# Quarantine and Verification Every selected file first lands below `/.quarantine/`. Repository paths are normalized as relative POSIX paths, traversal and absolute paths are rejected, resolved paths must remain beneath the root, and symlink roots/files are blocked. The agent runs non-root with a read-only container filesystem, dropped capabilities and narrow data mounts. Verification never imports or deserializes model content. It checks regular-file size, streams SHA-256 in bounded chunks, compares available upstream LFS SHA-256, parses only the bounded JSON header of Safetensors, inspects small JSON configuration for `auto_map`, and blocks known pickle/executable serialization and repository Python. `trust_remote_code=false` is the invariant. Hub scanner signals remain separate upstream evidence. All required files must pass before the job-scoped directory is atomically renamed to `repositories//`. Only then does the agent report completion. The control plane validates the report against the immutable plan and transactionally creates `ModelArtifact`, `ArtifactLocation`, `ArtifactInspection`, and `ArtifactSetMember` records. The set becomes `availability=local`, `completeness=complete`, and `status=verified`; its security state is `static_checks_passed_unapproved`, not supply-chain approved. Failed or cancelled work never creates verified DB records. Retained partials remain job-scoped for safe retry; cleanup is an explicit lifecycle operation. A manifest beside promoted bytes records job, repository, commit and file digests for crash reconciliation.