github / github/copilot-cli

Plugin-defined preToolUse hooks (hooks.json) do not fire - neither in main session nor subagents

Aperta
#2,540 7 commenti 4 reazioni 0 assegnatari Vedi su GitHub
area:agents area:plugins area:sessions
Lingua principale
Shell
Stelle
11.2k
Fork
1.9k
Merge medio
14h 16m
PR unite (30g)
6

Descrizione

### Describe the bug

preToolUse hooks defined in a plugin's `hooks.json` file are never executed. The hooks don't fire in the main agent session or in subagents spawned via the `task` tool.

This is distinct from #2392, which reports that config.json-defined hooks work in the main session but not subagents. In our case, **plugin-sourced hooks don't fire anywhere**.

### Affected version

1.0.18 (macOS)

### Steps to reproduce the behavior

1. Install a local plugin that defines a `preToolUse` hook in `hooks.json`:
```json
{
"version": 1,
"hooks": {
"preToolUse": [
{
"type": "command",
"bash": "./scripts/guardrails.sh",
"cwd": ".",
"timeoutSec": 10
}
]
}
}
```
2. The plugin's `plugin.json` references it with `"hooks": "hooks.json"`
3. The guardrails script outputs `{"permissionDecision": "deny", ...}` for matching commands (verified by running the script manually with piped JSON input)
4. Start a session in a project that has this plugin installed
5. Run a bash command that should be blocked (e.g., one containing `ghe-config-apply`)
6. **Result:** Command executes without any hook intervention
7. Manually running the same script with the same input correctly returns a deny decision

### Expected behavior

Plugin-defined preToolUse hooks should be loaded and executed for all tool calls, the same way config.json-defined hooks are.

### Additional context

- macOS, zsh, Copilot CLI 1.0.18
- Plugin installed via local path (`source.path` in config.json `installed_plugins`)
- The plugin's skills load and work correctly - only hooks are not firing
- Tested with two separate local plugins, both define preToolUse hooks in hooks.json, neither fires
- Related: #2392 (subagent hook enforcement), #2349 (hook allow short-circuit), #1730 (sessionStart hooks)

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by tracing how plugin.json references hooks.json and how plugin-defined preToolUse hooks are loaded before tool calls. Reproduce the issue with the local plugin and guardrails.sh, then compare that path with config.json-defined hooks and a command run in both the main session and a task subagent. Done means the plugin hook runs and its deny decision blocks matching commands in both contexts.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
shell
Ambito
cli
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
48/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.