{
  "$schema": "../schema/modules.manifest.schema.json",
  "acceptanceDimensions": [
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Desktop and 375px smoke evidence passes; the full viewport, zoom/reflow, assistive-technology, contrast, and disclosure matrix is incomplete.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-01",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "viewport overflow"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-02",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "zoom and reflow"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-03",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "keyboard and focus"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Desktop and 375px smoke evidence passes; the full viewport, zoom/reflow, assistive-technology, contrast, and disclosure matrix is incomplete.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-04",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "screen-reader structure"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-05",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "stable accessible names"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Desktop and 375px smoke evidence passes; the full viewport, zoom/reflow, assistive-technology, contrast, and disclosure matrix is incomplete.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-06",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "touch targets"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-07",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "WCAG contrast"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-08",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "reduced motion"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-09",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "small-screen table"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Desktop and 375px smoke evidence passes; the full viewport, zoom/reflow, assistive-technology, contrast, and disclosure matrix is incomplete.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-10",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "external links and social asset"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "A11Y-11",
      "initialStatus": "blocked",
      "scope": "public-v3-site",
      "title": "axe, validation, and manual assistive smoke"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Locally reproducible source/build/test evidence exists; no independent-machine reconstruction or deployed-bytecode comparison.",
        "Local Base evidence passes, but release evidence still lacks an independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-BASE-01",
      "initialStatus": "partial",
      "scope": "chain-and-cryptography",
      "title": "reproducible exact build/test/artifact evidence"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-BASE-02",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "finalized deployment roles, addresses, hashes, and authorization"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-BASE-03",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "independent exact-candidate audit"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-BASE-04",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "mandatory pinned-block fork execution"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Runtime sizes are measured below EIP-170; complete action gas/DoS and fork benchmarks remain.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-BASE-05",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "runtime size and gas headroom"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Exact adapter-mediated parity passes for the tested canonical grouped-reward receipt vector (10/10 dimensions and 13/13 required receipt fields per runtime); native schema identity remains false and broader parity is unclaimed.",
        "Release evidence still lacks a fresh independent checksum-root signature bound to this exact candidate."
      ],
      "id": "CHAIN-PARITY-01",
      "initialStatus": "partial",
      "scope": "chain-and-cryptography",
      "title": "dimension-by-dimension Base/Solana conformance"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-SOL-01",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "authorized bootstrap under new reviewed program IDs"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Local retained-artifact real-SBF lifecycle evidence passes 5/5 tests with 72 measured transactions, but no deployment is authorized.",
        "Release evidence still lacks an independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-SOL-02",
      "initialStatus": "partial",
      "scope": "chain-and-cryptography",
      "title": "native instruction lifecycle tests"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CHAIN-SOL-03",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "upgrade, rotation, revocation, pause, and recovery"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "CLAIMS-01",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "remove misleading Dilithium, PQ, ZK, FHE, and quantum claims"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-01",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "stable release JSON"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-02",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "ordinary HTTPS GET/HEAD"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-03",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "range, cache, content type, CORS"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-04",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "bootstrap checksums and authorization truth"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-05",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "clean-room offline reconstruction"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-06",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "corruption rejection"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-07",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "independent origin or limitation"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-08",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "cross-surface release identity"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-09",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "immutable history"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "HTTP-10",
      "initialStatus": "blocked",
      "scope": "release-fallback",
      "title": "preview URL/checksum validation"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-01",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "ML-DSA-65 native core and chain adapters"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-02",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "official vectors and malformed corpus"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-03",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "canonical binary envelope and contexts"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-04",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "AND-combined classical and ML-DSA authorization"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-05",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "key epochs, rotation, retirement, revocation, and recovery"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-06",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "direct-chain feasibility benchmarks"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-07",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "independent cryptography and integration audit"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "MLDSA-08",
      "initialStatus": "blocked",
      "scope": "chain-and-cryptography",
      "title": "chain-bound Base and Solana ML-DSA verification"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Local candidate build and fail-closed smoke evidence exist; no immutable preview URL, reviewed artifact promotion record, or production comparison.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-01",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "clean exact build"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-02",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "immutable preview record"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Local candidate build and fail-closed smoke evidence exist; no immutable preview URL, reviewed artifact promotion record, or production comparison.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-03",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "non-production fail-closed preview"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Local candidate build and fail-closed smoke evidence exist; no immutable preview URL, reviewed artifact promotion record, or production comparison.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-04",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "full no-value probes and suites"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-05",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "human digest approval"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-06",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "promote same artifact"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-07",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "protected production promotion"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-08",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "post-deploy identity comparison"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-09",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "rollback on mismatch"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "PREVIEW-10",
