Append-only, signed, on-chain-verifiable agent action log — record and audit what agents did.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Append-only, signed, on-chain-verifiable agent action log — record and audit what agents did.