Closes a zero-interaction RCE where a hostile repo's .aipass/hooks.json
(discovered via loader CWD walk-up, bridge wired globally) could run an
arbitrary command-type hook on SessionStart. Defense-in-depth:
Layer A (engine): refuse command-type hooks from per-project configs via
unconditional _source clobber; gate handler paths to aipass.* namespace.
Layer B (loader+CLI): trusted-project registry (path+sha256), fail-closed
trust-check, $AIPASS_HOME-only bootstrap (no TOFU), aipass init auto-enroll
+ new aipass trust/revoke commands.
Live acceptance test (real bridge, real payload) proves both gates block
independently. 1105 hooks + 133 aipass tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEAyLFCuo4uD934fwFxocz