Function hooks guide

Claude Code Function Hooks Explained

Claude Code function hooks subscribe to events. API calls show the methods a mod can use. Review both at the listed source commit.

Claude Code function hooks versus script hooks

Script hooks invoke shell commands in response to events. Function hooks register JS/TS modules inside Claude Code through hooks/hooks.json. That distinction matters when reading manifests and interpreting validation output. A Skills or MCP entry is not proof that function modules exist.

Read hooks, calls, and env reads together

The modern validator can list hooks (subscribed events), calls (mods API methods), and environment variable names read by a module. Preserve all modules, the CLI version, source SHA, and complete output. Environment names can be evidence; secret values should never be published.

A wildcard event subscription includes prompt and tool events. Matcher scope must remain visible. Merely observing a tool event can expose interception capability; the catalog does not assume that every call is modified.

Official review documentation ↗

Map capabilities without guessing

File reads map from $.fs.read; file writes from $.fs.write. Network capability includes $.http.fetch and remote model calls such as $.model.complete or $.model.fork. Environment reads map from $.env.get.

Prompt submission events, $.prompt.submit, or $.prompt.fill indicate prompt-changing capability. $.prompt.fill replaces the input draft without automatically submitting it. tool.call and tool.check indicate tool interception. The supported dictionary must match the inspected CLI version; an unknown API cannot be silently ignored.

Indirect channels keep uncertainty alive

$.process.run or spawn can start a program with capabilities that exceed the direct-call list. $.mcp.call needs a review of the actual server and tool. Cross-session messaging and custom APIs need their own evidence.

Tool parameters or results can affect files, networking, or environment use downstream. A successful complete validator inventory with no matching capability is labeled Not declared, even when indirect behavior is unreviewed. Missing or unsuccessful inventories remain Not verified; neither state rules out indirect capability. Sensitive settings, environment writes, model usage costs, and cross-session communication deserve additional notes.

Learn from official examples

Anthropic’s source includes agents-md, diff, sec-default, and telemetry examples. These illustrate function-mod patterns and are not counted as third-party entries in this directory. Read their actual source rather than inferring behavior from the name.

Official example source ↗Read installation and validation steps

Frequently asked questions

Does no direct network call mean no network access?

No. Processes, MCP, model calls, custom APIs, or modified downstream tool arguments can introduce network behavior. A complete successful validator inventory without a direct match shows Not declared; an incomplete or unsuccessful inventory shows Not verified. Neither excludes indirect network behavior.

What does Not declared mean?

The capability is not listed by claude plugin validate in the successful complete inventory for this source SHA. It is not a guarantee; dependencies and indirect behavior still need review.

What does Not found mean?

The capability was not found in complete static evidence for that source SHA and supported CLI. It is not an operating-system permission restriction or a security certification.