feat(extensions): let tool_call handlers revise tool input

A `tool_call` handler (extension or hook) could previously only block a
tool. It can now also return `input` to replace the arguments the tool
executes with, so a handler can normalize or rewrite a built-in's input
without reimplementing the tool.

The returned object is the raw execution input passed to the tool's
`execute` (the handler owns its correctness), not the normalized
`event.input` view, which may carry derived gate-only fields (e.g.
hashline `edit` `path`/`paths`) that are not real parameters. It is
ignored when `block` is set, and not applied to `computer` tool calls
whose event input is a synthetic actions view rather than the real
params. When multiple handlers set `input`, the last one wins.

Honored in both the extension and hook tool wrappers; documented in
docs/extensions.md, docs/hooks.md, and docs/skills/authoring-hooks.md.
This commit is contained in:
Larry Gordon
2026-07-25 23:16:04 -07:00
parent 667111575e
commit ed457a9d4f
9 changed files with 237 additions and 12 deletions
+1 -1
View File
@@ -252,7 +252,7 @@ Cancelable pre-events:
### Tool lifecycle
- `tool_call` (pre-exec, may block)
- `tool_call` (pre-exec, may block, or revise the tool's execution `input`)
- `tool_result` (post-exec, may patch content/details/isError)
- `tool_execution_start` / `tool_execution_update` / `tool_execution_end` (observability)
- `tool_approval_requested` / `tool_approval_resolved` (observability; emitted by `wrapper.ts` only when a tool requires approval and an approval handler is registered)