How it gets overlooked
The agent runs an ordinary development command. But the repository configuration points at code of its own. Reviewing the visible tool name alone can miss the configuration that changes what happens underneath.
A checkout can direct Git toward hooks in the working tree, configure command valued settings, or include editor tasks that run on folder open. Those files deserve review before you treat the workspace as a passive collection of source code.
What ClawMetry detects
ClawMetry scans supported workspace configuration for execution related settings. It reports the relevant key or configuration source, using known good command shapes to reduce noise. This detector reads the checkout itself, rather than relying only on the agent tool stream.
The difference that changes the finding
Triggering example
hooksPath = .githooks
Critical finding
Quiet comparison
Default .git/hooks path
No finding for this detector.
The checked example points Git hooks at a directory shipped in the working tree and produces a critical finding. A hooks path that points to the default Git hooks directory stays quiet. The finding identifies configuration that names code, not a recorded execution of that code.
Inspect the detector result
{
"kind": "repo_config_exec",
"severity": "critical",
"evidence": {
"keys": [
"core.hookspath"
],
"hits": [
{
"key": "core.hookspath",
"command": ".githooks",
"line": 2,
"manager": null
}
],
"config": ".git/config",
"observed": "repository_config"
}
}Download inputs and complete results (JSON)How the example was checked
These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.
The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.
What to check next
Inspect the setting, the referenced files and the origin of the checkout. Decide whether those programs are expected before allowing ordinary development operations. If a tool already ran, investigate its effects separately using the evidence available on the machine.
- Inspect the config key
- Review referenced code
- Check the repository origin
What this signal establishes
The scanner reports configuration, not execution. It does not prove a configured program ran or that the author intended harm.