      "initialStatus": "blocked",
      "scope": "publication",
      "title": "separate owner-confirmed Bazaar publication"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Recorded quickstart status is failed; cold flow exceeded the target and source-boundary review remained.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-01",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "cold completion target"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Recorded quickstart status is failed; cold flow exceeded the target and source-boundary review remained.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-02",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "one command and expected digest"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "No-value tests pass, but the complete quickstart acceptance flow is not closed.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-03",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "loopback and outbound deny"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "No-value tests pass, but the complete quickstart acceptance flow is not closed.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-04",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "zero dependencies and no secrets"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "No-value tests pass, but the complete quickstart acceptance flow is not closed.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-05",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "non-monetary fixture labels"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "No-value tests pass, but the complete quickstart acceptance flow is not closed.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-06",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "negative lifecycle demonstrations"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-07",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "HTTP release fallback"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-08",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "mobile and assistive access"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-09",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "no signing/payment/deploy CTA"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "No-value tests pass, but the complete quickstart acceptance flow is not closed.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "QUICK-10",
      "initialStatus": "blocked",
      "scope": "five-minute-no-value-quickstart",
      "title": "explicit stop banner"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-01",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "identity and source export parity"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-02",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "routing and method isolation"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not every one of the full V2 source-operation inventory has a resolved status-specific request/response and operational contract.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-03",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "request contract"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "V2 response schemas/fixtures remain unresolved for most source operations.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-04",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "response contract"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not every one of the full V2 source-operation inventory has a resolved status-specific request/response and operational contract.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-05",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "auth and audience"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not every one of the full V2 source-operation inventory has a resolved status-specific request/response and operational contract.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-06",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "side effects and atomicity"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not every one of the full V2 source-operation inventory has a resolved status-specific request/response and operational contract.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-07",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "privacy and logging"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not every one of the full V2 source-operation inventory has a resolved status-specific request/response and operational contract.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-08",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "CORS and cache"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not every one of the full V2 source-operation inventory has a resolved status-specific request/response and operational contract.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-09",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "dependency failure"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not every one of the full V2 source-operation inventory has a resolved status-specific request/response and operational contract.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-C-10",
      "initialStatus": "blocked",
      "scope": "every-v2-operation",
      "title": "V2 compatibility"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-F-01",
      "initialStatus": "blocked",
      "scope": "free-v2-operations",
      "title": "documented 2xx without payment header"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-F-02",
      "initialStatus": "blocked",
      "scope": "free-v2-operations",
      "title": "no wrapper/facilitator/KV"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-F-03",
      "initialStatus": "blocked",
      "scope": "free-v2-operations",
      "title": "freshness and dependency degradation"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-F-04",
      "initialStatus": "blocked",
      "scope": "free-v2-operations",
      "title": "free discovery counted once"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-M-01",
      "initialStatus": "blocked",
      "scope": "method-only-v2-operations",
      "title": "resolve every contract field"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-M-02",
      "initialStatus": "blocked",
      "scope": "method-only-v2-operations",
      "title": "explicit surface inclusion"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Not demonstrated by this additive manifest build.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-M-03",
      "initialStatus": "blocked",
      "scope": "method-only-v2-operations",
      "title": "helper-specific tombstone/auth/forwarding behavior"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-01",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "canonical challenge"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-02",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "exact terms"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-03",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "single approved wrapper"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Strong source/test evidence exists, but the complete per-route/per-failure acceptance vector is not recorded for every priced operation.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-04",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "verifier ordering"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Strong source/test evidence exists, but the complete per-route/per-failure acceptance vector is not recorded for every priced operation.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-05",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "atomic claim"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-06",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "request binding"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Strong source/test evidence exists, but the complete per-route/per-failure acceptance vector is not recorded for every priced operation.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-07",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "verify then settlement"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Strong source/test evidence exists, but the complete per-route/per-failure acceptance vector is not recorded for every priced operation.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-08",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "durable bound receipt"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Strong source/test evidence exists, but the complete per-route/per-failure acceptance vector is not recorded for every priced operation.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-09",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "retry and idempotent delivery"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Strong source/test evidence exists, but the complete per-route/per-failure acceptance vector is not recorded for every priced operation.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-10",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "ambiguity and reorg recovery"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Strong source/test evidence exists, but the complete per-route/per-failure acceptance vector is not recorded for every priced operation.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-11",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "safe client behavior"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V2-P-12",
      "initialStatus": "blocked",
