A coding-agent hook runs before the repository trust prompt. What is wrong with that design?

Instruction: Identify the startup trust boundary. Explain safe pre-trust inspection, deferred execution, changed repository configuration, and a meaningful regression test.

Context: Protect coding-agent startup from untrusted project hooks and configuration that executes before the user accepts the repository.

Updated

Prepare a stronger answer

The trust decision happens after the action it's supposed to protect. A repository-controlled hook can run as soon as the folder opens, before the user agrees to execute anything. A prompt shown afterward can't undo that execution...

This member answer includes:

  • • A complete, copyable sample answer
  • • A practical walkthrough
  • • Common mistakes and how to avoid them
  • • Guidance for adapting the answer to your experience
  • • Answered interviewer follow-ups
Unlock the full answer and preparation guide

One payment for one year of full access. No automatic renewal.

See pricing and everything included

Your preparation path

Work through these questions in order. Read the answer aloud, then explain it in your own words.

Related Questions