Which AI Coding Agents Let You Intercept Tool Calls? Twelve of the 13 AI coding agents reviewed on October 3, 2026 document a way to intercept a tool call before it runs, while Continue is the only one with no hook documentation, according to a survey of each vendor's hook or plugin documentation. Eight of the twelve can rewrite a call's input, but only Claude Code, Gemini CLI, GitHub Copilot and Amp can rewrite what a tool returns, and nine run shell commands from a config file while Amp, OpenCode and Cline run in-process code plugins. Claude Code, which introduced hooks in June 2025, added a second layer called Mods on October 1, 2026. Twelve of the 13 AI coding agents we checked on October 3, 2026 document a way to stop a tool call before it runs. Continue, the thirteenth, has no hook documentation. The twelve differ on what else a hook can do: eight can rewrite a call’s input, only four can fully rewrite what a tool returns, and only some let an administrator lock hooks so a developer cannot switch them off. 1. 01Blocking is universalAll twelve tools can stop a tool call, by a deny decision, an exit code or a thrown error. 2. 02Rewriting is notEight rewrite a call’s input. Claude Code, Gemini CLI, Copilot and Amp also rewrite its output. 3. 03Two designsNine run shell commands from a config file. Amp, OpenCode and Cline run code plugins in-process. 4. 04Check failure rulesSeveral hook systems let a call through when the hook itself crashes or times out. 01 — ContextWhat a hook does in a coding agent A coding agent works by calling tools: it runs shell commands, reads and edits files, and calls external services through MCP, the open protocol most agents use to plug in outside tools. A hook is a piece of your own code that the agent runs at a set moment, such as just before a tool call. Depending on the tool, the hook can let the call through, stop it, change its arguments, change what comes back or add a note to the agent’s context. That makes hooks the place a team puts rules it does not want to leave to the model’s judgement: never read a secrets file, never push to the main branch, always run the formatter after an edit. Claude Code, which introduced hooks https://code.claude.com/docs/en/hooks in June 2025, added a second layer on October 1, 2026 called Mods, which we covered in our explainer on Claude Code Mods https://www.digitalapplied.com/blog/claude-code-mods-function-hooks-explained . The other eleven tools here now offer something comparable, built one of two ways. Config-file hooks A JSON or TOML file maps an event to a command. The agent runs the command, passes the call as JSON and reads a decision back from its output or exit code. In-process plugins A JavaScript or TypeScript function runs inside the agent and receives the call as an object it can change or reject directly. 02 — The dataBlock, rewrite input, rewrite output The first table answers the question most teams start with: what can a hook actually change? “Not documented” means the vendor’s hook pages do not describe the ability. It is not a claim that the tool cannot do it. | Sources: each vendor’s hook or plugin documentation, read October 3, 2026. Claude Code covers settings hooks and Mods together. | | | | |---|---|---|---| | Tool | Block a call | Rewrite input | Rewrite output | |---|---|---|---| | Claude Code | Yes | Yes | Yes, for every tool | | OpenAI Codex | Yes | Yes | Partly: a block swaps the result for feedback | | Cursor | Yes | Yes | MCP tools only | | Gemini CLI | Yes | Yes, merged over the model’s arguments | Yes, by denial with a reason or a follow-up tool call | | GitHub Copilot | Yes | Yes | Yes | | Windsurf Devin Desktop | Yes, exit code 2 | Not documented | Not documented | | Kiro | Yes, non-zero exit | Not documented | Not documented | | Factory Droid | Yes | Yes | Not documented | | Augment | Yes | No, not yet implemented | No, output is read-only | | Amp | Yes | Yes | Yes, and can return a result without running the tool | | OpenCode | Yes, by throwing an error | Yes | Not documented | | Cline | Yes, by skipping the call | Not documented | Not documented | Rewriting input is the more useful power than it sounds. A hook that can only block forces the agent to try again; a hook that can rewrite can, for example, add a dry-run flag to a