# Adversarial Bug Report — harden-enforcement-layers ## Attack Vectors 1. **Hook bypass**: Can a user bypass the pre-push hook? 2. **Symlink attacks**: Does `install-hooks.sh` follow symlinks unsafely? 3. **Command injection**: Does `register-guards.sh` have injection vectors in its Python inline script or pi install call? ## Findings - Pre-push hook can be bypassed with `--no-verify` (documented), but this is by design — it's a deterrent layer - `install-hooks.sh` uses `cp` not `ln -sf` — no symlink following risk - `register-guards.sh` passes `$OPENCODE_SOURCE` and `$PI_SOURCE` to Python/pi — these are hardcoded framework paths, not user input. Safe. - Python inline script uses `$OPENCODE_CONFIG` which could theoretically contain special chars, but this is a framework path from a controlled location ## Verdict No exploitable vulnerabilities found.