# Per-Capability Specifications, Threat Models, and Trust Assumptions

> Generated from the canonical manifest. Every audited capability and route has an entry; this document adds no authority.

## `base-additive.canonical-reward-receipts-v3` — CanonicalRewardReceiptsV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Canonical EIP-712 grouped-reward lifecycle receipts with actor, identity, provenance, consent, validity, resource, action, payload, chain-domain, nonce, and replay bindings.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.consent-registry-v3` — ConsentRegistryV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Scoped EIP-712 consent grants and subject revocation.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.cross-chain-receipt-registry-v3` — CrossChainReceiptRegistryV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Route-specific informational cross-chain receipt registration through an immutable verifier; no bridge or value movement.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.deterministic-coverage-v3` — DeterministicCoverageV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Fully reserved native-asset coverage for explicit objects and deterministic objective triggers.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.e-i-p712-auth-v3` — EIP712AuthV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Internal EIP-712 authorization and nonce-domain primitive for additive Base modules.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.emergency-controls-v3` — EmergencyControlsV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Immutable governance and guardian pause controls with pause-safe exits.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.native-asset-ledger-v3` — NativeAssetLedgerV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Internal native-asset liability, credit, locked, reserved, and surplus accounting primitive.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.pinned-trust-adapters-v3` — PinnedTrustAdaptersV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Runtime-codehash-pinned informational KYA and ERC-8004 read adapters with no protected-decision grant.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.portable-receipts-v3` — PortableReceiptsV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Portable issuer-signed informational evidence and provenance receipts.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.reward-vault-v3` — RewardVaultV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Separately funded rewards isolated from protected principal and slashing.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.session-capabilities-v3` — SessionCapabilitiesV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Exact-call finite session capabilities with delegation, nonce, cap, expiry, and revocation.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.task-milestone-escrow-v3` — TaskMilestoneEscrowV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Native-asset task and milestone escrow with bilateral release and bounded recovery.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.v-n-s-v3` — VNSV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Commit/reveal convenience naming with expiry and delayed recovery; no authority meaning.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base-additive.voluntary-mutual-aid-v3` — VoluntaryMutualAidV3

**Kind:** capability / `base-additive-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Recipient-created voluntary native-asset mutual aid with donor and expiry recovery.

**Threats:** authorization replay; liability/accounting failure; unsafe lifecycle boundary; receipt field substitution; scope overclaim  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.accountability-bond-factory-v3` — AccountabilityBondFactoryV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** deployment-only factory; exact initcode and runtime hashes enforced

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.accountability-bond-v3-safe` — AccountabilityBondV3Safe

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** codehash-pinned canonical on-chain deadline fact; deterministic pre-agreed slash

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.accountability-canonical-source-v3` — AccountabilityCanonicalSourceV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** exact non-proxy append-only self-authenticated action timestamp source; runtime codehash is protocol-pinned

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.base-pilot-access-controller-v3` — BasePilotAccessControllerV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** bounded allowlist, deployment gate, allocation caps, and guardian coverage

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.base-sepolia-rehearsal-access-controller-v3` — BaseSepoliaRehearsalAccessControllerV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Rehearsal-only controller with no production authority.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No production implication.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.bond-math-lib-v3` — BondMathLibV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.bond-state-v3` — BondStateV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.canonical-identity-registry-v3` — CanonicalIdentityRegistryV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`excluded`  
**Spec:** Discovered source outside the canonical supported module boundary.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Requires reviewed disposition change before support.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.dispute-registry-v3` — DisputeRegistryV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`retired`  
**Spec:** Source retained as an excluded tombstone; it is not a supported V3 release capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Retirement must remain enforced across SDK, API, discovery, and deployment tooling.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.e-i-p712-base-v3` — EIP712BaseV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.e-r-c8004-identity-adapter-v3` — ERC8004IdentityAdapterV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** codehash-pinned read-only identity adapter; no protected-decision grant

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.e-r-c8004-validation-registry-v3-safe` — ERC8004ValidationRegistryV3Safe

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`retired`  
**Spec:** Source retained as an excluded tombstone; it is not a supported V3 release capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Retirement must remain enforced across SDK, API, discovery, and deployment tooling.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.evidence-registry-v3` — EvidenceRegistryV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** informational typed attestations only; no supported protected-decision consumer

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.i-accountability-canonical-source-v3` — IAccountabilityCanonicalSourceV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.i-dispute-subject-v3` — IDisputeSubjectV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.i-e-r-c8004-identity-registry` — IERC8004IdentityRegistry

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.i-mandate-execution-adapter-v3` — IMandateExecutionAdapterV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.i-pilot-access-controller-v3` — IPilotAccessControllerV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.legacy-k-y-a-adapter-v3` — LegacyKYAAdapterV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`excluded`  
**Spec:** Discovered source outside the canonical supported module boundary.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Requires reviewed disposition change before support.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.mandate-execution-adapter-v3` — MandateExecutionAdapterV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** principal-signed finite mandate with exact target, selector, value and execution binding

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.mandate-registry-v3` — MandateRegistryV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** non-empty sorted target/selector scope and finite spend/rate caps

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.multisig-governance-v3` — MultisigGovernanceV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** default-deny target/selector/value policy, committed policy updates, timelock, and proposal expiry

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.mutual-aid-pool-v3` — MutualAidPoolV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`retired`  
**Spec:** Source retained as an excluded tombstone; it is not a supported V3 release capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Retirement must remain enforced across SDK, API, discovery, and deployment tooling.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.objective-rule-schema-v3` — ObjectiveRuleSchemaV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`excluded`  
**Spec:** Discovered source outside the canonical supported module boundary.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Requires reviewed disposition change before support.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.partnership-bond-factory-v3` — PartnershipBondFactoryV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** deployment-only factory; coordinator and child runtime pinned

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.partnership-bond-v3-safe` — PartnershipBondV3Safe

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** mutual participant authorization and deterministic timeout recovery only

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.pull-payments-v3` — PullPaymentsV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.reward-program-v3` — RewardProgramV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`excluded`  
**Spec:** Discovered source outside the canonical supported module boundary.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Requires reviewed disposition change before support.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.safe-bond-factory-v3` — SafeBondFactoryV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** exact factory/child codehash validation and controller registration

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.signature-verifier-v3` — SignatureVerifierV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`internal`  
**Spec:** Internal interface, library, or base dependency; never an independently deployable supported capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No independent public/deployment claim is permitted.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.street-cred-v3` — StreetCredV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** informational-only and source-isolated from supported protected decisions

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.task-escrow-v3` — TaskEscrowV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`retired`  
**Spec:** Source retained as an excluded tombstone; it is not a supported V3 release capability.