deploy command and let it proceed. Codex requires a rewritten shell or patch call to keep a string command field, and Gemini CLI merges the hook’s arguments over the model’s rather than replacing them outright. Output rewriting matters for redaction: stripping a token from a command’s output before the model reads it. Claude Code’s settings hooks can replace the output of any tool, and its Mods can return a result of their own. Cursor limits this to MCP tools, and Codex can only swap a result for feedback text by blocking it. Gemini CLI’s denial swaps it the same way but can also substitute a follow-up tool’s result. No output hook undoes what the tool already did. Adding context is close to universal: eleven of the twelve document a way to put a note into the agent’s context, usually a field called additionalContext , and Windsurf’s pages describe none. 03 — The dataEvents, runtimes and who controls them The second table covers reach: how many moments in the agent’s run a hook can attach to, what kind of handler it can be, where hooks run and whether an administrator can enforce them. Event counts are as each vendor lists them and are not strictly comparable, because vendors split events at different grains. | Sources: each vendor’s hook or plugin documentation and reference pages, read October 3, 2026. | | | | |---|---|---|---| | Tool | Events | Handlers | Where it runs and admin control | |---|---|---|---| | Claude Code | 33, plus Mod events | Command, HTTP, MCP tool, prompt, agent; Mods in JS or TS | Terminal, IDE, SDK and cloud sessions. Managed-only switches for hooks and for Mods | | OpenAI Codex | 12 | Command, MCP tool | Local; managed remote MCP hooks on the cloud orchestrator. Managed-only switch; other hooks must be reviewed and trusted first | | Cursor | 21 | Command, prompt | Local and cloud agents, command hooks only in the cloud. Enterprise device and team hooks; any deny wins | | Gemini CLI | 11 | Command | Local. Project, user and system settings; a changed project hook is treated as untrusted | | GitHub Copilot | 14 | Command, HTTP, prompt session start only | CLI and the cloud agent’s Linux sandbox. Root-owned policy hooks, CLI only | | Windsurf Devin Desktop | 12 | Shell command | Local IDE. System hooks need root to disable; Enterprise dashboard | | Kiro | 13 triggers | Command, agent prompt | IDE, CLI and web. No managed hook location documented | | Factory Droid | 9 | Command | Local CLI. Organisation hooks cannot be removed lower down; managed-only switch | | Augment | 6 | Command script | CLI, VS Code, IntelliJ. Immutable system settings file | | Amp | 6 event types | TS or JS plugins on Bun | Local and Amp’s per-thread cloud machines. No admin control documented | | OpenCode | Tool, session, permission, file and other plugin events | JS or TS plugins | Local. No admin control documented | | Cline | 7 hooks | TypeScript SDK plugins | Local. Each hook can be set to fail closed | Documented hook events, config-file hook systems Vendor hook references, read October 3, 2026. Claude Code counts settings hook events only; Cursor counts 18 agent, 2 Tab and 1 app hook; Kiro counts triggers. More events is reach, not quality. Admin control is where the tools separate most. Claude Code, Codex and Factory Droid each have a managed-only switch that stops user and project hooks from loading. Cursor merges hooks from every source and, in the words of its hooks documentation https://cursor.com/docs/agent/hooks , “any deny wins”, whoever wrote the hook. GitHub’s hooks reference https://docs.github.com/en/copilot/reference/hooks-reference requires policy hooks to be root-owned files that a user setting cannot disable, but they apply to Copilot CLI only, not the cloud agent. For Amp, OpenCode, Kiro and Cline we found no documented admin control at all. Claude Code also fixes the order between its two layers: managed settings hooks run before any Mod sees a tool call, and a block from one of them is final. Our security checklist for Claude Code Mods https://www.digitalapplied.com/blog/claude-code-mod-security-review-checklist covers what to check before a team switches a third-party Mod on. 04 — The catchWhat happens when the hook itself fails A guardrail that crashes and lets the call through is not a guardrail. The vendors handle