AI DevelopmentDecision Matrix6 min readPublished October 3, 2026

Twelve coding agents, one question: can you stop the call?

Which AI Coding Agents Let You Intercept Tool Calls?

Claude Code, Codex, Cursor, Gemini CLI, Copilot and seven more compared: which events each hook system exposes, what it can block or rewrite, where it runs.

DA
Digital Applied Team
Research and practical guidance
CoverageOctober 3, 2026

Twelve of the 13 AI coding agents we checked on October 3, 2026 document a way to stop a tool call before it runs. Continue, the thirteenth, has no hook documentation. The twelve differ on what else a hook can do: eight can rewrite a call’s input, only four can fully rewrite what a tool returns, and only some let an administrator lock hooks so a developer cannot switch them off.

Key takeaways
  1. 01
    Blocking is universalAll twelve tools can stop a tool call, by a deny decision, an exit code or a thrown error.
  2. 02
    Rewriting is notEight rewrite a call’s input. Claude Code, Gemini CLI, Copilot and Amp also rewrite its output.
  3. 03
    Two designsNine run shell commands from a config file. Amp, OpenCode and Cline run code plugins in-process.
  4. 04
    Check failure rulesSeveral hook systems let a call through when the hook itself crashes or times out.

01 — ContextWhat a hook does in a coding agent

A coding agent works by calling tools: it runs shell commands, reads and edits files, and calls external services through MCP, the open protocol most agents use to plug in outside tools. A hook is a piece of your own code that the agent runs at a set moment, such as just before a tool call. Depending on the tool, the hook can let the call through, stop it, change its arguments, change what comes back or add a note to the agent’s context.

That makes hooks the place a team puts rules it does not want to leave to the model’s judgement: never read a secrets file, never push to the main branch, always run the formatter after an edit. Claude Code, which introduced hooks in June 2025, added a second layer on October 1, 2026 called Mods, which we covered in our explainer on Claude Code Mods. The other eleven tools here now offer something comparable, built one of two ways.

A
Config-file hooks
Claude Code, Codex, Cursor, Gemini CLI, Copilot, Windsurf, Kiro, Factory Droid, Augment

A JSON or TOML file maps an event to a command. The agent runs the command, passes the call as JSON and reads a decision back from its output or exit code.

Any language
B
In-process plugins
Amp, OpenCode, Cline, Claude Code Mods

A JavaScript or TypeScript function runs inside the agent and receives the call as an object it can change or reject directly.

JS or TS only

02 — The dataBlock, rewrite input, rewrite output

The first table answers the question most teams start with: what can a hook actually change? “Not documented” means the vendor’s hook pages do not describe the ability. It is not a claim that the tool cannot do it.

Sources: each vendor’s hook or plugin documentation, read October 3, 2026. Claude Code covers settings hooks and Mods together.
ToolBlock a callRewrite inputRewrite output
Claude CodeYesYesYes, for every tool
OpenAI CodexYesYesPartly: a block swaps the result for feedback
CursorYesYesMCP tools only
Gemini CLIYesYes, merged over the model’s argumentsYes, by denial with a reason or a follow-up tool call
GitHub CopilotYesYesYes
Windsurf (Devin Desktop)Yes, exit code 2Not documentedNot documented
KiroYes, non-zero exitNot documentedNot documented
Factory DroidYesYesNot documented
AugmentYesNo, not yet implementedNo, output is read-only
AmpYesYesYes, and can return a result without running the tool
OpenCodeYes, by throwing an errorYesNot documented
ClineYes, by skipping the callNot documentedNot documented

Rewriting input is the more useful power than it sounds. A hook that can only block forces the agent to try again; a hook that can rewrite can, for example, add a dry-run flag to a deploy command and let it proceed. Codex requires a rewritten shell or patch call to keep a string command field, and Gemini CLI merges the hook’s arguments over the model’s rather than replacing them outright.

Output rewriting matters for redaction: stripping a token from a command’s output before the model reads it. Claude Code’s settings hooks can replace the output of any tool, and its Mods can return a result of their own. Cursor limits this to MCP tools, and Codex can only swap a result for feedback text by blocking it. Gemini CLI’s denial swaps it the same way but can also substitute a follow-up tool’s result. No output hook undoes what the tool already did. Adding context is close to universal: eleven of the twelve document a way to put a note into the agent’s context, usually a field called additionalContext, and Windsurf’s pages describe none.

03 — The dataEvents, runtimes and who controls them

The second table covers reach: how many moments in the agent’s run a hook can attach to, what kind of handler it can be, where hooks run and whether an administrator can enforce them. Event counts are as each vendor lists them and are not strictly comparable, because vendors split events at different grains.