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** Retirement must remain enforced across SDK, API, discovery, and deployment tooling.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.threshold-consensus-v3` — ThresholdConsensusV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** objective attestation utility only; no supported protected-decision consumer

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `base.vaultfire-b-i-p-vault-v3` — VaultfireBIPVaultV3

**Kind:** capability / `base-module`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unavailable`, support=`supported`  
**Spec:** ERC-4626 deterministic accounting and explicit asset custody

**Threats:** reentrancy; authorization bypass; replay or domain confusion; accounting or lifecycle failure  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Solidity source identity and referenced tests match the frozen subtree.  
**Evidence:**   
**Open gaps:** No authorized deployment, runtime comparison, independent audit, or completed operations evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `mldsa.canonical-envelope` — Canonical HybridAuthorizationV1 codec

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** Fixed-width and length-prefixed binary envelope with strict domain, action, epoch, nonce, deadline, and payload binding.

**Threats:** algorithm confusion; downgrade; cross-domain replay; non-canonical encoding; side channel or denial of service  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `mldsa.chain-bound-verification` — Chain-bound ML-DSA verification

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** Base and Solana must verify an ML-DSA-65, FIPS 204 algorithm-target statement on-chain through the reviewed SP1 proof stack before atomic nonce consumption; no FIPS 140 validation or independent conformance certification is claimed.

**Threats:** false cryptographic receipt; hybrid downgrade; unbound proof; replay; resource-exhaustion denial of service  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `mldsa.native-provider` — Native ML-DSA-65 provider, FIPS 204 algorithm target

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** The native ML-DSA-65 provider is implemented and vector-tested as a FIPS 204 algorithm target. It has no FIPS 140 validation, independent conformance certification, or approved production operating environment.

**Threats:** algorithm confusion; downgrade; cross-domain replay; non-canonical encoding; side channel or denial of service  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `mldsa.hybrid-evm` — Hybrid EVM authorization

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** Require approved ECDSA/ERC-1271 AND ML-DSA-65 over one canonical envelope; no fallback.

**Threats:** algorithm confusion; downgrade; cross-domain replay; non-canonical encoding; side channel or denial of service  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `mldsa.hybrid-solana` — Hybrid Solana authorization

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** Require detached Ed25519 AND ML-DSA-65 over one canonical envelope; no signer-flag substitution.

**Threats:** algorithm confusion; downgrade; cross-domain replay; non-canonical encoding; side channel or denial of service  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `mldsa.key-lifecycle` — Hybrid key registry lifecycle

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** Monotonic epochs, delayed activation, irreversible revocation, distinct recovery, and no mixed-epoch downgrade.

**Threats:** algorithm confusion; downgrade; cross-domain replay; non-canonical encoding; side channel or denial of service  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `mldsa.truthful-claims` — Truthful cryptography claims

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** Remove or qualify unsupported Dilithium, ML-DSA, ZK, FHE, pq-secure, and quantum-resistant claims.

**Threats:** algorithm confusion; downgrade; cross-domain replay; non-canonical encoding; side channel or denial of service  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `mldsa.vectors-benchmarks-audit` — Vectors, benchmarks, and independent audit

**Kind:** capability / `cryptography-requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`deferred`  
**Spec:** Final ACVP vectors, malformed corpus, differential verification, resource benchmarks, and independent cryptography review.

**Threats:** algorithm confusion; downgrade; cross-domain replay; non-canonical encoding; side channel or denial of service  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** SP1 architecture, native guest core, and Base/Solana adapter source exist.; ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.; No quantum-resistance claim is permitted.  
**Evidence:**   
**Open gaps:** Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review.

## `parity.canonical-grouped-reward-receipt-v2` — Canonical grouped-reward receipt parity

**Kind:** capability / `cross-runtime-parity`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-applicable`, implementation=`implemented-source`, operations=`not-applicable`, support=`review-only`  
**Spec:** Exact adapter-mediated protocol parity for the retained canonical grouped-reward receipt vector; all declared dimensions and receipt bindings match while native schemas remain intentionally distinct.

**Threats:** lossy adapter; native field omission; stale artifact substitution; parity scope inflation  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `release.aggregate-gates` — Aggregate software and deployment-external gates

**Kind:** capability / `release-control`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-applicable`, implementation=`implemented-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Machine release model separates automatable software checks from deployment-external evidence and never authorizes deployment by itself.

**Threats:** evidence/source drift; scope overclaim; unauthorized activation; cross-runtime semantic mismatch  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** Chain-bound ML-DSA software gate and all deployment-external gates remain blocking.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-01` — Keep V3 additive and preserve V2

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`not-applicable`, support=`supported`  
**Spec:** Keep V3 additive and preserve V2.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-02` — Freeze V2 bytecode

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`not-applicable`, support=`supported`  
**Spec:** Freeze V2 bytecode.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-03` — Provide V2 ABI provenance

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Provide V2 ABI provenance.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-04` — Preserve V2 response behavior

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Preserve V2 response behavior.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-05` — Align V2 routes

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Align V2 routes.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-06` — Generate x402 and Bazaar metadata

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Generate x402 and Bazaar metadata.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-07` — Keep protocol, Bazaar, and x402 versions distinct

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`not-applicable`, support=`supported`  
**Spec:** Keep protocol, Bazaar, and x402 versions distinct.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-08` — Require live Bazaar evidence fail-closed

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`supported`  
**Spec:** Require live Bazaar evidence fail-closed.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-09` — Implement V3 contracts

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Implement V3 contracts.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-10` — Enforce native bond caps in contract

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Enforce native bond caps in contract.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-11` — Preserve aggregate liability through pull-payment credits

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Preserve aggregate liability through pull-payment credits.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-12` — Exercise V3 safety in Foundry

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Exercise V3 safety in Foundry.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-13` — Maintain solvency and stateful invariant coverage

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Maintain solvency and stateful invariant coverage.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-14` — Enforce loop bounds and static analysis

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Enforce loop bounds and static analysis.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-15` — Verify deterministic build and size

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Verify deterministic build and size.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-16` — Test PR7 API, SDK, indexer, x402, and Bazaar package

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Test PR7 API, SDK, indexer, x402, and Bazaar package.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-17` — Fail closed on V3 status and solvency

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`supported`  
**Spec:** Fail closed on V3 status and solvency.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-18` — Provide unsigned migration and proposal tooling

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`not-applicable`, support=`supported`  
**Spec:** Provide unsigned migration and proposal tooling.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-19` — Keep migration voluntary and rollback additive

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Keep migration voluntary and rollback additive.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-20` — Provide Base deployment and rollback fork gate

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Provide Base deployment and rollback fork gate.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-21` — Keep V3 address inventory empty until verified

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`fail-closed`, support=`supported`  
**Spec:** Keep V3 address inventory empty until verified.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-22` — Enforce default-off website actions

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`supported`  
**Spec:** Enforce default-off website actions.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-23` — Keep pilot gate fail-closed

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`supported`  
**Spec:** Keep pilot gate fail-closed.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-24` — Document multisig-only governance transport

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`supported`  
**Spec:** Document multisig-only governance transport.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-25` — Prepare audit, bounty, and operations

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unverified`, support=`deferred`  
**Spec:** Prepare audit, bounty, and operations.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-26` — Preserve no-deploy boundary

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`fail-closed`, support=`supported`  
**Spec:** Preserve no-deploy boundary.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `requirement.prompt-27` — Authorize pilot or mainnet

**Kind:** capability / `requirement`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`absent`, operations=`fail-closed`, support=`deferred`  
**Spec:** Authorize pilot or mainnet.

