# Independent acceptance checklist, row 18 Darkwing reviews Filbert's implementation without editing its source candidate. Dewey reviews visible connector presentation. No live connector manipulation. - Discovery accepts only safe matching binding name/seat from private regular files, never dereferences a token path and never serializes private fields. - Path traversal, symlinked binding/runtime/session paths and malformed records cannot cause arbitrary reads or an actionable/live row. - No owner, malformed owner, dead PID, missing identity, reused PID and boot mismatch are non-live. A positively matching live process is live. - STOP presence is visible as braked independently of process liveness. Its contents are not read or exposed; no STOP or lock is created or changed. - Ordinary completed messages remain idle. No false human attention regression. - Connector rows cannot borrow a native agent's registration for replies. Exercise replyToRow and HTTP using a fake executable hook; every connector attempt must be refused before that hook runs, including with forged tmux registration. Normal-agent reply tests must still pass. - Both existing board and WebUI distinguish the connector and brake state and omit reply controls. Preserve escaping, including hostile binding fixtures. - Discovery errors disclose no private JSON fields or raw contents. One bad binding must not silently manufacture a healthy row. - Candidate pins match before and after tests. Existing dirty attention changes remain intact; no unrelated source integration or live operation is inferred. After source approval, measure the real row read-only. Offline/braked behavior uses isolated fixtures unless the operator separately approves a live-service transition. Board replacement is its own protected gate.