Please do not commit live workflow roots, credentials, personal source archives, runtime queues, verification records derived from private data, or resume records containing sensitive paths.
Use disposable or synthetic workspaces for examples and tests. Treat verification records as potentially sensitive because they can contain artifact paths, source identifiers, and failure details.
The kernel performs filesystem reads requested by rule definitions and writes records beneath the configured PKS root. Artifact paths are resolved and must remain within the configured workspace, repository, or PKS roots. Review rule files before running verification against an unfamiliar workspace.
Queue snapshot checks are fail-closed: changed, added, and removed IDs must be declared explicitly. A post-hoc diff is not treated as proof that every observed mutation was intended.