How it gets overlooked
Your task stayed the same, but the agent configuration changed. A hook or instruction file can influence what happens around ordinary work. That makes the configuration itself something worth watching.
Consider a workspace with a hook command in the agent settings. The visible task may never mention that hook. Separately, changes to instruction and settings files after their first inventory can alter the environment the agent is following.
What ClawMetry detects
ClawMetry reports supported agent hook commands it did not install, and relevant configuration changes after a baseline exists. The finding identifies the configuration source so an operator can inspect the change in context.
The difference that changes the finding
Triggering example
Foreign hook command
Critical finding
Quiet comparison
ClawMetry hook only
No finding for this detector.
In the checked example, a foreign hook command in the settings file raises a critical finding. A file containing only the recognized ClawMetry hook stays quiet. This distinction keeps the observer’s own supported hook from becoming a warning by itself.
Inspect the detector result
{
"kind": "agent_config_tamper",
"severity": "critical",
"evidence": {
"file": ".claude/settings.local.json",
"commands": [
"node review-hook.js"
],
"count": 1,
"gitignored_by_convention": true,
"observed": "agent_config",
"readers": [
"claude_code",
"cursor"
],
"events": [
"Stop"
]
}
}Download inputs and complete results (JSON)How the example was checked
These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.
The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.
What to check next
Review the hook or file diff and compare it with expected setup changes. Establish who authorized it using your own change history. If the change is legitimate, retain that context; if it is unexpected, investigate before relying on later agent activity.
- Inspect the hook or diff
- Check authorized changes
- Review affected sessions
What this signal establishes
A finding does not identify the author or prove tampering was malicious. Changes made before the first inventory are part of the baseline.