EVIDENCE LANE / PROJECT INFORMATION
Security boundaries
Keep access explicit, preserve source identity and inspect actual effects.
Scope and ownership
Operations must stay within selected project paths, task contracts and granted connector scope. Read-only Studio navigation does not authorize changes. Workers perform bounded tool operations under the engine’s control.
Credentials and evidence
Keep credentials out of public examples, logs and project evidence. Configure external service access through its supported route. Redaction and attribution do not replace access checks.
Report a concern
Use the repository’s published security reporting instructions when available. Do not post secrets, exploitable private details or unredacted project data in a public issue. Keep the affected version and reproduction scope clear.