Every workflow the origin knows, the way GitHub lists them — by name:, grouped by
the · prefix — and how the device would run each one. Running is gated behind the crown:
a focused, foreground-only mode you take up on purpose and put down when done. Nothing here is fetched.
The one credential the device can't mint itself — a GitHub fine-grained PAT (Contents R/W)
you provision out of band and hold here. It stays in memory only: never a repo file, never a
workflow secret, never localStorage. A push needs it AND the crown up.
Paste any workflow YAML (from any repo or engine submodule) to see how the device would run it.