Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs get-engineering-done/ged installer, optionally with runtime flags.
Impact
Adds GED prompts to Codex, Claude, Gemini, or OpenCode command surfaces; later GED features may make opted-in HTTPS API calls.
Mechanism
User-invoked AI-agent command/skill installation
Rationale
This is not malicious, but its user-invoked installer modifies broad AI-agent control surfaces and the package includes credentialed network capabilities. Per policy, that concrete explicit-user-command capability warrants a warning rather than a block.
Evidence
package.jsonbin/install.jssrc/ged/adapters/runtime_catalog.jsonsrc/ged/vvuq.pysrc/ged/template_curation.pysrc/ged/commands/*.md~/.codex/skills/ged-*/SKILL.md~/.claude/commands/ged/*.md~/.gemini/commands/ged/*.md~/.config/opencode/command/ged-*.md
Network endpoints5
vvuq.dirkenglund.org/health/api/v1/contracts/open