# The model read the rule. It moved on.

> Instructions ask. Hooks enforce.

- **Format:** short video, 9 steps, ~50 seconds
- **Topic:** GitHub Copilot hooks for beginners — why an instruction is a request the model may drop, and how a preToolUse hook runs a script outside the model to deny a command, such as a commit with a Flutter import in the domain layer, before it runs.
- **Author:** Suthahar Jegatheesan (MSDEVBUILD)
- **Category:** GitHub Copilot · copilot
- **Published:** 2026-03-19
- **Tags:** githubcopilot, aiagents, devops, flutter, cleanarchitecture, automation, aicoding, msdevbuild
- **Canonical URL:** https://blog.msdevbuild.com/shorts/copilot-hooks-deny-before-it-runs/

---
## What you'll learn

- Why an instruction can be weighed and dropped by the model
- What a preToolUse hook is and where it runs
- How to write a guard script that exits 1 to deny

## Understand it one step at a time

### 1. A tidy annotation

The agent adds a Flutter import to a domain entity to get @immutable.

### 2. The rule was written down

AGENTS.md says it. The model read it and weighed it against a tidy annotation.

### 3. Commit, then CI fails

Without a hook, the commit goes through and CI fails twenty minutes later.

### 4. A hook runs outside the model

A preToolUse hook runs a script before the agent executes any tool.

### 5. The check is one grep

grep -rn "package:flutter/" lib/domain/ — any match, exit 1.

### 6. Same mistake, now denied

The agent asks to run git commit. The hook runs first and refuses.

### 7. The agent fixes it

It reads the reason, removes the import, and the next command is allowed.

### 8. One rule, one script

The Copilot hook calls the same script as the git pre-commit hook.

### 9. Instructions ask, hooks enforce

Trust the model for ideas. Trust your hooks for rules.

---

## The takeaway

**Instructions ask. Hooks enforce.**

A preToolUse hook runs outside the model, so it refuses the same mistake every time.
