Hook matcher rules: when mcp__sume__ names are exact, not regex

Claude Code reads a matcher of letters, digits, underscores and pipes as exact names, and other characters as regex. How to write it for Sume tools.

3 min readSume
All posts

mcp__sume__generate_image|mcp__sume__generate_video is an exact list of two tool names, not a regex. The Claude Code hooks reference says a matcher made only of letters, digits, _, -, spaces, commas and | is evaluated as an exact string or a set of alternatives. Add any other character, such as . or *, and it becomes an unanchored JavaScript regex.

That rule decides whether your guard covers the paid Sume tools you meant. mcp__sume__generate_.* is a regex and also matches tools you did not plan for. The exact form matches only the names you typed.

The rule, from the hooks reference

Matchers filter when a hook fires on tool events such as PreToolUse and PostToolUse.

Matcher evaluation (read 2026-10-08)
MatcherEvaluated asSume example
* or empty or omittedMatches every callEvery Sume and non-Sume tool
Letters, digits, _, -, space, comma, |Exact name or list of namesmcp__sume__tts_create|mcp__sume__music_create
Contains other charactersUnanchored JavaScript regexmcp__sume__.*
^Notebook style anchorsRegex, anchors honored^mcp__sume__generate_

Which Sume tools to name

Sume's tools docs list the paid generation tools: generate_image, generate_video, music_create, tts_create, stt_create, avatars_create, avatar-videos_create, kling-motion-control_create, image_upscale_create, rmbg_create, video_upscale_create and the timeline tools. Write and paid tools need an idempotency_key. The hyphen is allowed in the exact form, so mcp__sume__avatar-videos_create stays exact.

An exact list needs maintenance when new tools appear. A regex over the whole server is safer for a deny-by-default stance, and the hook body then decides by looking at tool_name and tool_input.

Steps

Write the matcher, then prove it matches. Add a hook that logs tool_name, call one Sume tool, and compare the logged value to your matcher by eye. Do the same for a tool you expect not to match, such as balance_get.

  • Use the exact form for a short, stable allow or deny list.
  • Use mcp__sume__.* plus a check inside the hook for a deny-by-default guard.
  • Remember that a server added through a plugin has a longer prefix, so test after any change in how Sume is installed.

A worked example

Say you want to guard voice and music creation only. The matcher mcp__sume__tts_create|mcp__sume__music_create is exact, so it cannot accidentally catch another tool whose name merely starts the same way. Now change it to mcp__sume__tts_.*. The dot and star turn it into a regex, and the pattern now also matches any future Sume tool whose name begins with tts_.

Neither form is wrong. They fail in opposite directions: the exact list misses a new paid tool until you add it, and the regex may prompt for a tool you did not mean to gate. Choose by which failure you can live with, and re-read Sume's tool inventory when you update the client.

What Sume does not do

Sume does not mark a tool as paid in the hook payload. Your hook sees a tool name and input only. The mapping from name to cost lives in Sume's docs and in tools_list and tools_schema, and the matcher is only as good as the list you copy from them.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume