AI called this Clean at 91.0% confidence as Benign with low false-positive risk.
Evidence for block
- Runtime CLI bootstraps bundled skills under ~/.interference.
- The coding agent can invoke workspace shell and web-fetch tools during user sessions.
- It reads configured local instruction files for agent context.
Evidence against
- package.json has no preinstall/install/postinstall lifecycle hook.
- All observed network calls are model metadata/update checks or selected AI-provider use.
- Credentials remain local in ~/.interference/auth.json and are applied only as provider environment variables.
- Workspace writes and shell commands are agent features; interactive CLI confirmation is implemented for asked actions.
- No hidden payload, exfiltration endpoint, persistence outside package state, or foreign agent-control-surface mutation found.
Behavioral surface
SourceChildProcessCryptoEnvironmentVarsFilesystemNetwork
ManifestWildcardDependency
scanned 65 file(s), 217 KB of source, external domains: api.moonshot.ai, api.openai.com, api.z.ai, github.com, models.dev, openrouter.ai, registry.npmjs.org