hook-failure-audit
>
git clone --depth 1 https://github.com/hoangsonww/Claude-Code-Agent-Monitor /tmp/hook-failure-audit && cp -r /tmp/hook-failure-audit/plugins/ccam-quality/skills/hook-failure-audit ~/.claude/skills/hook-failure-auditSKILL.md
# Hook Failure Audit Assess whether the hook pipeline is delivering events reliably, using the event counts and stream the dashboard already has. This is about *delivery* health (missing/dropped events), not about why a model errored. ## Input The user provides: **$ARGUMENTS** This may be: - empty or "all" — run every check (default) - "balance" — PreToolUse/PostToolUse balance only - "terminators" — missing Stop/SubagentStop only - "freshness" — stale-ingestion check only ## Data Sources | Endpoint | Returns | |----------|---------| | `GET /api/analytics` | `event_types` (counts per type: PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd), `daily_events` (365d), `total_subagents`, `sessions_by_status` — fleet-wide delivery balance | | `GET /api/stats` | `total_sessions`, `total_agents`, `total_events`, `events_today` — expected terminator counts and recency | | `GET /api/events?session_id=X` | Per-session stream — confirm which sessions are missing a `PostToolUse`, `Stop`, or `SubagentStop` | ## Report Sections ### 1. PreToolUse / PostToolUse Balance From `GET /api/analytics` `event_types`: `gap = PreToolUse − PostToolUse`. A positive gap means tools whose completion hook never arrived. Report the gap as a count and as a percentage of `PreToolUse`. A healthy pipeline keeps this near 0%. ### 2. Missing Terminators Compare `Stop` count against completed sessions (`sessions_by_status`) and `SubagentStop` against `total_subagents`/`total_agents` (from `/api/stats`). A shortfall means sessions or subagents that ran but never emitted a closing hook — likely dropped delivery or a crashed handler. Report expected vs observed for each. ### 3. Stale Ingestion Check `events_today` from `/api/stats` and the tail of `daily_events` from analytics. If recent days are empty while sessions exist, ingestion has stalled. Report the most recent day with events and how long ago that was. ### 4. Localize For the sessions with the largest gaps or missing terminators, pull `GET /api/events?session_id=X` and confirm which specific hook types are absent. List the offending session IDs. ## Output - A check-by-check report with a PASS / WARN / FAIL marker each (✅ / ⚠️ / ❌) and the expected-vs-observed numbers. - Rates as percentages to 2 decimals. - Cite exact `event_type` counts and `session_id` values — never fabricate. - End with an overall verdict (e.g., "4/4 checks passed" or "hook delivery DEGRADED") and the single highest-impact remediation (e.g., reinstall hooks via the dashboard Settings, or restart the server with `npm start`). - Read-only: only report what the API returns. If `curl` cannot reach `http://localhost:4820`, tell the user to start the dashboard with `npm start` from the repo root.
Operate and maintain the local MCP server for this repository. Use for MCP tool updates, policy-guard changes, host configuration, and MCP runtime troubleshooting.
Run release-readiness checks for this repository. Use when validating docs, scripts, verification coverage, and operational safety before merge or release.
Understand this repository quickly before making changes. Use for architecture discovery, ownership mapping, command selection, and initial implementation planning.
Review backend route and hook logic for regressions, data integrity risks, and missing tests.
Review React UI changes for behavior regressions, state consistency, and UX breakage.
Review MCP server changes for tool safety, schema quality, and host integration correctness.
Debug production-like issues in this repository with disciplined evidence gathering. Use when fixing failing workflows, regressions, flaky behavior, or data inconsistencies across hooks, API, DB, websocket, and UI.
Operate and maintain the local MCP server for this project. Use when creating MCP host config, troubleshooting tool connectivity, modifying tool domains, or adjusting safety policy flags.