Monitor public pages and JSON endpoints after agents disconnect, with polling and webhooks.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Monitor public pages and JSON endpoints after agents disconnect, with polling and webhooks.