      "scope": "priced-v2-operations",
      "title": "unsigned no-value preview probe"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-01",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "namespace isolation"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-02",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "exact default-closed release gate"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-03",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "conservative public metadata"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-04",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "non-executing retired write"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-05",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "no payment surface"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-06",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "no V2 fallback"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-07",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "allowlist and path parity"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-08",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "status-specific schemas"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Source/adversarial coverage exists; production durable store, live capability evidence, rate limiting, and settlement/finality observations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-09",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "receipt locator entropy"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Source/adversarial coverage exists; production durable store, live capability evidence, rate limiting, and settlement/finality observations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-10",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "durable receipt semantics"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Source/adversarial coverage exists; production durable store, live capability evidence, rate limiting, and settlement/finality observations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-11",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "coherent capability evidence"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Deployment addresses, authorities, facilitator/store/finality evidence, owner authorization, and listing evidence are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-12",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "authenticated activation record"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Source/review surfaces are bound locally; no deployed/public promotion identity or future-major evolution exercise exists.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-13",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "major-version evolution"
    },
    {
      "claimRule": "Only attributable evidence for this exact manifest/source identity may advance status.",
      "evidence": [],
      "gaps": [
        "Source/review surfaces are bound locally; no deployed/public promotion identity or future-major evolution exercise exists.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "V3-14",
      "initialStatus": "blocked",
      "scope": "every-v3-operation",
      "title": "source/public identity binding"
    }
  ],
  "asOf": "2026-08-31",
  "authority": {
    "nonAuthorityRule": "Generated counts and presentation files are never authority; only filtered sets from this manifest may produce counts.",
    "precedence": [
      "this-manifest",
      "frozen-release-identities",
      "current-machine-dispositions",
      "current-source-and-tests",
      "historical-documents"
    ],
    "purpose": "Additive whole-protocol source of truth; records capability and operation reality without activating, deploying, paying, signing, or modifying V2.",
    "releaseIdentity": {
      "evidenceCommit": "1be0f7e791ffc4ea68bb35228bc8fcac0ff302da",
      "sourceCommit": "bf4b97f65b7032c778d137bb52a432afc4615b51",
      "sourceSubtree": "0a521a25501cd9fe6a74401c99fde450128b22c9",
      "sourceTag": "v3-source-2026-08-27",
      "sourceTree": "a1fd90c26ae676c87a10e7d3e614e84961b2990c",
      "toolingCommit": "241ce24db4c1417acbf936c5b412352531aba2f1"
    },
    "sourceAudits": []
  },
  "capabilities": [
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.canonical-reward-receipts-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.canonical-reward-receipts-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Canonical EIP-712 grouped-reward lifecycle receipts with actor, identity, provenance, consent, validity, resource, action, payload, chain-domain, nonce, and replay bindings."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "CanonicalRewardReceiptsV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.consent-registry-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.consent-registry-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Scoped EIP-712 consent grants and subject revocation."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "ConsentRegistryV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.cross-chain-receipt-registry-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.cross-chain-receipt-registry-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Route-specific informational cross-chain receipt registration through an immutable verifier; no bridge or value movement."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "CrossChainReceiptRegistryV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.deterministic-coverage-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.deterministic-coverage-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Fully reserved native-asset coverage for explicit objects and deterministic objective triggers."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "DeterministicCoverageV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.e-i-p712-auth-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.e-i-p712-auth-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Internal EIP-712 authorization and nonce-domain primitive for additive Base modules."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "EIP712AuthV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.emergency-controls-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.emergency-controls-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Immutable governance and guardian pause controls with pause-safe exits."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "EmergencyControlsV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.native-asset-ledger-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.native-asset-ledger-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Internal native-asset liability, credit, locked, reserved, and surplus accounting primitive."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "NativeAssetLedgerV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.pinned-trust-adapters-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.pinned-trust-adapters-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Runtime-codehash-pinned informational KYA and ERC-8004 read adapters with no protected-decision grant."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "PinnedTrustAdaptersV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.portable-receipts-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.portable-receipts-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Portable issuer-signed informational evidence and provenance receipts."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "PortableReceiptsV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.reward-vault-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.reward-vault-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Separately funded rewards isolated from protected principal and slashing."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "RewardVaultV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.session-capabilities-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.session-capabilities-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Exact-call finite session capabilities with delegation, nonce, cap, expiry, and revocation."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "SessionCapabilitiesV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.task-milestone-escrow-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.task-milestone-escrow-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Native-asset task and milestone escrow with bilateral release and bounded recovery."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "TaskMilestoneEscrowV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.v-n-s-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.v-n-s-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Commit/reveal convenience naming with expiry and delayed recovery; no authority meaning."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "VNSV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base-additive.voluntary-mutual-aid-v3"
      ],
      "evidence": [],
      "gaps": [
        "No deployment, Base fork, deployed-bytecode comparison, independent audit, or production authorization.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base-additive.voluntary-mutual-aid-v3",
      "kind": "base-additive-module",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Recipient-created voluntary native-asset mutual aid with donor and expiry recovery."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "authorization replay",
          "liability/accounting failure",
          "unsafe lifecycle boundary",
