This repository contains a specification and example documents — not a deployed service. There is no running system here to compromise.
If you believe an example, schema, or piece of reference tooling in this
repository demonstrates an insecure pattern (for instance, a manifest example
that would encourage leaking secrets), please open an issue describing the
concern, or contact the maintainer listed in README.md for anything you would
prefer to disclose privately.
Conformant instances built on this framework are the responsibility of their authors; the framework's verification model (§6) is designed to make security properties checkable, but the checks themselves are supplied by adopters.