AI CLI Hooks Comparison
Research on which AI CLI coding tools support hooks, what hooks enable, and whether they’re necessary safeguards or nice-to-have features.
Which AI Coding Tools Have Hooks?
CLI Tools
| Tool | Hooks System | Status |
|---|---|---|
| Claude Code | Full lifecycle hooks (PreToolUse, PostToolUse, Stop, SessionStart, etc.) | Comprehensive |
| GitHub Copilot CLI | Full lifecycle hooks (preToolUse, sessionStart, sessionEnd, userPromptSubmitted) | Comprehensive |
| Droid (Factory) | Pre-commit hooks, extensible hooks system (shipping soon) | Partial |
| Aider | Limited to git pre-commit hooks only (disabled by default via --no-verify) | Minimal |
| Codex CLI | MCP-based extension with hook types (e.g., SummarizationHook) | Limited |
| Goose | Recipes system for workflows, no execution hooks | None |
| Gemini CLI | No documented hooks system | None |
| Warp AI Terminal | Workflow automation (Warp Drive), no execution hooks | None |
IDE Tools
| Tool | Hooks System | Status |
|---|---|---|
| Cursor | Full lifecycle hooks (beforeShellExecution, beforeMCPExecution, beforeReadFile, afterFileEdit, stop, session hooks) | Comprehensive |
| Windsurf | Full lifecycle hooks (pre_read_code, post_read_code, post_write_code, post_mcp_tool_use, post_cascade_response) | Comprehensive |
| Kilo Code | MCP Server integration, automatic error recovery, no execution hooks | None |
| Amp (Sourcegraph) | MCP configuration, no execution hooks | None |
| Augment Code | Agent mode automation, no execution hooks | None |
| Cline | Plan/Act modes, MCP integration, no execution hooks | None |
| Roo Code | Mode-based automation, MCP servers, no execution hooks | None |
| Continue.dev | MCP support, configuration-as-code, no execution hooks | None |
| Trae IDE | VS Code extensions, MCP support, no execution hooks | None |
| Zed | MCP support, agent panel, no execution hooks | None |
Summary: Only Claude Code, GitHub Copilot CLI, Cursor, and Windsurf have comprehensive hooks systems. Droid is shipping hooks soon.
Detailed Hook Comparison
Claude Code Hook Events
Claude Code provides multiple hook events that fire at different workflow stages:
- SessionStart: Fires when a session begins or resumes
- UserPromptSubmit: Fires when the user submits a prompt, before Claude processes it
- PreToolUse: Fires before tool execution (enables security scanning and blocking)
- PermissionRequest: Fires when a permission dialog appears
- PostToolUse: Fires after tool execution succeeds
- Notification: Fires when Claude Code sends notifications
- Stop: Fires when the main Claude Code agent finishes responding
- SubagentStop: Fires when subagent tasks complete
- PreCompact: Fires before compact operations
Hook Types:
- Command-Based Hooks: Execute bash scripts at specified lifecycle points (60-second default timeout)
- Prompt-Based Hooks: Use an LLM (Haiku) to evaluate whether to allow or block actions with intelligent decisions
{
"hooks": {
"PostToolUse": [
{
"matcher": "Write|Edit",
"hooks": [
{
"type": "command",
"command": "prettier --write $FILE_PATH",
"timeout": 30
}
]
}
]
}
} Cursor Hook Events
Cursor hooks (introduced in v1.7, beta feature) communicate over stdin/stdout using JSON:
- beforeShellExecution: Intercept shell commands before they run (can block)
- beforeMCPExecution: Control tool execution before MCP interactions (can block)
- beforeReadFile: Observe or block file reads
- afterFileEdit: Execute scripts after code modifications
- stop: Trigger actions when an agent session completes
- Session start/end hooks: Added January 2026
- Prompt hooks: Added January 2026
Configuration in ~/.cursor/hooks.json.
Windsurf Hook Events
Windsurf hooks receive JSON context and return results via exit codes:
- pre_read_code / post_read_code: Before/after reading code files
- pre_write_code / post_write_code: Before/after writing code files
- post_mcp_tool_use: After MCP tool invocation (logs server, tool, args, result)
- post_cascade_response: After Cascade completes a response (full audit trail)
- pre_user_prompt: Can block prompts containing prohibited content
Pre-hooks can block actions by exiting with exit code 2.
GitHub Copilot CLI Hook Events
Hooks configured in .github/hooks/*.json:
- sessionStart: Environment initialization, audit logging
- sessionEnd: Cleanup, session report generation
- userPromptSubmitted: Audit logging of user requests
- preToolUse: Most powerful — can approve/deny tool executions, block dangerous commands
Supports bash (Unix) and PowerShell (Windows) scripts with configurable timeouts.
