EVIDENCE LANE / PROJECT INFORMATION

Security boundaries

Keep access explicit, preserve source identity and inspect actual effects.

Scope and ownership

Operations must stay within selected project paths, task contracts and granted connector scope. Read-only Studio navigation does not authorize changes. Workers perform bounded tool operations under the engine’s control.

Credentials and evidence

Keep credentials out of public examples, logs and project evidence. Configure external service access through its supported route. Redaction and attribution do not replace access checks.

Report a concern

Use the repository’s published security reporting instructions when available. Do not post secrets, exploitable private details or unredacted project data in a public issue. Keep the affected version and reproduction scope clear.