1e76efbe28
Skipping `tests/`, `spec/`, ... in EXCLUDED_DIRS made those trees invisible to the guard, but `plugins_loader._load_directory_module` sets `submodule_search_locations=[plugin_dir]`, so a plugin `__init__.py` doing `from .tests import evil` imports and runs whatever lives there: a `tests/evil.py` with a destructive root remove scanned `dangerous` on main and `safe` on this branch. `_walk` also matched the names at any depth, so `src/spec/handler.py` — plain runtime code — went unscanned. Keep scanning everything; instead cap a critical finding located under a ROOT-level test dir at `high`, so the verdict is `caution` (confirmation required, `--force` overridable) rather than the un-overridable `dangerous`. Fixture strings still cannot brick an install, which was the reported problem, while a critical in any runtime file (`setup.sh`, `src/spec/...`) still yields `dangerous`. Trade-off stated in the PR body: hostile code deliberately placed under `tests/` is now force-installable rather than blocked outright. Docs no longer claim test code never runs.