Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The document says the hook scripts 'only output text' and 'don't modify files or run commands,' but the setup explicitly configures those scripts to be executed as shell commands by the hook system. That misleading assurance can cause users to under-trust the risk boundary and install auto-executed scripts with the same permissions as the agent, increasing the chance of unsafe deployment or review bypass.
