Intent-Code Divergence
Medium
- Confidence
- 96% confidence
- Finding
- The document's security section materially understates risk by claiming the scripts only output text and do not run commands, while the same guide configures them as command hooks and separately instructs users to execute another shell script directly. This contradiction can mislead users into granting trust to automatically executed local scripts without understanding that shell commands are being invoked on hook events.
