## Summary Policy packages are documented, but discovery is still mostly local paths. Support installing named packages as org policy. ## Acceptance criteria - [ ] Config syntax for package name + version range - [ ] Load from node_modules with integrity expectations - [ ] `DEBTLENS_DISABLE_PLUGINS` still honored - [ ] Docs + example policy package publishing guide
Summary
Policy packages are documented, but discovery is still mostly local paths. Support installing named packages as org policy.
Acceptance criteria
DEBTLENS_DISABLE_PLUGINSstill honored