Back to the proof page

Security checks

The repository runs one bounded security workflow. A green result means the named checks passed for that revision.

Covered

Not proved

Green does not mean malware-free or complete audit coverage. It does not prove safe live wiring, installation, or guaranteed behavior.

The plugin installs the Instruction Layer only. The Enforcement Layer guards need separate manual installation and live proof.

Reporting

Use GitHub private vulnerability reporting. Do not send live credentials, personal data, or a destructive proof of concept. See the repository security policy for the full boundary.