What struck me is how unglamorous the answer is. The article is basically saying: if you want to prevent a side effect, stop pretending the after-the-fact hook can save you. That sounds obvious once you say it out loud, but I still see people reach for the wrong extension point because it feels cleaner to “observe, then decide.” In agentic systems, that’s often too late.
The useful bit here is not the PreToolUse versus PostToolUse naming itself. It’s the insistence that a real gate belongs before execution, and that the tool service still has to enforce the same rule again. That second part is where a lot of teams get lazy. They treat the hook as the security boundary. It isn’t. It’s one boundary in a layered flow, and the actual business action still needs its own authorization, validation, and idempotency. If you skip that, you’ve built a demo with a permission check, not a production system.
I also liked the warning about async hooks. That detail matters because it’s the kind of thing that looks innocuous in a sample and becomes a footgun in production. If the hook can’t block, it’s not a gate, full stop. That’s the sort of distinction SDK docs should hammer harder, because the names make the wrong thing feel possible.
The article does a decent job separating “ask” from “allow,” though I’d still be careful about overreading the approval flow. Returning ask does not magically create a human-in-the-loop UI; you still need the handler on your side. That’s exactly the sort of place teams assume the framework will do more than it does.
One small thing I appreciated: the reminder that Agent SDK hooks and Claude Code hooks are not the same animal. People mix those up constantly, and then wonder why a policy works in one place and disappears in another. That confusion is not a footnote; it’s probably where half the implementation bugs will come from.
If I were wiring this up, I’d test the blocked paths first, not last. The article’s suggested checks are the right instinct: missing fields, over-limit requests, duplicate retries, lookup failures. A lot of teams test the happy path until the system is already talking to something expensive or irreversible. That’s backwards.
Reference: PreToolUse or PostToolUse? Where to Put a Check in the Claude Agent SDK