Needing elevated permissions for the eBPF hook makes sense given what it's doing, but the setup docs could be clearer about exactly what access it needs and why, since "grant this tool low-level kernel visibility" is a bigger ask than most CLI installs and I wanted more detail before running it.