Cryptographic signing for packs so the validator can distinguish first-party content from unverified community submissions and enforce trust levels (e.g. official / verified creator / unsigned). Only meaningful once the community pack browser exists — sequenced after it.
Acceptance
- Official packs ship signed; validator surfaces tier at import and in the library UI
- Unsigned packs still importable with a clear warning (local-first: the user decides)
- Signature scheme documented in docs/pack-validation.md
From docs/post-alpha-issues.md item 10 (Milestone 3 — community). Blocked by the community pack browser.
Cryptographic signing for packs so the validator can distinguish first-party content from unverified community submissions and enforce trust levels (e.g. official / verified creator / unsigned). Only meaningful once the community pack browser exists — sequenced after it.
Acceptance
From docs/post-alpha-issues.md item 10 (Milestone 3 — community). Blocked by the community pack browser.