The crown

Every workflow the origin knows, the way GitHub lists them — by name:, grouped by the · prefix — and how the device would run each one. Running is gated behind the crown: a focused, foreground-only mode you take up on purpose and put down when done. Nothing here is fetched.

the held token

The one credential the device can't mint itself — a GitHub fine-grained PAT (Contents R/W) you provision out of band and hold here. It stays in memory only: never a repo file, never a workflow secret, never localStorage. A push needs it AND the crown up.

no token held

add a workflow

Paste any workflow YAML (from any repo or engine submodule) to see how the device would run it.