cd /news/ai-agents/which-ai-coding-agents-let-you-inter… · home › topics › ai-agents › article
[ARTICLE · art-144427] src=digitalapplied.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Which AI Coding Agents Let You Intercept Tool Calls?

Twelve of the 13 AI coding agents reviewed on October 3, 2026 document a way to intercept a tool call before it runs, while Continue is the only one with no hook documentation, according to a survey of each vendor's hook or plugin documentation. Eight of the twelve can rewrite a call's input, but only Claude Code, Gemini CLI, GitHub Copilot and Amp can rewrite what a tool returns, and nine run shell commands from a config file while Amp, OpenCode and Cline run in-process code plugins. Claude Code, which introduced hooks in June 2025, added a second layer called Mods on October 1, 2026.

read11 min views1 publishedOct 3, 2026
Which AI Coding Agents Let You Intercept Tool Calls?
Image: Digitalapplied (auto-discovered)

Twelve of the 13 AI coding agents we checked on October 3, 2026 document a way to stop a tool call before it runs. Continue, the thirteenth, has no hook documentation. The twelve differ on what else a hook can do: eight can rewrite a call’s input, only four can fully rewrite what a tool returns, and only some let an administrator lock hooks so a developer cannot switch them off.

  1. 01Blocking is universalAll twelve tools can stop a tool call, by a deny decision, an exit code or a thrown error.
  2. 02Rewriting is notEight rewrite a call’s input. Claude Code, Gemini CLI, Copilot and Amp also rewrite its output.
  3. 03Two designsNine run shell commands from a config file. Amp, OpenCode and Cline run code plugins in-process.
  4. 04Check failure rulesSeveral hook systems let a call through when the hook itself crashes or times out.

01 — ContextWhat a hook does in a coding agent #

A coding agent works by calling tools: it runs shell commands, reads and edits files, and calls external services through MCP, the open protocol most agents use to plug in outside tools. A hook is a piece of your own code that the agent runs at a set moment, such as just before a tool call. Depending on the tool, the hook can let the call through, stop it, change its arguments, change what comes back or add a note to the agent’s context.

That makes hooks the place a team puts rules it does not want to leave to the model’s judgement: never read a secrets file, never push to the main branch, always run the formatter after an edit. Claude Code, which introduced hooks in June 2025, added a second layer on October 1, 2026 called Mods, which we covered in our explainer on Claude Code Mods. The other eleven tools here now offer something comparable, built one of two ways.

Config-file hooks

A JSON or TOML file maps an event to a command. The agent runs the command, passes the call as JSON and reads a decision back from its output or exit code.

In-process plugins

A JavaScript or TypeScript function runs inside the agent and receives the call as an object it can change or reject directly.

02 — The dataBlock, rewrite input, rewrite output #

The first table answers the question most teams start with: what can a hook actually change? “Not documented” means the vendor’s hook pages do not describe the ability. It is not a claim that the tool cannot do it.

Sources: each vendor’s hook or plugin documentation, read October 3, 2026. Claude Code covers settings hooks and Mods together.
Tool Block a call Rewrite input Rewrite output
--- --- --- ---
Claude Code Yes Yes Yes, for every tool
OpenAI Codex Yes Yes Partly: a block swaps the result for feedback
Cursor Yes Yes MCP tools only
Gemini CLI Yes Yes, merged over the model’s arguments Yes, by denial with a reason or a follow-up tool call
GitHub Copilot Yes Yes Yes
Windsurf (Devin Desktop) Yes, exit code 2 Not documented Not documented
Kiro Yes, non-zero exit Not documented Not documented
Factory Droid Yes Yes Not documented
Augment Yes No, not yet implemented No, output is read-only
Amp Yes Yes Yes, and can return a result without running the tool
OpenCode Yes, by throwing an error Yes Not documented
Cline Yes, by skipping the call Not documented Not documented

Rewriting input is the more useful power than it sounds. A hook that can only block forces the agent to try again; a hook that can rewrite can, for example, add a dry-run flag to a deploy command and let it proceed. Codex requires a rewritten shell or patch call to keep a string command field, and Gemini CLI merges the hook’s arguments over the model’s rather than replacing them outright.