          "receipt field substitution",
          "scope overclaim"
        ]
      },
      "title": "VoluntaryMutualAidV3",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.accountability-bond-factory-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.accountability-bond-factory-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "deployment-only factory; exact initcode and runtime hashes enforced"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "AccountabilityBondFactoryV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.accountability-bond-v3-safe"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.accountability-bond-v3-safe",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "custody",
        "slashing",
        "settlement"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "codehash-pinned canonical on-chain deadline fact; deterministic pre-agreed slash"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "AccountabilityBondV3Safe",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.accountability-canonical-source-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.accountability-canonical-source-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "slashing"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "exact non-proxy append-only self-authenticated action timestamp source; runtime codehash is protocol-pinned"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "AccountabilityCanonicalSourceV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.base-pilot-access-controller-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.base-pilot-access-controller-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "custody",
        "access"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "bounded allowlist, deployment gate, allocation caps, and guardian coverage"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "BasePilotAccessControllerV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.base-sepolia-rehearsal-access-controller-v3"
      ],
      "evidence": [],
      "gaps": [
        "No production implication.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.base-sepolia-rehearsal-access-controller-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Rehearsal-only controller with no production authority."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "BaseSepoliaRehearsalAccessControllerV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.bond-math-lib-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.bond-math-lib-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "BondMathLibV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.bond-state-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.bond-state-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "BondStateV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.canonical-identity-registry-v3"
      ],
      "evidence": [],
      "gaps": [
        "Requires reviewed disposition change before support.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.canonical-identity-registry-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Discovered source outside the canonical supported module boundary."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "excluded"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "CanonicalIdentityRegistryV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.dispute-registry-v3"
      ],
      "evidence": [],
      "gaps": [
        "Retirement must remain enforced across SDK, API, discovery, and deployment tooling.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.dispute-registry-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "retired",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Source retained as an excluded tombstone; it is not a supported V3 release capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "DisputeRegistryV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.e-i-p712-base-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.e-i-p712-base-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "EIP712BaseV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.e-r-c8004-identity-adapter-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.e-r-c8004-identity-adapter-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "codehash-pinned read-only identity adapter; no protected-decision grant"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "ERC8004IdentityAdapterV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.e-r-c8004-validation-registry-v3-safe"
      ],
      "evidence": [],
      "gaps": [
        "Retirement must remain enforced across SDK, API, discovery, and deployment tooling.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.e-r-c8004-validation-registry-v3-safe",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "retired",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Source retained as an excluded tombstone; it is not a supported V3 release capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "ERC8004ValidationRegistryV3Safe",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.evidence-registry-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.evidence-registry-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "informational typed attestations only; no supported protected-decision consumer"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "EvidenceRegistryV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.i-accountability-canonical-source-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.i-accountability-canonical-source-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "IAccountabilityCanonicalSourceV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.i-dispute-subject-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.i-dispute-subject-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "IDisputeSubjectV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.i-e-r-c8004-identity-registry"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.i-e-r-c8004-identity-registry",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "IERC8004IdentityRegistry",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.i-mandate-execution-adapter-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.i-mandate-execution-adapter-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "IMandateExecutionAdapterV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.i-pilot-access-controller-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.i-pilot-access-controller-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "IPilotAccessControllerV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.legacy-k-y-a-adapter-v3"
      ],
      "evidence": [],
      "gaps": [
        "Requires reviewed disposition change before support.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.legacy-k-y-a-adapter-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Discovered source outside the canonical supported module boundary."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "excluded"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "LegacyKYAAdapterV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.mandate-execution-adapter-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.mandate-execution-adapter-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "custody",
        "access",
        "routing"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "principal-signed finite mandate with exact target, selector, value and execution binding"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "MandateExecutionAdapterV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.mandate-registry-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.mandate-registry-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "custody",
        "access",
        "routing"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "non-empty sorted target/selector scope and finite spend/rate caps"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "MandateRegistryV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.multisig-governance-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.multisig-governance-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "custody",
        "access",
        "eligibility",
        "pricing",
        "slashing",
        "settlement",
        "disputes",
        "routing"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "default-deny target/selector/value policy, committed policy updates, timelock, and proposal expiry"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "MultisigGovernanceV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.mutual-aid-pool-v3"
      ],
      "evidence": [],
      "gaps": [
        "Retirement must remain enforced across SDK, API, discovery, and deployment tooling.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.mutual-aid-pool-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "retired",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Source retained as an excluded tombstone; it is not a supported V3 release capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "MutualAidPoolV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.objective-rule-schema-v3"
      ],
      "evidence": [],
      "gaps": [
