Extension packages are not executed
Deep Scan extracts and statically inspects an exact published artifact. Extension entrypoints, lifecycle hooks, and bundled executables are not launched by the scanner.
GuardRails analyzes privileged developer tooling. The product should make it easy to see what is isolated, what is retained, and where a result stops being a guarantee.
These statements describe the current web scanner and workspace—not the future native GuardRails IDE sandbox.
Deep Scan extracts and statically inspects an exact published artifact. Extension entrypoints, lifecycle hooks, and bundled executables are not launched by the scanner.
Reports preserve extension ID, version, artifact SHA-256, scanner build, ruleset, coverage, and limitations so a newer result cannot silently replace the reviewed evidence.
Workspace delivery targets are encrypted at rest and are excluded from audit exports. Test delivery responses return health metadata rather than stored credentials.
Published packages are prepared for analysis in an isolated runner. Results cross the boundary through a validated scan-result contract, not through extension-controlled output.
Notification attempts record delivery state, bounded retries, and safe error details. A failed Slack or email delivery does not change the underlying extension decision.
Missing required analysis, unverifiable artifact identity, and unsupported outcomes remain visibly incomplete instead of being converted into a reassuring score.
Do not include secrets, personal data, or unnecessary exploit material. Share the affected route or component, reproducible steps, expected impact, and a safe way to validate the issue through the support channel associated with your GuardRails workspace.