Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The document’s security section states the scripts 'only output text' and 'don’t modify files or run commands,' but the entire setup configures those scripts to be executed as hook commands. This misleading assurance can cause users to under-trust the risk of arbitrary shell-script execution in response to prompts or tool events, increasing the chance they enable unsafe automation without proper review.
