# Agent extension pre-install review Record evidence, not impressions. A manifest declaration is a claim to inspect; it is not proof of runtime behavior or confinement. ## Identity and provenance - Canonical source and maintainer: - Exact version or revision: - Artifact SHA-256 and where it was obtained: - Signature or attestation checked, method, and result: - License and redistribution terms: ## Installation surface - Document-only or executable: - Entry points and install scripts: - Hooks and when each runs: - Direct and transitive dependencies: - Files created or changed: ## Capability request - Filesystem scope: - Network destinations and protocols: - Secret or credential access: - Process/command execution: - Browser, UI, or external-account access: - Capabilities declared but denied: - Capabilities requested but undeclared: ## Lifecycle - Update channel and whether the version is pinned: - How an update changes permissions or dependencies: - Removal and rollback procedure: - Evidence retained after install or rejection: ## Decision - Decision: allow / reject / isolate for deeper review - Policy version: - Reviewer and date: - Evidence references: - Known unknowns and runtime checks still required: