Give your AI a memory it can prove: tamper-evident, offline-verifiable, SHA-256 receipts.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Give your AI a memory it can prove: tamper-evident, offline-verifiable, SHA-256 receipts.