Threat model

The website summarizes the security model so evaluators can inspect risk before installing.

Hostile cluster data

Logs, annotations, YAML, events, and CRD schema content must be treated as untrusted input.

Webview boundary

The Svelte view layer should not gain broad filesystem, shell, or HTTP capabilities.

Release gate

Security checks are treated as launch gates, not cleanup tasks after distribution.