Git checkout of pinned plugin SHA lacks post-checkout HEAD verification

Detects a 'git checkout' command targeting a specific commit SHA that is not followed within five minutes by a 'git rev-parse HEAD' integrity check. This behavior, known as 'Plugin4Shell', involves an attacker replacing a pinned commit with a malicious branch of the same name, potentially leading to unauthorized code execution if verification steps are absent.