#!/usr/bin/env bash # Scribe — PreToolUse rule arm for ACTIONS (#3476). # # The sibling of scribe_prior_art.sh. That hook is registered on Write|Edit and # asks "what is recorded about the file being written". This one asks "does a # standing rule speak to the command about to be run" — the question nothing # could ask before, and the reason every rule about which tool to reach for had # to live in the always-on preload instead. # # WHY A HOOK AND NOT AN INSTRUCTION. A reflex generates no query (note #3089): # you reach for `curl` confidently, with no moment of doubt, so a surface that # waits to be asked never fires. Here nothing is asked — the tool call IS the # query, and the reflex has to become a tool call before it can do anything. # # SILENT ON OUTAGE, deliberately, unlike the prior-art hook. A write is # occasional; a Bash call is not, and an "instance did not answer" line before # every command is the noise that gets a channel muted. scribe_prior_art.sh # still speaks for both when the instance is down. # # Env: # SCRIBE_URL / SCRIBE_TOKEN override for the settings.json dogfooding path. command -v jq >/dev/null 2>&1 || exit 0 command -v curl >/dev/null 2>&1 || exit 0 # PreToolUse delivers { session_id, cwd, tool_name, tool_input: {...}, ... } event=$(cat 2>/dev/null || true) tool_name=$(printf '%s' "$event" | jq -r '.tool_name // empty' 2>/dev/null) || exit 0 session_id=$(printf '%s' "$event" | jq -r '.session_id // empty' 2>/dev/null) || session_id="" event_cwd=$(printf '%s' "$event" | jq -r '.cwd // empty' 2>/dev/null) || event_cwd="" [ -n "$tool_name" ] || exit 0 # The action, as text. `.command` is Bash's field; the fallbacks let the matcher # in hooks.json widen to other tools without this script changing — which is the # whole reason the server side takes a name and a string rather than a schema. command_text=$(printf '%s' "$event" | jq -r ' .tool_input.command // .tool_input.url // .tool_input.prompt // empty' 2>/dev/null) || command_text="" [ -n "$command_text" ] || exit 0 # shellcheck source=plugin/hooks/scribe_defs.sh . "$(dirname "${BASH_SOURCE[0]}")/scribe_defs.sh" # scribe_config, not a hand-rolled pair of parameter expansions: it also treats # an UNEXPANDED `${...}` placeholder as unset, which would otherwise be sent as # a garbage Bearer token and 401 on every call (#2198's class). scribe_config || exit 0 # Bounded before encoding: a heredoc or a pasted script can be enormous, and # the verb and its target — the part a rule is about — sit at the front. The # server bounds it again; this keeps a huge payload off the wire in the first # place. `head -c`, never `cut -c`: cut truncates each LINE and caps nothing. command_text=$(printf '%s' "$command_text" | head -c 2000) # -sRr, never -rR: jq -R without -s reads LINE BY LINE, so a multi-line command # would encode per line and join with raw newlines — an invalid URL. cmd_enc=$(printf '%s' "$command_text" | jq -sRr '@uri' 2>/dev/null) || exit 0 tool_enc=$(printf '%s' "$tool_name" | jq -sRr '@uri' 2>/dev/null) || exit 0 repo_q="" lookup_dir=${event_cwd:-${CLAUDE_PROJECT_DIR:-$PWD}} repo_remote=$(git -C "$lookup_dir" remote get-url origin 2>/dev/null || true) if [ -n "$repo_remote" ]; then repo_enc=$(printf '%s' "$repo_remote" | jq -sRr '@uri' 2>/dev/null) || repo_enc="" [ -n "$repo_enc" ] && repo_q="&repo=${repo_enc}" fi # THE SHARED SESSION LEDGER, and the thing most worth getting right here. # # scribe_prior_art.sh keeps the rules it has already named in # /.rules.ids and passes them as exclude_rule_ids. This hook reads # and appends to that SAME file rather than keeping its own: two ledgers would # mean a rule named by one arm gets re-offered by the other, and the hint that # fires most often is exactly the one that must not repeat itself. # # The directory keeps the prior-art name on purpose — renaming it would orphan # every live session's state for a cosmetic gain. state_dir="${TMPDIR:-/tmp}/scribe-priorart" mkdir -p "$state_dir" 2>/dev/null || true rulefile="" rule_exclude_q="" if [ -n "$session_id" ]; then safe_sid=$(printf '%s' "$session_id" | tr -c 'A-Za-z0-9._-' '_') rulefile="$state_dir/${safe_sid}.rules.ids" if [ -f "$rulefile" ]; then rule_seen=$(tr '\n' ',' < "$rulefile" 2>/dev/null | sed 's/,$//') [ -n "$rule_seen" ] && rule_exclude_q="&exclude_rule_ids=${rule_seen}" fi fi # `|| exit 0` here, unlike the prior-art hook: there is no local arm whose # finding would be discarded, and an outage line before every command is worse # than silence. See the header. body=$(curl -fsS --max-time 5 \ -H "Authorization: Bearer ${token}" \ "${url%/}/api/plugin/tool-rules?tool=${tool_enc}&command=${cmd_enc}${repo_q}${rule_exclude_q}" 2>/dev/null) || exit 0 context=$(printf '%s' "$body" | jq -r '.context // empty' 2>/dev/null) || exit 0 [ -n "$context" ] || exit 0 # Remember what was named so it is not repeated this session. if [ -n "$rulefile" ]; then printf '%s' "$body" | jq -r '(.rule_ids // [])[]?' 2>/dev/null >> "$rulefile" || true fi jq -cn --arg ctx "$context" '{ hookSpecificOutput: { hookEventName: "PreToolUse", additionalContext: $ctx } }' 2>/dev/null || true exit 0