fix: preserve native library visibility - #6935
Contributor trust inconclusive
Investigator 1/3: Investigator 1 reviewed 34 PRs from member contributor matthewevans (10 with hydrated patches, 24 metadata-only). All hydrated patches show legitimate, sophisticated Magic: The Gathering engine development: parser bugfixes (PR #6853, #6882), engine refactors with extensive tests (PR #6819, #6933), agent workflow hardening (PR #6931), metagame data refreshes (PR #6835, #6810), WASM proposal fixes (PR #6830), BO3 concession controls (PR #6817), and parser IR modernization (PR #6806). No evidence of credential exfiltration, hidden network calls, dependency tampering, obfuscated code, CI tampering, or backdoors. The 24 metadata-only PRs follow consistent engine/parser refactor patterns. Contributor has focused activity in a single repository as a MEMBER with no broad cross-repo activity. Investigator 2/3: All hydrated patches in this shard are benign. The contributor (matthewevans) is a MEMBER of phase-rs/phase, and every PR targets that single repository. Fully reviewed patches consist of: (1) automated MTGJSON card-data refreshes (token catalogs and vintage date stamps), (2) metagame feed JSON updates from MTGGoldfish, (3) a changelog publication with gameplay/UI/AI release notes, (4) a Rust regression test for resolution-stack frame transitions, and (5) previewed parser/engine refactorings and AI security-hardening changes that bind AI actions to engine-validated proposals. None of the patches introduce network calls, credential handling, obfuscated code, dependency/script changes, or permission broadening. There is no cross-repository burst and no unsolicited PR activity. The metadata-only PRs are consistent with the same patterns (data feeds, parser refactors, client/UI fixes, engine journaling). No credible malicious or backdoor evidence was found. Investigator 3/3: Investigator 3 reviewed 33 assigned PRs from contributor 'matthewevans' across the phase-rs/phase repository. Ten PRs had full or preview patches hydrated; the remainder were metadata-only. All hydrated patches show legitimate, high-quality contributions to a Magic: The Gathering game engine (parser, engine core, AI, client UI). Code is extensively commented with Comprehensive Rules citations, includes thorough test coverage and integration tests, and contains no evidence of credential exfiltration, hidden network calls, obfuscated code, CI tampering, suspicious dependency changes, or backdoors. PR #6847 is an automated data feed refresh with no executable code. The contributor is a MEMBER of the organization with activity concentrated in a single legitimate project (plus its fork). No cross-repo pattern of concern. The metadata-only PRs follow consistent naming and description patterns matching the hydrated ones (parser refactors, engine fixes, AI improvements, documentation updates). Based on direct patch-level review of the highest-risk hydrated PRs and the absence of any suspicious signals, the contributor's history is assessed as safe. Patch-level safety guard downgraded the result to caution: 70 PRs were metadata-only after compact hydration.