akicita 0.1.1

Bounded autonomy for self-acting systems: an autonomy ladder (off/suggest/safe-apply/full), protected surfaces that never auto-apply, blast-radius caps, rate limits, and dedupe — named for the Lakota camp marshals who kept warriors inside the bounds
Documentation
# Security policy

## Reporting

Open a private security advisory on the GitHub repository, or email the
maintainer (see `Cargo.toml` authors). Please do not file public issues
for vulnerabilities in the marshal logic — e.g. a bypass that lets a
protected surface auto-apply.

## Scope

In scope:

- Bypass of the protected-surface list (basename or prefix).
- Escalation of autonomy level without writing the level file.
- Journal writes that evade the decision record.
- Dedupe or rate-limit behavior that permits unlimited applications.

Out of scope:

- Malicious content *inside* a permitted proposal — akicita bounds
  radius and rate, not intent. Use a deliberation layer for judgment.
- Attacks requiring write access to the operator's level file or
  journal — those are filesystem trust boundaries.
- Denial of service against the `check` call itself (it is in-process
  and already trusted by the caller's thread).

## Guidance

- Mount `journal_path` on an append-only or audited filesystem if the
  record must survive a compromised caller.
- Treat `level_path` as an operator control: owner-writable only.
- Pair with `xipe` (constitutional amendment lifecycle) for proposals
  that need deliberation and ratification before they even reach the
  marshal.