# Read-only source inspection checklist Blank template. It contains no Omarchy installation or runtime results. ## Identity - Canonical repository: - Repository owner: - Tag or release: - Full commit resolved from tag: - Source-check date: - Release-page URL: - License path and digest: - Host-displayed signature state (observation only): - Independent signature verification performed? no / yes, evidence: ## Selected source paths For each path, record why it was selected. Do not copy a repository wholesale when a bounded set answers the question. | Path | Raw bytes | SHA-256 | Question supported | Reviewed by | | --- | ---: | --- | --- | --- | | | | | | | ## Declared mechanisms - Install entry points found in text: - Download/package boundaries found in text: - Launcher or wrapper behavior found in text: - Flags that alter approval or unattended behavior: - Configuration ownership/default paths: - Update behavior: - Removal/reset behavior: - Network or external-service declarations: ## Claim boundaries - Findings supported by inspected text: - Runtime questions not answered by text: - Transitive artifacts not acquired or hashed: - Hardware behavior not tested: - Authentication/provider behavior not tested: - Filesystem/process/network behavior not observed: - Removal/rollback not tested: - Adoption or recommendation made? no ## Next decision - Stop / continue to a separately authorized disposable runtime test: - Reason: - Required authorization and isolation: - Exact evidence a runtime test must produce: