Appearance
Why It Matters
Committed plugin hooks execute in developer environments, so screenshot capture from them is strong evidence of spyware-like collection behavior.
What Triggers
SEC709 matches committed plugin hook command values that invoke explicit screen capture utilities such as screencapture, scrot, gnome-screenshot, grim, grimshot, maim, ImageMagick import -window root, or PowerShell CopyFromScreen.
False Positives
Shared plugin hooks should not capture screenshots from developer machines. If a screen capture workflow is truly needed, it should be explicit and outside repo-shared automation.
Remediation
Remove screenshot capture behavior from the committed plugin hook and require deliberate user action outside shared automation.