I maintain schemagate , an open-source library and MCP server that stops an AI agent from seeing database tables the user isn't allowed to read. It's a security tool, so "trust me" isn't good enough. A security team looking at it reasonably asks: is the project run properly, is the licensing clean, and is the package on PyPI really built from this repository? There are free, public answers to all three questions. This week I went through them in one sitting. Here's what each one took, includ...