Runnable demo: a CI gate that denies an agent's undeclared privileged tool action before it runs, with evidence in the Security tab. Built on assay.
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport — counts 0 tools · 0 res
· 0 prompts
permission surface via README inference
no tools enumerated yet for this server.
evidence-backed
findings quoted directly from the published source artifact — not inferred
last analysis: no-source
no code evidence — the analyzed source reached for no tracked permissions, tools, or hooks.