PAES treats model output, generated code, candidate weights, expert packages, retrieved content, and external datasets as untrusted inputs. Capability enforcement, promotion, artifact integrity, release activation, and durable state transitions are performed outside learned components.
Report suspected vulnerabilities privately to the project owner. Include the affected commit, reproduction steps, expected impact, and whether credentials or personal data are involved. Do not include live secrets in a report.
The default tool policy denies network access, arbitrary subprocess execution, writes outside the configured sandbox, release promotion, model activation, and expert graph mutation. Production deployments must retain these deny-by-default controls.