- Manifest validation
- Bounded benign actions
- Workspace escape prevention
- Dry-run planning
- Receipts and rollback
- Canonical Manifest SHA-256
- Static capability inspection
- CI-generated inspection artifact
- explicit resource-budget report;
- richer rollback verification;
- per-action deterministic result schema;
- experiment bundle linking manifest / receipt / generated artifact hashes.
- additional benign telemetry scenarios;
- platform-specific telemetry notes;
- detector-validation recipes.
- arbitrary command execution;
- stealth / persistence / credential access;
- bypass or evasion payload generation;
- uncontrolled networking.