Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `tokz statusline enable`; later Claude Code invokes its configured status line.
Impact
Persistent execution through the user's Claude Code status line after opt-in.
Mechanism
Explicit AI-agent statusLine configuration mutation
Rationale
No concrete malicious behavior was found, but explicit persistent AI-agent configuration mutation is a policy-relevant capability. It should be warned rather than blocked.
Evidence
package.jsondist/cli.jsdist/statusline-4UN2Q6BT.jsdist/chunk-T5J7LVH6.jsdist/chunk-65BQE6TI.js<homedir>/.claude/settings.json<homedir>/.tokz/litellm-prices.json<homedir>/.claude/projects/**/*.jsonl<project>/.mcp.json<homedir>/.claude.json
Network endpoints1
raw.githubusercontent.com/BerriAI/litellm/main/model_prices_and_context_window.json