Deliberately small allowlists, not executable-name or prompt heuristics.
Installation paths identify supported layouts; they do not authenticate code.
Overwritten process titles/argv are not reconstructed from names or environment.
If the remaining argv is unrecognizable, even a known installation is rejected.
Best-effort foreground-job inspection, not proof of native TUI keyboard ownership.
All failures are conservative; callers should pass the key through on errors.
Explicit, user-local installation. Install/uninstall without yes are read-only previews.
yes authorizes payload/templates, not implicit edits to shell or tmux user configuration.
Each user integration requires its own explicit configuration path; omitted integrations
are retained on reinstall, except exact owned references migrated to a new layout.
Run an extracted binary’s install --yes directly, rather
than placing an unowned regular file at the managed bin-symlink destination first.
Updates accept local native executables only; no downloads or version probes are performed.