# MiniModel Local Companion Boundary

The installed local companion performs the user's requested acquisition when a
browser cannot safely do so alone. It does not turn project sites into model
hosts, remote inference services, or arbitrary local command launchers.

## Session

Each session is origin-bound, browser-session-bound, short-lived, replay
protected, and approved through explicit user presence. Capability discovery
does not authorize conversion, transfer, installation, or account access.

## Typed Intents

The bounded API covers capability, model intent, exact peer import, pinned
source conversion, progress, cancellation, verification, installation,
activation, and safe diagnostics. Inputs use opaque registered identities.
They do not expose arbitrary shell commands, local paths, or unrestricted URLs.

## Route Ownership

One request chooses one route:

- exact qualified peer composition; or
- explicit pinned public source and one registered local conversion.

A timeout, refusal, corrupt piece, source drift, conversion rejection, crash,
or cancellation produces a typed terminal result. It does not silently begin a
different route or invoke remote inference.

## Storage Transaction

Bytes enter a bounded staging area, remain inactive while incomplete, and are
checked by piece, member, manifest, provenance, and qualification identity.
Only the complete accepted composition is atomically activated. Partial or
corrupt state is quarantined or deleted under explicit ownership rules.

## Evidence

Public-safe receipts omit credentials, invitation URLs, local paths, prompts,
model bytes, and raw private evidence. Source code, a configured companion, or
a reachable loopback port does not prove a real acquisition.
