Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `mcphosting connect`, `mcphosting import`, or `mcphosting deploy --configure`.
Impact
A user-selected remote MCP server can receive requests from a configured AI client.
Mechanism
explicit AI-client MCP configuration and remote JSON-RPC proxying
Rationale
Source inspection found explicit user-command AI-agent configuration and arbitrary remote MCP proxying, but no unconsented install-time mutation or concrete malicious behavior. Per policy, this is a warn-level capability risk.
Evidence
package.jsondist/index.cjs
Network endpoints2
mcphosting.com${slug}.mcphost.dev