Local function-tool coverage
MVP1 targets compatible local Codex sessions. Shell calls map to Bash in the hook matcher. Supported local apply_patch, function, and MCP tool paths can provide pre-tool callbacks; hosted tools and some specialized paths are outside the default boundary.
The fixture adapter exists in the current source build. Live installation, event ingestion, and enforcement are pending.
Hook sources and user trust
The intended user-level integration preserves ~/.codex/hooks.json or the active configuration representation supported by the installed host. Existing JSON and TOML hooks must remain intact; do not replace the user’s configuration wholesale.
Nonmanaged Codex hooks require explicit review and trust. A newly installed or changed hook definition may be skipped until trusted. Onboarding must guide the user through /hooks, then verify actual execution. TraceRook does not bypass host trust.
External reference: Codex hooks reference.
Return only supported decisions
The specification requires validated hookSpecificOutput.permissionDecision = "deny" for denial and empty successful output for no TraceRook override. Human review waits inside the synchronous command hook.
Do not implement a review hold with permissionDecision: "ask", continue: false, or an unsupported field combination. The host can treat invalid pre-tool output as a failed hook and continue the call. Exact behavior must be tested against the detected release.
A continuation is not a new gate
Codex write_stdin sends input to or polls an existing unified-exec session. It does not necessarily run PreToolUse again. Later input and nested activity cannot be presented as independently intercepted tool calls without actual evidence.
Hosted WebSearch does not use the local function-tool hook path, and specialized tools can opt out. PostToolUse may arrive when the original command finishes; that is observation after execution.
What enables a verified status
Record installation, trust, version, adapter schema, actual callback receipt, pre-tool test time, and host-specific coverage notes. Installed and untrusted is Needs trust, not Protected.
Acceptance requires a harmless deny test proving the body never ran, high-risk Block and Allow once paths with native host permissions preserved, expiry rejection, and failure-state checks. Until then, the current app shows real activity as Not integrated.