{"status":"pass","category":"SEC","severity":"medium","evidence":["Keine pre/postinstall-Hooks: Build-Backend hatchling, nur regulaere [project.scripts]-Entry-Points, kein cmdclass, kein setup.py (pyproject.toml:1-2,49).","README zeigt vollen, ungekuerzten Installationsbefehl transparent: 'uvx swiss-environment-mcp' und mcpServers-Config mit command 'uvx' (README.md:66-115,451-459) — kein Hide-behind-one-liner.","Keine Setup-Scripts mit dynamischem Code-Loading im Repo.","PyPI OIDC Trusted Publisher aktiv: .github/workflows/publish.yml mit permissions id-token:write, environment pypi, pypa/gh-action-pypi-publish@release/v1 (Sigstore-Attestation automatisch, kein API-Token).","Zusaetzlich MCP-Registry-Publishing via github-oidc (publish.yml publish-mcp-Job).","CONTRIBUTING.md vorhanden (erklaert Build-Prozess)."],"gaps":["README enthaelt keinen expliziten Sigstore-Verifikationsbefehl fuer Endnutzer (optionaler Katalog-Zusatz, nicht Pass-kritisch)."],"evaluator_notes":"applies_when erfuellt (deployment includes local-stdio). Alle harten Kriterien erfuellt (keine Hooks, transparenter Befehl, Trusted-Publisher/Sigstore). npm-Provenance N/A (Python). Unveraendert pass."}
