A build journal: how Project Starfish went from a single decision (deny by default) to governing real agents.
A CLI command-composition attack paper sent us back to our own threat model — and found a hardened defense we'd built a month earlier but never wired in.
A 50-category, 0–100 risk score; an operator Risk-Tolerance dial that never lifts the hard floors; and a calm, one-screen cockpit.
Closing the code audit, a durable audit log, and governance as an embeddable surface.
Deny-by-default as an overlay, and a lockdown the agent cannot switch off.
Free for personal and commercial use, with the trademark as the moat.
Governed, reversible deletion and a Custodian bound by hard rules.
The runtime spine, model independence, and the Evidence Gate: no unbacked word.
We stopped salvaging the fork, rebuilt clean, and hardened the skin.
Capability intake, runtime monitoring, and the portable overlay that became the product.
Phases 0 through 4: the trusted base everything else stands on.
Everyone ships skills. Nobody ships governance.