Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `agent-kit init` or supplies `--activate`.
Impact
Can influence configured AI tools within the chosen project.
Mechanism
Explicit CLI copies project-scoped AI-agent configuration and templates.
Rationale
This is not malicious, but it has an intentional, user-invoked AI-agent configuration capability that warrants a warning under the stated policy. No concrete malicious chain was found.
Evidence
package.jsondist/index.jsassistant-adapters/cursor-agent-kit.mdcassistant-adapters/codex-agents.mdantigravity/plugin.json.cursor/rules/cursor-agent-kit.mdc.cursor/agents/.codex/config.toml.codex/agents/.claude/agents/.github/copilot-instructions.md.antigravity/agent-kit/