No model-generated shell
Validator commands come from trusted adapters. Model text is never treated as an executable command.
SECURITY BY ARCHITECTURE
Verify is designed around J OS' capability model: intelligence can inspect broadly only where permission exists, while execution authority remains narrow, explicit and auditable.
Validator commands come from trusted adapters. Model text is never treated as an executable command.
Untrusted projects require isolated execution. No silent fallback to host execution.
Project reads and validator execution require distinct scoped capabilities.
Validation processes do not inherit J's full secret-bearing environment.
JVerify can run inside an institution's own infrastructure so source code and project information do not need to leave its security perimeter.
Authorization and validation outcomes can be surfaced through J OS audit and event facilities.