Inspector AI Boundary & Security 1.4.0
Phase 6.1 is a privacy-safe consumer facade, not a free DOM/CSS editor or AI design surface.
Allowed
- Read semantic state and sanitized audit.
- Read available policy intents.
- Request existing
rankOnly. - Delegate allowlisted intents and undo.
- Read injected Block manifest metadata.
Forbidden
- Raw HTML/DOM dumps or form values.
- Arbitrary attributes, HTML, CSS, or event handlers.
- Guardrail bypass or direct apply internals.
- Cloud requests or a second AI engine.
- Evaluating Block code while reading a manifest.
AI path
Signals → Policy → optional Local AI ranker → Intent → Validator → Guardrails → Semantic Apply → Audit / Undo. Inspector can display ranking results but cannot convert ranking into authority.
Production boundary
The concept defines Inspector as explicit/dev-oriented opt-in. Phase 6.1 exports Core only; there is no production-default visual bundle.
Freeze
Project 2 freeze: documentation reflects the shipped 1.4.0 surface through Phase 6.1. Inspector Overlay, visual selection UI, token probe, and every Phase 6.2+ stage are not started.