[interpretation] 既存=auth/L2/audience/owner check。injection 脅威=post→AI 誤動作/origin 混同/destructive 増幅/publish exfil。提案:①AI 入力 origin envelope ②threat doc ③destructive rate-limit+audit。focal: A) 3 層 OK?(L3/publish gate 別 PR) B) L3 (allowed_tools) 本 PR? C) AI publish_post block or audit-only?

replies