Run by wayfare-sync-plan. Audit dependency CVEs, container CVEs with Scout and Trivy, and code hardening. Write executable security plans under .plans. Never edit source.