What Hooks Enable That’s Impossible/Hard Without Them
1. Deterministic Security Enforcement (Impossible without hooks)
- Block destructive commands before execution (
rm -rf /,DROP DATABASE,git push --force origin main) - Without hooks: You can only detect damage after it happens — the data is already gone
- Real-world example: A fintech startup blocked 12 destructive commands in one week with zero incidents
2. File/Directory Protection (Impossible without hooks)
- Block modifications to production configs,
.envfiles, or sensitive directories - PreToolUse hooks intercept before the filesystem is touched
- Post-hoc scanning (SAST/DAST) cannot prevent file destruction
3. Mandatory Code Signing/Validation (Very hard without hooks)
- Enforce GPG signing on commits
- Require code formatting (prettier, gofmt) on every file write
- Without hooks: Relies on the LLM “remembering” to do this — probabilistic, not guaranteed
4. Audit Logging & Compliance (Hard without hooks)
- Automatic logging of every AI action with timestamps
- Required for SOC2, HIPAA, or enterprise compliance
- Without hooks: Requires manual review of session history
5. Eliminating LLM Probabilistic Behavior (Impossible without hooks)
- Claude might remember to run tests in one session but forget in the next
- Hooks make behavior deterministic: “When you edit TypeScript, prettier runs. Always.”
- Key insight: “No decisions, no memory requirements, no variance”
6. Context Injection (Very hard without hooks)
- Inject reminders or context into specific tool calls without blocking
- Example: “Remember to use the v2 API when calling this service”
- Without hooks: Must rely on system prompts or hope the LLM remembers
7. Real-Time Notifications (Hard without hooks)
- Push notifications when long tasks complete or when awaiting input
- Reported 45% reduction in context switching with voice notifications
Implementation Phases (Enterprise Adoption)
Organizations typically implement hooks in three phases:
- Phase 1: Basic Setup - Configure foundational hooks for logging, notifications, and monitoring
- Phase 2: Enhancement Hooks - Add hooks for custom notifications, automatic formatting, and convenience shortcuts
- Phase 3: Enforcement Hooks - Introduce sophisticated control through file protection, security scanning, and build validation
Real-World Results
Organizations implementing comprehensive hook systems report:
- Zero destructive commands executed (with 12 blocked in one week)
- 100% test coverage maintained automatically
- Real-time visibility into all agent operations
- 45% reduction in context switching through voice notifications
- Elimination of parallel agent conflicts through coordination
Verdict: Necessary Safeguard or Nice-to-Have?
For individual developers: Nice-to-have convenience features (auto-formatting, notifications)
For teams/enterprises: Necessary safeguard because:
- Prevention vs. Detection: Hooks prevent disasters; without them you can only audit after the fact
- Compliance Requirements: Many industries require audit trails and access controls
- Eliminating Human Error: Deterministic enforcement removes reliance on LLM “memory”
- Zero-Trust Principle: You cannot fully trust probabilistic AI behavior for security-critical operations
The critical insight: Without PreToolUse hooks, there is no execution point between the AI’s decision and filesystem/system changes. By the time you detect a problem, the damage is done.
Why Hooks Matter for Enterprise Adoption
Tools with comprehensive hooks (Claude Code, GitHub Copilot CLI, Cursor, Windsurf) are better positioned for enterprise adoption because hooks transform AI coding assistants from probabilistic tools into deterministic, auditable systems suitable for production environments.
Tools without hooks (Kilo, Amp, Augment, Cline, Roo Code, Continue.dev, Trae, Zed) rely on:
- MCP for extensibility (good for adding capabilities, not for security enforcement)
- Mode-based workflows (good for UX, not for deterministic control)
- Post-hoc review (cannot prevent damage, only detect it)
Key Differences: MCP vs Hooks
| Aspect | MCP (Model Context Protocol) | Hooks |
|---|---|---|
| Purpose | Add capabilities (tools, context) | Control/intercept behavior |
| Timing | Provides tools for AI to use | Intercepts before/after AI acts |
| Security | Cannot block dangerous operations | Can block before execution |
| Use Case | ”Give AI access to GitHub API" | "Block AI from deleting production files” |
Many tools have MCP but lack hooks. MCP is complementary, not a replacement for hooks.
Related Notes
- claude-code-2.0
- cursor
- windsurf
- aider
- goose
- codex
- kilo-code
- cline-custom-instructions
- roo-code
Sources
- Perplexity research (January 2026)
- Claude Code official documentation
- Cursor hooks documentation (v1.7+)
- Windsurf hooks documentation
- GitHub Copilot CLI documentation
- Community implementation reports