**Threats:** claim drift; release bypass; missing evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Machine records and cited repository evidence are accurate for the frozen identity.  
**Evidence:**   
**Open gaps:** Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.accountability.activate` — accountability.activate

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation accountability.activate; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.accountability.attest` — accountability.attest

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation accountability.attest; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.accountability.create` — accountability.create

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation accountability.create; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.accountability.expire` — accountability.expire

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation accountability.expire; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.accountability.force-exit` — accountability.force-exit

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation accountability.force-exit; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.accountability.fund` — accountability.fund

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation accountability.fund; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.partnership.approve` — partnership.approve

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation partnership.approve; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.partnership.cancel` — partnership.cancel

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation partnership.cancel; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.partnership.create` — partnership.create

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation partnership.create; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.partnership.expire` — partnership.expire

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation partnership.expire; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.partnership.force-exit` — partnership.force-exit

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation partnership.force-exit; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.partnership.fund` — partnership.fund

**Kind:** capability / `sandbox-mutation`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local fixture mutation partnership.fund; no wallet, RPC, signature, token, facilitator, or monetary value.

**Threats:** mock confused with production; state-machine divergence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Loopback-only deterministic fixture environment.  
**Evidence:**   
**Open gaps:** Not chain, payment, contract, testnet, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.pause-gate` — Sandbox pause gate

**Kind:** capability / `sandbox-cross-cutting`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Local fixture pause blocks mutations while bounded exits remain available; no guardian parity is claimed.

**Threats:** mock-production confusion; state-machine divergence  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Loopback fixture state is deterministic and non-monetary.  
**Evidence:**   
**Open gaps:** Not contract, chain, testnet, payment, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.read-models` — Sandbox state and solvency reads

**Kind:** capability / `sandbox-cross-cutting`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Local deterministic state and solvency views report fixture accounting only.

**Threats:** mock-production confusion; state-machine divergence  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Loopback fixture state is deterministic and non-monetary.  
**Evidence:**   
**Open gaps:** Not contract, chain, testnet, payment, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.receipts-idempotency` — Sandbox receipts and idempotency

**Kind:** capability / `sandbox-cross-cutting`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Deterministic local operation IDs and persisted fixture receipts demonstrate replay behavior only.

**Threats:** mock-production confusion; state-machine divergence  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Loopback fixture state is deterministic and non-monetary.  
**Evidence:**   
**Open gaps:** Not contract, chain, testnet, payment, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sandbox.x402-no-payment` — Sandbox no-payment x402 rehearsal

**Kind:** capability / `sandbox-cross-cutting`  
**Status:** audit=`not-applicable`, completion=`blocked`, deployment=`not-applicable`, implementation=`mock-only`, operations=`mock-only`, support=`review-only`  
**Spec:** Local challenge and fulfill endpoints use fixture units without signatures, facilitator, USDC, or settlement.

**Threats:** mock-production confusion; state-machine divergence  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Loopback fixture state is deterministic and non-monetary.  
**Evidence:**   
**Open gaps:** Not contract, chain, testnet, payment, or production parity.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.abi-bound-deployments` — Four ABI-bound SDK deployment identities

**Kind:** capability / `sdk-infrastructure`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`compatibility`  
**Spec:** ABI identities and capability/selector allowlists for accountability, partnership, governance, and mandate modules; addresses and runtime hashes remain null.

**Threats:** ABI mismatch; selector confusion; address substitution  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Fixture ABI identity is source evidence, not deployed-bytecode evidence.  
**Evidence:**   
**Open gaps:** No configured deployment address, runtime hash, or independent capability verifier.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.base-sepolia-rehearsal` — Base Sepolia SDK rehearsal seam

**Kind:** capability / `sdk-infrastructure`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-applicable`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Internal signed-fixture verification and rehearsal models only; never production attestation or deployment authority.

**Threats:** test seam exported as trust root; environment confusion  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Fixture signatures and rehearsal profiles are non-production evidence.  
**Evidence:**   
**Open gaps:** Rehearsal evidence has no production implication.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.bonds` — bonds

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`compatibility`  
**Spec:** Typed SDK logical read surface for bonds; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.capabilities` — capabilities

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Typed SDK logical read surface for capabilities; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.governance` — governance

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`compatibility`  
**Spec:** Typed SDK logical read surface for governance; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.mandates` — mandates

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`compatibility`  
**Spec:** Typed SDK logical read surface for mandates; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.pullcredits` — pullCredits

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`compatibility`  
**Spec:** Typed SDK logical read surface for pullCredits; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.solvency` — solvency

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`compatibility`  
**Spec:** Typed SDK logical read surface for solvency; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.taskescrow` — taskEscrow

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`retired`  
**Spec:** Typed SDK logical read surface for taskEscrow; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.verified-writes` — Evidence-gated SDK writes

**Kind:** capability / `sdk-infrastructure`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Local validation requires configured profile, ABI identity, selector/capability allowlist, canonical calldata, and independent deployment/capability verification.

**Threats:** write activation without evidence; calldata malleability; transport substitution  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Transport and evidence verifiers are separately trusted and currently unconfigured.  
**Evidence:**   
**Open gaps:** Canonical profiles have no deployment evidence, so practical writes remain blocked.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.versioned-package` — Versioned V3 SDK package surface

**Kind:** capability / `sdk-infrastructure`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`not-applicable`, support=`review-only`  
**Spec:** Additive zero-runtime-dependency TypeScript V3 SDK candidate with generated manifest data, Base/Solana adapters, receipts, crypto helpers, and x402 offline support; no signing, custody, broadcast, or settlement.

**Threats:** package/source drift; unsafe generic dispatch; version ambiguity  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** Repository source/build evidence does not establish the public package artifact.  
**Evidence:**   
**Open gaps:** Package is not published or verified equivalent to a registry artifact; no live V3 transport or deployment binding.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.x402-challenge` — x402.challenge

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Typed SDK logical read surface for x402.challenge; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.x402-discovery` — x402.discovery

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Typed SDK logical read surface for x402.discovery; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.x402-receipt` — x402.receipt

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Typed SDK logical read surface for x402.receipt; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `sdk.x402-status` — x402.status

**Kind:** capability / `sdk-logical-route`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Typed SDK logical read surface for x402.status; no configured V3 deployment or live reader is implied.

