Security
See repository SECURITY.md. Highlights from README:
- Hosted fetchers: local robots.txt pre-flight; refuse on Disallow
- External mutations (email sends, index pushes): dry-run by default; require
--live - CI: check-pii, stdlib-only / dependency-creep guards
- AI Staff: on Grok Bot, bot names are not security boundaries (shared cloud computer)
Install skills
npx skills add …
Hire AI Staff