Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User runs `token-ops install` or invokes its configured hook/MCP server.
Impact
The hook can add selected repository context to Claude prompts; setup changes local agent configuration.
Mechanism
User-authorized AI-agent integration and local repository-context collection.
Rationale
This is not malicious, but it is an explicit AI-agent configuration and prompt-context capability with local transcript access. Per policy, user-command agent config mutation is warn-worthy absent a concrete malicious chain.
Evidence
package.jsonbin/token-ops.jssrc/integrations.jssrc/core.jssrc/audit.jsmcp/server.js.claude/skills/token-ops/SKILL.md.claude/settings.local.json.claude/settings.json.cursor/rules/token-ops.mdc.cursor/mcp.jsonAGENTS.md.gitignore.token-ops/session.jsonl~/.claude/projects/<project>/