**Threats:** status mismatch; lossy route mapping; unbound response; write activation without evidence  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Canonical deployment profile remains unconfigured and transport evidence is external.  
**Evidence:**   
**Open gaps:** No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana-additive.vaultfire-v3-successor` — Vaultfire Solana V3 additive successor

**Kind:** capability / `solana-additive-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Anchor successor program with typed PDA lifecycles, native-SOL custody, grouped rewards, canonical receipts, fail-closed verifier adapters, pause/recovery, and generated IDL.

**Threats:** PDA or owner confusion; account substitution; replay; upgrade authority compromise; SBF/source drift  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** Undeployed and unauthorized; no independent-machine reproduction, malformed-Borsh fuzzing, upgrade-authority rehearsal, independent audit, or chain-bound ML-DSA verifier.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.ai-accountability-bonds` — ai_accountability_bonds

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Solana supported-candidate source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.ai-partnership-bonds` — ai_partnership_bonds

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Solana supported-candidate source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.anti-surveillance` — anti_surveillance

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`redesign-required`  
**Spec:** Solana redesign-required source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.belief-attestation-verifier` — belief_attestation_verifier

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`retired`  
**Spec:** Solana retired source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.dilithium-attestor` — dilithium_attestor

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`redesign-required`  
**Spec:** Solana redesign-required source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.flourishing-metrics-oracle` — flourishing_metrics_oracle

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`retired`  
**Spec:** Solana retired source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.identity-registry` — identity_registry

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Solana supported-candidate source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.mission-enforcement` — mission_enforcement

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`redesign-required`  
**Spec:** Solana redesign-required source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.multisig-governance` — multisig_governance

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Solana supported-candidate source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.privacy-guarantees` — privacy_guarantees

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Solana supported-candidate source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.production-belief-verifier` — production_belief_verifier

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`retired`  
**Spec:** Solana retired source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.reputation-registry` — reputation_registry

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`retired`  
**Spec:** Solana retired source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.trust-data-bridge` — trust_data_bridge

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`retired`  
**Spec:** Solana retired source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.validation-registry` — validation_registry

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`redesign-required`  
**Spec:** Solana redesign-required source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `solana.vaultfire-adapter` — vaultfire_adapter

**Kind:** capability / `solana-program`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`unavailable`, support=`review-only`  
**Spec:** Solana supported-candidate source; every singleton initializer remains disabled.

**Threats:** disabled bootstrap; PDA or owner confusion; account lifecycle mismatch; upgrade authority compromise  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Pinned source/program identity is not deployment evidence.  
**Evidence:**   
**Open gaps:** No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `surface.website-v3-review` — Built V3 website review surface

**Kind:** capability / `website-surface`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Next.js review surface builds and passes focused route, release, desktop/mobile smoke, overflow, touch-target, and metadata checks.

**Threats:** evidence/source drift; scope overclaim; unauthorized activation; cross-runtime semantic mismatch  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No immutable preview promotion record, production deployment evidence, full viewport/zoom/axe/manual assistive matrix, or owner approval.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `surface.x402-generated-review` — Generated x402 and review discovery surfaces

**Kind:** capability / `x402-generated-surface`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`unverified`, support=`review-only`  
**Spec:** Manifest-derived resources, OpenAPI, agent-card, and llms surfaces preserve V2 regression behavior and keep all V3 payment resources disabled.

**Threats:** evidence/source drift; scope overclaim; unauthorized activation; cross-runtime semantic mismatch  
**Mitigations:** Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization.  
**Trust assumptions:** Local retained evidence is authentic for the named source/artifact and does not establish public-chain state.  
**Evidence:**   
**Open gaps:** No authorized V3 deployment, live reader, pay-to, facilitator, settlement, or Bazaar indexing.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.a-i-accountability-bonds-v2` — AIAccountabilityBondsV2

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Objective rules and consent replace subjective accountability inputs.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.a-i-partnership-bonds-v2` — AIPartnershipBondsV2

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Mutual consent, bounded principal settlement, and pull payments are release obligations.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.agent-insurance-pool` — AgentInsurancePool

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Discretionary recipient/reason routing is outside the strict Base mission boundary.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.agent-s-l-a-enforcer` — AgentSLAEnforcer

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Generic opaque evidence and vote-driven remedies are intentionally retired.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.agent-safety-manager` — AgentSafetyManager

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Safety control is explicit mandate and pilot allowlisting, never behavioral scoring.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.anti-surveillance` — AntiSurveillance

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Privacy promises require a separately reviewed implementation; no unsupported V3 claim.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.belief-attestation-verifier` — BeliefAttestationVerifier

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Belief inference cannot control protected decisions in V3.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.compliance-registry` — ComplianceRegistry

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Compliance becomes objective signed evidence plus explicit authority.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.dilithium-attestor` — DilithiumAttestor

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Post-quantum attestation is outside the supported release until independently evidenced.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.e-r-c8004-identity-registry` — ERC8004IdentityRegistry

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** V3 consumes external identity read-only; identity is not eligibility by itself.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.e-r-c8004-reputation-registry` — ERC8004ReputationRegistry

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Reputation is informational only and has zero protected-decision influence.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.e-r-c8004-validation-registry` — ERC8004ValidationRegistry

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Stake custody and owner slashing are intentionally retired; no informational label remains.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.flourishing-metrics-oracle` — FlourishingMetricsOracle

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Flourishing metrics are subjective and prohibited from protected decisions.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.mission-enforcement` — MissionEnforcement

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Mission enforcement is replaced by explicit mandates and objective rules.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.multisig-governance` — MultisigGovernance

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Threshold governance is retained with bounded calls and no scoring automation.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.privacy-guarantees` — PrivacyGuarantees

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Broad privacy guarantees are not represented as implemented without proof.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.production-belief-attestation-verifier` — ProductionBeliefAttestationVerifier

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Production belief attestation remains outside V3 protected decisions.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.reputation-decay` — ReputationDecay

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Automated reputation decay cannot change access, value, disputes, or routing.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.scoped-delegation` — ScopedDelegation

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Delegation requires signed scope, nonce, deadline, and explicit execution adapter.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.v-k-p-delegation-registry` — VKPDelegationRegistry

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Delegation is consolidated into the explicit V3 mandate model.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.v-k-p-factory` — VKPFactory

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Legacy VKP creation has no supported release target.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.v-k-p-session-key-manager` — VKPSessionKeyManager

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Session authority is represented as bounded, expiring mandates.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-b-i-p-vault` — VaultfireBIPVault

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vault custody requires ERC-4626 accounting and explicit liability invariants.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-batch-onboarder` — VaultfireBatchOnboarder

