{"version":"2.1.295","anchor":"plugin-hooks-that-rewrite-tool-input-on-another-machine-are","canonical_anchor":"plugin-hooks-that-rewrite-tool-input-on-another-machine-are","heading":"Plugin hooks on another machine can no longer change a tool call's input","tier":"notice","area":"Hooks","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/plugin-hooks-that-rewrite-tool-input-on-another-machine-are","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Plugin hooks on another machine can no longer change a tool call's input\n\nIf a plugin hook on another machine changes a tool call's input, Claude Code now refuses the call instead of running it\n\n**What**\n\nHooks are actions that run automatically at set points. A `PreToolUse` hook runs before a tool call (an action Claude wants to take), and a `PermissionRequest` hook runs when a tool call needs a permission decision. Either one can send back `updatedInput` to change what the tool call does.\n\nThat change is now allowed only when the hook runs in the same environment as the tool call. If a plugin hook ran on another machine and changed the input of a call that runs here, Claude Code:\n\n- refuses the call\n\n- tells Claude to carry on without it and to tell you that a plugin hook changes this tool's input\n\n- logs a warning and lets the plugin know its change was refused\n\n**Why**\n\nThis keeps a hook running elsewhere from quietly changing what happens on the machine doing the work. If you write plugins, calls whose input your hook changes across machines will now be denied.\n\n- Area: Hooks\n- Names: `updatedInput`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}