Skip to main content

Knox Hooks and Events

Knox uses Claude Code hooks to inspect actions before and after they run. Hooks let Knox operate outside the model context. This matters because prompt injection can influence a model, but it cannot directly rewrite the external hook process.

Hook Configuration

The hook configuration lives in:
The main wrapper is:
The main enforcement script is:

PreToolUse

PreToolUse is the primary prevention hook. It runs before tool execution for:
  • Bash
  • Monitor
  • PowerShell
  • Read
  • Write
  • Edit
  • MultiEdit
  • NotebookEdit
  • CronCreate
  • MCP tools matching mcp__*
Typical decisions:
  • allow
  • deny
  • hard block
  • sanitize command
  • write audit entry
Examples:
  • risky shell command: blocked
  • protected file write: blocked
  • MCP tool input with injection string: blocked
  • safe command: allowed and optionally audited

ConfigChange

ConfigChange protects Knox itself. It checks changes to settings/config files that might disable hooks or remove Knox enforcement. If a change appears to disable Knox, it is blocked.

UserPromptSubmit

UserPromptSubmit scans submitted prompts for prompt injection patterns before they reach the model context. When a critical injection is detected, Knox exits in a way that prevents the poisoned prompt from being included in context.

InstructionsLoaded

InstructionsLoaded scans loaded instruction files for prompt injection. This hook is mainly audit-oriented because loaded instruction events are not always blockable in Claude Code. It still gives immediate visibility into suspicious instruction content.

CronCreate Matcher and TaskCreated Hook

CronCreate is handled as a PreToolUse matcher. TaskCreated is a dedicated hook. Together they guard scheduled or autonomous work. These hooks matter because agents are less supervised during background execution. Use them to inspect:
  • scheduled prompts
  • cron-like tasks
  • autonomous task creation
  • repeatable workflows that may execute later

PostToolUse

PostToolUse writes audit events after actions. It can also provide additional session context after denials so the agent understands that policy enforcement is active.

PermissionDenied

PermissionDenied records denied permission events for audit and escalation tracking.

SubagentStart

SubagentStart records subagent activity and helps preserve attribution. This is important for Qoris-style harness workflows where multiple subagents can contribute to one user-visible worker goal.

FileChanged

FileChanged lets Knox notice policy/config changes such as updates to:

SessionStart and SessionEnd

SessionStart and SessionEnd maintain session state. They help with:
  • denial counters
  • audit grouping
  • cleanup
  • session summaries

Event Summary

Developer Safety Pack Angle

For product packaging, these hooks support the claim:
Knox checks developer-agent actions before execution, protects its own enforcement path, and records an audit trail for every important decision.