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Batch onboarding is excluded until identity and consent invariants are proven.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-bond-insurance-pool` — VaultfireBondInsurancePool

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Discretionary mutual-aid routing is intentionally retired from supported Base V3.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-capability-credentials` — VaultfireCapabilityCredentials

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Capabilities become explicit signed mandates, not inferred trust.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-dispute-resolution` — VaultfireDisputeResolution

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Generic dispute voting over opaque evidence is intentionally retired.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-e-r-c8004-adapter` — VaultfireERC8004Adapter

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** The supported adapter is identity-only; reputation cannot gate protected decisions.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-forum-registry` — VaultfireForumRegistry

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Forum/social routing is not part of supported V3 protocol decisions.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-name-service` — VaultfireNameService

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Naming is convenience metadata and has no release obligation.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-reputation-staking` — VaultfireReputationStaking

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Reputation-linked staking would couple scoring to value and is retired.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-street-cred` — VaultfireStreetCred

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** StreetCred is non-authoritative evidence and cannot control protected decisions.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** V3 deployment, independent audit, and operations are absent.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-task-escrow` — VaultfireTaskEscrow

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Quality/discretion-driven task disputes are intentionally retired from supported Base V3.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-teleporter-bridge` — VaultfireTeleporterBridge

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`deferred`  
**Spec:** Cross-chain execution is unsupported until authenticated message semantics are reviewed.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-trust-attestation` — VaultfireTrustAttestation

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Trust attestations cannot become eligibility, pricing, settlement, or routing inputs.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `v2-contract.vaultfire-trust-oracle` — VaultfireTrustOracle

**Kind:** capability / `v2-contract-disposition`  
**Status:** audit=`historical-scope-only`, completion=`not-applicable`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`retired`  
**Spec:** Trust scores are prohibited as protected-decision inputs.

**Threats:** unsafe semantic carryover; ABI provenance drift; legacy authority confusion  
**Mitigations:** Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation.  
**Trust assumptions:** Frozen V2 inventory observations remain unchanged and are not newly revalidated.  
**Evidence:**   
**Open gaps:** Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `x402.v3-durable-receipt-store` — V3 durable receipt store source

**Kind:** capability / `x402-infrastructure`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`implemented-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Redis-capable source models concurrency, binding, replay, finality, timeout recovery, and audit chaining while V3 settlement remains disabled.

**Threats:** atomicity failure; receipt replay; ambiguous settlement; reorg; locator enumeration  
**Mitigations:** Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation.  
**Trust assumptions:** A production Redis-compatible store and chain/facilitator observations would be external trust dependencies.  
**Evidence:**   
**Open gaps:** No production store configuration, facilitator observation, settlement, deployed capability binding, or live enumeration control.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-bonds-agent-bond-status` — GET /api/x402/bonds/agent-bond-status

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: look up any agent's bond posture (active accountability + partnership bonds, total staked, partner addresses). Reads ERC-8004 + AIAccountabilityBondsV2 + AIPartnershipBondsV2 live on-chain.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-bonds-overview` — GET /api/x402/bonds/overview

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: protocol-wide bond pulse (active bonds, per-chain breakdown, locked value, both Flourishing Metrics dimension sets). Live snapshot from on-chain queries across AIAccountabilityBondsV2, AIPartnershipBondsV2, and FlourishingMetricsOracle.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-oracle-agent-stake-usd` — GET /api/x402/oracle/agent-stake-usd

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** USD-denominated agent stake — composes Vaultfire bond data (ETH stake) × Chainlink ETH/USD price feed. Returns stake in USD with full audit trail (bond count, ETH staked, Chainlink price, feed address). Uniquely enabled by the Chainlink integration: Vaultfire owns the agent-truth side, Chainlink owns the market-data side.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-oracle-chainlink-status` — GET /api/x402/oracle/chainlink-status

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Free discovery beacon for the Vaultfire Chainlink oracle namespace — no payment required. Lists every supported (chain, pair) feed with live freshness, attribution to Chainlink, and links to the priced endpoints.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-oracle-price-feed` — GET /api/x402/oracle/price-feed

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Read any supported Chainlink Data Feed (ETH/USD, BTC/USD, LINK/USD, USDC/USD, AVAX/USD, MATIC/USD) on Base, Avalanche, Arbitrum, or Polygon. Returns answer, decimals, roundId, updatedAt, and freshness status. Data source: Chainlink decentralized oracle network — Vaultfire reads the on-chain AggregatorV3 proxy and exposes it via x402.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-agent-status` — GET /api/x402/trust/agent-status

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Look up any AI agent's on-chain trust profile — ERC-8004 registration, bond count, trust score (0–95), VNS name, and explorer link. Queries real smart contracts across 4 chains.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-agentproof-evidence` — GET /api/x402/trust/agentproof-evidence

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire × AgentProof bridge (draft RFC). Fetch a public AgentProof report (results.json), SHA-256-verify against an agent-supplied digest, return a normalized evidence envelope with overall score, six-category breakdown, command-check status, and browser-crawl summary. Display-layer only; never modifies on-chain values, never re-scores. AgentProof: github.com/dicnunz/agentproof.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-analytics` — GET /api/x402/trust/analytics

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Composite trust profile — Street Cred badge, identity, bonds, reputation in one call. Aggregates 4+ on-chain reads.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-bonds` — GET /api/x402/trust/bonds

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: list all active partnership bonds for any agent (bond count, partner addresses, locked stake). Reads AIPartnershipBondsV2 live on-chain.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-bridge` — GET /api/x402/trust/bridge

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Cross-chain bridge state — message counts, paused status, relayer count, synced totals. Live read from VaultfireTeleporterBridge.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-contracts` — GET /api/x402/trust/contracts

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Full contract registry — 134 verified smart contracts across 4 mainnet chains with addresses.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-credentials` — GET /api/x402/trust/credentials

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Capability credentials — total credentials, active credentials, task proofs. Live read from VaultfireCapabilityCredentials.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-disputes` — GET /api/x402/trust/disputes

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Dispute resolution stats per chain — filed, resolved, total stake at risk. Live read from VaultfireDisputeResolution.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-flourishing-metrics` — GET /api/x402/trust/flourishing-metrics

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Read the latest FlourishingMetricsOracle round for a metric key — value + roundId. The oracle aggregates ecosystem health signals.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-governance-proposals` — GET /api/x402/trust/governance-proposals

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Read a MultisigGovernance transaction by id — target, value, calldata, executed flag, confirmation count, expiry.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-health` — GET /api/x402/trust/health

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Service health check + discovery beacon — free, no payment required. Lists all 75 priced endpoints with metadata for crawlers.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-history` — GET /api/x402/trust/history

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Trust history timeline for an agent — registration, bonds, vouches and slashes assembled from on-chain state.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-insurance` — GET /api/x402/trust/insurance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Insurance pool stats per chain — balance, contributors, claims paid out. Live read from VaultfireBondInsurancePool.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-leaderboard` — GET /api/x402/trust/leaderboard

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Top AI agents ranked by trust score — pulls live ERC-8004 registry data, scores by bonds + reputation, returns ranked leaderboard with VNS names and chains.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-multi-chain-status` — GET /api/x402/trust/multi-chain-status

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Aggregate an agent's on-chain status across all 4 chains in a single call — per-chain registration, bonds, trust score plus omnichain summary.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-performance` — GET /api/x402/trust/performance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Trust oracle performance — attestations, quality score, task completions for an agent. Live read from VaultfireTrustOracle.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-protocol-stats` — GET /api/x402/trust/protocol-stats

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — the trust layer for the agentic web. 77 x402 endpoints on Base for AI agent identity (ERC-8004), accountability bonds, on-chain reputation, and Chainlink oracle data. — This endpoint: protocol-wide stats (total registered agents, active bonds, per-chain breakdown, total locked value).

