Skip to content

Expose agentId in subagentStart hook for secure parent-child policy correlation #5059

Description

@F4r4m4rz

Describe the feature or problem you'd like to solve

The subagentStart hook provides the parent session’s sessionId, but does not expose the agentId of the subagent being started.

Subsequent hooks triggered by that subagent, such as preToolUse, use the subagent’s agentId as their sessionId. This means there is currently no deterministic way to associate a subagent’s tool calls with the parent session before those tool calls occur.

This becomes a problem when implementing security or policy enforcement around hooks. For example, a parent session may establish a policy context containing its working directory, repository, branch, and allowed operations. Subagents should inherit that context, but without knowing their agentId at subagentStart, their later preToolUse calls cannot be safely mapped back to the parent.

This is especially important in Fleet mode, where multiple subagents may execute concurrently and heuristic correlation based on working directory, timing, or agent name would not be reliable.

Proposed solution

Example prompts or workflows

No response

Additional context

No response

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:agentsSub-agents, fleet, autopilot, plan mode, background agents, and custom agentsarea:pluginsPlugin system, marketplace, hooks, skills, extensions, and custom agents

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions