Security

Trust levels

Planned definitions for Official, Reviewed, Community and Unverified marketplace labels.

Availability note — these docs describe both working and planned product areas. Account authentication, administrator-managed AIHK/AICA tenant regions and keys, signed-in Composer runs and public Guard scans are connected. Skills, Memory, Agents, Workflows, Apps, billing, the public SDK/CLI and the unified API are previews unless a section explicitly says otherwise.


Roadmap and package-contract reference: this page describes the intended GenCMS runtime. The current deployment persists workspace records and drafts but does not execute marketplace Skills, index Memory for retrieval, publish packages, or run Agents, Workflows or Apps. See the deployed API reference for the routes available today.

Marketplace labels are not active. These definitions are a proposed contract for a future marketplace. Current catalogue entries are unpublished, unscanned design concepts and do not claim one of these publisher or review states.

LabelMeaningNot a claim that
GenCMS OfficialPublished by GenCMS / IGEARS TECHNOLOGY LIMITED.It is free of defects.
ReviewedPassed automated scanning and selected human review.Every line was audited.
CommunityPublished by a third-party publisher.GenCMS endorses the publisher.
UnverifiedNot reviewed beyond minimal platform checks.It is unsafe — only that nobody checked.

The label always appears next to the Guard status and the permission list, because a trust label alone tells you who published something, not what it does.