Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User selects Agent mode or an authorized Telegram owner sends /agent or plan actions.
Impact
Approved actions can modify the selected workspace or run shell commands; skill-file contents may be exposed to the configured AI provider.
Mechanism
LLM-directed workspace tools with approval-gated shell and file application.
Rationale
The package is not malicious, but it provides a high-impact AI-agent capability with broad approved shell execution and external skill-file reads. This warrants a warning for informed deployment rather than a publication block.
Evidence
package.jsonindex.tsmodes/agent/tool-executor.tsmodes/agent/approval.tsmodes/telegram/handlers.tsai/ai.config.tsmodes/agent/orchestrator.tsmodes/telegram/agent-run.ts