Tell HN: Claude 4.7 is ignoring stop hooks
TL;DR Highlight
Anthropic’s Claude Code reveals a security feature designed to ignore instructions within tool results inadvertently disables stop hooks, prompting workarounds and bug reports.
Who Should Read
Developers building automated workflows with Claude Code, or those controlling agent behavior with stop hooks/lifecycle hooks.
Core Mechanics
- Claude Code’s stop hook operates in two distinct ways: a ‘true control’ method using exit code 2 + stderr, and a method outputting JSON to stdout, which differ fundamentally.
- The stdout JSON method feeds into the model’s tool result context, an area Anthropic intentionally trained the model to disregard instructions within for prompt injection defense—meaning hook commands are designed to be ignored.
- Claude correctly ignores content in the tool result context as a security measure, preventing prompt injection attacks, but this also affects hook commands.
- Solutions include delivering hooks via user context instead of tool results, or adding explicit instructions to the system prompt stating specific hooks are trustworthy.
- Using exit code 2 provides deterministic control outside the agent’s inference layer, ensuring the model cannot ignore the signal; this is the preferred method for critical flow control.
- Claude Code documentation specifies that the `cat` command always exits with code 0, necessitating exit code 2 for forced interruption in stop hooks.
- A Claude Code team member (Thariq) requested users experiencing this issue to submit a ‘stop hook not firing’ report via the /feedback command, confirming the bug is acknowledged.
- Changes to the stop hook schema are suspected; one user observed Opus 4.7 ignoring hook responses while Claude 4.6 responded appropriately, suggesting a potential schema alteration.
Evidence
- "Claude Code team member Thariq confirmed awareness of the issue and requested bug reports via the /feedback command. A developer’s deep testing revealed Claude 4.6’s sensitivity to hooks contrasted with Opus 4.7’s complete disregard, potentially due to a schema change. Analysis suggests ignoring instructions in the tool result context is an intentional, trained behavior for prompt injection defense, though the side effect is undesirable. Some users reported overall reduced response quality in Claude 4.7 and considered migrating to Claude 5.5, with one criticizing the current hook/skill system as a temporary fix."
How to Apply
- "To reliably interrupt execution in Claude Code’s stop hook, use exit code 2 instead of the stdout JSON method. If implementing hooks as requests to the model, supplement with explicit instructions in the system prompt to trust those specific hook directives. Report malfunctioning stop hooks via the /feedback command with the message ‘stop hook not firing’. For automated tasks like test execution or file validation, execute commands directly within the hook script rather than requesting the model to perform them, ensuring deterministic execution."
Terminology
Related Papers
Show HN: adamsreview – better multi-agent PR reviews for Claude Code
Claude Code에서 최대 7개의 병렬 서브 에이전트가 각각 다른 관점으로 PR을 리뷰하고, 자동 수정까지 해주는 오픈소스 플러그인이다. 기존 /review나 CodeRabbit보다 실제 버그를 더 많이 잡는다고 주장하지만 커뮤니티에서는 복잡도와 실효성에 대한 회의론도 나왔다.
How Fast Does Claude, Acting as a User Space IP Stack, Respond to Pings?
Claude Code에게 IP 패킷을 직접 파싱하고 ICMP echo reply를 구성하도록 시켜서 실제로 ping에 응답하게 만든 실험으로, 'Markdown이 곧 코드이고 LLM이 프로세서'라는 아이디어를 네트워크 스택 수준까지 밀어붙인 재미있는 사례다.
Show HN: Git for AI Agents
AI 코딩 에이전트(Claude Code 등)가 수행한 모든 툴 호출을 자동으로 추적하고, 어떤 프롬프트가 어느 코드 줄을 작성했는지 blame까지 가능한 버전 관리 도구다.
Principles for agent-native CLIs
AI 에이전트가 CLI 도구를 더 잘 사용할 수 있도록 설계하는 원칙들을 정리한 글로, 에이전트가 CLI를 도구로 활용하는 빈도가 높아지면서 이 설계 방식이 실용적으로 중요해지고 있다.
Agent-harness-kit scaffolding for multi-agent workflows (MCP, provider-agnostic)
여러 AI 에이전트가 서로 역할을 나눠 협업할 수 있도록 조율하는 scaffolding 도구로, Vite처럼 설정 없이 빠르게 멀티 에이전트 파이프라인을 구성할 수 있다.
Show HN: Tilde.run – Agent sandbox with a transactional, versioned filesystem
AI 에이전트가 실제 프로덕션 데이터를 건드려도 롤백할 수 있는 격리된 샌드박스 환경을 제공하는 도구로, GitHub/S3/Google Drive를 하나의 버전 관리 파일시스템으로 묶어준다.