Appearance
Why It Matters
Screen capture from a shared hook is spyware-like behavior because it can silently collect tokens, chats, dashboards, terminals, or other sensitive material visible on the developer's desktop.
What Triggers
SEC703 matches executable hook lines that invoke explicit screen capture utilities such as screencapture, scrot, gnome-screenshot, grim, grimshot, maim, ImageMagick import -window root, or PowerShell CopyFromScreen.
False Positives
Shared committed hooks should not capture screenshots from developer machines. Any legitimate screenshot workflow should be explicit, local-only, and outside repo-shared automation.
Remediation
Remove screenshot capture behavior from the shared hook and require deliberate, user-driven capture outside committed automation.