02 Oct 2026 · 8 min read
A Vibe Coding Stack for a DevOps Engineer
Claude Code, a DevOps skill pack, a scanning layer, an agent dashboard, and three scoped MCP servers for errors, clusters and tickets.
devops claude-code mcp-serversBy Kelvin · 28 September 2026 · Updated 28 Sep 2026 · 8 min read


Your agent just ran npm test in a project that uses pnpm. It formatted a file with the wrong linter config. It ran rm -rf build when you only wanted build/tmp cleared. None of this is a hallucination in the usual sense — the agent read your instructions correctly, it just doesn't share the muscle memory you built up over years of working in this specific repository. You can fix each mistake by correcting the agent in chat, but that fix lives only in that conversation. The next session, or the next teammate who runs the same agent, hits the same wall.
Hooks exist to close that gap without rewriting your prompt every time. A hook is your own script, wired to a specific moment in the agent's lifecycle, that runs automatically — no matter who is driving the agent or what they typed. It's the difference between asking an assistant nicely and installing a guardrail.
Strip away the vendor-specific JSON and every hook implementation has the same three parts:
The reporting-back part is what separates a hook from a plain shell alias. A hook can inspect what the agent is about to do — the exact command, the file path, the diff — and then allow it, block it, or hand back a message the agent has to read before continuing. That loop (agent proposes an action → your script inspects it → your script decides) is what turns "please don't do X" from a suggestion into an enforced rule.
Two apps in this directory document hook support in enough depth to compare directly: Claude Code and Cursor. Both converged on nearly the same shape independently, which is a reasonable signal that this is close to the "right" design for the problem, not just one vendor's preference.
Anthropic's agentic coding tool for the terminal, IDE, desktop and web
🔥 Claude Pro billed annually: $17/month instead of $20Claude Code hooks live in settings.json, at the user level (~/.claude/settings.json), the project level (.claude/settings.json, meant to be committed and shared), a project-local gitignored file, or bundled inside a plugin. The structure nests an event name, a matcher, and a list of handlers:
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "${CLAUDE_PROJECT_DIR}/.claude/hooks/block-rm.sh"
}
]
}
]
}
}
The event catalog covers the full turn: SessionStart and SessionEnd per session; UserPromptSubmit, Stop and StopFailure per turn; PreToolUse, PostToolUse, PostToolUseFailure and PermissionRequest per tool call; plus narrower events like FileChanged, SubagentStart, SubagentStop, TaskCreated and TaskCompleted.
A command hook receives a JSON object on stdin describing the moment — for PreToolUse that includes tool_name, tool_input (the actual command or file edit being proposed), the session id, and the current working directory. The hook talks back through its exit code: 0 means proceed, and any JSON printed to stdout is read as a structured decision; 2 is a hard block — for PreToolUse it stops the tool call outright, for UserPromptSubmit it rejects the prompt, for Stop it keeps the agent going instead of letting it end the turn. A hook that wants to actively deny an action rather than merely inspect it prints something like:
{
"hookSpecificOutput": {
"hookEventName": "PreToolUse",
"permissionDecision": "deny",
"permissionDecisionReason": "Destructive command blocked by hook"
}
}
Handlers aren't limited to shell commands, either — the same configuration shape supports HTTP endpoints, MCP tool calls, prompts sent back to Claude for a judgment call, and even spawning a subagent to evaluate something more involved than a regex can handle.
The AI-first code editor with agents, background agents and fast autocomplete
🔥 Save 20% with annual billingCursor's implementation lives in hooks.json rather than its general settings file, at the enterprise, team, project (.cursor/hooks.json) or user (~/.cursor/hooks.json) level, in that priority order. The shape is close enough to Claude Code's that switching mental models between the two takes minutes, not hours:
{
"version": 1,
"hooks": {
"beforeShellExecution": [
{ "command": "./hooks/audit.sh" }
],
"afterFileEdit": [
{ "command": "./hooks/format.sh" }
]
}
}
Where Claude Code has four or five tool-call events, Cursor names more than a dozen: lifecycle events (sessionStart, sessionEnd), tool-use events (preToolUse, postToolUse, postToolUseFailure), subagent events (subagentStart, subagentStop), shell- and file-specific events (beforeShellExecution, afterShellExecution, beforeReadFile, afterFileEdit), MCP-specific events (beforeMCPExecution, afterMCPExecution), and a few others (beforeSubmitPrompt, preCompact, stop). Each hook definition can set a matcher regex, a timeout, and a failClosed flag that decides whether a crashing hook script should block the action it was supposed to review (the default is to fail open, i.e. let the action through). Cursor also supports a "prompt" type alongside "command", which routes the decision through an LLM judgment call instead of a script.
The use cases cluster into a handful of recurring patterns:
afterFileEdit or PostToolUse hook that runs prettier or black on whatever file the agent just touched, so style stays consistent regardless of which model wrote the code.PreToolUse/beforeShellExecution hook that greps the proposed shell command for rm -rf, git push --force, or DROP TABLE and denies it before it runs.package.json's packageManager field and rejects an npm install in a pnpm repo instead of relying on the agent to notice a lockfile.Stop hook that fires a system notification when a long agent turn finishes, so you don't have to keep a terminal tab in view.None of these require the agent's cooperation. That's the point: a prompt instruction is a request the model might forget under context pressure; a hook runs every time, deterministically, in your own code.

