LPM treats this as warn-only first-party agent extension lifecycle risk. The MCP server has explicit tools to inspect local MCP configuration and generate its own proxy config, and to modify a selected Git repository. No unconsented install-time control-surface mutation or exfiltration is established.
Static reason
No blocking static signals were detected.
Trigger
An MCP client explicitly calls generate_proxy_config or repo_cleanup_apply.
Impact
Can copy configured MCP server command/env entries into ~/.tokesave.config.json and alter .gitignore/Git index for the requested repository.
Mechanism
Agent extension setup and user-invoked repository mutation.
Rationale
This is a first-party MCP extension with explicit setup and destructive repository-maintenance capabilities, but source inspection found no lifecycle abuse, stealth persistence, remote payload, or exfiltration. Warn for the meaningful agent-extension/control-surface capability rather than block.
Evidence
package.jsonsrc/index.jssrc/config_generator.jssrc/repo_cleanup.jssrc/fetcher.js~/.cursor/mcp.json~/.config/Claude/claude_desktop_config.json~/.kiro/settings/mcp.json~/.tokesave.config.json.gitignore