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-relationships` — GET /api/x402/trust/relationships

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vouching graph slice for an agent — counts of vouches given/received, total stake, slash record, bond partnerships, plus an integrity composite.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-reputation-decay` — GET /api/x402/trust/reputation-decay

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Read an agent's current decayed reputation score — decayed score, base score, days since last activity, and total activities. Helpful for showing freshness-adjusted reputation.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-risk-score` — GET /api/x402/trust/risk-score

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Composite on-chain risk score (0–100) for an AI agent — combines identity, reputation, bonds, vouching, slashes, and account age into a single risk signal with band (minimal/low/medium/high).

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-safety-status` — GET /api/x402/trust/safety-status

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Read an agent's current safety status from the AgentSafetyManager contract — status enum (Active/Paused/Suspended/Banned), last change timestamp, who changed it, and reason.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-scoped-delegations` — GET /api/x402/trust/scoped-delegations

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** List the capability scope ids granted to an address from the ScopedDelegation registry.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-sla-status` — GET /api/x402/trust/sla-status

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Read an agent's SLA performance — active SLAs, total stake, total penalized, and violation count from AgentSLAEnforcer.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-street-cred` — GET /api/x402/trust/street-cred

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — the trust layer for the agentic web. 77 x402 endpoints on Base for AI agent identity (ERC-8004), accountability bonds, on-chain reputation, and Chainlink oracle data. — This endpoint: look up any address's Vaultfire Street Cred profile (soulbound badge tier None/Bronze/Silver/Gold/Platinum, score 0-95, identity registration, active bonds, staked ETH). Reads VaultfireStreetCred.computeScore() on Base.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-vns-resolve` — GET /api/x402/trust/vns-resolve

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Resolve VNS names to addresses (forward) or addresses to VNS names (reverse) across Base, Arbitrum, and Polygon. Falls back to ERC-8004 identity registry for full coverage.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-get-api-x402-trust-vouching` — GET /api/x402/trust/vouching

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Reputation staking profile — vouches received and given, total stake, slashes. Live read from VaultfireReputationStaking.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-accept-bid` — POST /api/x402/actions/accept-bid

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Accept a bid on a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — assigns the task to the chosen bidding agent and locks the work phase.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-approve-work` — POST /api/x402/actions/approve-work

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Approve completed work on a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — releases USDC from escrow to the assigned agent (minus protocol fee).

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-attest-belief` — POST /api/x402/actions/attest-belief

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Legacy V2 transaction-preparation route; no ML-DSA, Dilithium, zero-knowledge, or post-quantum verification is established.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-batch-onboard` — POST /api/x402/actions/batch-onboard

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** One-shot atomic agent onboarding on Base — registers ERC-8004 identity, sets URI, posts initial bond. Pay $0.50 USDC. Base only.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-bridge-trust-message` — POST /api/x402/actions/bridge-trust-message

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Send a cross-chain reputation message via Avalanche Teleporter / cross-chain bridge — propagate score from one chain to another. Pay $0.40 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-cancel-task` — POST /api/x402/actions/cancel-task

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Cancel a Vaultfire task escrow and trigger USDC refund per contract rules. Pay $0.15 USDC, sign in your wallet — only the task requester can cancel.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-challenge-bond-metrics` — POST /api/x402/actions/challenge-bond-metrics

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Challenge submitted metrics on an AI Accountability Bond. Pay $0.25 USDC, post a counter-stake, file the challenge on-chain.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-commit-vns-name` — POST /api/x402/actions/commit-vns-name

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Step 1/2 of Vaultfire Name Service registration: commit-reveal. Submit the keccak256 commitment hash. Wait commitment window, then call register-vns-name. Pay $0.10 USDC. Available on Base, Arbitrum, Polygon.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-contribute-insurance` — POST /api/x402/actions/contribute-insurance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Contribute ETH to the Vaultfire Bond Insurance Pool — community-owned reserve that backstops slashed bonds. Pay $0.20 USDC; ETH amount sent via wallet (payable contribute()).

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-create-accountability-bond` — POST /api/x402/actions/create-accountability-bond

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics (income distribution, poverty rate, health outcomes, mental health, education access, purpose/agency) show real societal impact. Morals over metrics, on-chain. — This endpoint: create an AI accountability bond on AIAccountabilityBondsV2. Pay $0.50 USDC, receive an unsigned payable tx, sign in your wallet — no private keys handled server-side.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-create-partnership-bond` — POST /api/x402/actions/create-partnership-bond

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics (human growth, autonomy, dignity, tasks mastered, creativity) show real human↔agent impact. Morals over metrics, on-chain. — This endpoint: create an AI partnership bond on AIPartnershipBondsV2. Pay $0.50 USDC, receive an unsigned payable tx with your stake, sign locally in your wallet. No private keys handled server-side.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-create-session-key` — POST /api/x402/actions/create-session-key

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Create an ERC-7702 session key with capability scoping — temporary delegated authority bounded by spend limit, expiry, and target whitelist. Pay $0.25 USDC, sign in wallet to authorize.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-create-task` — POST /api/x402/actions/create-task

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Post a task with USDC escrow on VaultfireTaskEscrow. Pay $0.30 USDC, sign in your wallet — funds locked trustlessly until an agent completes the task. 1% protocol fee, refunded if cancelled. Multi-chain (Base, Avalanche, Arbitrum, Polygon).

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-create-vkp-vault` — POST /api/x402/actions/create-vkp-vault

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Create a Verifiable Knowledge Proof (VKP) vault — an ERC-4626-style data vault with privacy budget, retention window, and access tier. Pay $0.40 USDC, sign in wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-deactivate-agent` — POST /api/x402/actions/deactivate-agent

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Deactivate your ERC-8004 agent registration on Vaultfire. Pay $0.10 USDC, sign in your wallet — only the agent itself can deactivate. Reversible by re-registering.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-dispute-task` — POST /api/x402/actions/dispute-task

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Open a dispute on a Vaultfire task escrow. Pay $0.25 USDC, sign in your wallet — freezes the escrow pending governance resolution. Either party may dispute.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-file-attestation` — POST /api/x402/actions/file-attestation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** File a belief attestation on the BeliefAttestationVerifier contract (zk proof + public inputs). Pay $0.25 USDC, receive a fully-encoded unsigned transaction, sign in your wallet. No private keys handled server-side.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-file-insurance-claim` — POST /api/x402/actions/file-insurance-claim

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** File a claim against the Bond Insurance Pool — supply the affected bond id, off-chain evidence URL, and evidence hash. Pay $0.30 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-file-vouch` — POST /api/x402/actions/file-vouch

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** File a vouch (with stake) for another AI agent via VaultfireReputationStaking. Pay $0.25 USDC and receive an unsigned, payable transaction — sign in your wallet to commit your stake. No private keys handled server-side.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-grant-consent` — POST /api/x402/actions/grant-consent

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Grant consent for a specific purpose hash on the ERC-8004 Identity Registry. Pay $0.05 USDC, sign in your wallet — privacy-preserving consent flagging.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-issue-credential` — POST /api/x402/actions/issue-credential

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Issue an ERC-8004 capability credential to an agent — typed claim signed by your address that the holder can present elsewhere in the network. Pay $0.30 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-mint-street-cred` — POST /api/x402/actions/mint-street-cred

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Mint your Vaultfire Street Cred badge — an ERC-5192 soulbound token reflecting your on-chain reputation tier. Pay $0.20 USDC, sign in your wallet on Base. One badge per address, non-transferable.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-register-agent` — POST /api/x402/actions/register-agent

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Register an AI agent on the ERC-8004 Identity Registry. Pay $0.50 USDC and receive a fully-encoded unsigned transaction (calldata + gas estimate + chain ID) — sign locally in your wallet to become the registered agent. No private keys ever touch our servers.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-register-for-partnership` — POST /api/x402/actions/register-for-partnership

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Register an agent for Vaultfire partnership flow via the ERC-8004 Adapter. Pay $0.30 USDC, sign in your wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-register-vns-name` — POST /api/x402/actions/register-vns-name

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Step 2/2 VNS registration. Reveal the agent name + secret matching your earlier commit. Mints VNS subdomain on Base, Arbitrum, or Polygon. Pay $0.30 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-report-mission-violation` — POST /api/x402/actions/report-mission-violation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Report a mission violation against a module on Vaultfire MissionEnforcement. Pay $0.15 USDC, sign in your wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-report-surveillance-violation` — POST /api/x402/actions/report-surveillance-violation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Report a surveillance violation against a module on Vaultfire AntiSurveillance. Pay $0.15 USDC, sign in your wallet — privacy-preserving (only the evidence hash goes on-chain).

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-request-bond-distribution` — POST /api/x402/actions/request-bond-distribution

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Request distribution payout for a Vaultfire bond (partnership or accountability). Pay $0.10 USDC, sign in your wallet to trigger the distribution flow on-chain.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-request-validation` — POST /api/x402/actions/request-validation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Open a validation request on the ERC-8004 Validation Registry — request that N independent validators verify a claim about an agent. Pay $0.25 USDC, post a bounty, sign in your wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-revoke-consent` — POST /api/x402/actions/revoke-consent

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Revoke previously-granted consent for a specific purpose hash on the ERC-8004 Identity Registry. Pay $0.05 USDC, sign in your wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-revoke-credential` — POST /api/x402/actions/revoke-credential

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Revoke a previously-issued capability credential by id. Effective immediately on-chain. Pay $0.15 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-revoke-session-key` — POST /api/x402/actions/revoke-session-key

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Revoke a previously created ERC-7702 session key by id. Immediate, on-chain. Pay $0.10 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-slash-reputation` — POST /api/x402/actions/slash-reputation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Slash a misbehaving agent's reputation stake (governance-gated on-chain check). Pay $0.30 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-stake-as-validator` — POST /api/x402/actions/stake-as-validator

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Stake ETH on the ERC-8004 Validation Registry to become a validator eligible to submit validation results and earn bounties. Pay $0.20 USDC, sign in your wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-submit-accountability-metrics` — POST /api/x402/actions/submit-accountability-metrics

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when these on-chain Flourishing Metrics show real impact. Morals over metrics, on-chain. — This endpoint: submit Flourishing Metrics scores (income distribution, poverty rate, health outcomes, mental health, education access, purpose/agency) to AIAccountabilityBondsV2. Pay $0.25 USDC, sign in your wallet — six dimensions of human flourishing recorded on-chain.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-submit-feedback` — POST /api/x402/actions/submit-feedback

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Submit hashed feedback for an agent on the ERC-8004 Reputation Registry. Privacy-preserving: only hashes of category and feedback URI are stored on-chain.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-submit-partnership-metrics` — POST /api/x402/actions/submit-partnership-metrics

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Submit hashed partnership metrics (humanGrowth, autonomy, dignity, tasksMastered, creativity + progressNotesHash) to AIPartnershipBondsV2. Privacy-preserving — only hashes go on-chain.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-submit-trust-attestation` — POST /api/x402/actions/submit-trust-attestation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Submit a signed trust attestation to the Vaultfire Trust Oracle — typed score about a target agent with confidence + evidence hash. Pay $0.30 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-submit-validation` — POST /api/x402/actions/submit-validation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Submit a validation result on the ERC-8004 Validation Registry as a staked validator. Pay $0.25 USDC, sign in your wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-submit-work` — POST /api/x402/actions/submit-work

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Submit completed work for a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — submits a deliverable URI/hash on-chain so the requester can approve or dispute.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-transfer-vns-name` — POST /api/x402/actions/transfer-vns-name

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Transfer ownership of a VNS name to another address. Pay $0.20 USDC. Available on Base, Arbitrum, Polygon.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-trigger-reputation-decay` — POST /api/x402/actions/trigger-reputation-decay

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Trigger time-based reputation decay for an agent — anyone can call; on-chain math applies decay since last activity. Pay $0.10 USDC.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-unvouch` — POST /api/x402/actions/unvouch

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Revoke a previously filed vouch on VaultfireReputationStaking and unlock your stake. Pay $0.10 USDC, sign in your wallet.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-actions-update-agent-uri` — POST /api/x402/actions/update-agent-uri

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Update the agentURI of a registered ERC-8004 agent. Pay $0.10 USDC and receive an unsigned transaction — sign locally in your wallet (which must be the registered agent). No private keys touch our servers.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-contract-call` — POST /api/x402/contract-call

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** Generic on-chain read against any of the 134 Vaultfire Protocol contracts across Base, Avalanche, Arbitrum, and Polygon. Pass { chain, contract (name or address), function (name or canonical signature), args[] } and receive the decoded return value plus block provenance. Read-only (view/pure) calls only.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-post-api-x402-trust-email-verify` — POST /api/x402/trust/email-verify

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`deployed-v2-observed`, implementation=`legacy-v2`, operations=`live-v2-observed`, support=`supported`  
**Spec:** x402-Email Spec v0.1 verifier (paid bazaar lane, $0.01 USDC). Validates a sender address, accountability bond reference, and x402 payment header from an inbound email and returns a routing recommendation (inbox | review | spam) plus combined trust score, bond status, and signed _x402 receipt. A free public verifier (no bazaar receipt) is also available at POST /api/x402/email/verify for recipient mail filters.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Response schema/fixture remains unresolved in imported registry.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-delete-api-agent-webhooks` — DELETE /api/agent/webhooks

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-abis` — GET /api/abis

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-abis-name` — GET /api/abis/[name]

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-admin-recent-payers` — GET /api/admin/recent-payers

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-adapter` — GET /api/agent/adapter

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-agent-insurance` — GET /api/agent/agent-insurance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-agent-safety` — GET /api/agent/agent-safety

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-analytics` — GET /api/agent/analytics

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-attestation` — GET /api/agent/attestation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-bridge` — GET /api/agent/bridge

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-compliance` — GET /api/agent/compliance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-credentials` — GET /api/agent/credentials

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-discover` — GET /api/agent/discover

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-disputes` — GET /api/agent/disputes

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-flourishing` — GET /api/agent/flourishing

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-governance` — GET /api/agent/governance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-insurance` — GET /api/agent/insurance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-keys` — GET /api/agent/keys

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-mission` — GET /api/agent/mission

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-partnerships` — GET /api/agent/partnerships

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-performance` — GET /api/agent/performance

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-premium` — GET /api/agent/premium

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-privacy` — GET /api/agent/privacy

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-reputation-decay` — GET /api/agent/reputation-decay

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-routing` — GET /api/agent/routing

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-scoped-delegation` — GET /api/agent/scoped-delegation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-sla-enforcer` — GET /api/agent/sla-enforcer

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-status` — GET /api/agent/status

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-tasks` — GET /api/agent/tasks

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-trust` — GET /api/agent/trust

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-validation` — GET /api/agent/validation

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-vns` — GET /api/agent/vns

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-vouching` — GET /api/agent/vouching

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-agent-webhooks` — GET /api/agent/webhooks

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-contracts` — GET /api/contracts

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-cron-heartbeat` — GET /api/cron/heartbeat

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-gifs` — GET /api/gifs

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-health` — GET /api/health

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-hub-activity` — GET /api/hub/activity

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-hub-stats` — GET /api/hub/stats

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-live` — GET /api/live

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-openapi-json` — GET /api/openapi.json

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-protocol-bond-counts` — GET /api/protocol/bond-counts

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-protocol-distributions` — GET /api/protocol/distributions

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-protocol-recent` — GET /api/protocol/recent

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-well-known-agent-card-json` — GET /api/.well-known/agent-card.json

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-get-api-well-known-x402-email-json` — GET /api/.well-known/x402-email.json

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-bond` — POST /api/agent/bond

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-keys` — POST /api/agent/keys

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-premium` — POST /api/agent/premium

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-register` — POST /api/agent/register

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-route` — POST /api/agent/route

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-status-batch` — POST /api/agent/status/batch

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-tasks` — POST /api/agent/tasks

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v2.v2-source-post-api-agent-webhooks` — POST /api/agent/webhooks

**Kind:** operation / `v2`  
**Status:** audit=`historical-scope-only`, completion=`blocked`, deployment=`not-applicable`, implementation=`partial-source`, operations=`unverified`, support=`review-only`  
**Spec:** Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.

**Threats:** cross-route replay; request/response contract drift; authorization or audience bypass; dependency ambiguity; privacy leakage  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here.  
**Evidence:**   
**Open gaps:** Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.bond` — GET /api/v3/bonds/:bondId

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed V3 bond lookup by unsigned identifier.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.bond-party` — GET /api/v3/bonds

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed bond lookup by the required party query parameter.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.contract` — GET /api/v3/contracts/:name

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`review-only`  
**Spec:** Static V3 contract metadata by canonical name.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.contracts` — GET /api/v3/contracts

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`review-only`  
**Spec:** Static V3 contract catalog with null addresses until independently verified.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.dispute` — GET /api/v3/disputes/:disputeId

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed objective dispute lookup.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.evidence` — GET /api/v3/evidence/:evidenceHash

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Deferred evidence lookup with no deployment claim.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.governance-proposal` — GET /api/v3/governance/proposals/:proposalId

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed governance proposal status lookup.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.mandate` — GET /api/v3/mandates/:mandateHash

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Canonical plural V3 mandate lookup.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.mandate-compat` — GET /api/v3/mandate/:mandateHash

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Singular V3 compatibility wrapper over the plural route; no V2 fallback.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.migration` — GET /api/v3/migration/dispositions

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`review-only`  
**Spec:** Static migration capability and safety dispositions.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.pull-credit` — GET /api/v3/pull-credits

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed pull credit query by contract, asset, and holder.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.retired-partnership-write` — POST /api/v3/x402/actions/create-partnership-bond

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`retired`  
**Spec:** Non-executing retired partnership-bond write tombstone.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.solana-health` — GET /api/v3/solana/health

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`review-only`  
**Spec:** Source-only Solana health without RPC or executable claims.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.solvency` — GET /api/v3/protocol/solvency

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Unconfigured solvency readiness response.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.status` — GET /api/v3/protocol/status

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`review-only`  
**Spec:** Static unconfigured protocol readiness response.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.task` — GET /api/v3/tasks/:taskId

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`retired`  
**Spec:** Deferred task escrow read model.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.x402-challenge` — GET /api/v3/x402/challenges/:challengeId

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed V3 challenge lookup.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.x402-challenge-status` — GET /api/v3/x402/challenge-status

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`review-only`  
**Spec:** Static unavailable V3 payment-challenge capability status.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.x402-discovery` — GET /api/v3/x402/discovery

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`metadata-only`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed V3 x402 discovery with no payment candidates.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

## `route.v3.x402-receipt` — GET /api/v3/x402/receipts/:requestId

**Kind:** operation / `v3`  
**Status:** audit=`source-review-not-independent`, completion=`blocked`, deployment=`not-deployed-not-authorized`, implementation=`partial-source`, operations=`fail-closed`, support=`review-only`  
**Spec:** Fail-closed durable receipt evidence lookup.

**Threats:** V2 fallback; accidental payment activation; status/schema drift; malformed dynamic path; fabricated live data  
**Mitigations:** Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback.  
**Trust assumptions:** Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured.  
**Evidence:**   
**Open gaps:** No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.; Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate.

