A 29-session test on Claude Code v2.1.273 ran the same protected-directory rule two ways, as prose in CLAUDE.md and as a PreToolUse hook. Both held on a plain task. The comparison that separates them rests on four runs.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Anthropic's memory documentation sets a 200-line target per instruction file and reserves real blocking for a hook. Everything written in markdown arrives as context the model weighs against your last message.
Publishers:code.claude.com
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives60
- Confidence62
A stuck rebase made force-pushing to main the locally correct move. Reviewing agent output scales with what the agent writes; a short list of things it must never do does not.
Reality
- Evidence40
- Adoption12
- Hype gap+22
- Incentives45
- Confidence42
A PreToolUse hook on an AI coding agent returned "allow" for every file under a non-ASCII directory name, for weeks, with no log line and no exception.
Reality
- Evidence63
- Adoption12
- Hype gap−5
- Incentives42
- Confidence55
A developer leaked live keys into agent transcripts three times before replacing a polite memory note with a hook that denies the read outright.
Reality
- Evidence45
- Adoption10
- Hype gap+28
- Incentives35
- Confidence48