AI called this Suspicious at 89.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- package.json has non-CI prepare hook invoking simple-git-hooks.
- package.json configures pre-commit to run `bun run lint --fix`.
Evidence against
- No preinstall/install/postinstall hooks.
- CLI imports and server startup occur only after user invokes bin commands.
- Credential files are stored under package-owned COPILOT_API_HOME/default directory with mode 0600.
- Network calls target configured providers and GitHub/OpenAI/Anthropic authentication or API endpoints.
- --claude-code only generates and copies a launch command after explicit user selection.
Behavioral surface
SourceChildProcessCryptoDynamicRequireEnvironmentVarsFilesystemNetworkShellWebSocket
Supply chainHighEntropyStringsMinifiedProtestwareTelemetryUrlStrings
ManifestNo manifest risk signals triggered.
scanned 22 file(s), 1.95 MB of source, external domains: api.anthropic.com, api.deepseek.com, api.github.com, api.githubcopilot.com, api.openai.com, auth.openai.com, chatgpt.com, dashscope.aliyuncs.com, docs.github.com, gh.io, github.com, opencode.ai, openrouter.ai, radix-ui.com, react.dev, www.w3.org