Skip to content

hooks/log-gam.sh reads .tool_result, so every failed command is logged as a success #57

Description

@e-q

hooks/log-gam.sh:28:

EXIT_CODE=$(echo "${INPUT}" | jq -r '.tool_result.exit_code // 0')

The PostToolUse hook payload field is tool_response, not tool_result. From the 2.1.238 binary:

hook_event_name:"PostToolUse",tool_name:e,tool_input:r,tool_response:n,tool_use_id:t,duration_ms:l

So .tool_result never resolves, the // 0 fallback always fires, and STATUS is always success. Every failed GAM mutation gets written to the audit log as having succeeded.

For a hook whose whole purpose is an audit trail, a status field that reads success unconditionally is worse than no status field — it looks like evidence and isn't.

Suggested fix

Change .tool_result to .tool_response — but check what the Bash tool_response actually carries first. I wasn't able to confirm from the docs or the binary that it exposes an exit code at all. If it doesn't, either key the status off stderr content or drop the field, rather than logging a value that can't be computed.

Worth a regression check either way: a hook that always reports success passes every eyeball test.


Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238). One of five separate findings from the same pass.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions