Claude Code 2.1.288 hooks fail closed: a Sume spend guard script

Claude Code 2.1.288 now blocks a tool call when a PreToolUse hook can't match or serialize input. A small guard script for Sume paid calls.

6 min readSume
All posts

Claude Code 2.1.288 (2026-10-02) makes PreToolUse and PermissionRequest hooks fail closed: if matching fails or the tool input cannot be serialized to JSON, the call is blocked instead of running. That makes a Sume spend guard safer, because an error in the hook can no longer let a paid call through.

The script below blocks Sume write calls that lack an idempotency_key or a max_spend_usd.

What changed

The same release re-prompts when an OAuth scope grows and fixes an MCP call that ran twice for results over 16 MB. The hook change is the one that matters for guards.

At a glance

Hook outcomes under 2.1.288, read 2026-10-03.
SituationResult
Hook exits 0Call proceeds
Hook exits 2Call blocked, stderr shown
Matching fails or input not JSON-serializableCall blocked (fail closed)
Sume write call lacks idempotency_keyRejected by Sume

A guard script

A command hook reads JSON on stdin and exits with code 2 to block, writing a reason to stderr. The matcher should cover the Sume server's tools; adjust the name prefix to the name you gave the server.

Sume itself requires idempotency_key on write and paid tools and offers max_spend_usd as an option, so the script enforces the option you want to make mandatory.

#!/usr/bin/env python3
import json, sys

data = json.load(sys.stdin)
name = data.get("tool_name", "")
args = data.get("tool_input", {})
if name.startswith("mcp__sume__"):
    paid_like = "idempotency_key" in args
    if paid_like and "max_spend_usd" not in args:
        sys.stderr.write("Sume write call needs max_spend_usd")
        sys.exit(2)
sys.exit(0)

Limits and what is not verified

The script is a sketch: the tool-name prefix depends on your server name, and I did not run it against Claude Code. Hook configuration lives in Claude Code's settings, which this post does not reproduce.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume