Skip to main content

Installation

Adapter Status

The Anthropic Agent SDK has a dedicated result helper: checkAnthropicToolUse. The helper returns a tool_result error block. Your SDK tool loop must call it before execution and must not execute the tool when it returns a rejection. Claude Code command hooks use a different host contract. A valid PreToolUse denial can block a covered call, but a command-hook timeout, process failure, or malformed result can continue through Claude Code’s normal permission flow. Do not describe a Claude Code command hook as a complete fail-closed boundary. Use the generic model-budget helpers recordModelUsage and checkModelBudget around Anthropic SDK responses when the host owns the model loop and can read response usage. HTTP note: emit a typed http intent only when the intercepted tool input explicitly contains a valid method. Otherwise retain web_fetch; never infer GET.

Usage

checkAnthropicToolUse does not register itself with Claude Code and cannot stop a tool if the host never calls it. For Claude Code command hooks, test both a policy denial and a hook timeout before making a coverage claim.

Tool Name Mapping

checkAnthropicToolUse maps Anthropic tool names to Sigil action types automatically:

What Gets Sent to Sigil

For each tool call, the following intent is submitted to /v1/authorize:

Rejection Response

When Sigil denies or holds an action, checkAnthropicToolUse returns a tool_result error block that Claude understands:
Claude will receive this as a tool error and adjust its behavior accordingly.

Configuration