# Security Report vulnerabilities privately through GitHub Security Advisories. Never attach live secrets or business output. This verifier is offline and proof-only. It never executes tools, reads result bodies, opens spill locators, accesses the network or grants access. Inline MCP tools expose no filesystem paths. File tools constrain input/output to a real workspace, reject absolute paths, traversal and symlinks, cap input at 256 KiB, create artifacts atomically and verify them by read-back. Body-shaped and secret-shaped fields are rejected recursively. A verified report proves only internal consistency of supplied digests, byte counts and classifications. It does not prove producer authenticity, non-omission, spill availability, source correctness or real-world completeness.