HaiAI123

Curated Global AI Tools Directory

Industry update
Flat

Claude Code hooks in practice: blocking dangerous commands with exit code 2

10/10/2026 — 10/10, 05:16·1 sources (all)·1 reports (all)

Key takeaways

  • A hands-on post walks through three Claude Code hooks attached to events such as PreToolUse in .claude/settings.json, using exit code 2 to b…

Background & analysis

On October 10, 2026, a DEV Community post introduced three Claude Code hooks designed to block dangerous commands before they run. The author's premise is that Claude Code is very good at running commands, which is exactly the problem when it runs the wrong one. Hooks, in this setup, act as a safety net that runs before every action instead of relying on the model to remember a user's rules.

According to the post, the hooks are configured in .claude/settings.json, both per event (PreToolUse, PostToolUse, Notification, and others) and per tool (Bash, Write|Edit, and so on). A hook receives the event as JSON on stdin. If it exits with code 2, the action is blocked and the text written to stderr is sent back to the model.

One of the examples is .claude/hooks/block-dangerous-commands.sh, which is able to stop git push --force, git push origin +main, and git reset --hard. The author says that when Claude was made to attempt a force push during testing, the hook successfully blocked it. The post also cautions that regex-based hooks are only an early warning: readers have already found variants that bypass the first version of the rules.

AI-generated from 1 reports · updated 1 day ago

Latest turnThe author shares three Claude Code hooks configured per event in .claude/settings.json; a hook exits with code 2 to block an action and passes its stderr back to the model. One example blocks git push --force, git push origin +main and git reset --hard, and in a real session Claude reported the forced push as blocked by a PreToolUse hook. The post also notes that regex hooks are an early warning rather than a guarantee, after a reader found forced-push variants that slipped past the first patterns.

Related AI tools

24-hour heatHeat index 45 · peak 89 · 23h ago
24 hours agonow

Reports on this story headlines open the original

Yesterday
  1. The author shares three Claude Code hooks configured per event in .claude/settings.json; a hook exits with code 2 to block an action and passes its stderr back to the model. One example blocks git push --force, git push origin +main and git reset --hard, and in a real session Claude reported the forced push as blocked by a PreToolUse hook. The post also notes that regex hooks are an early warning rather than a guarantee, after a reader found forced-push variants that slipped past the first patterns.

    DEV Community · AIAI score 68

Other stories people are talking about

How is heat calculated?About the method

Heat counts how many independent sources covered a story in the last 48 hours: one source counts once no matter how many posts it published, decaying with a 24-hour half-life. What ranks first is what many people are talking about.

This page aggregates public feeds. Headlines and summaries are machine-organized and remain the property of the original authors; verify important facts at the source. If you believe a headline or summary infringes your rights, email the contact address in the footer with the page URL and basis of your claim, and we will remove or replace it after review.

Surge
Discussion rising fast
New
First report within 6 hours
Rising
Still gathering discussion

Back to AI industry updates →