Beyond Claude Code and Cursor, hooks show up as a documented capability on several other apps in the ecosystem overview, including Cline, Kiro, Devin Desktop (formerly Windsurf), Factory, Google Antigravity and Gemini CLI. Configuration file names and event lists differ per app, so treat any specific event name or JSON field in this piece as Claude Code- or Cursor-specific unless you've checked that app's own documentation — the concept transfers, the exact syntax does not.
| App | Hooks documented | Config lives in |
|---|---|---|
| Claude Code | Yes | settings.json (user, project, or plugin-scoped) |
| Cursor | Yes | hooks.json (enterprise, team, project, or user) |
| Cline | Yes | Check Cline's own docs for current file/event names |
| Kiro | Yes | Check Kiro's own docs for current file/event names |
| Devin Desktop (Windsurf) | Yes | Check Devin's own docs for current file/event names |
| Factory | Yes | Check Factory's own docs for current file/event names |
A hook that can block a destructive command can also become the destructive thing itself, and this is where hooks stop being a pure convenience and start being a real part of your threat model. A command hook runs with your own shell permissions, not some sandboxed subset — if you paste in a hook script from a blog post or a shared plugin without reading it, you've granted it the same access to your filesystem, credentials and network that you have. Project-level hook configuration files are usually meant to be committed and shared with a team, which means anyone who can open a pull request against your repository can potentially add or modify a hook that will silently execute on every teammate's machine the next time they run the agent there — the same review discipline you'd apply to a new CI step or a postinstall script belongs here too.
Two settings are worth knowing before you turn hooks on for a shared project. Claude Code's plugin-distributed hooks run automatically as soon as a plugin is enabled, with no separate opt-in step, so only install plugins from sources you trust. Cursor's failClosed flag defaults to false, meaning a hook script that errors out fails open and lets the underlying action through — flip it to true for anything security-critical, like the destructive-command blocker, where a silent script crash should not silently remove your safety net.

You don't need a hooks framework on day one. A reasonable on-ramp:
PostToolUse/afterFileEdit hook that runs your formatter after every edit — low risk, immediately visible payoff.PreToolUse/beforeShellExecution hook that blocks the one destructive command pattern that has actually bitten you or a teammate before (force-pushes, rm -rf, dropping a table).package.json.A hook is not a smarter prompt — it's code that runs whether or not the agent remembers to ask. If you've corrected the same agent mistake more than twice, that's the signal it's worth turning into a hook instead of a reminder. Start with formatting and one destructive-command guard, treat any hook script — yours or a teammate's — with the same scrutiny as a CI step that runs on every push, and check the deals page and glossary if you're still deciding which app's ecosystem to build this habit in.
Anthropic's agentic coding tool for the terminal, IDE, desktop and web
🔥 Claude Pro billed annually: $17/month instead of $20The AI-first code editor with agents, background agents and fast autocomplete
🔥 Save 20% with annual billing
02 Oct 2026 · 8 min read
Claude Code, a DevOps skill pack, a scanning layer, an agent dashboard, and three scoped MCP servers for errors, clusters and tickets.
devops claude-code mcp-servers
01 Oct 2026 · 8 min read
A verified walkthrough of AGENTS.md rules, SKILL.md packs, subagents, MCP servers, hooks and plugins in Google Antigravity.
google-antigravity setup-guide mcp
30 Sep 2026 · 8 min read
A practical walkthrough of Copilot instructions, agent mode, MCP servers and the CLI, with verified commands from the docs.
github-copilot agent-mode mcpBrowse 296 apps, skills, subagents and MCP servers, mapped to the apps they work with.
See the ecosystem map