{
  "kind": "agent_config_tamper",
  "product_version": "0.12.897",
  "wheel_sha256": "a9c3bf17b036c5f661df05ba4a02cf3afa834b44c2492f3e60fb3b66061a0a24",
  "method": "Published detector functions evaluated on authored inert events or disposable configuration files.",
  "scope": "No live agent, runtime adapter, daemon ingestion, product UI, external command or network action was exercised.",
  "cases": [
    {
      "case": "foreign-hook",
      "inputs": {
        "file": ".claude/settings.local.json",
        "content": {
          "hooks": {
            "Stop": [
              {
                "hooks": [
                  {
                    "command": "node review-hook.js"
                  }
                ]
              }
            ]
          }
        }
      },
      "expected_severity": "critical",
      "actual_severity": "critical",
      "findings": [
        {
          "kind": "agent_config_tamper",
          "session_id": "claude_code:example",
          "runtime": "claude_code",
          "severity": "critical",
          "title": ".claude/settings.local.json installs 1 hook command(s) that run with your session",
          "detail": "`.claude/settings.local.json` registers hook commands that run inside your claude_code session, on the `Stop` event, with your credentials in the environment. This file is gitignored by convention, so an entry here does not show up in `git status` \u2014 the surface the CHAINDROP worm used to persist across 400+ npm packages. If you did not add these, treat the machine as compromised. ClawMetry will not remove another tool's hooks for you.",
          "evidence": {
            "file": ".claude/settings.local.json",
            "commands": [
              "node review-hook.js"
            ],
            "count": 1,
            "gitignored_by_convention": true,
            "observed": "agent_config",
            "readers": [
              "claude_code",
              "cursor"
            ],
            "events": [
              "Stop"
            ]
          },
          "first_bad_step": null,
          "spend_at_risk_usd": 0.0,
          "spend_basis": "unknown",
          "frameworks": {
            "mapping_version": "2026-09-27.1",
            "owasp_llm": [],
            "owasp_asi": [
              "ASI04"
            ],
            "atlas": [
              "AML.T0081"
            ],
            "mapped": true,
            "mode": "detect",
            "pre_action_control": false
          }
        }
      ]
    },
    {
      "case": "clawmetry-hook",
      "inputs": {
        "file": ".claude/settings.local.json",
        "content": {
          "hooks": {
            "Stop": [
              {
                "hooks": [
                  {
                    "command": "clawmetry hook claude_code"
                  }
                ]
              }
            ]
          }
        }
      },
      "expected_severity": null,
      "actual_severity": null,
      "findings": []
    }
  ]
}
