{"version":"2.1.285","anchor":"plugin-hooks-pretooluse-deny-and-sessionappend-rework","canonical_anchor":"plugin-hooks-pretooluse-deny-and-sessionappend-rework","heading":"Plugin hook modules can block a tool call before it runs","tier":"notice","area":"Hooks","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/plugin-hooks-pretooluse-deny-and-sessionappend-rework","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Plugin hook modules can block a tool call before it runs\n\nA plugin hook that runs before a tool call can now deny it, and plugins get a clear reason when a message they add to the session is refused\n\n**Unclear.** It is not clear whether this plugin hook path is switched on for anyone, or what check decides that.\n\n**What**\n\nA hook is a piece of code that Claude Code runs automatically at a set moment. `PreToolUse` is the moment just before a tool call, meaning an action Claude takes such as reading a file or running a command. A hook of this kind supplied through the plugin hook system can now deny the tool call. When it does, the result shows as an error naming the hook and the tool, in the form `Error: Hook PreToolUse:<tool>`.\n\nThe way a plugin adds messages to the current session, meaning the ongoing conversation, is also stricter. It now accepts only two kinds of entry:\n\n- A hidden user message that is not shown as something you typed\n\n- A system notice\n\nAnything else is refused, and the refusal says why.\n\n**Why**\n\nThis extends the plugin hook system, which is not documented, so that a plugin can stop a tool call before it happens rather than only observe it. Plugin authors who add messages to a session should expect other kinds of entry to be turned away.\n\n- Area: Hooks\n- Names: `PreToolUse`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5"}