        "Requires reviewed disposition change before support.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.objective-rule-schema-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Discovered source outside the canonical supported module boundary."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "excluded"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "ObjectiveRuleSchemaV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.partnership-bond-factory-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.partnership-bond-factory-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "deployment-only factory; coordinator and child runtime pinned"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "PartnershipBondFactoryV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.partnership-bond-v3-safe"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.partnership-bond-v3-safe",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "custody",
        "settlement"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "mutual participant authorization and deterministic timeout recovery only"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "PartnershipBondV3Safe",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.pull-payments-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.pull-payments-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "PullPaymentsV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.reward-program-v3"
      ],
      "evidence": [],
      "gaps": [
        "Requires reviewed disposition change before support.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.reward-program-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Discovered source outside the canonical supported module boundary."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "excluded"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "RewardProgramV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.safe-bond-factory-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.safe-bond-factory-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "access"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "exact factory/child codehash validation and controller registration"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "SafeBondFactoryV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.signature-verifier-v3"
      ],
      "evidence": [],
      "gaps": [
        "No independent public/deployment claim is permitted.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.signature-verifier-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "internal",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal interface, library, or base dependency; never an independently deployable supported capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "internal"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "SignatureVerifierV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.street-cred-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.street-cred-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "informational-only and source-isolated from supported protected decisions"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "StreetCredV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.task-escrow-v3"
      ],
      "evidence": [],
      "gaps": [
        "Retirement must remain enforced across SDK, API, discovery, and deployment tooling.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.task-escrow-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "retired",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Source retained as an excluded tombstone; it is not a supported V3 release capability."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "TaskEscrowV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.threshold-consensus-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.threshold-consensus-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "objective attestation utility only; no supported protected-decision consumer"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "ThresholdConsensusV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "base.vaultfire-b-i-p-vault-v3"
      ],
      "evidence": [],
      "gaps": [
        "No authorized deployment, runtime comparison, independent audit, or completed operations evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "base.vaultfire-b-i-p-vault-v3",
      "kind": "base-module",
      "parity": {
        "api": "metadata-only",
        "base": "behavioral-subset",
        "sdk": "adapter-required",
        "solana": "unknown"
      },
      "protectedDecisionInfluence": [
        "custody",
        "pricing"
      ],
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "ERC-4626 deterministic accounting and explicit asset custody"
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unavailable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "reentrancy",
          "authorization bypass",
          "replay or domain confusion",
          "accounting or lifecycle failure"
        ]
      },
      "title": "VaultfireBIPVaultV3",
      "trustAssumptions": [
        "Solidity source identity and referenced tests match the frozen subtree."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.canonical-envelope"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.canonical-envelope",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Fixed-width and length-prefixed binary envelope with strict domain, action, epoch, nonce, deadline, and payload binding."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "algorithm confusion",
          "downgrade",
          "cross-domain replay",
          "non-canonical encoding",
          "side channel or denial of service"
        ]
      },
      "title": "Canonical HybridAuthorizationV1 codec",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.chain-bound-verification"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.chain-bound-verification",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Base and Solana must verify an ML-DSA-65, FIPS 204 algorithm-target statement on-chain through the reviewed SP1 proof stack before atomic nonce consumption; no FIPS 140 validation or independent conformance certification is claimed."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "false cryptographic receipt",
          "hybrid downgrade",
          "unbound proof",
          "replay",
          "resource-exhaustion denial of service"
        ]
      },
      "title": "Chain-bound ML-DSA verification",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.native-provider"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.native-provider",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "The native ML-DSA-65 provider is implemented and vector-tested as a FIPS 204 algorithm target. It has no FIPS 140 validation, independent conformance certification, or approved production operating environment."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "algorithm confusion",
          "downgrade",
          "cross-domain replay",
          "non-canonical encoding",
          "side channel or denial of service"
        ]
      },
      "title": "Native ML-DSA-65 provider, FIPS 204 algorithm target",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.hybrid-evm"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.hybrid-evm",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Require approved ECDSA/ERC-1271 AND ML-DSA-65 over one canonical envelope; no fallback."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "algorithm confusion",
          "downgrade",
          "cross-domain replay",
          "non-canonical encoding",
          "side channel or denial of service"
        ]
      },
      "title": "Hybrid EVM authorization",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.hybrid-solana"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.hybrid-solana",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Require detached Ed25519 AND ML-DSA-65 over one canonical envelope; no signer-flag substitution."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "algorithm confusion",
          "downgrade",
          "cross-domain replay",
          "non-canonical encoding",
          "side channel or denial of service"
        ]
      },
      "title": "Hybrid Solana authorization",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.key-lifecycle"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.key-lifecycle",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Monotonic epochs, delayed activation, irreversible revocation, distinct recovery, and no mixed-epoch downgrade."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "algorithm confusion",
          "downgrade",
          "cross-domain replay",
          "non-canonical encoding",
          "side channel or denial of service"
        ]
      },
      "title": "Hybrid key registry lifecycle",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.truthful-claims"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.truthful-claims",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Remove or qualify unsupported Dilithium, ML-DSA, ZK, FHE, pq-secure, and quantum-resistant claims."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "algorithm confusion",
          "downgrade",
          "cross-domain replay",
          "non-canonical encoding",
          "side channel or denial of service"
        ]
      },
      "title": "Truthful cryptography claims",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "mldsa.vectors-benchmarks-audit"
      ],
      "evidence": [],
      "gaps": [
        "Production chain-bound ML-DSA remains blocked: final SP1 guest ELF digest; production verifier pin (final SP1 program verification key); real Groth16 proof bound to the final guest; real-proof Base verification tests; real-proof Solana verification tests; Base gas and Solana compute/heap performance evidence; canonical atomic nonce consumption bound to proof verification; independent cryptography and chain-integration review."
