Appearance
Why It Matters
Committed Claude command hooks run automatically in shared environments, so screen capture from them is strong spyware-like behavior.
What Triggers
SEC707 matches committed Claude settings command hooks that invoke explicit screen capture utilities such as screencapture, scrot, gnome-screenshot, grim, grimshot, maim, ImageMagick import -window root, or PowerShell CopyFromScreen.
False Positives
Shared committed Claude hooks should not capture screenshots from developer desktops. If screen capture is needed at all, it should be explicit and outside committed repo automation.
Remediation
Remove screenshot capture behavior from the committed Claude hook and require deliberate user action outside shared automation.