Security model

Verified is review, not a guarantee.

Users should evaluate source repositories, publisher status, license, manifest, permissions, network access, and release integrity before running packages.

Review chain

registrylocal
Source repository
↓
Manifest
↓
Permission declaration
↓
Registry validation
↓
User review
↓
Runtime permission enforcement

Verified means

Publisher identity reviewed, source repository verified, release integrity checked, manifest inspected, and permission declarations reviewed.

It does not mean guaranteed safe, malware-proof, or officially endorsed forever.