      ],
      "id": "mldsa.vectors-benchmarks-audit",
      "kind": "cryptography-requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Final ACVP vectors, malformed corpus, differential verification, resource benchmarks, and independent cryptography review."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "algorithm confusion",
          "downgrade",
          "cross-domain replay",
          "non-canonical encoding",
          "side channel or denial of service"
        ]
      },
      "title": "Vectors, benchmarks, and independent audit",
      "trustAssumptions": [
        "SP1 architecture, native guest core, and Base/Solana adapter source exist.",
        "ML-DSA-65 is a FIPS 204 algorithm target. No FIPS 140 validation or independent algorithm conformance certification is claimed.",
        "No quantum-resistance claim is permitted."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "parity.canonical-grouped-reward-receipt-v2"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "parity.canonical-grouped-reward-receipt-v2",
      "kind": "cross-runtime-parity",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Exact adapter-mediated protocol parity for the retained canonical grouped-reward receipt vector; all declared dimensions and receipt bindings match while native schemas remain intentionally distinct."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "implemented-source",
        "operations": "not-applicable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "lossy adapter",
          "native field omission",
          "stale artifact substitution",
          "parity scope inflation"
        ]
      },
      "title": "Canonical grouped-reward receipt parity",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "release.aggregate-gates"
      ],
      "evidence": [],
      "gaps": [
        "Chain-bound ML-DSA software gate and all deployment-external gates remain blocking.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "release.aggregate-gates",
      "kind": "release-control",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Machine release model separates automatable software checks from deployment-external evidence and never authorizes deployment by itself."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "evidence/source drift",
          "scope overclaim",
          "unauthorized activation",
          "cross-runtime semantic mismatch"
        ]
      },
      "title": "Aggregate software and deployment-external gates",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-01"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-01",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Keep V3 additive and preserve V2."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "not-applicable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Keep V3 additive and preserve V2",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-02"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-02",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Freeze V2 bytecode."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "not-applicable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Freeze V2 bytecode",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-03"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-03",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Provide V2 ABI provenance."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Provide V2 ABI provenance",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-04"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-04",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Preserve V2 response behavior."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Preserve V2 response behavior",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-05"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-05",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Align V2 routes."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Align V2 routes",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-06"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-06",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Generate x402 and Bazaar metadata."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Generate x402 and Bazaar metadata",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-07"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-07",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Keep protocol, Bazaar, and x402 versions distinct."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "not-applicable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Keep protocol, Bazaar, and x402 versions distinct",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-08"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-08",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Require live Bazaar evidence fail-closed."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Require live Bazaar evidence fail-closed",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-09"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-09",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Implement V3 contracts."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Implement V3 contracts",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-10"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-10",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Enforce native bond caps in contract."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Enforce native bond caps in contract",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-11"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-11",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Preserve aggregate liability through pull-payment credits."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Preserve aggregate liability through pull-payment credits",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-12"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-12",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Exercise V3 safety in Foundry."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Exercise V3 safety in Foundry",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-13"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-13",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Maintain solvency and stateful invariant coverage."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Maintain solvency and stateful invariant coverage",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-14"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-14",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Enforce loop bounds and static analysis."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Enforce loop bounds and static analysis",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-15"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-15",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Verify deterministic build and size."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Verify deterministic build and size",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-16"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-16",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Test PR7 API, SDK, indexer, x402, and Bazaar package."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Test PR7 API, SDK, indexer, x402, and Bazaar package",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-17"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-17",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Fail closed on V3 status and solvency."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Fail closed on V3 status and solvency",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-18"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-18",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Provide unsigned migration and proposal tooling."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "not-applicable",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Provide unsigned migration and proposal tooling",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-19"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-19",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Keep migration voluntary and rollback additive."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Keep migration voluntary and rollback additive",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-20"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-20",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Provide Base deployment and rollback fork gate."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Provide Base deployment and rollback fork gate",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-21"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-21",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Keep V3 address inventory empty until verified."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Keep V3 address inventory empty until verified",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-22"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-22",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Enforce default-off website actions."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Enforce default-off website actions",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-23"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-23",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Keep pilot gate fail-closed."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Keep pilot gate fail-closed",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-24"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-24",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Document multisig-only governance transport."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Document multisig-only governance transport",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-25"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-25",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Prepare audit, bounty, and operations."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Prepare audit, bounty, and operations",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-26"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-26",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Preserve no-deploy boundary."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Preserve no-deploy boundary",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "requirement.prompt-27"
