Skip to content
CCAR-FAcademy
Domain 1 · Statement 1.5 5 of 7
1.5

Apply Agent SDK hooks for tool call interception and data normalization

  • PostToolUse hooks intercept tool results and transform them before the model processes them — the right place for data normalization.
  • Outgoing tool-call interception hooks enforce compliance by blocking policy-violating actions before they execute.
  • A blocked call should redirect to an alternative workflow (e.g. human escalation), not just return an opaque error.
  • Choose hooks when a business rule requires guaranteed compliance; choose prompt instructions only for judgment-based guidance.
  • Normalizing timestamps, status codes and units in code removes reasoning the model would otherwise do imperfectly and for free tokens.
  • Hooks are auditable artifacts — a reviewer can verify a few lines of code instead of sampling model behavior.

Hooks are the Agent SDK's interception points around tool use. They matter for two reasons the exam cares about: data normalization on the way in, and policy enforcement on the way out. Both give you deterministic behavior in a system that is otherwise probabilistic.

PostToolUse: transform results before the model sees them

A PostToolUse hook fires after a tool executes and before the result enters the model's context.10 That is the right place to normalize heterogeneous formats. In practice an agent talks to several MCP servers written by different teams: one returns Unix epoch seconds, another ISO 8601 strings, a third returns numeric status codes where a fourth returns human labels. Left alone, the model spends tokens reconciling formats and occasionally gets it wrong — comparing a 10-digit epoch to a date string, or guessing that status 3 means shipped.

Normalizing in a PostToolUse hook means the model only ever sees one canonical shape: ISO 8601 timestamps, an enumerated status vocabulary, consistent currency units. The transformation is code, so it is exact and free of reasoning cost. It also keeps tool descriptions honest: you are not documenting four date formats and hoping.

Interception on the outgoing side: enforce policy

The mirror-image pattern intercepts an outgoing tool call and can block it. This is where business rules with hard boundaries live — refunds above $500, deletions outside a sandbox, writes to production. A blocked call should not merely fail: it should redirect to an alternative workflow, typically by returning a denial that tells the agent to escalate instead.13 The agent then calls escalate_to_human on the next iteration, and the outcome is a correct escalation rather than an error.

Deterministic vs probabilistic compliance

The decision rule the exam wants: a business rule that must always hold goes in a hook; guidance goes in the prompt.11

Mechanism Put the rule here when Compliance you get Worked example
Interception hook The rule is a hard boundary that must always hold Deterministic — checked in code against the actual tool input "Never refund more than $500 without approval"
Prompt instruction The rule is guidance the model should weigh Probabilistic — a non-zero failure rate you have accepted "Prefer offering a replacement before a refund for damaged goods"

Hooks are also independently auditable: you can point a compliance reviewer at a few lines of code rather than at a distribution of model behavior.

The two patterns compose. Normalize inputs so the model reasons over clean data, gate outputs so its decisions cannot cross a hard line, and reserve the prompt for everything that genuinely requires judgment.

PostToolUse normalization before the model sees the resultShow that heterogeneous MCP results pass through a PostToolUse hook and reach the model in a single canonical shape.ClaudeClaudeMCP tool A epoch secondsMCP tool AepochsecondsMCP tool B ISO 8601MCP tool BISO 8601PostToolUse hookPostToolUsehookCanonical result in contextCanonicalresult incontexttool_use requesttool_use requestraw result1772585501raw result2026-03-01T12:00:00ZISO 8601 plusstatus vocabularyone consistentformat only
PostToolUse normalization before the model sees the result

Show that heterogeneous MCP results pass through a PostToolUse hook and reach the model in a single canonical shape.

one transition at a time
Hook enforcement vs prompt guidanceGive the learner a decision rule: hard business rules go in hooks for deterministic guarantees, judgment calls go in the prompt.Hook enforcementprompt guidanceHard business ruleHard businessruleInterception hookInterception hookDeterministic guaranteeDeterministicguaranteeJudgment callJudgment callPrompt instructionPrompt instructionProbabilistic complianceProbabilisticcompliancerefund ceiling, prerequisiteorderingenforced on tool input in codetone,replacement-before-refundpreferencenon-zero failure rate accepted
Hook enforcement vs prompt guidance

Give the learner a decision rule: hard business rules go in hooks for deterministic guarantees, judgment calls go in the prompt.

Click a rule type to reveal a worked example of each.

PostToolUse normalization across heterogeneous MCP tools

Scenario 1 · Customer Support Resolution Agent

lookup_order (legacy service) returns { created: 1772585501, status: 3 }. get_customer (new service) returns { createdAt: "2026-03-01T12:00:00Z", status: "active" }. A billing MCP server returns amounts in cents; another in dollars.

