Audit dormant async hooks before they wake up
Use
when:
upgrading
Codex
CLI
to
0.148.0,
importing
hooks,
or
enabling
a
plugin
containing
hooks.
A
command
handler
marked
async:
true
was
previously
parsed
but
skipped
outside
SessionEnd;
it
now
runs
in
the
background.
Any
“pre”
hook
that
operators
thought
was
dormant
can
therefore
begin
making
network
calls,
writing
files,
or
emitting
context
after
the
triggering
operation
has
already
continued.
async:
true
for
bounded
telemetry,
notifications,
and
advisory
analysis
whose
late
result
is
harmless.
In
a
staging
workspace,
configure
one
delayed
asynchronous
PreToolUse
canary
that
writes
an
owned
sentinel
and
returns
a
block
request;
configure
a
synchronous
twin
against
a
second
harmless
command.
Open
/hooks
and
record
each
handler’s
displayed
Mode.
Trigger
both
commands,
preserve
hook
start/completion
receipts,
then
inspect
when
the
sentinel
and
any
model-visible
context
arrive.
Keep
SessionEnd
synchronous.
Acceptance
check:
pass
only
if
/hooks
labels
the
canary
Async,
the
first
harmless
command
proceeds
without
waiting
and
is
not
blocked
or
rewritten,
and
its
sentinel
appears
later
at
a
safe
turn
boundary.
The
synchronous
twin
must
delay
or
block
its
command
as
configured.
Shutdown
must
cancel
unfinished
async
work,
and
no
sentinel
may
leak
into
another
thread.
Fail
the
rollout
if
an
async
handler
can
change
the
originating
operation,
if
completion
is
unreceipted,
or
if
concurrency
exceeds
the
intended
per-session
bound.
Caveat: asynchronous means non-authoritative, not safe. The process still receives event data and can cause external side effects on its own. Review commands and credentials, set timeouts and output limits, and treat delayed model context as untrusted observation. Documentation is temporarily contradictory, so pin 0.148.0 and rerun this canary after upgrades.