Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `revuiw run` with the Claude Code adapter, or invokes explicit `ci` commands.
Impact
The package changes Claude's trust state for the reviewed workspace; configured commands and agent execution carry their declared review privileges.
Mechanism
User-command AI-agent trust mutation and configured review orchestration.
Rationale
The package is not malicious by static source inspection, but its explicit CLI path mutates a global Claude trust setting. Per policy, that concrete user-command agent-config mutation warrants a warning rather than a block.
Evidence
package.jsondist/cli.jsdist/chunk-KOWP67L4.jsdist/chunk-BEOYTOBT.jsdist/chunk-WBMYE2SU.jsdist/chunk-W5RKW2WI.js~/.claude.json.revuiw/revuiw.config.ts
Network endpoints3
api.github.com/repos/${repository}/issues/${pullRequestNumber}/commentsapi.github.com/repos/${repository}/pulls/${pullRequestNumber}/comments