MWIP Core v0.2 Incubation Security Review
Scope reviewed
The review covers the Core schema, C0/C1 fixtures and deterministic local conformance runner. No network service, credential processing, identity binding, tenant storage, payment, provider adapter or effect executor exists in this repository.
Findings
The runner rejects an unsupported profile version, unknown operation class and settlement_authorized: true. It treats malformed/missing Core values as validation failure. A focused repository secret-pattern scan found no credential material in implementation artifacts.
Remaining risks and gates
This is a schema/tooling review, not a production control-plane or external-effect security review. Canonical JSON/signature formats, evidence retention, key distribution, identity binding, privacy redaction and effect approval are out of Core v0.2 scope and need separate profiles/reviews. C0/C1 conformance must not be advertised as authorization, payment, settlement or runtime execution certification.
Pilot result
The fixture corpus passes the deterministic runner. KKQTVH, Dilinhland, Avatar Forge and Kien-Truc-Viet remain recorded as v0.1 migration candidates. FitLove now has an emitted v0.2 discovery projection represented by fixtures/c0-c1/valid-fitlove-wellness.json; it passes the independent runner at the current incubation baseline, so the evidence is limited to C0/C1 discovery and safety posture. This does not certify identity binding, control-plane binding, privacy redaction, approval, provider execution, payment, settlement or production compatibility.