Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs npx framer-to-code or install.sh, then invokes conversion scripts.
Impact
Installs or replaces two agent skills; conversion can download content from the user-selected site.
Mechanism
explicit Claude skill installation and website mirroring
Rationale
This is an explicit user-command mutation of an AI-agent skill directory, which warrants a warning under policy. Source inspection found no lifecycle-triggered mutation, credential collection, exfiltration, or remote payload execution.
Evidence
package.jsonbin/install.mjsinstall.shplugins/framer-to-code/skills/framer-to-code/scripts/crawl.mjsplugins/framer-to-code/skills/framer-to-code/scripts/build.mjsplugins/framer-to-code/skills/framer-to-code-hard/scripts/strip.mjs~/.claude/skills/framer-to-code~/.claude/skills/framer-to-code-hard<user-selected-output-directory>
Network endpoints4
github.com/iamshubhransh/framer-to-code.git