Urgent.News

What's breaking now, across thousands of outlets.

AI

Claude Code's hook matcher mcp__lab fired 0 times in 42 calls, though the same string worked as a permission rule

Across 14 headless runs of Claude Code 2.1.289, a hook whose matcher was the server prefix mcp__lab fired 0 times in 42 calls to that server's tools, while mcp__lab__.* fired 42 of 42, and the same bare mcp__lab passed to --allowedTools approved every call it covered. Two more strings stayed silent: an if condition of mcp__lab (0 of 42), and the documented fix mcp__lab__.* itself once the same…

In 42 calls to Claude Code's server, the hook matcher "mcp__lab" fired 0 times, while "mcp__lab__.*" fired all 42 times. The same bare "mcp__lab" passed the "allowedTools" check for every covered call. Two other strings, "mcp__lab (0 of 42)" and the documented fix "mcp__lab__.*" when bundled in a plugin (0 of 9), also did not fire.

The hook matcher in an MCP server usually logs calls or checks them before execution, but in this case, the matcher did not fire at all. The source material reveals that the matcher string does nothing when compared as an exact string and matches no tool. The documentation explains that a matcher that matches nothing does not break anything visible.

They tested various plausible strings by creating a three-tool MCP server and registering 22 hook groups to see which ones fired for which tool. The documentation clarifies that the bare server prefix in a permission rule means the whole server, and that a wildcard "*" is used for glob matching. They also discovered that the matcher "mcp__lab" is an exact name that no tool has, while it is the whole server as a permission rule and an if condition according to the docs.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at dev.to →

More in AI

When the AI Brain Crashes: The 'Naked Position' Crisis and Engineering Trade-offs Under Fail-Open Mechanisms

When the AI Brain Crashes: The 'Naked Position' Crisis and Engineering Trade-offs Under Fail-Open Mechanisms Tags: #algotrading #crypto #ai #buildinpublic The Midnight Alert It was 00:12 AM on October…

  • AI-driven crypto trading system crashed on October 10, 2026, at 00:12 AM
  • System went into Naked Position mode, exposing leveraged positions
  • Engineering team chose fail-open mechanism to avoid panic-sell executions

More from Sunday 11 October →