Sources: each vendor’s hook or plugin documentation and reference pages, read October 3, 2026.
ToolEventsHandlersWhere it runs and admin control
Claude Code33, plus Mod eventsCommand, HTTP, MCP tool, prompt, agent; Mods in JS or TSTerminal, IDE, SDK and cloud sessions. Managed-only switches for hooks and for Mods
OpenAI Codex12Command, MCP toolLocal; managed remote MCP hooks on the cloud orchestrator. Managed-only switch; other hooks must be reviewed and trusted first
Cursor21Command, promptLocal and cloud agents, command hooks only in the cloud. Enterprise device and team hooks; any deny wins
Gemini CLI11CommandLocal. Project, user and system settings; a changed project hook is treated as untrusted
GitHub Copilot14Command, HTTP, prompt (session start only)CLI and the cloud agent’s Linux sandbox. Root-owned policy hooks, CLI only
Windsurf (Devin Desktop)12Shell commandLocal IDE. System hooks need root to disable; Enterprise dashboard
Kiro13 triggersCommand, agent promptIDE, CLI and web. No managed hook location documented
Factory Droid9CommandLocal CLI. Organisation hooks cannot be removed lower down; managed-only switch
Augment6Command scriptCLI, VS Code, IntelliJ. Immutable system settings file
Amp6 event typesTS or JS plugins on BunLocal and Amp’s per-thread cloud machines. No admin control documented
OpenCodeTool, session, permission, file and other plugin eventsJS or TS pluginsLocal. No admin control documented
Cline7 hooksTypeScript SDK pluginsLocal. Each hook can be set to fail closed

Documented hook events, config-file hook systems

Vendor hook references, read October 3, 2026. Claude Code counts settings hook events only; Cursor counts 18 agent, 2 Tab and 1 app hook; Kiro counts triggers. More events is reach, not quality.
Claude Code
33
Cursor
21
GitHub Copilot
14
Kirotriggers
13
OpenAI Codex
12
Windsurf
12
Gemini CLI
11
Factory Droid
9
Augment
6

Admin control is where the tools separate most. Claude Code, Codex and Factory Droid each have a managed-only switch that stops user and project hooks from loading. Cursor merges hooks from every source and, in the words of its hooks documentation, “any deny wins”, whoever wrote the hook. GitHub’s hooks reference requires policy hooks to be root-owned files that a user setting cannot disable, but they apply to Copilot CLI only, not the cloud agent. For Amp, OpenCode, Kiro and Cline we found no documented admin control at all.

Claude Code also fixes the order between its two layers: managed settings hooks run before any Mod sees a tool call, and a block from one of them is final. Our security checklist for Claude Code Mods covers what to check before a team switches a third-party Mod on.

04 — The catchWhat happens when the hook itself fails

A guardrail that crashes and lets the call through is not a guardrail. The vendors handle this differently, and few make it prominent.

  • Codex documents that an error, a timeout or a malformed reply from a pre-tool hook can fail without blocking the tool, and that background hooks cannot block anything.
  • Cursor has a failClosed setting that makes a failing hook block the call. It is off by default.
  • Cline lets each plugin hook choose fail-open or fail-closed.
  • Gemini CLI treats hook output that is not valid JSON as an allow.
  • Copilot drops the output of a config-file prompt-submission hook, so prompt rewriting works only from its SDK.
Test the failure path

Before relying on a blocking hook, make it fail on purpose: exit with an error, sleep past its timeout and print invalid output. Then confirm the call it guards is stopped in each case. If it is not, the rule is advisory, whatever the configuration file says.

05 — TimelineHow fast hooks spread across coding agents

Claude Code’s changelog shows hooks shipping in version 1.0.38 at the end of June 2025. Within fifteen months, most of the field had a version. Several tools also borrow Claude Code’s format directly: Copilot CLI reads hooks from Claude Code’s settings files, and Cursor says its exit-code behaviour matches Claude Code’s for compatibility.

Claude Code hooksVersion 1.0.38
Jun 30, 2025
Cursor hooks (beta)Version 1.7
Sep 29, 2025
Factory Droid hooksCLI 0.24.0
Nov 12, 2025
Windsurf Cascade HooksVersion 1.12.31, all tiers
Nov 13, 2025
Gemini CLI hooksAnnounced on Google’s developer blog
Jan 28, 2026
Copilot hooks in VS CodeVS Code 1.110 release
Mar 6, 2026
Amp Plugin APIOfficial release
May 6, 2026
Codex hooksGeneral availability
May 14, 2026
Claude Code ModsVersion 2.1.287
Oct 1, 2026

We could not find a first-release date on a primary page for Kiro, Augment, OpenCode, Cline, or Copilot’s CLI and cloud agent, so they are left off the timeline. Windsurf has since been renamed Devin Desktop, and its November 2025 launch of Cascade Hooks is covered separately.

