#!/usr/bin/env bash
# Blocks text that holds a full Social Security number: three digits, two
# digits, four digits, with a dash, a space, or nothing between the groups.
# The last four digits on their own pass.
#
# Reads text on standard input. For Claude Code hook JSON, the values of
# session_id, transcript_path, cwd, and tool_use_id are removed first, since
# those ids and paths can hold long digit runs by chance.

input=$(cat)

cleaned=$(printf '%s\n' "$input" | sed -E 's/"(session_id|transcript_path|cwd|tool_use_id)"[[:space:]]*:[[:space:]]*"([^"\\]|\\.)*"/"\1":""/g')

if printf '%s\n' "$cleaned" | grep -Eq '(^|[^0-9])[0-9]{3}[- ]?[0-9]{2}[- ]?[0-9]{4}([^0-9]|$)'; then
  echo "Blocked: a full Social Security number. Use only the last four digits." >&2
  exit 2
fi

exit 0
