PINNED PUBLIC-DRAFT PROOF SNAPSHOT This is verbatim output from a reproducible ACX proof run. The suite keeps growing; run `npm test` at the checked-out release for the complete live test list and total. ########## PROOF 1: conformance suite snapshot ########## > agent-cartridge@0.1.0 test > node --experimental-sqlite --test 'test/*.test.mjs' ✔ acx.agent-graph/1 accepts fuzzy prose with hard reference invariants (4.671542ms) ✔ information cycles are valid because routes do not execute task loops (0.446083ms) ✔ knowledge modules are descriptions only and all actor/knowledge refs fail closed (0.307833ms) ✔ malformed collection fields return issues instead of throwing (0.339542ms) ✔ discovery cards remain safe for malformed top-level collections and items (1.503ms) ✔ periodic cadence needs an interval and fuzzy weights stay in [0,1] (0.31025ms) ✔ self-routes, empty cardinality, empty returns, and ambiguous loop bindings fail closed (0.3115ms) ✔ route triggers are structured and returned knowledge uses an explicit reverse route (0.307584ms) ✔ duplicate structured triggers and periodic freshness without a bound fail closed (0.261ms) ✔ graph and convergence bounds fail closed (0.277042ms) ✔ mandatory direction for the same knowledge has one acyclic source (0.42175ms) ✔ convergence requires at least two distinct loops (0.242958ms) ✔ convergence only accepts loop exports that reach the output steward (0.151583ms) ✔ publication profile rejects incomplete discovery metadata (0.470458ms) ✔ publication profile requires pinned ACX loops and rejects secret-like metadata (0.5125ms) ✔ publication rejects private extension keys and local home-path disclosure (0.552459ms) ✔ agent graph signing binds the canonical graph and verifies as portable (2.95775ms) ✔ agent graph verification rejects knowledge or identity tampering (2.214667ms) ✔ verification rejects a correctly signed graph with an invalid publication structure (0.71075ms) ✔ agent graph verification checks all in-toto count bindings (1.137ms) ✔ namespace proof upgrades an agent graph from portable to trusted (1.065458ms) ✔ agent graph card exposes a safe deterministic discovery summary (1.174084ms) ✔ §12.1 header bytes: application_id at offset 68, user_version at offset 60 (10.318958ms) ✔ §12.1 Cartridge.open rejects a non-.acx file (wrong application_id) (4.390458ms) ✔ §12.2 sqlar names must be zone-prefixed; zoneOf classifies rom/save (0.074541ms) ✔ JCS is independent of key insertion order (0.065ms) ✔ oidJcs is key-order independent; oidRaw is byte-stable (0.147042ms) ✔ §12.3 ROM manifest hash is reproducible from the same ROM objects (6.396ms) ✔ §12.3 DSSE/in-toto sign+verify round-trip; keyid form; subject.digest = manifest_hash (0.668333ms) ✔ §12.3 tamper: mutating the signed payload fails DSSE verification (0.2625ms) ✔ §12.3 tamper: verifying with the wrong public key fails (0.32425ms) ✔ §12.6 trust: unsigned cartridge -> legacy (5.603667ms) ✔ §12.6 trust: valid signature + unknown signer -> portable (5.612041ms) ✔ §12.6 trust: valid signature + registered signer -> trusted (5.381958ms) ✔ §12.6 trust: signer is our own local key -> local (5.989916ms) ✔ §12.6 trust: mutated ROM object after signing -> tampered (4.71625ms) ✔ §12.4 loadTrustRegistry refuses private key material (0.516208ms) ✔ §12.8 scrub blocks an AWS access key (0.452709ms) ✔ §12.8 scrub blocks a PEM private key (0.182208ms) ✔ §12.8 scrub blocks a GitHub token (0.138792ms) ✔ §12.8 scrub passes clean input (0.046ms) ✔ §3.4 strip-to-ROM: manifest hash equal when only SAVE rows are removed (8.14075ms) ✔ §12.7 sqlar skills are extractable byte-for-byte and index content_sha256 matches (4.522542ms) ✔ export produces a valid .acx with ROM objects, a skill index, and capabilities (0.943125ms) ✔ exported cartridge id embeds the publisher + slug (0.088958ms) ✔ field-learned records are quarantined by default (no repoId leaks into ROM memory) (0.269042ms) ✔ unknown-signer verification is portable; registered signer is trusted/local (4.384292ms) ✔ strip-to-ROM on the exported cartridge preserves the manifest hash (2.139542ms) ✔ a ROM tamper on the exported cartridge is detected (1.614458ms) ✔ §7.5 scrub gate FAILS CLOSED: export is blocked when a portable record carries a secret (7.056125ms) ✔ rebuilding the ROM manifest from the stored objects reproduces the signed hash (0.860416ms) ✔ C1: rewriting signed sqlar content with a stale objects.oid is detected as tampered (19.527458ms) ✔ C1: rewriting a capability proficiency to verified with a stale oid is tampered (9.406875ms) ✔ §7.4 mergeRecords never collapses across the tier boundary (0.195667ms) ✔ §7.3 mergeRecords is commutative (order-independent survivor) (0.8565ms) ✔ §8 harness-requirements manifest matches its schema (requiredTools, no forbidden keys) (0.090209ms) ✔ §4.2 DSSE envelope contains exactly {payloadType, payload, signatures} (8.44425ms) ✔ §7.6 stored memory payload carries schema-required zone + artifactFingerprint (7.934291ms) ✔ §7.5 scrub gate catches hex secrets, access_token=, passwd= (H2) and passes clean text (0.159083ms) ✔ §4.5 unverifiable envelope (no key) never claims the signature is valid (7.951041ms) ✔ local-hash-128 embed is 128-dim, deterministic, and L2-normalized (1.755083ms) ✔ empty text embeds to an all-zero vector (0.092916ms) ✔ materializes a genuine LanceDB dataset into the SAVE zone without breaking the ROM signature (697.35ms) ✔ §10.2 update shrinks sigma and conservative R = mu - 3*sigma (0.921958ms) ✔ §10.2 levelFor + careerTierForLevel bucket the conservative rating (0.8065ms) ✔ base58btc round-trips arbitrary bytes incl. leading zeros (0.1415ms) ✔ §10.2 makeBenchmark seals a held-out slice and is deterministic (0.6825ms) ✔ §10.3 referenceSolver is deterministic and ROM-bound (0.222125ms) ✔ §10.2 a weak agent fails the sigma gate -> no VC issued (4.98ms) ✔ §10.2 a strong agent earns a σ-gated VC (4.913291ms) ✔ §10.1 credential proof round-trips (eddsa-jcs-2022) (5.138708ms) ✔ §10.1 verifyLevelCredential accepts a valid, gated, ROM-bound credential (4.769791ms) ✔ §10.1 verifyLevelCredential rejects self-issuance (issuer == subject) (4.241ms) ✔ §10.1 verifyLevelCredential rejects a ROM digest mismatch (anti-transplant) (4.37ms) ✔ §10.1 verifyLevelCredential rejects a revoked credential (4.552208ms) ✔ §10.1 verifyLevelCredential rejects a tampered credential body (4.323042ms) ✔ §7.1 validateRecord accepts a well-formed portable record (0.760291ms) ✔ §7.1 validateRecord accepts a well-formed field-learned record (0.064666ms) ✔ §7.1 validateRecord rejects missing boolean portable (0.165333ms) ✔ §7.1 validateRecord rejects portable=true with a codebaseFingerprint (0.063084ms) ✔ §7.1 validateRecord rejects portable=true with a repoId (0.056667ms) ✔ §7.1 validateRecord rejects portable=false without a codebaseFingerprint (0.052708ms) ✔ §7.3 artifactFingerprint is exactly 10 hex chars (0.415792ms) ✔ §7.3 artifactFingerprint excludes portable + codebaseFingerprint (tier-independent) (0.102959ms) ✔ §7.3 artifactFingerprint is stable under tag reordering + case + whitespace (0.087541ms) ✔ §7.3 mergeRecords is idempotent (merge twice == merge once) (0.904541ms) ✔ §7.3 mergeRecords resolves conflicts: longer text, worse impact, max xp, union tags, latest ts (0.106ms) ✔ §7.3 mergeRecords dedupes by artifactFingerprint