Appearance
Why It Matters
Microphone recording from a committed plugin hook is surveillance behavior that can silently collect private conversations or ambient audio from the developer environment.
What Triggers
SEC724 matches plugin hook commands that invoke explicit microphone capture utilities such as arecord, parecord, parec, rec, sox -d, or ffmpeg with audio-oriented selectors like audio=, -f alsa, -f pulse, microphone, or mic.
False Positives
Shared committed plugin hooks should not record audio from developer machines. Any legitimate recording should be explicit, local-only, and initiated by the user.
Remediation
Remove microphone capture behavior from the committed plugin hook and require deliberate user-driven recording outside shared automation.