Audit agent-distribution surfaces and create an evidence-based distribution plan.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Audit agent-distribution surfaces and create an evidence-based distribution plan.