No package execution
Static analysis extracts and inspects published artifacts without launching extension entrypoints, lifecycle scripts, or embedded binaries.
The product processes intelligence about privileged developer tooling. Its own architecture, disclosure process, and claims must withstand the same scrutiny.
Static analysis extracts and inspects published artifacts without launching extension entrypoints, lifecycle scripts, or embedded binaries.
Reports retain registry source, version, artifact SHA-256, ruleset, provider coverage, and limitations.
Severity, evidence class, analysis coverage, and benchmark limits remain visible so a result is never presented as a guarantee.
Do not include secrets or exploit users. Contact the GUARDRAILS team through your established support channel with reproduction details, affected component, and impact.