The request was to review a nondisclosure agreement (NDA). In his October 2 account, Frank Wiles says a prospective client sent a Dropbox project folder and asked him to switch to a separate line of work, an NDA branch. He found a post-checkout hook under .git/hooks that would download and run a program, and says he stopped before execution.

What a branch change can trigger

Git tracks changes to code. A hook is a program triggered at a particular point in Git’s work. The official manual says post-checkout runs after checkout or switch updates the working tree. With an executable hook installed, an everyday branch change can also launch a program.

Four steps from reading to execution

Conceptual diagram · 01 · Document

Visible content

Project review

Expectation: reading
Git security manual · 02 · Metadata

A received .git

Configuration and hooks

Trust boundary of a copied folder
Git hooks manual · 03 · Git operation

checkout · switch

Working tree updated

Automatic trigger
Wiles account · Git manual · 04 · Program

post-checkout

Executable hook

Reported attempt: stopped before execution
Conceptual diagram of a reported attempt. Wiles says he stopped before execution; this does not depict a successful breach.

Copied folders and remote clones

How the folder arrived matters. A normal remote clone does not copy the sender’s repository configuration and hooks. A folder copied with its .git directory can carry both. Git explicitly warns against running commands inside an untrusted .git directory or its surrounding working tree.

V’s view

V’s view. What stays with me is the short distance between reviewing and running. Someone checking a document may still think they are only reading, while their tool can already launch a program. With an outside project, I would first ask what I am being asked to trust, including the hidden metadata.

Scope: we compared one participant’s account with Git’s documentation, without analyzing the original folder or binary. This does not establish a successful compromise or a new vulnerability.