bsamiee/Rasm/tree/main/plugins/function-hooks
function-hooks
A Claude Code plugin that refuses or rewrites tool calls according to policy and, when observation is enabled, records hook events as database rows per lineage.
About this mod
Part of the Rasm agent harness marketplace under plugins/. The plugin registers hook modules that intercept tool calls (tool.call) and can deny or rewrite them by policy. With observation enabled, hook events are persisted as database rows and findings are delivered per lineage. The hook implementation reads files, writes files, executes subprocesses, spawns subagents, and reads environment variables such as HOME.
Installation
Check the author's README for the marketplace and plugin name first. Commands may change as the repository evolves.
claude plugin marketplace add bsamiee/Rasm claude plugin install function-hooks
Original text / README
[RASM]
Rasm is a polyglot monorepo with macOS-first development and portable code and tooling for Linux and Windows.
[01]-[LAYOUT]
Rasm/
├── apps/ # One directory per app or group of related apps
├── libs/ # Packages, one directory per language
│ ├── dotnet/
│ ├── python/
│ └── typescript/
├── tests/ # Shared test support per language and suites outside libs/
├── eng/ # Repository engineering projects, one directory per language
│ └── dotnet/
├── infra/ # Pulumi program declaring repository resources
├── tools/
│ ├── ast-grep/ # Outlines, rules, and utilities per language
│ ├── interface/ # Desktop application interfaces, one directory per application
│ ├── nx/ # Nx plugin inferring a project from each project file
│ └── yak/ # Script installing a published Rhino plug-in's yak package
├── plugins/ # Agent harness marketplace, one directory per plugin
├── mise.toml # Tool binaries and process environment
├── global.json # .NET SDK versions
├── nx.json # Task graph
├── package.json # Catalog rows except tool plugins, root Nx targets
├── pnpm-workspace.yaml # TypeScript workspace globs and dependency catalog
├── pyproject.toml # Python dependency groups and tool tables
├── Directory.Packages.props # .NET central package versions
├── Directory.Build.props # .NET build defaults and project classification by tree position
├── Directory.Build.targets # .NET items, host package references, and policy targets
├── NuGet.config # NuGet source and package folder
├── Workspace.slnx # .NET solution
├── Xcode.xcconfig # Build settings every Xcode project inherits at project level
├── tsconfig.base.json # Compiler options every TypeScript project extends
├── tsconfig.json # Root TypeScript project over files outside every package
├── vitest.config.ts # Test and coverage options every project config imports
├── vite.config.ts # Bundling options every UXP build target runs from its project directory
├── biome.json # TypeScript and JSON formatting and lint
├── pmd.xml # Java lint rules
├── sgconfig.yml # ast-grep rule directories and language parsing
├── .editorconfig # Editor settings and .NET analyzer severity
├── .swift-format # Swift lint and format rules
├── .swiftlint.yml # Swift lint rules swift-format lacks
├── .lldbinit # LLDB MCP server start every Xcode scheme's Run loads
├── .yamllint.yaml, .yamlfmt # YAML lint and format
├── .github/ # Continuous integration and repository workflows
├── .claude/ # Agent harness knowledge and settings
├── .mcp.json # Agent harness MCP servers
├── .codex/ # Codex harness settings
├── CLAUDE.md # Agent standards, AGENTS.md is its symlink
└── README.md
[02]-[FLOW]
flowchart LR
subgraph toolchain ["Toolchain"]
direction TB
mise_tools["mise.toml [tools], global.json"] --> binaries["Tool binaries"]
mise_env["mise.toml [env]"] --> processes["Every process"]
xcode["xcode-select"] --> apple_tools["Xcode toolchain and macOS SDK"]
brew["Homebrew formula ghidra"] --> ghidra_tool["Ghidra install"]
end
subgraph dependencies ["Dependencies"]
direction TB
catalog_ts["pnpm-workspace.yaml catalog"] --> lock_ts["pnpm-lock.yaml"]
catalog_py["pyproject.toml groups"] --> lock_py["uv.lock, .venv/bin on PATH"]
catalog_net["Directory.Packages.props"] --> restore["rasm:restore"]
catalog_net --> eng_net["eng/dotnet"] --> upgrade["rasm:upgrade"]
packages["packages.toml rows"] --> upgrade
catalog_swift[".xcodeproj package requirements"] --> lock_swift["Package.resolved"]
end
subgraph taskgraph ["Task graph"]
direction TB
plugins["nx.json plugins"] --> projects["Project per project file: language and host tags, empty targets"]
target_defaults["nx.json targetDefaults by tag:language:*"] --> bodies["Target body per language"]
root_nx["package.json nx"] --> root_targets["Root targets rasm:*"]
end
subgraph commands ["Commands"]
direction TB
lint["nx run rasm:lint"] --> checkers["Every portable checker, one process each over the tree"]
format_tree["nx run rasm:format"] --> writers["Every portable writer, then dotnet format"]
check_all["nx run-many -t check"] --> project_check["Build, typecheck, or test per project"]
check_affected["nx affected -t check"] --> project_check
ci["ci.yml"] --> setup["setup action"] --> ci_steps["rasm:check, affected check per host runner"]
end
toolchain --> dependencies --> taskgraph --> commands
[03]-[TASKS]
