Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The document states that the hook scripts 'only output text' and 'don't modify files or run commands,' but the configuration explicitly executes shell scripts as hook commands. This misrepresents the trust boundary and can cause operators to enable executable hooks under a false sense of safety, increasing the chance of arbitrary code execution if those scripts are changed, replaced, or behave unexpectedly.
