In Claude Code, a "block" hook could let commands through

A hook that reads “Block commands that...” is supposed to block. Until Claude Code 2.1.294, according to the Claude Code release notes on GitHub, prompt and agent hooks written that way could allow exactly what they were meant to stop.
At a glance
- Claude Code 2.1.294, released on GitHub on October 8, lists two changes, a fix and an improvement, and both concern hooks whose text is written as a plain instruction to the model.
- The release improves how Stop and SubagentStop prompt hooks phrased as instructions, for example “Carry on if the build is broken”, are judged, so Claude should be less likely to quit early.
- The release notes do not explain what went wrong, which earlier versions were affected, or how the new judging works, so existing block hooks deserve a fresh test after updating.
If you have not followed hooks closely, the system started out narrower. Earlier community guides described hooks whose type “is always 'command'” and listed only six events: PreToolUse, PostToolUse, SessionStart, Stop, Notification and SubagentStop. Anthropic's documentation now names LLM prompts and subagents as handler types too, and both changes in this release concern those newer kinds of hooks.
Prompt and agent hooks like “Block commands that...” could allow what they should block
The first change is a plain bug fix. Prompt and agent hooks written as instructions, with “Block commands that...” given as the example, could end up allowing what they were supposed to block. Version 2.1.294, which landed on GitHub on October 8, fixes that behaviour.
The stakes depend on where such a hook sits. PreToolUse fires before a tool call executes and can block it, and a PreToolUse deny survives bypassPermissions and --dangerously-skip-permissions. A hook that wrongly said yes there opened a gate meant to stay shut even in those modes. The notes name no event for this fix, so treat PreToolUse as the case to check rather than a confirmed one.
Stop and SubagentStop hooks get improved judging on when Claude may quit
The second change targets the end of a turn. In Anthropic's documentation, Stop fires “When Claude finishes responding” and SubagentStop fires “When a subagent finishes”. Version 2.1.294 improves how prompt hooks on these events are judged when they are written as instructions, like “Carry on if the build is broken”.
According to a guide on vibecoding.app, Stop is one of the events that can block, and its typical uses are verification loops and “you're not done yet” checks. The release notes state the intended result plainly: Claude is less likely to stop early. They do not describe what the judging looked like before the change or after it.
How does a prompt hook reach a decision?
Anthropic's documentation describes hooks as “user-defined shell commands, HTTP endpoints, MCP tool calls, LLM prompts, or subagents that execute automatically at specific points in Claude Code’s lifecycle.” When an event fires and a matcher matches, Claude Code passes JSON context about the event to the handler, which can inspect it and optionally return a decision.
For a prompt or agent hook, the reader is a model, and your sentence is its whole brief. Picture a doorman handed a note about who to keep out: if he misreads it, the people on the list walk straight in.
A guide on vibecoding.app quotes Anthropic's documentation on why hooks exist at all: so that “certain actions always happen rather than relying on the LLM to choose to run them.” That is the promise a block hook is meant to keep.
In our view, that is the uncomfortable side of prompt hooks: they hand the guarantee back to a model reading English, and here the wording decided the outcome. The notes also omit which versions were affected and how the judging changed, likely the first question for anyone relying on block hooks.
Retesting block hooks after 2.1.294
After updating, rerun any prompt or agent hook phrased as “Block commands that...” against a command it should stop, and check whether Stop and SubagentStop hooks keep Claude working when the build is broken. The release notes do not say whether hooks on other events, or command and HTTP hooks, need similar attention.
Related stories
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
