A hook is a piece of code that Claude Code runs automatically at a set moment. PreToolUse is the moment just before a tool call, meaning an action Claude takes such as reading a file or running a command. A hook of this kind supplied through the plugin hook system can now deny the tool call. When it does, the result shows as an error naming the hook and the tool, in the form Error: Hook PreToolUse:<tool>.
The way a plugin adds messages to the current session, meaning the ongoing conversation, is also stricter. It now accepts only two kinds of entry:
- A hidden user message that is not shown as something you typed
- A system notice
Anything else is refused, and the refusal says why.
This extends the plugin hook system, which is not documented, so that a plugin can stop a tool call before it happens rather than only observe it. Plugin authors who add messages to a session should expect other kinds of entry to be turned away.
It is not clear whether this plugin hook path is switched on for anyone, or what check decides that.