## Why The bounded exact `openai` canary restored fresh credential supply but produced no usable credentials, while historical production evidence shows that narrower ecosystem and integration terms can reach different cohorts. A small source-specific keyword wave can test those higher-signal surfaces without expanding broad generic discovery or scan concurrency. ## What Changes - Add three source-specific OpenAI ecosystem queries to each of GitHub, GitLab, and DockerHub. - Apply exact per-query page, page-size, and claim bounds so every new query is independently constrained. - Preserve existing query rotation, target deduplication, revision-aware rescan limits, Docker digest authority, scan concurrency, and keycheck behavior. - Run one controlled production canary per new query and measure discovery, scans, new OpenAI credentials, explicit API outcomes, and usable yield. - Retain, revise, or remove individual queries based on measured bounded evidence rather than fetched volume. ## Capabilities ### New Capabilities - `openai-ecosystem-discovery`: Source-specific bounded discovery for OpenAI integration signatures and deployable ecosystem projects, with per-query canary evidence. ### Modified Capabilities None. ## Impact The change affects `app/config.yaml`, focused query-configuration tests, authority-managed source rotation, and production canary operations. Existing allowlisted query override code is reused unchanged. There is no schema migration, new dependency, detector change, global concurrency increase, or credential recheck policy change.