across different ids (0.091959ms) ✔ §7.3 mergeRecords keeps distinct records distinct (0.061333ms) ✔ §7.2 codebaseFingerprint never contains the repo name/label (0.405375ms) ✔ §7.2 codebaseFingerprint is stable for the same salt + identity (0.123417ms) ✔ §7.2 codebaseFingerprint differs across installation salts (org quarantine) (0.060042ms) ✔ §7.2 codebaseFingerprint rejects a weak (<256-bit) salt (0.075792ms) ✔ §7.2 canonicalRepoIdentity normalizes scheme/credentials/.git/scp forms equally (0.046ms) ✔ share agent prepares only the verified artifact and generated discovery card (11.358584ms) ✔ share agent dry-run is non-mutating and refuses unsafe identity changes (4.149583ms) ✔ share workflow preserves signed bytes and renders a reviewable PR body (2.726417ms) ✔ share agent graph preserves signed bytes and explains its non-executing scope (5.707417ms) ✔ share accepts signed sub-namespace publishers for path-independent graph artifacts (2.767125ms) ✔ share refuses symlinked registry destinations before any outside write (2.103625ms) ✔ share preparation is idempotent and registry policy rejects private keys (3.944625ms) ✔ acx.cal/1 publish profile accepts a complete, bounded workflow (2.4755ms) ✔ CAL conditions are closed structured data and resolve declared state (0.149834ms) ✔ structural linter rejects duplicates, dangling conditions, and malformed completion contracts (0.353375ms) ✔ structural linter rejects unknown fields and malformed objects without throwing (0.285958ms) ✔ cyclic workflows fail closed unless limits.maxSteps bounds the loop (0.223916ms) ✔ slot staffing checks role, proven tier/level, capability, and stack (0.122583ms) ✔ workflow signing binds the canonical document and verifies as portable (4.435209ms) ✔ workflow verification rejects content tampering and publisher-binding tampering (0.954625ms) ✔ workflow verification rejects a valid signature with incomplete in-toto bindings (0.573791ms) ✔ workflow verification upgrades a namespace-proven publisher to trusted (0.85ms) ✔ workflow verification fails closed for a key-compromise revocation (0.594667ms) ✔ workflow lint separates portable structure checks from roster readiness (0.269709ms) ℹ suites 0 ℹ fail 0 ℹ cancelled 0 ℹ skipped 0 ℹ todo 0 ℹ duration_ms 775.468209 ########## PROOF 2: smoke (export->verify->strip->tamper) ########## exported cartridge: io.github.agentibus/scenario-research-designer@22f2ae29-54e8-441a-8853-1c9e84a91873 rom_manifest_hash: sha256:1726cf1e6025c166e06dc839a5cbae6c900f0ffa3e0b1235be8b78e88ee09943 ROM objects: 21 skills: [ 'expertise-designer' ] capabilities: [ 'implement-feature[pkg:generic/benchmarking+pkg:generic/research+pkg:generic/ux]', 'build-dag[pkg:generic/snowflake+pkg:pypi/apache-airflow+pkg:pypi/dbt-core]' ] verify (empty registry): warning / portable - Signature valid but signer not in trust registry. verify (trusted registry, local key): verified / local - Signed by this instance. strip-to-ROM equal: true (before==after: true ) verify (objects.oid tamper): invalid / tampered - ROM content diverges from signed manifest (object hash mismatch). verify (SKILL.md content tamper, oid stale): invalid / tampered - ROM content diverges from signed manifest (object hash mismatch). SMOKE OK ########## PROOF 3: prove-level (earn + verify unfakeable level) ########## cartridge ROM digest: sha256:1726cf1e6025c166e06dc839a5cbae6c900f0ffa3e0b1235be8b78e88ee09943 benchmark acx-bench-dag-de@2026.07.1: 160 tasks, held-out slice digest sha256:d16bf83a37c399775… weak agent (competence 14): NOT ISSUED — gating failed: sigma=2.230 (<1.5?), games=50 (>=30?) | R=5.80 tier=junior strong agent (competence 33): ISSUED ✅ | mu=33.03 sigma=1.232 games=90 passRate=60% R=29.34 => acxLevel=29 tier=principal credential verification: VALID ✅ capability build-dag effective proficiency (resolved from attestation): VERIFIED tier=principal mu=33.03 sigma=1.232 ROM signature after attaching attestation: warning / portable (intact ✅) standalone VC: /tmp/acx-prove-level-/level-attestation.json anti-gaming — self-issued credential: REJECTED ✅ [ 'self-issuance rejected (issuer == subject)' ] anti-transplant — VC on mutated ROM: REJECTED ✅ [ 'ROM digest binding mismatch' ] revocation — status bit set: REVOKED ✅ PROVABLE LEVEL OK — level earned from re-run, cryptographically verified, unfakeable ########## PROOF 4: CLI export ########## cartridge id: io.github.agentibus/scenario-research-designer@025edd67-cc60-47b8-a059-ddd839c29db5 rom hash: sha256:f479be021b8ea2e55cc6e3e33b95df9d151196548dfc854dedbe578be7120642 keyid: ed25519:17bb8c9290fd2a3d0c3a434ad0e99544d809dbff1540d64be0bab2274df14f66 signing key: /tmp/demo.acx.key.pem (private — keep secret, outside cartridge) field-learned: quarantined (default) wrote: /tmp/demo.acx ########## PROOF 5: CLI inspect ########## == meta == acx.agent_name = Scenario Research Designer acx.cartridge_id = io.github.agentibus/scenario-research-designer@025edd67-cc60-47b8-a059-ddd839c29db5 acx.created_at = 2026-04-03T13:35:46.190Z acx.declared_level = 4 acx.embedding_engine = {"id":"local-hash-128","dim":128} acx.model = gemini-2.5-pro acx.provider = gemini acx.publisher_id = io.github.agentibus acx.role = designer acx.rom_manifest_hash = sha256:f479be021b8ea2e55cc6e3e33b95df9d151196548dfc854dedbe578be7120642 acx.spec_version = 0.1 acx.vec0_format = 1 == ROM objects == total: 21 (memory:1, cartridge:9, sqlar:11) == skills (acx_skill) == - expertise-designer: Specialized designer expertise on research, ux, benchmarking. Use when a task matches this agent's d == capabilities == - implement-feature[pkg:generic/benchmarking+pkg:generic/research+pkg:generic/ux] verified=false - build-dag[pkg:generic/snowflake+pkg:pypi/apache-airflow+pkg:pypi/dbt-core] verified=false == memory (by zone) == rom: 1 == attestations == (none) ########## PROOF 6: CLI verify (empty registry) ########## status: warning trust: portable summary: Signature valid but signer not in trust registry. keyid: ed25519:17bb8c9290fd2a3d0c3a434ad0e99544d809dbff1540d64be0bab2274df14f66 signedAt: 2026-04-03T13:35:46.190Z issues: Signer keyid not in trust registry exit=0 ########## PROOF 7: CLI strip (ROM-intact proof) ########## rom hash before strip: sha256:f479be021b8ea2e55cc6e3e33b95df9d151196548dfc854dedbe578be7120642 rom hash after strip: sha256:f479be021b8ea2e55cc6e3e33b95df9d151196548dfc854dedbe578be7120642 hash-equality proof: EQUAL (ROM intact; SAVE removed) wrote: /tmp/demo.rom.acx exit=0 ########## PROOF 8: CLI level (earn a level) ########## cartridge rom digest: sha256:f479be021b8ea2e55cc6e3e33b95df9d151196548dfc854dedbe578be7120642 benchmark: acx-bench-dag-de@2026.07.1 (160 tasks, held-out 96) level: ISSUED acxLevel: 29 tier: principal rating: mu=32.85 sigma=1.191 games=90 pass@1=60% R=29.27 credential verify: VALID capability build-dag -> resolvable as VERIFIED via attestation (ROM signature left intact) wrote VC: /tmp/demo.level-attestation.json exit=0 ########## PROOF 9: stock sqlite3 sqlar interop (extract skills) ########## rom/skills/expertise-designer/SKILL.md ########## PROOF 10: file(1) magic + header ########## /tmp/demo.acx: SQLite 3.x database, application id 1094932529, user version 16777472, last written using SQLite version 3053002, file counter 14, database pages 33, cookie 0xa, schema 4, UTF-8, version-valid-for 14