Output rewriting matters for redaction: stripping a token from a command’s output before the model reads it. Claude Code’s settings hooks can replace the output of any tool, and its Mods can return a result of their own. Cursor limits this to MCP tools, and Codex can only swap a result for feedback text by blocking it. Gemini CLI’s denial swaps it the same way but can also substitute a follow-up tool’s result. No output hook undoes what the tool already did. Adding context is close to universal: eleven of the twelve document a way to put a note into the agent’s context, usually a field called additionalContext, and Windsurf’s pages describe none.

03 — The dataEvents, runtimes and who controls them #

The second table covers reach: how many moments in the agent’s run a hook can attach to, what kind of handler it can be, where hooks run and whether an administrator can enforce them. Event counts are as each vendor lists them and are not strictly comparable, because vendors split events at different grains.

Sources: each vendor’s hook or plugin documentation and reference pages, read October 3, 2026.
Tool Events Handlers Where it runs and admin control
--- --- --- ---
Claude Code 33, plus Mod events Command, HTTP, MCP tool, prompt, agent; Mods in JS or TS Terminal, IDE, SDK and cloud sessions. Managed-only switches for hooks and for Mods
OpenAI Codex 12 Command, MCP tool Local; managed remote MCP hooks on the cloud orchestrator. Managed-only switch; other hooks must be reviewed and trusted first
Cursor 21 Command, prompt Local and cloud agents, command hooks only in the cloud. Enterprise device and team hooks; any deny wins
Gemini CLI 11 Command Local. Project, user and system settings; a changed project hook is treated as untrusted
GitHub Copilot 14 Command, HTTP, prompt (session start only) CLI and the cloud agent’s Linux sandbox. Root-owned policy hooks, CLI only
Windsurf (Devin Desktop) 12 Shell command Local IDE. System hooks need root to disable; Enterprise dashboard
Kiro 13 triggers Command, agent prompt IDE, CLI and web. No managed hook location documented
Factory Droid 9 Command Local CLI. Organisation hooks cannot be removed lower down; managed-only switch
Augment 6 Command script CLI, VS Code, IntelliJ. Immutable system settings file
Amp 6 event types TS or JS plugins on Bun Local and Amp’s per-thread cloud machines. No admin control documented
OpenCode Tool, session, permission, file and other plugin events JS or TS plugins Local. No admin control documented
Cline 7 hooks TypeScript SDK plugins Local. Each hook can be set to fail closed

Documented hook events, config-file hook systems

Vendor hook references, read October 3, 2026. Claude Code counts settings hook events only; Cursor counts 18 agent, 2 Tab and 1 app hook; Kiro counts triggers. More events is reach, not quality. Admin control is where the tools separate most. Claude Code, Codex and Factory Droid each have a managed-only switch that stops user and project hooks from . Cursor merges hooks from every source and, in the words of its hooks documentation, “any deny wins”, whoever wrote the hook. GitHub’s hooks reference requires policy hooks to be root-owned files that a user setting cannot disable, but they apply to Copilot CLI only, not the cloud agent. For Amp, OpenCode, Kiro and Cline we found no documented admin control at all.

Claude Code also fixes the order between its two layers: managed settings hooks run before any Mod sees a tool call, and a block from one of them is final. Our security checklist for Claude Code Mods covers what to check before a team switches a third-party Mod on.

04 — The catchWhat happens when the hook itself fails #

A guardrail that crashes and lets the call through is not a guardrail. The vendors handle this differently, and few make it prominent.

