Claude Code hooks in practice: blocking dangerous commands with exit code 2
10/10/2026 — 10/10, 05:16·1 sources (all)·1 reports (all)
Key takeaways
- A hands-on post walks through three Claude Code hooks attached to events such as PreToolUse in .claude/settings.json, using exit code 2 to b…
Background & analysis
On October 10, 2026, a DEV Community post introduced three Claude Code hooks designed to block dangerous commands before they run. The author's premise is that Claude Code is very good at running commands, which is exactly the problem when it runs the wrong one. Hooks, in this setup, act as a safety net that runs before every action instead of relying on the model to remember a user's rules.
According to the post, the hooks are configured in .claude/settings.json, both per event (PreToolUse, PostToolUse, Notification, and others) and per tool (Bash, Write|Edit, and so on). A hook receives the event as JSON on stdin. If it exits with code 2, the action is blocked and the text written to stderr is sent back to the model.
One of the examples is .claude/hooks/block-dangerous-commands.sh, which is able to stop git push --force, git push origin +main, and git reset --hard. The author says that when Claude was made to attempt a force push during testing, the hook successfully blocked it. The post also cautions that regex-based hooks are only an early warning: readers have already found variants that bypass the first version of the rules.
AI-generated from 1 reports · updated 1 day ago
Latest turnThe author shares three Claude Code hooks configured per event in .claude/settings.json; a hook exits with code 2 to block an action and passes its stderr back to the model. One example blocks git push --force, git push origin +main and git reset --hard, and in a real session Claude reported the forced push as blocked by a PreToolUse hook. The post also notes that regex hooks are an early warning rather than a guarantee, after a reader found forced-push variants that slipped past the first patterns.
Related AI tools
- Heat index
- 45
- All sources
- 1
- All reports
- 1
- First seen
- 1 day ago
Reports on this story headlines open the original
The author shares three Claude Code hooks configured per event in .claude/settings.json; a hook exits with code 2 to block an action and passes its stderr back to the model. One example blocks git push --force, git push origin +main and git reset --hard, and in a real session Claude reported the forced push as blocked by a PreToolUse hook. The post also notes that regex hooks are an early warning rather than a guarantee, after a reader found forced-push variants that slipped past the first patterns.
DEV Community · AIAI score 68
Other stories people are talking about
- Heat index 96NewClaude Code orchestration: Sub-Agents, Hooks, and Skills1 sources
- Heat index 77Claude Code to add AGENTS.md support1 sources
- Heat index 76Tutorial: a first testing task for Claude Code1 sources
- Heat index 25Guide compares Codex and Claude Code terminal coding CLIs1 sources
- Heat index 45What Claude Code Skills are: building an agent extension from scratch1 sources
How is heat calculated?About the methodHide
Heat counts how many independent sources covered a story in the last 48 hours: one source counts once no matter how many posts it published, decaying with a 24-hour half-life. What ranks first is what many people are talking about.
This page aggregates public feeds. Headlines and summaries are machine-organized and remain the property of the original authors; verify important facts at the source. If you believe a headline or summary infringes your rights, email the contact address in the footer with the page URL and basis of your claim, and we will remove or replace it after review.
- Surge
- Discussion rising fast
- New
- First report within 6 hours
- Rising
- Still gathering discussion
