#!/usr/bin/env bash # Scribe plugin — UserPromptSubmit push channel (knowledge auto-inject, Path A). # # On each user prompt, asks the operator's Scribe instance for a TITLE-FIRST # awareness hint: the few notes that clear the per-user auto-inject gates # (high-confidence threshold, margin gate, session dedup, top-k). Titles + ids # only — never bodies; the agent calls get_note(id) to pull anything it judges # relevant. Most turns inject nothing. # # TWO ARMS SINCE #3852, on one request. Rules and preferences are retrieved # against the same prompt and returned in the same payload, ahead of the notes # menu. That arm exists because the two act arms are keyed on a file write or # a command, so a rule governing what to SAY — extract intent from loose # phrasing, raise a conflict before acting, end a finding with an offer — had # no moment to fire at. The operator's message is the only query that exists # before a response is composed. # # The two arms are gated separately server-side: turning the notes menu off # leaves rules arriving, because they are different claims with different # costs of being missed. # # Best-effort enrichment ONLY: unlike the SessionStart channel there is no # static floor here. If the instance is unconfigured/unreachable, or anything # fails, the hook stays SILENT and exits 0 — it must never block a prompt. # # Config (same as scribe_session_context.sh), exported to the hook by Claude Code # with the userConfig key UPPERCASED (see #2198 — reading the lowercase spelling # silently disables this hook, and silence is indistinguishable from "nothing # cleared the threshold"): # CLAUDE_PLUGIN_OPTION_API_ENDPOINT base URL, no trailing slash # CLAUDE_PLUGIN_OPTION_API_TOKEN fmcp_ API key (sensitive) # SCRIBE_URL / SCRIBE_TOKEN override for the settings.json dogfooding path. # # Session dedup: each surfaced note id is remembered in a per-session file so a # note is injected at most once per session. Passed back as exclude_ids. set -uo pipefail # shellcheck source=plugin/hooks/scribe_defs.sh . "$(dirname "${BASH_SOURCE[0]}")/scribe_defs.sh" command -v jq >/dev/null 2>&1 || exit 0 command -v curl >/dev/null 2>&1 || exit 0 # UserPromptSubmit delivers a JSON event on stdin: { prompt, session_id, cwd, ... } event=$(cat 2>/dev/null || true) prompt=$(printf '%s' "$event" | jq -r '.prompt // empty' 2>/dev/null) || prompt="" session_id=$(printf '%s' "$event" | jq -r '.session_id // empty' 2>/dev/null) || session_id="" event_cwd=$(printf '%s' "$event" | jq -r '.cwd // empty' 2>/dev/null) || event_cwd="" # Nothing to retrieve against. [ -n "$prompt" ] || exit 0 # Unconfigured install → silent (auto-inject is pure enrichment). scribe_config || exit 0 # Cap the query length — a giant prompt makes a giant URL for no extra signal. # `head -c`, not `cut -c1-2000`: cut is line-oriented and caps EACH LINE, so a # long multi-line prompt sailed past the budget entirely. Same defect as the # prior-art hook's code cap; this copy was missed when that one was fixed, and # scripts/check_plugin.py caught it. q=$(printf '%s' "$prompt" | head -c 2000) # `-sRr`, not `-rR`: jq -R reads LINE BY LINE, so a multi-line prompt encoded as # several lines joined by raw newlines and the request died. Single-line prompts # worked, which is why this looked healthy — the long, substantial prompts most # worth retrieving against were exactly the ones silently dropped. -s slurps. q_enc=$(printf '%s' "$q" | jq -sRr '@uri' 2>/dev/null) || exit 0 # Resolve the working repo's remote so the server can scope to the bound project. repo_dir=${event_cwd:-${CLAUDE_PROJECT_DIR:-$PWD}} repo=$(git -C "$repo_dir" remote get-url origin 2>/dev/null || true) repo_q="" if [ -n "$repo" ]; then enc=$(printf '%s' "$repo" | jq -sRr '@uri' 2>/dev/null) || enc="" [ -n "$enc" ] && repo_q="&repo=${enc}" fi # Per-session dedup: ids already injected this session are skipped. state_dir="${TMPDIR:-/tmp}/scribe-autoinject" mkdir -p "$state_dir" 2>/dev/null || true # RULES DEDUP IN A DIFFERENT DIRECTORY, and it has to be this one. The rule # ledger is SHARED by every arm that can name a rule — the two PreToolUse # hooks already keep it under scribe-priorart — so that one session keeps ONE # list and a rule named here is not re-announced before the next Bash call. # A private copy here would make each arm's "already seen" mean something # different, which is the state #3749/#3750 exist to keep coherent. The # directory name is the prior-art hook's history, not a scope claim. rule_state_dir="${TMPDIR:-/tmp}/scribe-priorart" mkdir -p "$rule_state_dir" 2>/dev/null || true idfile="" rulefile="" exclude_q="" if [ -n "$session_id" ]; then # session_id is an opaque token from Claude Code; keep only filename-safe chars. safe_sid=$(printf '%s' "$session_id" | tr -c 'A-Za-z0-9._-' '_') idfile="$state_dir/${safe_sid}.ids" rulefile="$rule_state_dir/${safe_sid}.rules.ids" if [ -f "$idfile" ]; then seen=$(tr '\n' ',' < "$idfile" 2>/dev/null | sed 's/,$//') [ -n "$seen" ] && exclude_q="&exclude_ids=${seen}" fi # AGED, not read flat: an exclusion that never expires means a rule surfaced # once in a long session is silenced for the rest of it, even as the session # stops holding what it was told. scribe_rules_live carries the reasoning. rule_seen=$(scribe_rules_live "$rulefile") [ -n "$rule_seen" ] && exclude_q="${exclude_q}&exclude_rule_ids=${rule_seen}" fi body=$(curl -fsS --max-time 5 \ -H "Authorization: Bearer ${token}" \ "${url%/}/api/plugin/retrieve?q=${q_enc}${repo_q}${exclude_q}" 2>/dev/null) || exit 0 [ -n "$body" ] || exit 0 context=$(printf '%s' "$body" | jq -r '.context // empty' 2>/dev/null) || exit 0 [ -n "$context" ] || exit 0 # Remember the surfaced ids so they aren't injected again this session. if [ -n "$idfile" ]; then printf '%s' "$body" | jq -r '.note_ids[]? // empty' 2>/dev/null >> "$idfile" || true fi # Rules onto the SHARED ledger, stamped so they can age out. Only FRESH ids # come back in rule_ids (#3752) — a rule rendered as a repeat is already on # the ledger, and re-appending it would keep pushing its stamp forward so it # never aged at all. if [ -n "$rulefile" ]; then printf '%s' "$body" | jq -r '.rule_ids[]? // empty' 2>/dev/null \ | scribe_rules_append "$rulefile" fi jq -n --arg c "$context" \ '{hookSpecificOutput: {hookEventName: "UserPromptSubmit", additionalContext: $c}}' exit 0