# Comparative Baseline: Onyx Analysis vs myStarterKit

This comparison file uses the Onyx-based runtime analysis as a baseline for evaluating secure-by-default retrofits in myStarterKit.

Comparison themes:

- architecture reconstruction versus starter implementation boundaries
- trust-boundary clarity versus implicit runtime assumptions
- attack-surface coverage for RAG and agent workflows
- retrofit control opportunities for authorization, policy, and telemetry

The document exists as evidence context for portfolio review and is not presented as an upstream project endorsement.
