**English** | [简体中文](README.cn.md)
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references dynamic require/import behavior.
scripts/copy-flag-assets.jsView on unpkg · L6Manifest entrypoint contains risky behavior absent from dist/build output.
scripts/scaffold-app.jsView on unpkg · L12Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install-cursor-rules.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/@visactor.jsView on unpkgPackage source references dynamic require/import behavior.
scripts/copy-flag-assets.jsView on unpkg · L6Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install-cursor-rules.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/@visactor.jsView on unpkgManifest entrypoint contains risky behavior absent from dist/build output.
scripts/scaffold-app.jsView on unpkg · L12