Validate the Proposed Mutation
Validate the content an operation proposes to write before authorizing that operation.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
A tool request replaces a10-line note with 900 lines under an 800-line teaching policy. Inspecting the existing disk file would allow it because the policy concerns the proposed content.
Mechanism
Read pre-execution tool input and validate target and a present string content field. Count proposed lines under an explicit rule; for edits, construct the version-bound resulting state first. Reject oversized or invalid inputs through the host’s verified blocking protocol and leave the file unchanged. Execute the same allowed payload, recording target, policy and decision. Check coverage of other mutation paths.
Bad example
Approve the 900-line replacement because the disk note has only 10 lines, below 800. Count missing content as an empty string and check again after writing.
Good example
Before approval, inspect this request's content using a teaching newline-separated count with limit 800. Reject 900 lines with the old file unchanged; missing or non-string content is invalid. Verify the actual host's pre-execution blocking contract rather than substituting a post-write warning.
Why the change matters
The current file is old state and cannot establish compliance of proposed state. Validating the payload and binding it to execution can stop oversized mutation beforehand. Invalid input must not masquerade as empty content.
Observable expectation
Teaching cases:900 lines without a trailing newline are rejected and the 10-line file hash stays unchanged; a valid 800-line input passes this policy; missing and numeric content are rejected. Test the trailing-newline counting convention too, and demonstrate pre-write blocking through an actual host request.
Limits
The 800 limit is illustrative. Byte counts, binary content, patch edits and other tools need distinct or additional validation. Version conditions address changes between checking and writing. A configured hook name alone does not establish registration or effective blocking.