feat: publish Sandwich Hime tooling preview

Publish the exact sanitized Agent Skill and VS Code preview source tree with independent license boundaries, deterministic provenance manifests, and no private development history. Material design and implementation assistance was provided by OpenAI Codex.

Signed-off-by: Cole Speelman <crspeelman@gmail.com>
This commit is contained in:
2026-08-12 20:33:51 -04:00
commit 6df87bc958
51 changed files with 7424 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
<!-- SPDX-License-Identifier: AGPL-3.0-only -->
# Security policy
Report suspected vulnerabilities privately to security@sandwichhime.com.
Include the affected version, platform, reproduction steps, and expected
impact without secrets or unnecessary personal data. Expect a best-effort
acknowledgement within three business days, initial triage within seven, and
an update at least every fourteen days while work remains open.
The preview has no bug bounty. Good-faith research that avoids privacy harm,
service disruption, credential access, persistence, and public disclosure
before a reasonable remediation period is welcome.
The Agent Skill is instruction text. The VS Code extension starts a locally
installed Hime-san only inside a trusted workspace and never downloads or
upgrades it. Syntax highlighting remains available in untrusted workspaces;
all subprocess-backed features are disabled.