Use a pre-tool hook when the agent should not run arbitrary shell or network calls.

Start with an allowlist of safe tools, then deny everything else for sensitive repos.

Log denials so you can see which prompts keep asking for blocked tools.

Test with a tiny task that tries a denied tool and confirm it stops cleanly.

Keep hooks in version control so teammates get the same guardrails.

Change one variable at a time and confirm what actually helped.

If a company policy is involved, rule that out before chasing client settings.

Write the working steps into a short checklist for next time.

Export or screenshot a good setup so reinstalls are faster.

If it still flakes, retest on a clean network such as phone hotspot.