Every product is a plain-text Markdown + JSON file kit. It governs and documents; it never executes code, holds credentials, or takes an irreversible action on its own.
Installs into its own buyer-chosen folder. Never overwrites existing files.
Every change is previewable before it is applied. No silent, irreversible actions.
Spend, publish, delete, and credential-adjacent steps require named human approval.
Delete the installed folder and nothing else is touched. A rollback guide ships in every kit.
Deny-by-default: dangerous tool calls are tiered, gated, and audited before anything runs. The T4 human-approval floor for spend, publish, delete, and credential-adjacent actions cannot be lowered.
Execute code, or take destructive action without preview and approval.
Request or hold credentials, API keys, seed phrases, or wallet secrets.
Auto-publish, auto-post, or auto-purchase on the operator's behalf.
Security products (e.g. prompt-injection defense) are strictly defensive, with regression suites.
Written contracts & verification — run alongside platform-native permissions, not instead of them.
Binding never-store lists cover credentials, keys, and sensitive identifiers.