Aftermath

Trust model

Security

Aftermath executes repository commands to produce verification evidence. Treat it as a privileged local tool.

Do not run against untrusted repositories without reviewing .aftermath.toml, package scripts, and CI workflows that may be discovered.

Full policy: SECURITY.md · threat model