Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `aperture adapter sync` or `aperture reference warmup`.
Impact
A later AI client may start the configured Aperture MCP server in that project.
Mechanism
Project-scoped MCP configuration and reference-asset/model downloads.
Rationale
The package contains an explicit command that modifies AI-agent control files, which warrants a warn verdict under policy. It has no lifecycle hooks and the reviewed source shows scoped, user-invoked behavior rather than malicious execution.
Evidence
package.jsondist/commands/adapter.jsdist/adapter-sync.jsdist/adapter-templates.jsdist/reference/warm.jsdist/reference/model.jsAGENTS.mdCLAUDE.md.claude/settings.json.cursor/rules/aperture.mdc.github/copilot-instructions.md.codex/config.toml.mcp.json.aperture/runtime/reference
Network endpoints3
/@aperture-engine/reference-assets@<version>/dist