Issue Agent Passports and verify agent authority before value moves. Signed verification records.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Issue Agent Passports and verify agent authority before value moves. Signed verification records.