Prepared for Frantic bounty #21, runx skill: dependency CVE audit.
The governed skill is in skill/dependency-cve-audit. The named real target is
minimistjs/minimist tag v1.2.5, commit
aeb3e27dae0412de5c0494e9563a5f10c82cc7a9.
The live run writes:
artifacts/report.jsonartifacts/report.mdartifacts/evidence.jsonreceipts/<receipt-id>.json
The target checkout itself is not part of the published delivery repository; the evidence records its public repository, tag, commit, and manifest digest.