Collection boundary
- Read-only metadata permissions
- No Git blobs or source file contents
- Short-lived installation access tokens
- Repository limits enforced per entitlement
Security
The MVP is designed around read-only permissions and server-side credential handling.
Report suspected vulnerabilities privately through the support identity configured at deployment. Do not include credentials or customer data.