# Local Companion Boundary

The installed companion performs explicit user-approved model operations that
a browser catalog cannot safely perform. MiniModel.org supplies bounded
metadata only; it cannot invoke arbitrary commands, paths, or URLs.

## Allowed Operations

- report bounded capabilities and resource limits;
- accept one exact catalog intent;
- import one exact qualified composition from one consenting peer;
- acquire one immutable public source revision for explicit local conversion;
- stream bounded progress and terminal typed errors;
- cancel real transfer, hashing, conversion, and verification work;
- independently verify all six SLM2 members; and
- atomically install and activate a complete accepted composition.

The API does not accept arbitrary shell commands, arbitrary filesystem paths,
unrestricted URLs, or instruction-file handoffs.

## Session Security

Loopback discovery and every command require an ephemeral challenge, approved
origin, browser-session binding, user presence, least-privilege scope, replay
protection, expiration, and explicit consent. Credentials stay out of URLs,
catalog data, Git, logs, screenshots, and public receipts.

## Storage And Recovery

Staging and activation are separate. Partial pieces and source files remain
inactive; complete member and composition identities are recomputed before an
immutable activation pointer changes. Cancellation, disk-full, crash, or power
loss preserves a truthful journal and never starts a hidden retry.

## Current Evidence

This document specifies the required boundary. It does not prove that the
current companion implements the SLM2 import/conversion operation, that a peer
is reachable, or that any model is qualified. The catalog remains empty until
matching current evidence exists.
