Appearance
Why It Matters
Camera capture from a shared hook is spyware-like behavior because it can silently collect sensitive imagery from the developer environment.
What Triggers
SEC711 matches executable hook lines that invoke explicit camera capture utilities such as imagesnap, fswebcam, or ffmpeg with camera-oriented selectors like video=, /dev/video, -f v4l2, -f video4linux2, webcam, or camera.
False Positives
Shared committed hooks should not activate a developer's camera. Any legitimate capture should be explicit, local-only, and initiated by the user.
Remediation
Remove camera capture behavior from the shared hook and require deliberate user-driven capture outside committed automation.