Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The document claims the hook scripts 'only output text' and 'don't modify files or run commands', but the configuration explicitly defines shell command hooks that are executed by the agent environment. This mismatch can mislead users into underestimating the trust boundary and permission level of the configured scripts, increasing the chance they enable risky automation without proper review.
