{
  "_readme": "Recommended Claude Code hooks for multi-agent-pipeline, the same registrations `install` writes into ~/.claude/settings.json (install/claude.mjs configureSettings). Merge the `hooks` object into your ~/.claude/settings.json to make these deterministic PreToolUse gates real (exit 2 blocks the tool call). A PreToolUse matcher is a regex over the TOOL NAME, so each gate registers on a tool name and reads the command from its stdin payload. Three PreToolUse gates ship here: (1) pre-commit-check.sh on Bash, which acts only on a `git commit` and blocks a secret in the staged diff; (2) agent-guard.sh on Bash, on Edit|Write|NotebookEdit, and on WebFetch plus every multi-agent-toolkit tool (WebFetch|mcp__multi-agent-toolkit__.*). Always, it blocks AI/assistant attribution in a commit message and a force-push, delete or mirror push to a protected branch (main/master/develop), including one inside a subshell or a `bash -c` / `eval` line. With MULTI_AGENT_UNATTENDED=1 in the hook's environment it also applies the unattended policy: no push, PR or tracker write, no Keychain read, no fetch outside the host allowlist (curl, WebFetch, the toolkit's web tools, agent_run_steps and open_url), no package install, and no write into a protected path (features/unattended-security.md); (3) check-read-size.sh on Read|Bash, which inspects Read plus the shell commands that read a file whole (cat/head/tail/sed), returns immediately for everything else, and routes an oversized read to a cheap worker instead of the caller's own rung; it is inert until `prefs.global.bulkRead.mode` is set to observe or enforce. Failure behaviour: pre-commit-check.sh and check-read-size.sh fail open on an internal error. agent-guard.sh fails open when attended, so a guard bug cannot break a legitimate tool call, and fails closed under MULTI_AGENT_UNATTENDED=1, where nobody is there to notice a gap. None of the three executes the inspected command, and none needs run-specific arguments. The other deterministic gates (evidence, consensus, intent, learnings) take run-specific arguments and are phase-enforced by the pipeline instead. Three capture hooks ship alongside them and block nothing: (4) SessionEnd runs capture-flush.sh --if-stale, which writes a run's triage findings and durable learnings into the per-repo stores when the run ended before Phase 5, where those writes otherwise happen; the same hook runs note-session.sh, which records the mechanical shape of a session outside the pipeline (tools used, commands that failed, calls the user refused). (5) PreCompact runs capture-flush.sh without --if-stale: a compaction summarizes the conversation mid-phase, so it is the moment unflushed findings are at risk, and both writes are idempotent, so a finished run costs two no-op writes. The staleness test exists only so a session exit does not re-flush a run that already finished. (6) SessionStart runs capture-resume.sh, which prints at most two lines: an unfinished run and how to resume it, and a stale pipeline-observation queue. No capture hook calls a model or reads a payload - note-session.sh keeps a command's first word and an exit code, never an argument or any output - and all exit 0 on every path, because a hook that fails a session over bookkeeping costs more than the bookkeeping. multi-agent:setup offers to merge this block.",
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/pre-commit-check.sh\"",
            "timeout": 15,
            "statusMessage": "Scanning staged changes for secrets..."
          },
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/agent-guard.sh\"",
            "timeout": 10,
            "statusMessage": "Checking commit/push safety (attribution + force-push)..."
          }
        ]
      },
      {
        "matcher": "Edit|Write|NotebookEdit",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/agent-guard.sh\"",
            "timeout": 10,
            "statusMessage": "Checking the edit target..."
          }
        ]
      },
      {
        "matcher": "WebFetch|mcp__multi-agent-toolkit__.*",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/agent-guard.sh\"",
            "timeout": 10,
            "statusMessage": "Checking the fetch host..."
          }
        ]
      },
      {
        "matcher": "Read|Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/check-read-size.sh\"",
            "timeout": 10,
            "statusMessage": "Checking read size..."
          }
        ]
      }
    ],
    "PreCompact": [
      {
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/capture-flush.sh\" --quiet",
            "timeout": 20,
            "statusMessage": "Persisting what this run learned before compaction..."
          }
        ]
      }
    ],
    "SessionEnd": [
      {
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/capture-flush.sh\" --if-stale --quiet",
            "timeout": 20,
            "statusMessage": "Persisting what this run learned..."
          },
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/note-session.sh\"",
            "timeout": 20,
            "statusMessage": "Noting this session..."
          }
        ]
      }
    ],
    "SessionStart": [
      {
        "matcher": "startup|resume|clear|compact",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/scripts/capture-resume.sh\"",
            "timeout": 10,
            "statusMessage": "Checking for unfinished runs..."
          }
        ]
      }
    ]
  }
}
