Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The document claims the hook scripts 'only output text' and 'don't modify files or run commands,' but the configuration explicitly invokes shell scripts as commands, and one documented script scaffolds new skills. This mismatch can mislead users into granting trust or enabling hooks under false assumptions, increasing the chance of unintended code execution or file changes in the agent's runtime context.
