#!/bin/sh # Claude Code PreToolUse hook (matcher: Bash): deny shell commands that read # files without going through notevi. A guardrail, not a jail — it catches the # common readers at command position, not every conceivable bypass. cmd=$(jq -r '.tool_input.command // empty') readers='cat|head|tail|less|more|sed|awk|cut|rg|grep|egrep|fgrep|find|fd|strings|xxd|hexdump|od|tac|nl' pattern='(^|[;&|(`]|\$\()[[:space:]]*('$readers')([[:space:]]|$)' if printf '%s' "$cmd" | grep -qE "$pattern"; then echo "blocked: read/search files only through notevi (run 'notevi -doc' for usage)" >&2 exit 2 fi vcs='jj[[:space:]]+(file[[:space:]]+show|diff)|git[[:space:]]+(show|diff|grep|cat-file|blame|log)' if printf '%s' "$cmd" | grep -qE "(^|[;&|(\`])[[:space:]]*($vcs)"; then echo "blocked: use 'notevi read -r REV FILE' / 'notevi grep -r REV' instead of raw jj/git reads" >&2 exit 2 fi exit 0