Agreed, and the run correlation point is the sharpest part of this. Right now the provenance stops at the artifact: upstream commit, hardening log, version tag, all in the OCI layer, none of it tied to the run that produced the weird output. That makes behavior drift hard to attribute. Worth flagging that effective permissions do not exist as a field yet. A skill's real reach is whatever the agent grants plus whatever the instructions talk the model into. That is a gap to close rather than data to expose. On isolation, same page. Hardening shrinks blast radius, it does not replace execution boundaries or an approval path.