01
No silent publishing
Live posting requires an approval record. Paid spend is outside v1.0.0.
Security
DRAX defaults to dry-run, explicit approvals, least-privilege platform tokens, source allowlists, reproducible assets, and a permanent manual fallback.
01
Live posting requires an approval record. Paid spend is outside v1.0.0.
02
Playwright is a controlled experimental adapter, never the only path to a platform.
03
Credentials are scoped, ignored, rotated, and excluded from prompts, artifacts, and logs.
Verification baseline
The initial target is an OWASP ASVS Level 1-aligned hosted surface and SCVS Level 1-aligned package process, with higher controls activated as sensitive integrations enter production.
Send a concise report to einstenrodrigues.dev@gmail.com. Do not include active credentials or personal data.