Compare / Claude Code hooks libraries and guardrail tools (2026)

Claude Code hooks libraries and guardrail tools compared (2026)

Published 2026-10-11 · Last verified 2026-10-11 · 859 words · figures link to their sources; numbers change daily.

Hooks are the part of Claude Code that runs outside the model: a script that fires before a tool call, after it, or when Claude tries to stop, and can allow, block or inject context (hooks docs). Because they are deterministic, they are where guardrails belong — and in 2026 there are a lot of places to get them. This page compares the ones you can verify, with star counts and last-commit dates taken from the GitHub API on the date in the "last verified" line above. Numbers move; click through before quoting them.

Two honesty notes up front. HookCrate's own free hooks are the newest and smallest entry here, with no GitHub history yet. And several projects below are better than HookCrate at what they do — a 22-plugin marketplace is a bigger safety net than two hooks, and a 55,000-star curated list will always surface more.

The comparison

ProjectWhat it isStarsLast commitLicenceSource
awesome-claude-codeCurated list of Claude Code resources; no dedicated hooks section, but 36 entries mention hooks, concentrated under Security and Observability55,4162026-10-11not assertedAPI, README
context-modeHook-driven context-window optimisation ("sandboxes tool output") — the largest hook-based project by stars26,4942026-10-11see repoAPI
claude-code-hooks-masteryEducational: every hook event with a working uv single-file script, error-code and flow-control walkthroughs3,9382026-03-04see repoAPI
claude-code-prompt-improverA single UserPromptSubmit hook that rewrites vague prompts1,9452026-10-01MITAPI
hooks-multi-agent-observabilityDashboard fed by hook events across agents1,5452026-02-08not assertedAPI
abideGuardrail: checks every edit against your AGENTS.md rules and makes the agent fix violations; Claude Code, Codex, OpenCode5772026-10-10MITAPI
hcomHook-based messaging between agents across terminals5662026-10-10see reposame search
claude-code-hooks"22-plugin installable marketplace: safety, cost, observability"; README badge claims 1,949 tests5382026-10-04MITAPI, README
awesome-claude-code-modsScanner-generated catalogue of mods (JS/TS function hooks for Claude Code 2.1.287+): "3088 mods · Last scanned 2026-10-10", with per-mod access badges4792026-10-11CC0-1.0API, README
gryphYAML policy security layer for coding agents, hooks into Claude Code1742026-10-05Apache-2.0API
HookCrate free hooksTwo MIT hooks — credential-guard (PreToolUse) and evidence-gate (Stop + PostToolUse) — packaged as a plugin marketplace0 (repo not yet public)2026-10-11MITthis site

Repos that mention hooks in the awesome list but had under 100 stars when checked (agent-guard 31, parry-guard 45) are left out of the table, not because they are worse, but because the cut-off was set before looking.

Reading the table

If you want breadth, start with the lists. awesome-claude-code is the biggest, but hooks are scattered through it — search the README for "hook". awesome-claude-code-mods is narrower and more useful for one thing: it is generated by scanning GitHub and records what each mod can read, write, run or send over the network, which is exactly the question you have before installing someone's hook.

If you want install-and-forget safety, the karanb192 marketplace is the most complete free option. Twenty-two hooks, each a plugin with tests and a README, grouped by event, installed with /plugin marketplace add. HookCrate's two free hooks overlap with its "protecting secrets" category; it covers far more ground (dangerous-command blocking, cost, notifications).

If you want to understand hooks before adopting any of this, disler's hooks-mastery is still the clearest walkthrough of every event and exit code, though its last commit is older than the others and newer events may be missing.

Guardrails that are not strictly hook libraries — abide, gryph — are worth knowing. abide checks edits against your written rules and reports a measured violation rate; gryph enforces YAML policy. Both are broader than a hook and need more setup.

Where HookCrate fits

HookCrate's free tier is deliberately small: two hooks that each do one thing with a precise, actionable block message, tested against stdin payloads, zero dependencies beyond bun. credential-guard stops a literal API key going into curl/wget/HTTP tool calls while letting $VAR through; evidence-gate refuses "done" until every checklist item has an evidence: line. If you want those two behaviours and nothing else, they are a two-command install. If you want a toolbox, pick one of the larger collections above and add these only if they fill a gap. The guides on blocking credential leaks and the Stop-hook evidence pattern explain the implementations in full, so you can also just write your own.

FAQ

Are hooks safer than asking Claude to follow rules in CLAUDE.md?

Yes, for anything you need enforced rather than encouraged. A CLAUDE.md rule is a request the model may weigh against others; a hook is code that runs every time and can return exit 2 to block. The hooks docs define that contract.

Can I install hooks from several of these sources at once?

Yes. Hooks from different plugins and from your own settings.json all run for a matching event; if any of them blocks, the action is blocked. Keep each hook fast — a Stop hook that calls a model or the network slows every turn.

How were the star counts gathered?

From the public GitHub REST API (/repos/{owner}/{repo} and /search/repositories) on the date in the "last verified" line, with no authentication. Each row links the exact endpoint. Counts change daily; this page is a snapshot, not a leaderboard.

Related guides

Related packs

  • Credential Guard — Blocks shell and HTTP tool calls that would ship a literal API key or token to an outbound command.
  • Evidence Gate — Refuses to let a task be marked complete while checklist criteria are unchecked or lack an evidence line.