How do I check a Claude Agent SDK tool call without touching the prompt?

Register a hook: a callback the SDK invokes at a named point in the loop, most usefully PreToolUse before a tool call runs or PostToolUse after it returns. The callback receives the tool’s name and arguments, or its result for PostToolUse, and it runs in your own process, entirely outside the model’s context, so nothing about the check has to be phrased as an instruction the model might ignore or forget.

A matcher pattern scopes a hook to specific tools, "Write|Edit" for file writes or a regex like ^mcp__ for every MCP tool, or you can omit it to run on every call. The callback’s return value decides what happens next: an empty object lets the call through unchanged, while a permissionDecision of deny blocks it and hands the model a reason it can act on, rather than a call that just silently vanished. A PostToolUse hook can’t stop a call already made, but it can attach additionalContext to the result before the model reads it. A hook scoped to ^mcp__ is a natural place to catch an MCP call failing in a way the model itself never sees, before it reaches the rest of the loop.

sources

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y