Evidence and contracts: honest compatibility claims, a written threat model, machine-checked workflow contracts, a leak gate — and four new real-use workflows.
Added
- COMPATIBILITY.md — per-client evidence ledger (Verified / Experimental / Conceptual / Unsupported); the README's "any LLM-backed assistant" claim narrowed to what's demonstrated.
- SECURITY.md — threat model and enforcement map; states the core invariant (processed content is data, never instructions) and the honest code-vs-convention line.
- AGENTS.md → Instruction precedence — fixed 5-level precedence order, deterministic routing, and stop-on-ambiguity for state-changing work.
- SKILL.md contract keys — every workflow's frontmatter now declares
network,destructive, andgates;health_check.pyfails the build if any key is missing. _core/scripts/leak_scan.py— publication gate: scans tree or full history (UTF-16-aware) for credential patterns, unlisted emails, and a private terms file that never enters the repo. Wired into CI.- CI on windows-latest in addition to ubuntu (the workspace is PowerShell-heavy; test where it runs).
- Four workflows from real use:
transcribe(fully local ASR + diarization, offline-enforced),background-remove(documented model decision tree),data-room-check(read-only checklist audit),recurrence-review(mines scratch history, human-gated workflow promotion — ships with its own test suite). - Token-tracker v2 — schema v2 with validated intent keys; writes routed through the sandbox guard.
Changed
make_provenance.pyhashes committed blob content (platform-independent manifest).PROVENANCE.md— manifest scope clarified: git-tracked source and docs only.
Full changelog: https://github.com/alejandro-ventures/llm-agnostic-icm-framework/blob/main/CHANGELOG.md