  • Codex documents that an error, a timeout or a malformed reply from a pre-tool hook can fail without blocking the tool, and that background hooks cannot block anything.
  • Cursor has afailClosed setting that makes a failing hook block the call. It is off by default.
  • Cline lets each plugin hook choose fail-open or fail-closed.
  • Gemini CLI treats hook output that is not valid JSON as an allow.
  • Copilot drops the output of a config-file prompt-submission hook, so prompt rewriting works only from its SDK.

Before relying on a blocking hook, make it fail on purpose: exit with an error, sleep past its timeout and print invalid output. Then confirm the call it guards is stopped in each case. If it is not, the rule is advisory, whatever the configuration file says.

05 — TimelineHow fast hooks spread across coding agents #

Claude Code’s changelog shows hooks shipping in version 1.0.38 at the end of June 2025. Within fifteen months, most of the field had a version. Several tools also borrow Claude Code’s format directly: Copilot CLI reads hooks from Claude Code’s settings files, and Cursor says its exit-code behaviour matches Claude Code’s for compatibility.

  • Claude Code hooksVersion 1.0.38
  • Jun 30, 2025
  • Cursor hooks (beta)Version 1.7
  • Sep 29, 2025
  • Factory Droid hooksCLI 0.24.0
  • Nov 12, 2025
  • Windsurf Cascade HooksVersion 1.12.31, all tiers
  • Nov 13, 2025
  • Gemini CLI hooksAnnounced on Google’s developer blog
  • Jan 28, 2026
  • Copilot hooks in VS CodeVS Code 1.110 release
  • Mar 6, 2026
  • Amp Plugin APIOfficial release
  • May 6, 2026
  • Codex hooksGeneral availability
  • May 14, 2026
  • Claude Code ModsVersion 2.1.287
  • Oct 1, 2026

We could not find a first-release date on a primary page for Kiro, Augment, OpenCode, Cline, or Copilot’s CLI and cloud agent, so they are left off the timeline. Windsurf has since been renamed Devin Desktop, and its November 2025 launch of Cascade Hooks is covered separately.

06 — Practical implicationsChoosing a tool by what the hook must do #

Many teams run more than one agent, so the portable choice is a small script that reads JSON on standard input and answers with a decision. Nine of the twelve tools can call it from a config file, with a thin wrapper for each vendor’s field names. The instruction files these agents read differ in the same way, as our table of which tool reads which file shows. For teams that want guardrails designed and tested across their agent stack, our AI transformation work covers policy, hooks and rollout.

07 — MethodMethod and as-of date #

A comparison of documented hook behaviour. Digital Applied did not run every hook system; the table reports what each vendor documents.

  • What was collected
  • For 13 coding agents: whether a documented hook can block a tool call, rewrite its input, rewrite its output and add context; event count; handler types; where hooks run; administrator enforcement; and the first-release date where a primary page states it.
  • Sources
  • Each vendor’s own hook, plugin or SDK documentation, reference pages and changelogs. Release times for Claude Code from its changelog and npm publish times. No third-party comparisons were used.
  • As-of date
  • October 3, 2026. None of the twelve vendors’ hook pages shows a last-updated date.
  • Inclusion
  • A tool is included if its documentation describes code that runs before a tool call and can stop it. Continue was checked and excluded: its documentation index lists no hooks page.
  • Limitations
  • “Not documented” is not “impossible”. Amp’s fuller manual now requires sign-in, so its public plugin API reference was used. Kiro documents only a workspace hook location.
  • Refresh
  • Re-read every vendor’s hook reference monthly and on any major release. Correct cells in place with a dated note.

Write the rule once, then prove it blocks

Pick the two or three rules your team would be most embarrassed to see broken, write each as one hook script, and wire it into every agent your developers use. Then break the script on purpose and confirm the call it guards still stops.

── more in #ai-agents 4 stories · sorted by recency
── more on @claude code 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/which-ai-coding-agen…] indexed:0 read:11min 2026-10-03 · —