Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The guide's security section states that hook scripts only output text and do not modify files or run commands, but the same document references an extract script that creates a skill scaffold. This creates a misleading trust boundary: operators may enable these hooks believing they are non-mutating, when the documented tooling can perform filesystem changes or execute additional logic with the agent's permissions.