      ],
      "evidence": [],
      "gaps": [
        "Repository audit identifies material missing, unresolved, external, deployment, or operational evidence.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "requirement.prompt-27",
      "kind": "requirement",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Authorize pilot or mainnet."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "absent",
        "operations": "fail-closed",
        "support": "deferred"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "claim drift",
          "release bypass",
          "missing evidence"
        ]
      },
      "title": "Authorize pilot or mainnet",
      "trustAssumptions": [
        "Machine records and cited repository evidence are accurate for the frozen identity."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.accountability.activate"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.accountability.activate",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation accountability.activate; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "accountability.activate",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.accountability.attest"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.accountability.attest",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation accountability.attest; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "accountability.attest",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.accountability.create"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.accountability.create",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation accountability.create; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "accountability.create",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.accountability.expire"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.accountability.expire",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation accountability.expire; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "accountability.expire",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.accountability.force-exit"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.accountability.force-exit",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation accountability.force-exit; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "accountability.force-exit",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.accountability.fund"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.accountability.fund",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation accountability.fund; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "accountability.fund",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.partnership.approve"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.partnership.approve",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation partnership.approve; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "partnership.approve",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.partnership.cancel"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.partnership.cancel",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation partnership.cancel; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "partnership.cancel",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.partnership.create"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.partnership.create",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation partnership.create; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "partnership.create",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.partnership.expire"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.partnership.expire",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation partnership.expire; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "partnership.expire",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.partnership.force-exit"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.partnership.force-exit",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation partnership.force-exit; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "partnership.force-exit",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.partnership.fund"
      ],
      "evidence": [],
      "gaps": [
        "Not chain, payment, contract, testnet, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.partnership.fund",
      "kind": "sandbox-mutation",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local fixture mutation partnership.fund; no wallet, RPC, signature, token, facilitator, or monetary value."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "mock confused with production",
          "state-machine divergence"
        ]
      },
      "title": "partnership.fund",
      "trustAssumptions": [
        "Loopback-only deterministic fixture environment."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.pause-gate"
      ],
      "evidence": [],
      "gaps": [
        "Not contract, chain, testnet, payment, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.pause-gate",
      "kind": "sandbox-cross-cutting",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Local fixture pause blocks mutations while bounded exits remain available; no guardian parity is claimed."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "mock-production confusion",
          "state-machine divergence"
        ]
      },
      "title": "Sandbox pause gate",
      "trustAssumptions": [
        "Loopback fixture state is deterministic and non-monetary."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.read-models"
      ],
      "evidence": [],
      "gaps": [
        "Not contract, chain, testnet, payment, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.read-models",
      "kind": "sandbox-cross-cutting",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Local deterministic state and solvency views report fixture accounting only."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "mock-production confusion",
          "state-machine divergence"
        ]
      },
      "title": "Sandbox state and solvency reads",
      "trustAssumptions": [
        "Loopback fixture state is deterministic and non-monetary."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.receipts-idempotency"
      ],
      "evidence": [],
      "gaps": [
        "Not contract, chain, testnet, payment, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.receipts-idempotency",
      "kind": "sandbox-cross-cutting",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Deterministic local operation IDs and persisted fixture receipts demonstrate replay behavior only."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "mock-production confusion",
          "state-machine divergence"
        ]
      },
      "title": "Sandbox receipts and idempotency",
      "trustAssumptions": [
        "Loopback fixture state is deterministic and non-monetary."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sandbox.x402-no-payment"
      ],
      "evidence": [],
      "gaps": [
        "Not contract, chain, testnet, payment, or production parity.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sandbox.x402-no-payment",
      "kind": "sandbox-cross-cutting",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Local challenge and fulfill endpoints use fixture units without signatures, facilitator, USDC, or settlement."
      },
      "status": {
        "audit": "not-applicable",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "mock-only",
        "operations": "mock-only",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "mock-production confusion",
          "state-machine divergence"
        ]
      },
      "title": "Sandbox no-payment x402 rehearsal",
      "trustAssumptions": [
        "Loopback fixture state is deterministic and non-monetary."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.abi-bound-deployments"
      ],
      "evidence": [],
      "gaps": [
        "No configured deployment address, runtime hash, or independent capability verifier.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.abi-bound-deployments",
      "kind": "sdk-infrastructure",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "ABI identities and capability/selector allowlists for accountability, partnership, governance, and mandate modules; addresses and runtime hashes remain null."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "compatibility"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "ABI mismatch",
          "selector confusion",
          "address substitution"
        ]
      },
      "title": "Four ABI-bound SDK deployment identities",
      "trustAssumptions": [
        "Fixture ABI identity is source evidence, not deployed-bytecode evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.base-sepolia-rehearsal"
      ],
      "evidence": [],
      "gaps": [
        "Rehearsal evidence has no production implication.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.base-sepolia-rehearsal",
      "kind": "sdk-infrastructure",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Internal signed-fixture verification and rehearsal models only; never production attestation or deployment authority."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "test seam exported as trust root",
          "environment confusion"
        ]
      },
      "title": "Base Sepolia SDK rehearsal seam",
      "trustAssumptions": [
