Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `lumaline install`, then Claude Code invokes the configured status line.
Impact
Changes a first-party AI-agent configuration and causes periodic network requests/display of signed sponsored content.
Mechanism
Explicit Claude Code statusLine configuration plus signed remote sponsored-feed polling.
Rationale
No concrete malicious chain was found, but explicit user-command mutation of an AI-agent configuration is a policy-defined warning surface. The behavior is disclosed and reversible, so blocking is not warranted.
Evidence
package.jsonbin/lumaline.mjssrc/install.mjssrc/statusline.mjssrc/client/window.mjssrc/client/auth.mjs~/.claude/settings.json~/.claude/settings.json.lumaline-bak~/.lumaline/prior-statusline.json~/.lumaline/ad-cache.json~/.lumaline/impression-state.json~/.lumaline/audit.log~/.lumaline/device-token.json