
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
opencode-claude-code-hooks
Advanced tools
Run existing Claude Code PreToolUse and PostToolUse command guardrails in OpenCode.
Run existing Claude Code command guardrails in OpenCode without copying their commands or settings.
Add the package to the OpenCode plugin array.
{
"plugin": ["opencode-claude-code-hooks"]
}
OpenCode installs the package when it starts. The plugin reads these Claude files at every tool call.
~/.claude/settings.json<git-root>/.claude/settings.json<git-root>/.claude/settings.local.jsonPreToolUse and PostToolUse command hooksBash, Edit, and WriteupdatedInput replacementadditionalContextCLAUDE_PROJECT_DIR set to the Git project rootSettings are read at runtime, so editing a Claude hook does not require reinstalling this plugin.
Stop cannot preserve Claude timing with OpenCode's current stable plugin APIif handlers stay manualFor a dry-run report before installation, use the compatibility route in dsh-movein.
npx claude-to-opencode --hooks-only
npx claude-to-opencode --hooks-only --apply
The test suite runs real hook child processes and checks blocking, input replacement, project-root discovery, and post-tool feedback on Linux, macOS, and Windows.
npm ci
npm test
MIT
FAQs
Run existing Claude Code PreToolUse and PostToolUse command guardrails in OpenCode.
The npm package opencode-claude-code-hooks receives a total of 14 weekly downloads. As such, opencode-claude-code-hooks popularity was classified as not popular.
We found that opencode-claude-code-hooks demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.