A PostToolUse hook maps every result into one canonical shape before it reaches the model. The agent then compares dates, reasons about statuses and totals amounts without ever seeing the underlying inconsistency — and without you having to describe four formats in tool descriptions.

typescript
const STATUS_CODES: Record<number, string> = {
  1: 'pending', 2: 'processing', 3: 'shipped', 4: 'delivered', 5: 'canceled',
};

// PostToolUse: runs after the tool executes, before the model sees the result.
function normalizeToolResult(toolName: string, raw: unknown) {
  const out = structuredClone(raw) as Record<string, any>;

  // Unix epoch seconds -> ISO 8601
  for (const key of ['created', 'updated', 'createdAt', 'updatedAt']) {
    const v = out[key];
    if (typeof v === 'number') out[key] = new Date(v * 1000).toISOString();
  }

  // Numeric status codes -> enumerated vocabulary
  if (typeof out.status === 'number') {
    out.status = STATUS_CODES[out.status] ?? 'unknown';
  }

  // Cents -> decimal currency, always with an explicit unit
  if (typeof out.amountCents === 'number') {
    out.amount = out.amountCents / 100;
    out.currency = out.currency ?? 'USD';
    delete out.amountCents;
  }

  return out; // the model only ever sees the canonical shape
}
PostToolUse hook normalizing timestamps, statuses and currency

Blocking a refund above threshold and redirecting to escalation

Scenario 1 · Customer Support Resolution Agent

Policy: refunds above $500 require human approval. A prompt instruction gets this right most of the time; a hook gets it right every time.

The interception hook inspects the outgoing process_refund call, denies it when the amount exceeds the threshold, and returns a reason that names the alternative. The agent reads the denial in its next iteration and calls escalate_to_human with a structured handoff (see 1.4). Note that the check runs on the tool input, so it cannot be talked around.

typescript
const REFUND_LIMIT = 500;

function interceptToolCall(toolName: string, input: Record<string, any>) {
  if (toolName === 'process_refund' && Number(input.amount) > REFUND_LIMIT) {
    return {
      decision: 'deny' as const,
      reason:
        'Blocked: refunds above $' + REFUND_LIMIT + ' require human approval. ' +
        'Call escalate_to_human with the customer ID, root cause, amount and a ' +
        'recommended action instead.',
    };
  }
  return { decision: 'allow' as const };
}

// Deterministic: the limit is enforced on the actual tool input, so no prompt
// wording, jailbreak or reasoning slip can exceed it.
Outgoing tool-call interception with redirection

Choosing the mechanism: hook or prompt?

Scenario 1 · Customer Support Resolution Agent

Sort each rule by whether a single violation is acceptable.

Rule What one violation costs Mechanism
"Refunds over $500 need approval" A financial incident Hook
"Never call process_refund before identity is verified" Money sent to the wrong account Hook — a prerequisite gate (1.4)
"Offer a replacement before a refund for damaged goods under warranty" A suboptimal but defensible choice Prompt
"Match the customer's tone; be concise" A worse reply, nothing more — pure judgment Prompt
"Timestamps must be ISO 8601 before reasoning" The model converts epochs itself, imperfectly PostToolUse hook, not a prompt instruction

The trap on the exam is an option that proposes prompt reinforcement for something in the first two rows, or an elaborate classifier/ML pipeline for something in the last row.

  • Relying on prompt instructions to enforce a hard business rule such as a refund ceiling instead of an interception hook because prompt compliance is probabilistic and one violation is one financial incident.
  • Asking the model to normalize heterogeneous timestamps, status codes or units in its reasoning instead of doing it in a PostToolUse hook because you pay tokens for work code does exactly and for free.
  • Blocking a policy-violating tool call with an opaque error and no alternative instead of redirecting to an escalation workflow because the agent has no path forward and the customer gets a dead end.
  • Deriving enforcement state from what the model says rather than from actual tool inputs and results because the hook then trusts the very thing it is meant to constrain.
  • The phrase "guaranteed", "always", "must never" in a stem is a hook signal; "prefer", "when appropriate", "calibrate" is a prompt signal.
  • PostToolUse is the term the guide uses for intercepting results before the model processes them — expect it named explicitly in options about data format inconsistency across MCP tools.
  • Distractors often propose a self-reported confidence score, a sentiment threshold, or a separately trained classifier where a deterministic hook or a prompt tweak is the proportionate answer; prefer the mechanism that matches the rule's hardness.
References — 3 sources
  1. Hooks reference Anthropic The `PreToolUse` schema that implements a prerequisite gate, and `PostToolUse`’s `updatedToolOutput`, which replaces a tool result before it reaches the model.
  2. Configure permissions Anthropic The allow/ask/deny rule layer and the `canUseTool` callback — the availability controls, none of which expresses an ordering constraint.
  3. Intercept and control agent behavior with hooks Anthropic The SDK callback form of tool-call interception, for building on the Agent SDK rather than settings files.
All sources verified ·

Live product docs — where they differ from the exam guide, answer from the guide. All references

Exam guide, verbatim — what is measured

Knowledge of

  • Hook patterns (e.g., PostToolUse) that intercept tool results for transformation before the model processes them
  • Hook patterns that intercept outgoing tool calls to enforce compliance rules (e.g., blocking refunds above a threshold)
  • The distinction between using hooks for deterministic guarantees versus relying on prompt instructions for probabilistic compliance

Skills in

  • Implementing PostToolUse hooks to normalize heterogeneous data formats (Unix timestamps, ISO 8601, numeric status codes) from different MCP tools before the agent processes them
  • Implementing tool call interception hooks that block policy-violating actions (e.g., refunds exceeding $500) and redirect to alternative workflows (e.g., human escalation)
  • Choosing hooks over prompt-based enforcement when business rules require guaranteed compliance
Back to top