diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml
new file mode 100644
index 0000000..2300ff5
--- /dev/null
+++ b/.github/workflows/docs.yml
@@ -0,0 +1,24 @@
+# Does this organisation advertise what it has?
+#
+# The landing drifts silently: a repository is created, and nothing in any
+# repository fails because no page mentions it. esbuildsandbox closes a sandbox
+# leak in a dependency, and was on no page of the organisation that found it.
+#
+# ⛔ NOT `on: [push, pull_request]`: both fire for a branch with a pull request
+# open, so every push runs the check twice.
+#
+# ⛔ It needs NO secret. Listing a public organisation and reading its surfaces
+# are public reads, so this runs on github.token.
+name: docs
+
+on:
+ pull_request:
+ push:
+ branches: [main]
+
+permissions:
+ contents: read
+
+jobs:
+ current:
+ uses: go-fleettools/fleettools/.github/workflows/docs-current.yml@main
diff --git a/hugo.toml b/hugo.toml
index d95b451..a01bf8b 100644
--- a/hugo.toml
+++ b/hugo.toml
@@ -12,6 +12,11 @@ disableKinds = ["taxonomy", "term", "RSS", "sitemap", "404"]
type = "lib + cli"
blurb = "Fetch a URL → DOM → CSS cascade (var()/@media/dark-mode) → run the page's JavaScript → full box-model layout (flex/grid/tables/position) → paint anti-aliased text, gradients, images and SVG to an image.RGBA / PNG. Pure Go, CGO_ENABLED=0, no Chromium; ships a `render` CLI."
badge = true
+[[params.repos]]
+ name = "esbuildsandbox"
+ role = "One function, against one leak"
+ type = "lib"
+ blurb = "A safe ResolveDir for esbuild's pkg/api. A caller bundling untrusted source installs an OnResolve/OnLoad plugin and it looks complete — every import in its own tests goes through it. But the bundler expands a glob dynamic import, import(`./${lang}/index.js`), by walking ResolveDir on the real filesystem through its internal resolver, bypassing the plugin entirely. Whatever that directory is — \"/\" is a common default — is what gets walked, following symlinks. This returns a directory where that walk finds nothing."
[[params.repos]]
name = "browserproxy"
role = "Remote-browser service"