- Targets call one tool, arguments on the command, configuration in the tool's own file
nx run rasm:checkruns lint and typecheck of root TypeScript files and every Python filenx run <project>:<target>runs one target of one projectnx run <project>:installinstalls a project's Release product into its hostnx run <project>:packbuilds a Rhino plug-in's yak package under.artifacts/rhino/with a manifestyak specderives from its buildnx run rasm:upgrademoves catalogs, Swift package locks, tool binaries, and application packages to their newest buildsnx run rasm:cleanclears .NET build outputs and all tool cache foldersnx run rasm:rewrite -- --filter='^<id>$' <path>applies one rule's fix across a pathnx run rasm:outline -- <path>lists a path's declarations,--itemsselects local, exported, imported, or all items,--viewthe depthnx run rasm:interfaceapplies eachtools/interface/<app>/apply.py,-- <app>one, and prints every outcome as one JSON document- Workspace plugin names each project's tags and empty targets by project file,
@nx/dotnetand@nx/vitestinfer theirs - Tools one host supplies join a project's target, root targets hold commands no project owns
- Inputs name the files a tool reads and its version as
runtime, outputs name the files it writes - Caches and outputs sit under root
.cache/and.artifacts/, each tool relocated through one setting every run reads, or its skill states why not
[04]-[OWNERS]
| [INDEX] | [CONCERN] | [OWNER] |
| :-----: | :----------------------------- | :------------------------------------------------------------------------------------ |
| [01] | Tool binary | mise.toml [tools] at latest, prereleases included |
| [02] | Process variable | mise.toml [env] |
| [03] | SDK version | global.json for .NET, xcode-select for Swift |
| [04] | Package version | pnpm-workspace.yaml catalog, pyproject.toml group, Directory.Packages.props row |
| [05] | .NET tool package | dotnet dnx <id> on the command |
| [06] | Task graph | nx.json, root package.json nx |
| [07] | Checker configuration | Tool's own file, pyproject.toml [tool.*] for every Python tool |
| [08] | Secret | Doppler, read through doppler run around the command |
| [09] | Resource or repository setting | Typed row of the program under infra/, applied by nx run rasm:infra:up |
| [10] | Tool with no consumer | Machine setup |
| [11] | Application package | packages.toml row beside the script installing it |
| [12] | Ghidra install | Homebrew formula ghidra, path named in mise.toml [env] |
| [13] | Xcode build setting | Xcode.xcconfig, per-product rows in the .xcodeproj target |
| [14] | Swift package version | .xcodeproj package requirement |
| [15] | Agent harness plugin | plugins/<name> |
- Package rows and
.editorconfiganalyzer rows hold a one-line purpose comment, every other configuration file holds section dividers alone - Tool rows name a release where
latestresolves a development build - Tool consumers are targets, MCP rows, skills,
.gitattributesfilters, and CLAUDE.md[CLI_TOOLING]rows - Facts sit once in their owning file, other files name the owner
- Mini configs, wrappers, and aliases beside an owner are corrected at the owner
[05]-[QUALITY]
- .NET: Roslyn analyzers at
latest-all, warnings as errors, code style enforced in build - Python:
ruff,ty, andmypyat zero findings - TypeScript:
biome checkat zero findings,tsc --buildunder strict options - Swift: warnings as errors, strict memory safety, Swift 7 upcoming features,
swift-format lint --strictandswiftlint lintat zero findings - Java:
google-java-format --aospandpmd checkat zero findings - Tree:
yamllint,yamlfmt -lint,actionlintwithshellcheckover workflow run steps, and ast-grep rule families - Writers:
dotnet format,ruff format, Biome, yamlfmt,google-java-format,swiftlint lint --fixthenswift-formatper Xcode project - Failing checks are fixed in the code or the rule, severity stays as configured
[06]-[STRUCTURE]
- Apps group by product under
apps/<product>/, with a<host>/folder per host application - Libraries group by language under
libs/<language>/, with host-bound packages under a<host>/folder - Build and task graph read a project's host from the
<host>/folder on its path - Every
libs/package is independently consumable, references siblings through declared dependencies, and points down an acyclic graph - Projects under a
rhinofolder compile againstRhinoCommon,RhinoHosttokengrasshopperaddsGrasshopper2 - Installed Rhino supplies host assemblies at runtime, build output holds none
- Project files define projects, never
project.json - Project files are
.csproj,package.jsonwithtsconfig.json,pyproject.toml, and.xcodeproj Workspace.slnxlists every project.csproj.xcodeprojbasenames name the Nx project, its scheme, and its product- Projects hold no
src/directory and no folder with one file, folders group by domain per language - Changes replace structure in place, one commit holds change and removal, new structure keeps its predecessor's name
- Packages, namespaces, routes, contracts, and directories carry no version suffix or
v1folder - Schema libraries apply the delta from owning types to the live database, with no migration file or history table
- Displays, documents, and defaults show imperial units, domain values hold SI quantities converted at the boundary
