Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `intent install` or `intent hooks install`.
Impact
Can alter project or user AI-agent behavior and block edits pending skill loading.
Mechanism
Explicit agent-config and hook installation
Rationale
Source inspection found explicit user-command agent-control mutations but no unconsented install-time execution, exfiltration, or destructive behavior. Flag as a warning for the persistent AI-agent capability rather than block as malware.
Evidence
package.jsondist/cli.mjsdist/command-LISGZlho.mjsdist/command-C7-B6-UW.mjsdist/staleness-DAcV0ARw.mjsAGENTS.md.codex/hooks.json.claude/settings.json.copilot/hooks/hooks.json.intent/hooks/intent-codex-gate.mjs.tanstack/intent/hooks/intent-codex-gate.mjs
Network endpoints1
registry.npmjs.org/${encodeURIComponent(packageName)}/latest