Skip to content

Judge the Installer's Hook Ownership by File Name, Not Substring #1905

Description

@ptr727

Summary

host-setup/agent-safety/claude/install.py decides which hook registrations belong to the kit with a substring test on each hook's command: GUARD_STEM (gh-write-guard) for PreToolUse and SWEEP_STEM (stray-process-sweep) for SessionEnd. It does this both when re-registering and in registration_problems.

Failure

A maintainer's own hook whose command merely contains one of those stems, such as a wrapper named my-gh-write-guard-audit.sh, is treated as the kit's. Every install removes it without a word, and --report counts it as a registration of the kit's hook.

Fix direction

Judge ownership by the file name the command runs, the way #1900's kit_prefix judges the CLAUDE_CODE_SHELL_PREFIX value. runs_hook already compares paths, and that comparison could decide ownership too.

This was found by a local review of #1900. It predates that branch and is not part of its diff.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions