Please report vulnerabilities through GitHub's private vulnerability reporting for opsle/affected-verification when available, or contact the repository maintainers privately.
The prototype does not execute catalog commands, access a network, load plugins, or evaluate model output. Treat normalized evidence, catalogs, policies, and shadow relevance as untrusted input. A plan must not authorize execution by itself.