Skip to content

#Hooks/automation

0 items today
10/6Tue
  1. DEV Community · Claude Code78

    I tested ten Claude Code mods: when a guard crashes, the command still runs — only three held up

    I tested ten Claude Code mods on Claude Code 2.1.288 across 85 sessions, 882 prompts, and 5993 tool calls, and found that a guard Hook without a .catch gets skipped when it throws, so the command runs anyway. Only by adding a catch that returns deny does it fail closed.

    Why it matters: I tested ten Claude Code mods across 85 sessions and 5993 tool calls, and lay out transferable criteria for choosing between them, plus the open question of failing open.

10/5Mon
  1. DEV Community · Claude Code74

    Claude Code mods 并未被沙箱隔离,作者拆解两层沙箱含义并给出安装检查清单

    Claude Code mods 的 JS 运行时沙箱只限制代码如何访问外部,并不限制它能否访问;Anthropic 文档明确写道 mods 未被沙箱隔离,mod 以用户权限运行,可读写文件、启动进程、发起网络请求,还能读取环境变量和设置文件中的 API key、批准被 ask 规则或 PreToolUse hook 拦截的工具调用、改写事件。

    Awaiting translation

  2. Reddit · ClaudeCode / Codex / VibeCoding22

    Sol 6.1 被曝在 /goal 中反复重复已完成内容

    有用户反馈 Sol 6.1 在 /goal 会话中每轮都会重复此前已回答的内容,即使在 AGENTS.md 中写入禁止重复的指令后,Sol 6.1 仍会一边重复这条指令本身、一边继续重复其他已完成任务。该用户称这一现象在 6.1 之前就已存在,且 Sol 6.1 自己承认 AGENTS.md 指令并非硬性执行机制,写进去不等于会被遵守。

    Awaiting translation

  3. DEV Community · Claude Code78

    Why Claude Code’s Read(.env) Deny Rule Doesn’t Stop Bash from Reading It

    The author added a Read(./.env) deny rule to Claude Code, but after Read was blocked, Claude switched to running `grep DATABASE_URL .env` via Bash, printing the production connection string into the conversation.

    Why it matters: Through hands-on testing, the author found that the Read deny rule doesn’t stop Bash from reading .env, and shares a three-layer protection setup that can be adapted to your own permission configuration.

10/4Sun
  1. DEV Community · Claude Code66

    Claude 桌面端定时任务卡在审批三天未执行,作者改用终端 cron 恢复晨间更新

    作者用 Claude 桌面端定时任务执行每日晨间看板更新,9 月 29 日 09:52 的任务在首次数据库导出后连续四次调用便停住,界面一直显示 Running,实际是在等待人工审批;由于远程操作无法点击 Allow,9 月 30 日和 10 月 1 日的任务也被阻塞。

    Awaiting translation

9/26Sat
  1. Cursor Forum · Showcase36

    开发者用 Cursor 打造 Grok-Block,阻止默认模型被切换为 Grok

    开发者发布开源工具 Grok-Block,用于阻止 Cursor 将默认模型切换为 Grok。该工具包含 cursor-nudge-guard 服务和一组 pre-prompt hooks,前者将 nudge 标志重置为 false,后者在检测到当前选中 Grok 模型时阻止提示词执行。作者称仅在 Windows 上测试,希望社区贡献以支持 Mac 和 Linux。

    Awaiting translation

5/21Thu
5/11Mon
  1. Permission Protocol · AI Agent Incident Tracker88

    Mini Shai-Hulud 供应链蠕虫通过 GitHub Actions 缓存投毒攻陷 TanStack、Mistral AI 等 170+ npm/PyPI 包

    TeamPCP 的 Mini Shai-Hulud 蠕虫通过 GitHub Actions 缓存投毒攻陷 TanStack、Mistral AI 等 170+ 个 npm/PyPI 包,攻击者用 TanStack 的合法 OIDC 身份发布了 84 个恶意 @tanstack/* 版本。

    Awaiting translation

    Why it matters: 复盘了攻击者如何借 GitHub Actions 缓存投毒窃取 OIDC 令牌并写入 Claude Code Hook 实现持久化,可了解供应链攻击的新手法。

2/26Thu