Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `agentspec install` or an install/update/spec command and confirms the target.
Impact
User-approved remote content can influence the configured AI agent or enable an OpenCode plugin.
Mechanism
Remote content deployment into AI-agent configuration surfaces.
Rationale
No concrete malicious or unconsented install-time behavior was found. The package nevertheless has a real explicit-user-command AI-agent configuration mutation capability, which warrants a warning under the stated policy.
Evidence
package.jsondist/index.jsdist/chunk-7UFIFFQO.jsdist/chunk-LOEGUI22.jsAGENTS.md.codex/config.toml.claude/settings.jsonopencode.json~/.agentspec/store/~/.agentspec/backups/
Network endpoints2
api.agentspec.shraw.githubusercontent.com/${owner}/${repo}/${ref}/package.json