Guardrails, session risk analysis, token savings, and PII detection in one plugin install. Credential cloaking lands next.
How it works
Run it once from any Claude Code session: terminal, desktop app, or IDE.
Installs at the user level and follows you across every project and session. No per-repo setup needed.
Missing a binary? The plugin installs it on demand, with no sudo. Re-check anytime with /hoop:doctor.
Hoop’s toolbelt for Claude Code: agent guardrails, credential cloaking, session risk analysis, token savings, and PII detection.
What’s in the box
Blocks catastrophic tool calls before they run: rm -rf ~, secret exfil, curl | sh, force-push. Hooks run before permissions, so it holds even in auto-accept sessions.
/hoop:risk-report scans your session transcripts for leaked PII and secrets, entirely on your machine. Reports are value-free: entity types and counts, never the values.
Command routing cuts token spend 60 to 90% on supported commands, measured honestly with julius savings. Errors and warnings are always kept verbatim.
Live PII masking of command and search outputs plus a prompt guard: 45 entity types across 12 countries, checksum validated. Scan any diff or file with /hoop:pii-scan.
Hands the agent a fake localhost DSN and swaps in the real credential on egress, so secrets never reach the model or your logs. Landing in the plugin next.
One command checks every binary, repairs duplicate hooks, and keeps the whole toolbelt healthy. Run it whenever something feels off.
Need to govern everything your AI agents are doing?
hoop enforces the same guardrails, credential handling, risk scoring, and data masking, but centrally. It covers every agent and every protocol, not just Claude Code sessions on one machine.