You can't tell what this produces from a description, and the obvious
way to show it — screenshot a real run — would put someone's actual repo
names in a public README.
So the sample is generated: assets/make-sample.mjs builds a throwaway
HOME of invented repos, invented files and invented sessions, and the
real miner runs against that. The picture is what the tool genuinely
produces, from data that never existed. The generator ships next to the
asset so the next person can regenerate rather than edit a screenshot.
Also widen validate's path filter. It's a required check, so a PR that
only touches a plugin's README or assets matched no pattern, never
reported, and could not be merged — the same trap the workflow-file and
policy-file entries above already work around. Adding the plugin doc
paths lets this PR (and the next one) clear the gate on its own.
No-Verification-Needed: docs asset, dev-only generator, and CI trigger paths — no plugin runtime surface