10000app
10000app #0111 · PMF pre-judgment 90/100 · $18 one-time evidence pack under strong GitHub warnings and workflow-security substitutes

The untrusted job still passes.
Did its cache save silently stop?

Map sanitized cache paths after GitHub's read-only-token change. Connect who can trigger, which SHA/scope is shared, whether save is read-only, which trusted workflow restores later, and where a safe push-triggered save belongs—without pasting YAML, keys or logs.

Free · browser-only

Untrusted cache boundary map

Trust gateADD SANITIZED RECORDS
Valid / invalid / duplicate0 / 0 / 0
Recorded / review / cannot tell0 / 0 / 0
Trust / shared-scope gaps0 / 0
Save / external-input gaps0 / 0
Trusted-consumer / replacement / test gaps0 / 0 / 0
Boundary fixtures0 / 10
PathTrigger / trust / scopeRestore / saveInput / consumerReplacement / testEvidence / ownerDecision / result

Poison-path, regression and trusted-save queue

    “Evidence recorded” proves only coherent abstract metadata. This page did not inspect a workflow, cache key/path, SHA, expression, token, permissions or logs; calculate actual cache scope; save/restore a cache; change a workflow; prove poisoning resistance; or guarantee performance.