A hook is a command that Claude Code runs automatically at set points, for example before or after it uses a tool. A project hook is one defined in a project's own settings. When Claude Code wraps a project hook in a sandbox (a restricted environment that limits what the command can reach), it now checks that the result really is a deny-by-default sandbox launch. Deny-by-default means everything is blocked unless it is explicitly allowed.
If the check fails, the hook is not run, and the failure is logged at error level. The earlier check looked only at whether the wrapped command began with a fixed profile prefix. That check has been replaced by the new one.
This is a security hardening step. A project hook that is meant to run inside a strict sandbox will not run at all unless that sandbox is confirmed to be in place.