Sep 15, 2026

Enforce Claude Code Rules with Hooks from Claude Code Mastery

A 543-star guide-and-template repo whose hook scripts turn CLAUDE.md suggestions into deterministic blocks — plus the research case for one-task-one-chat.

#tutorial#claude-code#best-practices#security

Your CLAUDE.md says "don't touch .env". The model reads it, weighs it against the rest of the context, and sometimes edits the file anyway. The 543-star claude-code-mastery repo ships hook scripts that block instead of suggest — and backs the pattern with a guide covering global config, MCP servers, commands, and skills.

One disclosure up front: the README marks this V2 guide obsolete and points to newer versions — a V5 article, a Starter Kit, and a standalone MDD npm package with 21 modes. The repo's installable parts are still present (verified September 15, 2026: hooks/, skills/, templates/, commands/, and GUIDE.md), so read this as a working template set plus a V3 guide, not the author's latest word.

Why This Skill Matters

The core argument is enforcement over suggestion. A rule in CLAUDE.md is parsed by the LLM and weighed against other context — maybe followed. A PreToolUse hook always runs, and exit code 2 blocks the operation outright. The README quotes a community member whose secret-blocking hook fires a few times per week: "Claude does not respect CLAUDE.md rules very rigorously."

The second argument is single-purpose chats. The README's table of studies includes an arXiv paper reporting a 39% performance drop when topics are mixed across multi-turn conversations, Chroma's context-rot research on recall degrading as context grows, and a context-pollution writeup where 2% early misalignment led to a 40% failure rate. Its golden rule: one task, one chat.

Installation

The documented quick start copies hooks, settings, and skills into ~/.claude/ (prerequisites: Python 3.8+ and jq):

git clone https://github.com/TheDecipherist/claude-code-mastery.git
cd claude-code-mastery

mkdir -p ~/.claude/hooks
cp hooks/* ~/.claude/hooks/
chmod +x ~/.claude/hooks/*.sh

# Review and customize before overwriting your settings!
cp templates/settings.json ~/.claude/settings.json

mkdir -p ~/.claude/skills
cp -r skills/* ~/.claude/skills/

Real Workflow: Block Secrets and Dangerous Commands

  1. Know what you installed. The five hook scripts and their trigger points: block-secrets.py (PreToolUse, blocks .env access), block-dangerous-commands.sh (PreToolUse, blocks rm -rf and similar), end-of-turn.sh (Stop, quality gates), after-edit.sh (PostToolUse, runs formatters), and notify.sh (Notification, desktop alerts).
  2. Read the exit-code contract that makes hooks deterministic, straight from the README:
CodeMeaning
0Success, allow operation
1Error (shown to user only)
2Block operation, feed stderr to Claude
  1. Verify the install inside Claude Code: run /hooks to confirm hooks loaded and /skills for skills.
  2. Use what else ships in the repo: two skills (commit-messages for conventional commits, security-audit for vulnerability checks) and three commands (/new-project, /security-check, /pre-commit).

Tips

  • Merge, don't overwrite: if you already have a settings.json, the README says to merge the hooks section manually rather than replace the file.
  • The templates directory also carries a global CLAUDE.md and a project-level starter — the guide's part 1 covers using the global file as a security gatekeeper.
  • Start a fresh chat per task; the README's research table is the reason.
  • If you want the banner's standalone package instead, the README documents npm install -g @thedecipherist/mdd && mdd install.

When Not to Use This

The V2 label is the boundary: for current guidance the README itself redirects to the V5 article, the Starter Kit, and the MDD package. Treat the repo as a copy-paste source of working hook scripts and templates, and check the linked newer material before standardizing a team setup on it.


See the leaderboard for more skills.