Hooks
Attach your own scripts before and after tool calls, and block when needed. Works with system notifications and tool approval.
Drop in a script
Put a script in your project's .neox/hooks/ or the user-level ~/.neox/hooks/ directory, and Neox runs it at the matching moment:
.neox/hooks/
pre-tool-call before a tool runs — can block it
post-tool-call after a tool runs
pre-session before a session starts
post-session after a session endsScripts can be .sh / .py / .js, or extension-less. At runtime they receive a JSON payload on stdin (tool name, arguments, etc.) and can read these environment variables: NEOX_HOOK_TYPE, NEOX_TOOL_NAME, NEOX_WORKSPACE, NEOX_SESSION_ID.
The exit code is the verdict:
| Exit code | Result |
|---|---|
0 | Allow |
1 | Block this tool call (pre-* only) |
2 | Block, and return the script's output to the agent as the reason |
Scripts are killed after 10 seconds without returning.
Match specific tools only
Configure matchers in .neox/settings.json (or ~/.neox/settings.json) instead of spawning a process for every call:
{
"hooks": {
"PreToolUse": [
{
"matcher": "execute_shell|write_file",
"hooks": [{ "type": "command", "command": "./guard.sh", "timeout": 10 }]
}
],
"PostToolUse": []
}
}matcher is a regex over tool names; leave it empty to match all. Exit with code 2 to block, or print {"decision":"block","reason":"..."} — the reason is returned to the agent.
Project-level and user-level configs both apply; project-level runs first.
System notifications
Neox notifies you when a background task finishes or the context approaches its limit:
- macOS — native notifications
- Linux —
notify-send - Windows — system toast
To turn them off:
NEOX_OS_NOTIFICATIONS=offTool-call approval
When writing files or running shell commands, Neox asks for confirmation based on risk level. Three approval modes:
- Auto (default) — only critical operations ask for confirmation
- Manual — confirm everything other than reading
- Dangerous — nothing asks for confirmation
See Tool use.
Common patterns
- Run lint before commits; block on failure
- Record every agent file write into your own audit log
- Block changes to production directories, returning the reason so the agent picks another path
- Archive artifacts automatically when a session ends

