A loaded hooks file is not a migrated security policy.Unsupported events and partial decisions require explicit acceptance tests.

Five mapped points.

Beforeprompt + tool

Reject prompts or deny tools; no pre-approval or input rewrite.

Aftertool result

Block with feedback or attach source-attributed context.

Lifecyclestart + stop

Startup is detached; Stop can force another paid model step.

Keep native controls authoritative.

5 / 10

Codex hook events supported

Regex

unanchored matcher behavior

Sync

command handlers only

Process

one config loaded at startup

Pin bridge + protocol. Reuse Host core peers.

Do not trade a missing peer for a duplicated Agent, Tools, Session, or Cordis closure.

Use the complete install and acceptance guide.

The canonical guide covers exact versions, plugin topology, supported events, semantic gaps, policy boundaries, cancellation, restart, and removal.

Read the complete guide