I wrap up the series with the operational side: how to launch the workflow daily. A persistent plan.md, pre-commit hooks as guardrails, a multi-level CI pipeline, and a simple audit to adopt an existing repo.
Audit
pi-secured-setup v1.1.0 maps against the OWASP AI Agent Security Cheat Sheet. HMAC-chained audit log, bash exfiltration detection, rate limiting, prompt injection scanner, and 14 Dependabot advisories closed.
A test suite can show good coverage and miss an obvious bug. To measure real quality, I look at four complementary axes, with a simple audit to apply to an existing project.