What the reviewer found
PreToolUse runs .claude/hooks/pre-write.sh on Write and .claude/hooks/pre-bash.sh on Bash; both only print warnings about .env, requirements.txt, rm -rf of sample dirs and pip install, then exit 0. Local only, never blocks.
What was read
The hook definition and the 2 scripts it runs, fetched from anthropics/claude-cookbooks:
skills/.claude/settings.jsonskills/.claude/hooks/pre-write.shskills/.claude/hooks/pre-bash.sh
What the static scan said
The 26-rule scan found nothing in this file; the review read it anyway.
How this review was made
Fable 5.1 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.