You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Jul 22, 2026. It is now read-only.
When a repo defines hooks, the "Hook results" dialog shows hook names (e.g. bootstrap-frontend-deps, generate-wails-bindings) with "Running..." and "Trust" buttons — but there is no way to view what the hooks actually do before executing or trusting them.
This is a security concern. Users are asked to run or trust arbitrary code from a repo without being able to inspect it first.
Current behavior
Dialog lists pending hooks by name only
Options are "Run" or "Trust" with no way to see the hook contents
Users must blindly trust the hook or go find the hook definition file manually
Expected behavior
Each hook entry should have a "View" or expand/disclosure action that shows the actual commands the hook will execute
Users can review the hook source before deciding to run or trust
Consider showing the file path (e.g. .workset/hooks.yaml) so users know where it lives
Security considerations
Hooks execute arbitrary shell commands — users should always be able to inspect before running
"Trust" implies persisting the decision, so inspecting before trusting is especially important
This is similar to how VS Code prompts for workspace trust and shows what extensions/tasks will run
Problem
When a repo defines hooks, the "Hook results" dialog shows hook names (e.g.
bootstrap-frontend-deps,generate-wails-bindings) with "Running..." and "Trust" buttons — but there is no way to view what the hooks actually do before executing or trusting them.This is a security concern. Users are asked to run or trust arbitrary code from a repo without being able to inspect it first.
Current behavior
Expected behavior
.workset/hooks.yaml) so users know where it livesSecurity considerations
Environment