HookGraph adds bounded static provenance from supported AI-agent hook configuration to literal repository-local scripts and their findings.
Highlights:
- Maps config → script → finding paths without executing commands.
- Makes dynamic, missing, outside-root, symlink, cycle, depth, and resource boundaries explicit.
- Renders graph evidence in terminal, JSON, Markdown, HTML, and the reusable GitHub Action.
Proof boundary: HookGraph shows statically provable local references; it does not predict runtime control flow or prove that a hook is safe.
Full Changelog: v0.2.0...v0.3.0