Two related fixes exposed when install.sh was first staged post-audit: 1. shellcheck invocation in setup-hooks.sh lacked -x, causing SC1091 (info) to fire for any .sh file that sources another, blocking the pre-commit hook on legitimate scripts. 2. The shellcheck source= directive in install.sh pointed to 'deploy-manifest.sh' (bare filename). With -x, shellcheck resolves this from CWD (repo root), where the file doesn't exist. Updated to 'scripts/deploy-manifest.sh' — the correct repo-root-relative path. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gv5iNACZxumtF2k6TsK18q