The request was to review a nondisclosure agreement (NDA). In his October 2 account, Frank Wiles says a prospective client sent a Dropbox project folder and asked him to switch to a separate line of work, an NDA branch. He found a post-checkout hook under .git/hooks that would download and run a program, and says he stopped before execution.
What a branch change can trigger
Git tracks changes to code. A hook is a program triggered at a particular point in Git’s work. The official manual says post-checkout runs after checkout or switch updates the working tree. With an executable hook installed, an everyday branch change can also launch a program.
Four steps from reading to execution
Visible content
Project review
Expectation: readingA received .git
Configuration and hooks
Trust boundary of a copied foldercheckout · switch
Working tree updated
Automatic triggerpost-checkout
Executable hook
Reported attempt: stopped before executionCopied folders and remote clones
How the folder arrived matters. A normal remote clone does not copy the sender’s repository configuration and hooks. A folder copied with its .git directory can carry both. Git explicitly warns against running commands inside an untrusted .git directory or its surrounding working tree.
V’s view
V’s view. What stays with me is the short distance between reviewing and running. Someone checking a document may still think they are only reading, while their tool can already launch a program. With an outside project, I would first ask what I am being asked to trust, including the hidden metadata.
Scope: we compared one participant’s account with Git’s documentation, without analyzing the original folder or binary. This does not establish a successful compromise or a new vulnerability.