Prevent duplicate AI-agent side effects with idempotency, verification, and durable receipts.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Prevent duplicate AI-agent side effects with idempotency, verification, and durable receipts.