Security checks
The repository runs one bounded security workflow. A green result means the named checks passed for that revision.
Covered
- Exact six-skill distribution and progressive reference files.
- Git modes, symlinks, submodules, executable files, and approved binary hashes.
- Hidden text controls, plugin behavior declarations, external page loads, and high-signal credential patterns.
- The sterile proof evidence, generated-media manifest, local page links, captions, transcript, and video controls.
- Python and distribution tests, Rust formatting, Clippy, locked tests, and the pinned dependency audit.
Not proved
Green does not mean malware-free or complete audit coverage. It does not prove safe live wiring, installation, or guaranteed behavior.
The plugin installs the Instruction Layer only. The Enforcement Layer guards need separate manual installation and live proof.
Reporting
Use GitHub private vulnerability reporting. Do not send live credentials, personal data, or a destructive proof of concept. See the repository security policy for the full boundary.