The old hook claimed parallel scans with 45s timeouts. In reality every scan ran synchronously inside the Promise executor, so they ran one after another, the timers could never fire, and with no lock every concurrent session ran its own full scan. Drag the sliders to see what each design actually does.
Sequential per session; every session scans; timers dead; semgrep fetches rules over the network every Stop.
Clean tree = no scan. Machine-wide lock = one scan total. Scans genuinely parallel; child_process kills at 45s. semgrep only with a local config (skipped here: none). Secret scan capped.