No tracked Horilla source file is modified. Each context starts as a clean git archive of the exact contract commit. Horilla ships migration package stubs, so manage.py makemigrations creates only startup migration files in disposable source/dependency trees; each case records those paths in generated_migrations_inventory.log. base/views.py and base/urls.py are hash-checked before and after execution. SQLite databases, canaries, and the attacker program are generated runtime artifacts.