The purge register: who guards what now

Divergence purge #3835, PR 2 of 6 · the drift register in shared/rules/cc-native-first.md, rendered · 2026-08-31

Why every verdict is a measurement

plugin settings.json     CC reads pick(["agent","subagentStatusLine"]): ork's 26 deny rules NEVER enforced
canary probe (2.1.251)   permissions.deny blocked a scripted Bash tool_use under --dangerously-skip-permissions,
                         with NO hooks loaded; the control arm executed. Zero spend, now a CI step (REGRESSED on failure).
consumers                dispatcher rosters, SECURITY_HOOKS registry and the security suite were READ, not grepped
                         (the register's own 2026-06-05 audit was ~60% wrong for skipping exactly that).

Pick a hook, see its fate

The push

PRlands
1 (#3836)the vehicle: consent-gated writer into the operator's settings scope, doctor audit, canary tripwire in CI
2 (this)the register + evidence record; settles #3629 out of scope
3dead four + compound-command-validator + agent-browser-safety deleted
4egress ASK tier, cron-guard, team-size-gate, restrict-bash deleted; pre-commit runner rehomed to git hooks
5security baseline amended, then file-guard + credential-read-guard (after the enforcement probe is green)
6git-validator + dangerous-command-blocker; security suite becomes native-mechanism tripwires

The user story this serves: two users hit hook Yes/No prompts every few minutes and escaped with dangerously-skip-permissions, which disabled everything. The probe shows native deny survives that exact flag; the prompts did not need to exist.