A local receipt and approval gate for AI agent sessions. The agent can act, but it cannot sign.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
A local receipt and approval gate for AI agent sessions. The agent can act, but it cannot sign.