Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The documentation explicitly describes an `http` hook type that automatically POSTs event JSON to a URL, but it does not warn that hook events may contain sensitive prompts, tool metadata, file paths, or other session context that could be transmitted off-host. In a CLI/plugin context where hooks fire automatically at many lifecycle events, this omission can lead users to enable silent data exfiltration without understanding the privacy and security implications.
