Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs install.sh or the CLI install/update command.
Impact
Installed instructions can influence future agent behavior; no unconsented mutation or concrete malicious payload was found.
Mechanism
Explicit AI-agent skill deployment with GitHub-backed content retrieval.
Rationale
The root npm package has no lifecycle hooks or executable entrypoint, so it does not mutate systems on installation. Its explicit installer targets AI-agent control surfaces, creating a bounded extension-lifecycle risk that warrants a warning under policy.
Evidence
package.jsoninstall.shcli/bin.mjscli/core.mjsskills/no-ai-attribution/SKILL.md~/.claude/skills/<skill>~/.agents/skills/<skill>~/.gemini/skills/<skill>~/.skillsdeck/installed.json<project>/.claude/skills/<skill><project>/.agents/skills/<skill><project>/.gemini/skills/<skill>