Vague Triggers
High
- Confidence
- 82% confidence
- Finding
- This guidance recommends a user-level always-on hook with an empty matcher, causing a command to run on every prompt across all projects and sessions. Because hooks execute external scripts with the agent's permissions, global persistence materially increases blast radius and makes any compromised or unsafe script far more dangerous.