this differently, and few make it prominent. - Codex documents that an error, a timeout or a malformed reply from a pre-tool hook can fail without blocking the tool, and that background hooks cannot block anything. - Cursor has a failClosed setting that makes a failing hook block the call. It is off by default. - Cline lets each plugin hook choose fail-open or fail-closed. - Gemini CLI treats hook output that is not valid JSON as an allow. - Copilot drops the output of a config-file prompt-submission hook, so prompt rewriting works only from its SDK. Before relying on a blocking hook, make it fail on purpose: exit with an error, sleep past its timeout and print invalid output. Then confirm the call it guards is stopped in each case. If it is not, the rule is advisory, whatever the configuration file says. 05 — TimelineHow fast hooks spread across coding agents Claude Code’s changelog shows hooks shipping in version 1.0.38 at the end of June 2025. Within fifteen months, most of the field had a version. Several tools also borrow Claude Code’s format directly: Copilot CLI reads hooks from Claude Code’s settings files, and Cursor says its exit-code behaviour matches Claude Code’s for compatibility. - Claude Code hooksVersion 1.0.38 - Jun 30, 2025 - Cursor hooks beta Version 1.7 - Sep 29, 2025 - Factory Droid hooksCLI 0.24.0 - Nov 12, 2025 - Windsurf Cascade HooksVersion 1.12.31, all tiers - Nov 13, 2025 - Gemini CLI hooksAnnounced on Google’s developer blog - Jan 28, 2026 - Copilot hooks in VS CodeVS Code 1.110 release - Mar 6, 2026 - Amp Plugin APIOfficial release - May 6, 2026 - Codex hooksGeneral availability - May 14, 2026 - Claude Code ModsVersion 2.1.287 - Oct 1, 2026 We could not find a first-release date on a primary page for Kiro, Augment, OpenCode, Cline, or Copilot’s CLI and cloud agent, so they are left off the timeline. Windsurf has since been renamed Devin Desktop, and its November 2025 launch of Cascade Hooks https://www.digitalapplied.com/blog/windsurf-swe-1-5-cascade-hooks-november-2025 is covered separately. 06 — Practical implicationsChoosing a tool by what the hook must do Many teams run more than one agent, so the portable choice is a small script that reads JSON on standard input and answers with a decision. Nine of the twelve tools can call it from a config file, with a thin wrapper for each vendor’s field names. The instruction files these agents read differ in the same way, as our table of which tool reads which file https://www.digitalapplied.com/blog/coding-agent-instruction-files-which-tool-reads-what shows. For teams that want guardrails designed and tested across their agent stack, our AI transformation https://www.digitalapplied.com/services/ai-transformation work covers policy, hooks and rollout. 07 — MethodMethod and as-of date A comparison of documented hook behaviour. Digital Applied did not run every hook system; the table reports what each vendor documents. - What was collected - For 13 coding agents: whether a documented hook can block a tool call, rewrite its input, rewrite its output and add context; event count; handler types; where hooks run; administrator enforcement; and the first-release date where a primary page states it. - Sources - Each vendor’s own hook, plugin or SDK documentation, reference pages and changelogs. Release times for Claude Code from its changelog and npm publish times. No third-party comparisons were used. - As-of date - October 3, 2026. None of the twelve vendors’ hook pages shows a last-updated date. - Inclusion - A tool is included if its documentation describes code that runs before a tool call and can stop it. Continue was checked and excluded: its documentation index lists no hooks page. - Limitations - “Not documented” is not “impossible”. Amp’s fuller manual now requires sign-in, so its public plugin API reference was used. Kiro documents only a workspace hook location. - Refresh - Re-read every vendor’s hook reference monthly and on any major release. Correct cells in place with a dated note. Write the rule once, then prove it blocks Pick the two or three rules your team would be most embarrassed to see broken, write each as one hook script, and wire it into every agent your developers use. Then break the script on purpose and confirm the call it guards still stops.