Knox Hooks and Events
Knox uses Claude Code hooks to inspect actions before and after they run. Hooks let Knox operate outside the model context. This matters because prompt injection can influence a model, but it cannot directly rewrite the external hook process.Hook Configuration
The hook configuration lives in:PreToolUse
PreToolUse is the primary prevention hook.
It runs before tool execution for:
- Bash
- Monitor
- PowerShell
- Read
- Write
- Edit
- MultiEdit
- NotebookEdit
- CronCreate
- MCP tools matching
mcp__*
- allow
- deny
- hard block
- sanitize command
- write audit entry
- risky shell command: blocked
- protected file write: blocked
- MCP tool input with injection string: blocked
- safe command: allowed and optionally audited
ConfigChange
ConfigChange protects Knox itself.
It checks changes to settings/config files that might disable hooks or remove Knox enforcement.
If a change appears to disable Knox, it is blocked.
UserPromptSubmit
UserPromptSubmit scans submitted prompts for prompt injection patterns before they reach the model context.
When a critical injection is detected, Knox exits in a way that prevents the poisoned prompt from being included in context.
InstructionsLoaded
InstructionsLoaded scans loaded instruction files for prompt injection.
This hook is mainly audit-oriented because loaded instruction events are not always blockable in Claude Code. It still gives immediate visibility into suspicious instruction content.
CronCreate Matcher and TaskCreated Hook
CronCreate is handled as a PreToolUse matcher. TaskCreated is a dedicated hook.
Together they guard scheduled or autonomous work.
These hooks matter because agents are less supervised during background execution.
Use them to inspect:
- scheduled prompts
- cron-like tasks
- autonomous task creation
- repeatable workflows that may execute later
PostToolUse
PostToolUse writes audit events after actions.
It can also provide additional session context after denials so the agent understands that policy enforcement is active.
PermissionDenied
PermissionDenied records denied permission events for audit and escalation tracking.
SubagentStart
SubagentStart records subagent activity and helps preserve attribution.
This is important for Qoris-style harness workflows where multiple subagents can contribute to one user-visible worker goal.
FileChanged
FileChanged lets Knox notice policy/config changes such as updates to:
SessionStart and SessionEnd
SessionStart and SessionEnd maintain session state.
They help with:
- denial counters
- audit grouping
- cleanup
- session summaries
Event Summary
Developer Safety Pack Angle
For product packaging, these hooks support the claim:Knox checks developer-agent actions before execution, protects its own enforcement path, and records an audit trail for every important decision.
