hooks/log-gam.sh:28:
EXIT_CODE=$(echo "${INPUT}" | jq -r '.tool_result.exit_code // 0')
The PostToolUse hook payload field is tool_response, not tool_result. From the 2.1.238 binary:
hook_event_name:"PostToolUse",tool_name:e,tool_input:r,tool_response:n,tool_use_id:t,duration_ms:l
So .tool_result never resolves, the // 0 fallback always fires, and STATUS is always success. Every failed GAM mutation gets written to the audit log as having succeeded.
For a hook whose whole purpose is an audit trail, a status field that reads success unconditionally is worse than no status field — it looks like evidence and isn't.
Suggested fix
Change .tool_result to .tool_response — but check what the Bash tool_response actually carries first. I wasn't able to confirm from the docs or the binary that it exposes an exit code at all. If it doesn't, either key the status off stderr content or drop the field, rather than logging a value that can't be computed.
Worth a regression check either way: a hook that always reports success passes every eyeball test.
Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238). One of five separate findings from the same pass.
hooks/log-gam.sh:28:EXIT_CODE=$(echo "${INPUT}" | jq -r '.tool_result.exit_code // 0')The PostToolUse hook payload field is
tool_response, nottool_result. From the 2.1.238 binary:So
.tool_resultnever resolves, the// 0fallback always fires, andSTATUSis alwayssuccess. Every failed GAM mutation gets written to the audit log as having succeeded.For a hook whose whole purpose is an audit trail, a status field that reads
successunconditionally is worse than no status field — it looks like evidence and isn't.Suggested fix
Change
.tool_resultto.tool_response— but check what the Bashtool_responseactually carries first. I wasn't able to confirm from the docs or the binary that it exposes an exit code at all. If it doesn't, either key the status off stderr content or drop the field, rather than logging a value that can't be computed.Worth a regression check either way: a hook that always reports success passes every eyeball test.
Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238). One of five separate findings from the same pass.