Action-path lab

AI coding isn't the risk. Unmapped action paths are.

Start with a normal-looking PR. In four moves, Trace shows whether the path can reach workflow control, credentials, tools, deploy authority, and the proof trail your team would need after the action.

Normal signal Agent opens a PR

Useful, reviewable, and usually not the dangerous part.

Hidden path PR changes workflow, package, or tool config

Now the path can influence commands and tools that run somewhere else.

Real exposure Automation has credentials

That is where code assistance can become action authority.

Proof gap Proof is split across systems

The question becomes who approved what, with which credential, and what happened.