Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `intent install` or `intent hooks install`.
Impact
Can alter configured agent behavior within the selected project or user scope.
Mechanism
Explicit AI-agent config and hook installation
Rationale
Source inspection found no lifecycle execution or concrete malicious behavior. Per policy, explicit user-command AI-agent configuration mutation is a warning-level dangerous capability.
Evidence
package.jsondist/cli.mjsdist/command-CiYh0V3W.mjsdist/command-C7-B6-UW.mjsdist/staleness-DAcV0ARw.mjsAGENTS.mdCLAUDE.md.cursorrules.github/copilot-instructions.md.claude/settings.json.codex/hooks.json.copilot/hooks/hooks.json.intent/hooks/intent-*-gate.mjs~/.tanstack/intent/hooks/intent-*-gate.mjs
Network endpoints1
registry.npmjs.org/<package>/latest