PreToolUse
Runs before a tool executes.
Best for:
- Blocking unauthorized transactions.
- Enforcing refund limits.
- Checking prerequisites.
- Preventing policy violations.
Example: Refund > $500 → block and escalate before process_refund executes.
PostToolUse
Runs after a tool returns.
Best for:
- Trimming verbose results.
- Normalizing MCP outputs.
- Keeping only fields needed by the agent.
Example: Tool returns 40 fields → retain status, shipping date and tracking number.
Escalation: Good Triggers
- Explicit request for a human.
- Policy gap.
- Permission boundary.
- High-risk operation.
- Deterministic hook blocks an action.
Escalation: Bad Triggers
- Negative sentiment alone.
- Profanity alone.
- Self-reported model confidence alone.
Memory: Prompts guide. Hooks enforce.