What the reviewer found
Architecture notes for the DuDuClaw Rust project: "overrides" is an agent.toml config override, and the ~/.claude/settings.json and .mcp.json mentions describe how the project registers its own MCP server. The body was truncated at 48 KB, but every flagged line sits in the visible part and the file only documents the codebase.
What was read
The file as it ships in zhixuli0406/DuDuClaw:
CLAUDE.md
What the static scan said
The scan flagged 3things. The reviewer kept 0 and dismissed 3 as false.
P1Instruction-override phrasing — false positiveAS1Reads agent configuration directories — false positiveAS2Reads MCP configuration — false positive
How this review was made
Fable 5.1 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.