Repository navigation
fix(plugins): quote ${CLAUDE_PLUGIN_ROOT} in hook commands, prefix hookify examples - #81670
Open
ozdemirsarman wants to merge 2 commits into
Open
ozdemirsarman wants to merge 2 commits into
ozdemirsarman wants to merge 2 commits into
Conversation
Hook commands are executed through a shell, so an unquoted
${CLAUDE_PLUGIN_ROOT} word-splits when the plugin is installed under a path
containing a space (e.g. a macOS user directory like "/Users/Jane Doe/...").
For hookify this is fatal rather than cosmetic: python3 receives "/Users/Jane"
as its script argument and exits non-zero on every PreToolUse event, so the
plugin fails on every single tool call.
$ export CLAUDE_PLUGIN_ROOT="/tmp/plugin dir with spaces/hookify"
$ bash -c "python3 ${CLAUDE_PLUGIN_ROOT}/hooks/pretooluse.py"
python3: can't open file '/tmp/plugin': [Errno 2] No such file or directory
# after
$ bash -c "python3 \"${CLAUDE_PLUGIN_ROOT}/hooks/pretooluse.py\"" <<< '{"tool_name":"Bash"}'
{}
learning-output-style, explanatory-output-style and ralph-wiggum use the same
unquoted pattern and are fixed alongside. security-guidance already quotes the
variable; this brings the rest in line with it.
Fixes anthropics#78490
load_rules() globs for `.claude/hookify.*.local.md`, but the shipped examples are named `dangerous-rm.local.md`, `console-log-warning.local.md`, etc. Copied into a project as-is - which is what "see examples/" invites - none of them match the glob, so they silently never run. Nothing errors and nothing is logged; the rule just does not exist as far as the plugin is concerned. Renames the four examples to the `hookify.*.local.md` form and states the prefix requirement in the writing-rules skill. Fixes anthropics#79143
This was referenced Jul 27, 2026
3 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #78490
Fixes #79143
Two small, independent defects that both leave hookify installed-but-broken. One commit each.
1. Unquoted
${CLAUDE_PLUGIN_ROOT}breaks hooks on paths with spaces (#78490)hooks.jsoncommands are executed through a shell, so an unquoted${CLAUDE_PLUGIN_ROOT}word-splits when the plugin lives under a path containing aspace — e.g. a macOS user directory like
/Users/Jane Doe/....For hookify this is not cosmetic.
python3receives/Users/Janeas its scriptargument and exits non-zero on every
PreToolUseevent, so the plugin fails onevery single tool call.
Repro
learning-output-style,explanatory-output-styleandralph-wiggumuse the sameunquoted pattern and are fixed alongside.
security-guidancealready quotes thevariable — this brings the rest in line with it.
2. Example rules never load when copied (#79143)
load_rules()globs for.claude/hookify.*.local.md(
plugins/hookify/core/config_loader.py:210), but the shipped examples are nameddangerous-rm.local.md,console-log-warning.local.md, etc.Copied into a project as-is — which is what "see
examples/" invites — none of themmatch the glob, so they silently never run. Nothing errors and nothing is logged; as
far as the plugin is concerned the rule does not exist.
Repro (
.claude/in a project, with the dangerous-rm example, input{"tool_name":"Bash","tool_input":{"command":"rm -rf /"}})The four examples are renamed to the
hookify.*.local.mdform, and thewriting-rulesskill now states that the prefix is required.Testing
hooks.jsonfiles still parse as valid JSON.PreToolUsehook executed withCLAUDE_PLUGIN_ROOTset to a path containing aspace: fails before the change, returns
{}after..claude/under both the old and the new filename: onlythe prefixed name is picked up and evaluated.