abyss-machine is public source for a host-local organ. Treat accidental state
publication as the main security risk.
- tokens, password files, SSH material, vault manifests, or restic secrets
- raw typed text, browser captures, screenshots, transcripts, and private retrieval packs
- generated host facts or histories from
/var/lib/abyss-machine - large runtime artifacts, model weights, caches, backups, and indexes from
/srv/abyss-machine
- public-safe templates and examples
- code and tests that can run without private host data
- schemas that describe shape without embedding live records
- docs that explain how local state is generated and maintained
Run public tests and scan the staged tree for obvious token patterns and known private path classes before pushing.
Artifact signing policy is public and source-safe. Contract ABI signatures fingerprint public source surfaces only; do not sign or publish live host evidence, secrets, captures, model caches, runtimes, or backup material as a release substitute.
Validation lanes are runner-neutral OS Abyss contracts. Public lanes use public-safe inputs only.