Ran it. Normal mode was fine, but the agent could patch Proof of Done in node_modules and skip the check and with permissions off it could just delete the hooks. Fixed the first onee the hook now runs from a protected folder and checks its own files first and the same attack got caught on the rerun. The permissions-off case can't be fully stopped locally, but verify still catches it afterwards, so CI is the real answer there. Thanks for pushing on this, it's in v0.3.0.
Adam Lewis
Product Engineer/Architect navigating the AI revolution
This is the piece I was hoping someone would write, because the hook is hard. What happens when the agent edits the hook itself, or the config that registers it, so the check never gets a chance to run? Show me the run where the agent disables the hook and still declares done.