Appearance
Why It Matters
Microphone recording from a committed Claude hook is surveillance behavior that can silently collect private conversations or ambient audio from the developer environment.
What Triggers
SEC720 matches Claude settings command hooks that invoke explicit microphone capture utilities such as arecord, parecord, parec, rec, sox -d, or ffmpeg with audio-oriented selectors like audio=, -f alsa, -f pulse, microphone, or mic.
False Positives
Shared committed Claude hooks should not record audio from developer machines. Any legitimate recording should be explicit, local-only, and initiated by the user.
Remediation
Remove microphone capture behavior from the committed Claude hook and require deliberate user-driven recording outside shared automation.