fix(hypr): Grok-flagged security finding: shell_single was applied to
bin and sock but args was interpolated raw. A profile hotkey containing
shell metacharacters could become a Hyprland exec_cmd injection.
- src/hypr.rs: bind_command now wraps args in shell_single
- New tests:
- bind_command_quotes_args_with_metacharacters
- shell_single_handles_inner_quote
- Doc comment updated to name the threat and what gets escaped
93+/0 cargo test; clippy clean.
Hyprland binds called `ipc` twice so mapped keys never reached the daemon.
Overlays now use mpv with wayland-app-id and JSON reload. Empty window_match
matches nothing. Ctrl-c clears binds. Proven: send_shortcut to unfocused
XWayland, mpv overlay class enboxer-vfx.