Lasso Claude-hooks — Productivity skill for Claude Code
Prompt injection defense hooks: scans files, web fetches, and command output in real-time.
How to install Lasso Claude-hooks
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open lasso-security/claude-hooks and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Lasso Claude-hooks does
A collection of security and utility hooks for [Claude Code](https://docs.anthropic.com/en/docs/claude-code). Hooks allow you to extend Claude Code's behavior by running custom scripts at key points during execution.
Alternatives in Productivity
- Linear - Ticket Management — You are tasked with managing Linear tickets, including creating tickets from thoughts documents, updating exis 10k ★
- Nosqli — NoSQL injection scanner (MongoDB/Mongoose/operator-injection DBs) — auth bypass via $ne/$gt operators, bracket 4.5k ★
- Tradingview MCP — Real-time crypto & stock screening, advanced technical indicators, Bollinger Bands intelligence, candlestick p 2.6k ★
README
Claude Hooks
A collection of security and utility hooks for [Claude Code](https://docs.anthropic.com/en/docs/claude-code). Hooks allow you to extend Claude Code's behavior by running custom scripts at key points during execution.
**Research Paper**: For detailed analysis of indirect prompt injection vulnerabilities in Claude Code, see: [The Hidden Backdoor in Claude Coding Assistant](https://www.lasso.security/blog/the-hidden-backdoor-in-claude-coding-assistant)
Available Hooks
🛡️ Prompt Injection Defender
Defense against **indirect prompt injection** attacks. Scans tool outputs (files, web pages, command results) for injection attempts and warns Claude about suspicious content via PostToolUse hooks.
Quick Start
Option 1: Interactive Installation (Recommended)
If you have this repo added as a Claude Code skill, simply tell Claude:
"install the prompt injection defender"
Claude will handle the entire installation process for you.
Option 2: Install Script
# Clone this repo, then run the installer pointing to your project
git clone https://github.com/lasso-security/claude-hooks.git
cd claude-hooks
./install.sh /path/to/your-project
What gets installed
The installer copies hook files to your project and configures Claude Code:
your-project/
└── .claude/
├── hooks/
│ └── prompt-injection-defender/
│ ├── post-tool-defender.py
│ └── patterns.yaml
└── settings.local.json ← hook configuration
📖 **For manual installation and more options, see [INSTALLATION.md](INSTALLATION.md)**
Understanding Prompt Injection
The Problem: Indirect Prompt Injection
When Claude Code reads files, fetches web pages, or runs commands, malicious instructions can be hidden in that content:
# README.md (looks innocent)
Welcome to our project!
## Installation
...
...
Related Skills
Pi Code
Claude Code experience for the pi coding agent: reads your .claude config (rules, commands, skills, hooks, out
Special Skills
Graph engineering and bounded-behavior plugins for coding agents: validated workflow graphs, loop limits, rece
Workflow Harness
A harness for running a team of Claude Code agents on a software project. Five roles, each with its own identi
Jared Init
Bootstrap Jared on a project — introspect the board, write docs/project-board.md, run one-time migration of le
Skillers
Learn from your workflow patterns and suggest skills, hooks, and agents. Analyze transcripts or get recommenda
Kitsune MCP Usage
Complete guide to kitsune MCP tools — search, extract, scrape, debug. Includes web research workflow, docs loo
Related Agents
Security Architecture
Boucle implements a defense-in-depth security model to protect against prompt injection attacks and maintain t
AI Ethics Reviewer
AI / ML ethics + responsible-AI specialist — bias, fairness, model selection, dataset provenance, automated-de
Tracker Id Auditor
PR-time backup — regex-scans diffs for tracker IDs (sprint tags, iteration markers, ticket numbers, ask number