06 — Practical implicationsChoosing a tool by what the hook must do

Rules must hold for every developer, centrally
A tool with a managed-only switch or root-owned policy
Claude Code, Codex, Factory, Copilot CLI
Secrets must be stripped from tool output
A tool that rewrites output for every tool
Claude Code, Gemini CLI, Copilot, Amp
Unsafe commands should be fixed, not just refused
A tool that rewrites tool input
Eight of twelve
Same rules across several agents
Write one script, wire it into each config file
Config-file hooks

Many teams run more than one agent, so the portable choice is a small script that reads JSON on standard input and answers with a decision. Nine of the twelve tools can call it from a config file, with a thin wrapper for each vendor’s field names. The instruction files these agents read differ in the same way, as our table of which tool reads which file shows. For teams that want guardrails designed and tested across their agent stack, our AI transformation work covers policy, hooks and rollout.

07 — MethodMethod and as-of date

Methodology

A comparison of documented hook behaviour. Digital Applied did not run every hook system; the table reports what each vendor documents.

What was collected
For 13 coding agents: whether a documented hook can block a tool call, rewrite its input, rewrite its output and add context; event count; handler types; where hooks run; administrator enforcement; and the first-release date where a primary page states it.
Sources
Each vendor’s own hook, plugin or SDK documentation, reference pages and changelogs. Release times for Claude Code from its changelog and npm publish times. No third-party comparisons were used.
As-of date
October 3, 2026. None of the twelve vendors’ hook pages shows a last-updated date.
Inclusion
A tool is included if its documentation describes code that runs before a tool call and can stop it. Continue was checked and excluded: its documentation index lists no hooks page.
Limitations
“Not documented” is not “impossible”. Amp’s fuller manual now requires sign-in, so its public plugin API reference was used. Kiro documents only a workspace hook location.
Refresh
Re-read every vendor’s hook reference monthly and on any major release. Correct cells in place with a dated note.
Next step

Write the rule once, then prove it blocks

Pick the two or three rules your team would be most embarrassed to see broken, write each as one hook script, and wire it into every agent your developers use. Then break the script on purpose and confirm the call it guards still stops.

Agentic AI implementation

Put guardrails on every coding agent your team runs

Digital Applied designs hook policies, tests their failure paths and rolls them out across Claude Code, Codex, Cursor and the rest.

Hook policy designFailure-path testsCentral rollout
Before you rely on a hook

Check four things

  • →Can it block, not just log?
  • →Does a crash block or allow?
  • →Can a user switch it off?
  • →Does it run in the cloud agent?
Questions and answers

Practical questions

As of October 3, 2026, Claude Code, OpenAI Codex, Cursor, Gemini CLI, GitHub Copilot, Windsurf (now Devin Desktop), Kiro, Factory Droid, Augment, Amp, OpenCode and Cline all document a way to intercept tool calls. Continue has no hook documentation.
Digital Applied newsletter

Deep dives on AI, marketing and development.

Practical guides and fresh insights by email. No recycled takes.

Related dispatches

Continue reading

AI Development

Same Coding Model, Up to 5x the Cost: The Harness Matters

A UC Berkeley and Arena study ran seven models in three coding harnesses. Success barely moved; cost moved up to 5x. All 42 measured rows, with intervals.

September 17, 2026 · 9 minRead
AI Development

What Coding Agents Do Without Asking: A Permission-Defaults Census

Headless permission defaults for 12 coding-agent CLIs: which write files without asking, which refuse until you pass a flag, and which actually sandbox.

August 22, 2026 · 23 minRead
AI Development

Two Agent CLIs Shipped. Here Is What Actually Changed

Claude Code v2.1.234 hardened the remaining pre-approval NTLM path accesses. Codex CLI 0.148.0 added Bedrock and session forking. What changed for operators.

August 18, 2026 · 14 minRead
AI Development

Claude Code Auto Mode Lands on Bedrock and Vertex AI

Auto mode's classifier-gated permissions are now default on AWS Bedrock, Vertex AI, and Foundry. What enterprise teams should review before rollout.

July 13, 2026 · 12 minRead
AI Development

Building Games With Astra: A Practical Playtest Guide

Plan an Astra-assisted game around a playable loop, repeatable checks and human feedback. Use a practical playtest method before investing in more polish.

September 9, 2026 · 6 minRead
AI Development

AI-Built Forms: Keep User Input When Submission Fails

Test AI-built forms beyond a successful submit. Preserve valid input, explain errors and distinguish a rejected request from an outcome still unknown.

September 6, 2026 · 4 minRead
Google Search

See more Digital Applied analysis in your Google results by adding us as a preferred source.

Add as a preferred source