No repo here scanned for committed credentials. The hook is self-contained rather than delegating to a Makefile, because this repo has none and a hook reaching into a sibling repo breaks the moment this one is cloned elsewhere. Scans the outgoing range rather than full history: history carries settled findings — test fixtures, vendored third-party code — and a gate that fails on something unfixable gets bypassed within a week. Setting core.hooksPath means pql init must replant its replication shims into .githooks, which is why they are gitignored here alongside the tracked pre-push. Same layout pql itself uses. Co-Authored-By: Claude <noreply@anthropic.com>