GitHub Copilot hooks
Hooks are preview functionality and execute with VS Code's permissions. Use
them only when behavior must execute deterministically at an agent lifecycle
event. Inspect the installed version and active hook schema before authoring.
Workflow
- Inspect the active host's hook schema, policies, event payload, extension
platform, and Agent Debug Logs.
- Choose the narrowest event:
SessionStart, UserPromptSubmit, PreToolUse,
PostToolUse, PreCompact, SubagentStart, SubagentStop, or Stop.
- Put workspace configuration in
.github/hooks/<purpose>.json. Use a narrow
Python 3.11+ handler when input-dependent logic is required.
- Read one JSON object from stdin; validate event name and required fields;
treat prompts and tool inputs as untrusted data.
- Emit only documented JSON to stdout. Put diagnostics on stderr, bound runtime
with a timeout, and choose fail-open/fail-closed behavior explicitly.
- Test synthetic allow, deny, malformed, unrelated-tool, and timeout payloads
before enabling the hook.
Rules
- Do not interpolate untrusted hook fields into a shell command.
- Do not hardcode credentials or parse the unstable transcript format when a
documented input field suffices.
- Do not rely on matcher filtering across hosts; validate
tool_name yourself.
- Use
PreToolUse for a single permission decision; reserve session stopping
for a genuine session-wide condition.
- Never enable or distribute a hook without making its executable behavior visible.
Read events and results, use safe handler
patterns, and run verification.
Completion
JSON parses, the handler is injection-safe and bounded, all branches have
offline tests, platform commands are explicit, no secret is stored, preview
status is stated, and a separately authorized VS Code smoke confirms the event.
1---2name: github-copilot-hooks3description: Use for creating, reviewing, debugging, or testing GitHub Copilot agent hooks in Visual Studio Code, including .github/hooks JSON, lifecycle events, Python handlers, permissions, and structured stdin/stdout. Do not use for advisory instructions, one-off commands, CI workflows, or shell profile hooks.4---56# GitHub Copilot hooks78Hooks are preview functionality and execute with VS Code's permissions. Use9them only when behavior must execute deterministically at an agent lifecycle10event. Inspect the installed version and active hook schema before authoring.1112## Workflow13141. Inspect the active host's hook schema, policies, event payload, extension15 platform, and Agent Debug Logs.162. Choose the narrowest event: `SessionStart`, `UserPromptSubmit`, `PreToolUse`,17 `PostToolUse`, `PreCompact`, `SubagentStart`, `SubagentStop`, or `Stop`.183. Put workspace configuration in `.github/hooks/<purpose>.json`. Use a narrow19 Python 3.11+ handler when input-dependent logic is required.204. Read one JSON object from stdin; validate event name and required fields;21 treat prompts and tool inputs as untrusted data.225. Emit only documented JSON to stdout. Put diagnostics on stderr, bound runtime23 with a timeout, and choose fail-open/fail-closed behavior explicitly.246. Test synthetic allow, deny, malformed, unrelated-tool, and timeout payloads25 before enabling the hook.2627## Rules2829- Do not interpolate untrusted hook fields into a shell command.30- Do not hardcode credentials or parse the unstable transcript format when a31 documented input field suffices.32- Do not rely on matcher filtering across hosts; validate `tool_name` yourself.33- Use `PreToolUse` for a single permission decision; reserve session stopping34 for a genuine session-wide condition.35- Never enable or distribute a hook without making its executable behavior visible.3637Read [events and results](references/artifact-contracts.md), use [safe handler38patterns](references/patterns.md), and run [verification](references/verification.md).3940## Completion4142JSON parses, the handler is injection-safe and bounded, all branches have43offline tests, platform commands are explicit, no secret is stored, preview44status is stated, and a separately authorized VS Code smoke confirms the event.