feat: add shared agent hooks and Claude Code permissions to the template - #37
Merged
Merged
Conversation
mjun0812
force-pushed
the
feat/agent-hooks-and-rules
branch
from
September 7, 2026 23:11
97f4f43 to
f5b0773
Compare
- Add .agents/hooks/format-python.sh, a PostToolUse hook that runs ruff format and ruff check --fix on the Python file an agent just edited - Wire the hook for Claude Code (.claude/settings.json) and Codex (.codex/hooks.json) using the same event schema - Pre-approve uv run --frozen, uv sync, uv lock and read-only git commands for Claude Code and deny reading .env files - Ignore .claude/settings.local.json in generated projects - Record the TYPE_CHECKING import rule, the parallel pytest note, the --no-verify ban, the run command and the agent hooks in AGENTS.md
mjun0812
force-pushed
the
feat/agent-hooks-and-rules
branch
from
September 7, 2026 23:12
f5b0773 to
f2b8190
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview and Background
Generated projects now ship a shared agent hook that formats and lints every Python file right after Claude Code or Codex edits it, a committed Claude Code settings file with pre-approved development commands, and an
AGENTS.mdthat records the project-specific rules established over the last template changes. Previously the template only providedAGENTS.md/CLAUDE.mdtext: agents had to be prompted for everyuv runinvocation, formatting only happened at commit time through prek, and rules such as theTYPE_CHECKINGimport pattern or the coverage threshold lived only in CI failures.Related Issues
None
Implementation Approach
.agents/hooks/format-python.sh, serves both tools because Claude Code and Codex use the same hook event schema (PostToolUse,matcher, command hooks, exit code 2 = feedback to the agent). The script reads the hook JSON from stdin and collects Python paths fromtool_input.file_path(Claude CodeEdit/Write) or from the*** Add File/*** Update Filelines oftool_input.command(Codexapply_patch, which also matchesEdit|Write). It runsruff formatandruff check --fix; diagnostics that cannot be auto-fixed go to stderr with exit code 2 so the agent fixes them itself. Non-Python edits exit 0 immediately. The script changes to the hook'scwd(falling back to the git root) so relative paths resolve wherever the agent was started..claude/settings.jsonis the committed, team-wide Claude Code configuration: it wires the hook and pre-approvesuv run --frozen,uv sync,uv lockand read-only git commands, while denyingReadof.envfiles..claude/settings.local.json(personal overrides) is added to the generated.gitignore..codex/hooks.jsonwires the same hook for Codex with the documentedhooks.jsonshape.AGENTS.mdgains the rules that are otherwise only enforced by tooling: never edituv.lockby hand, theTYPE_CHECKINGimport pattern required by Ruff'sTCrules, that pytest runs in parallel (-n 0for--pdb) and CI fails below 80% branch coverage, nevergit commit --no-verify, the run command, and a note that the agent hook already formats edits.Changes
template/.agents/hooks/format-python.sh: new hook script (shellcheck and shfmt clean).template/.claude/settings.json: permissions andPostToolUsehook.template/.codex/hooks.json:PostToolUsehook.template/.gitignore: ignore.claude/settings.local.json.template/AGENTS.md: rules listed above.README.md: describe the agent configuration files.Impact
.pyfile, the file is formatted immediately and remaining lint errors are fed back to the agent. Users see fewer permission prompts in Claude Code for the listed commands.permissions.allowfrom a project only after the workspace has been trusted once interactively; hooks run regardless. Codex loads project hooks only for trusted projects.jq,uv, andgiton PATH; all are present in the dev container and required by the existing workflow.Validation Results
Direct script tests in a generated Python 3.14 project (stdin JSON crafted from the documented shapes):
End-to-end with Claude Code in the same project:
Codex end-to-end could not be completed:
codex execloaded the session hooks but the account hit its usage limit before the edit. The Codex path is covered by theapply_patch-shaped direct test above and by the documentedtool_input.commandfield.