What the reviewer found
UserPromptSubmit: runs .claude/hooks/scripts/hooks.py, which plays a sound file from .claude/hooks/sounds and appends the full hook input (including the prompt text) to .claude/hooks/logs/hooks-log.jsonl inside the project. Local only, exits 0 always, nothing leaves the machine.
What was read
The hook definition and the script it runs, fetched from shanraisshan/claude-code-best-practice:
.claude/settings.json.claude/hooks/scripts/hooks.py
What the static scan said
The 26-rule scan found nothing in this file; the review read it anyway.
How this review was made
Fable 5.1 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.