⬡
L-classification
Every repo is mapped to (R)AI's threat taxonomy: L0 through L5, VCCE, ActionGate-relevant. Not vibes — layer-specific evidence.
◈
Runtime, not static
We prioritise tools that operate at the interaction layer — runtime interception, not pre-deploy scanning. Same architectural position as (R)AI.
✦
Open by default
MIT or Apache-2.0. Auditable. No black-box vetted repos — if we can't read it, we can't trust it, and neither can you.
◻
Maintained
Active commits in the last 90 days. Threat surfaces move fast. A repo that hasn't been touched since the threat class emerged isn't protection — it's theatre.