1. Run local proof
Install the release tarball, audit the repo, and open the static report. No API key, hosting, telemetry, or source upload.
Run a local report, add CI proof, print a README badge block, and keep the same public repo attached if you later need the fixed-price outside proof path.
Use public/test inputs only. Do not put secrets, production credentials, private customer data, payment data, or private repo access into proof reports.
Install the release tarball, audit the repo, and open the static report. No API key, hosting, telemetry, or source upload.
Generate `.github/workflows/agentproof.yml` with safe defaults, Step Summary output, report artifact upload, and a score gate.
Print a README badge/proof block that links to the workflow, checkout handoff, and safe intake builder for the public repo.