PostToolUseFailure\",# Called when tool execution fails (2.1.20+)\n    \"PermissionRequest\", # Called when permission dialog would appear\n    \"Notification\",      # Called on system notification (2.1.20+)\n    \"SubagentStart\",     # Called when subagent spawns (2.1.20+)\n    \"SubagentStop\",      # Called when a subagent stops\n    \"Stop\",              # Called when stopping execution\n    \"TeammateIdle\",      # Called when teammate agent becomes idle (2.1.33+)\n    \"TaskCompleted\",     # Called when a task finishes execution (2.1.33+)\n    \"ConfigChange\",      # Called when config is modified (2.1.49+)\n    \"InstructionsLoaded\",# Called when instructions are loaded (2.1.33+)\n    \"PreCompact\",        # Called before message compaction\n    \"PostCompact\",       # Called after compaction (2.1.76+)\n    \"WorktreeCreate\",    # Called when git worktree is created (2.1.50+)\n    \"WorktreeRemove\",    # Called when git worktree is removed (2.1.50+)\n    \"StopFailure\",       # Called on error (2.1.78+)\n    \"TaskCreated\",       # Called when task created (2.1.84+)\n    \"CwdChanged\",        # Called on working dir change (2.1.83+)\n    \"FileChanged\",       # Called on file change (2.1.83+)\n    \"Elicitation\",       # MCP elicitation request (2.1.76+)\n    \"ElicitationResult\", # MCP elicitation response (2.1.76+)\n]\n```\n\n**SDK vs CLI availability**: Most events work in both JSON\nhooks (CLI) and Python SDK hooks. `PermissionRequest` is\nCLI-only. `Setup`, `SessionStart`, `SessionEnd`, and\n`Notification` are CLI-only (JSON hooks).\n`WorktreeCreate` and `WorktreeRemove` are command-only\nhooks (no Python SDK callback). They do not support\nmatchers.\n\n### Event Summary\n\n| Event | Trigger | Blockable | Matcher |\n|-------|---------|-----------|---------|\n| `Setup` | Plugin installed/enabled | No | No |\n| `SessionStart` | Session begins | No | No |\n| `SessionEnd` | Session ends normally | No | No |\n| `UserPromptSubmit` | User submits input | No | No |\n| `PreToolUse` | Before any tool runs | Yes | Tool name |\n| `PostToolUse` | After tool completes | No | Tool name |\n| `PostToolUseFailure` | Tool execution fails | No | Tool name |\n| `PermissionRequest` | Permission dialog | Yes | Tool name |\n| `SubagentStart` | Subagent spawns | No | No |\n| `SubagentStop` | Subagent completes | No | No |\n| `Stop` | Agent stops | No | No |\n| `TeammateIdle` | Teammate idle | No | No |\n| `TaskCompleted` | Task finishes | No |"},{"path":"skill-card.md","content":"## Description:\n\nEvaluate hook security, performance, and SDK compliance. Use for audits\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to audit Claude Code hooks for security, performance, SDK compliance, reliability, and maintainability before deployment.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Broad triggers may cause the skill to appear in general security or performance conversations where hook-specific audit guidance is not intended.\n\nMitigation: Invoke the skill deliberately for hook-related audits and verify that its guidance applies to the hook implementation under review.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-hooks-eval)\n- [ClawHub metadata homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract)\n- [Hook evaluation criteria](modules/evaluation-criteria.md)\n- [Python SDK hook types](modules/sdk-hook-types.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with code blocks, scoring rubrics, and configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes hook event references, security and performance evaluation criteria, quality gates, and audit workflow examples.]\n\n## Skill Version(s):\n\n1.9.19 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Evaluate hook security, performance, and SDK compliance. Use for audits Skill: hooks-eval Owner: athola Summary: Evaluate hook security, performance, and SDK compliance. Use for audits Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:03:12.768Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:27:41.806Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:27:36.109Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:44:30.079Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:08.983Z | u","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1315,"uniquenessScore":50,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T23:35:28.120Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T23:35:28.120Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T07:02:06.858Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}