        "Fixture signatures and rehearsal profiles are non-production evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.bonds"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.bonds",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for bonds; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "compatibility"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "bonds",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.capabilities"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.capabilities",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for capabilities; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "capabilities",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.governance"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.governance",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for governance; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "compatibility"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "governance",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.mandates"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.mandates",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for mandates; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "compatibility"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "mandates",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.pullcredits"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.pullcredits",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for pullCredits; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "compatibility"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "pullCredits",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.solvency"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.solvency",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for solvency; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "compatibility"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "solvency",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.taskescrow"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.taskescrow",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for taskEscrow; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "taskEscrow",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.verified-writes"
      ],
      "evidence": [],
      "gaps": [
        "Canonical profiles have no deployment evidence, so practical writes remain blocked.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.verified-writes",
      "kind": "sdk-infrastructure",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Local validation requires configured profile, ABI identity, selector/capability allowlist, canonical calldata, and independent deployment/capability verification."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "write activation without evidence",
          "calldata malleability",
          "transport substitution"
        ]
      },
      "title": "Evidence-gated SDK writes",
      "trustAssumptions": [
        "Transport and evidence verifiers are separately trusted and currently unconfigured."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.versioned-package"
      ],
      "evidence": [],
      "gaps": [
        "Package is not published or verified equivalent to a registry artifact; no live V3 transport or deployment binding.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.versioned-package",
      "kind": "sdk-infrastructure",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Additive zero-runtime-dependency TypeScript V3 SDK candidate with generated manifest data, Base/Solana adapters, receipts, crypto helpers, and x402 offline support; no signing, custody, broadcast, or settlement."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "not-applicable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "package/source drift",
          "unsafe generic dispatch",
          "version ambiguity"
        ]
      },
      "title": "Versioned V3 SDK package surface",
      "trustAssumptions": [
        "Repository source/build evidence does not establish the public package artifact."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.x402-challenge"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.x402-challenge",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for x402.challenge; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "x402.challenge",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.x402-discovery"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.x402-discovery",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for x402.discovery; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "x402.discovery",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.x402-receipt"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.x402-receipt",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for x402.receipt; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "x402.receipt",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "sdk.x402-status"
      ],
      "evidence": [],
      "gaps": [
        "No live deployment-bound adapter; API mapping may be unavailable, retired, or adapter-required.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "sdk.x402-status",
      "kind": "sdk-logical-route",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Typed SDK logical read surface for x402.status; no configured V3 deployment or live reader is implied."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "status mismatch",
          "lossy route mapping",
          "unbound response",
          "write activation without evidence"
        ]
      },
      "title": "x402.status",
      "trustAssumptions": [
        "Canonical deployment profile remains unconfigured and transport evidence is external."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana-additive.vaultfire-v3-successor"
      ],
      "evidence": [],
      "gaps": [
        "Undeployed and unauthorized; no independent-machine reproduction, malformed-Borsh fuzzing, upgrade-authority rehearsal, independent audit, or chain-bound ML-DSA verifier.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana-additive.vaultfire-v3-successor",
      "kind": "solana-additive-program",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Anchor successor program with typed PDA lifecycles, native-SOL custody, grouped rewards, canonical receipts, fail-closed verifier adapters, pause/recovery, and generated IDL."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "PDA or owner confusion",
          "account substitution",
          "replay",
          "upgrade authority compromise",
          "SBF/source drift"
        ]
      },
      "title": "Vaultfire Solana V3 additive successor",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.ai-accountability-bonds"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.ai-accountability-bonds",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "behavioral-subset"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana supported-candidate source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "ai_accountability_bonds",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.ai-partnership-bonds"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.ai-partnership-bonds",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "behavioral-subset"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana supported-candidate source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "ai_partnership_bonds",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.anti-surveillance"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.anti-surveillance",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "absent"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana redesign-required source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "redesign-required"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "anti_surveillance",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.belief-attestation-verifier"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.belief-attestation-verifier",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "retired"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana retired source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "belief_attestation_verifier",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.dilithium-attestor"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.dilithium-attestor",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "absent"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Historical or candidate name only; no supported post-quantum attestation or quantum-resistance claim."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "redesign-required"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "dilithium_attestor",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.flourishing-metrics-oracle"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.flourishing-metrics-oracle",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "retired"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana retired source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "flourishing_metrics_oracle",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.identity-registry"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.identity-registry",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "behavioral-subset"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana supported-candidate source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "identity_registry",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.mission-enforcement"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.mission-enforcement",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "absent"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana redesign-required source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "redesign-required"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "mission_enforcement",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.multisig-governance"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.multisig-governance",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "behavioral-subset"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana supported-candidate source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "multisig_governance",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.privacy-guarantees"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.privacy-guarantees",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "behavioral-subset"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana supported-candidate source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "privacy_guarantees",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.production-belief-verifier"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.production-belief-verifier",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "retired"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana retired source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "production_belief_verifier",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.reputation-registry"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.reputation-registry",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "retired"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana retired source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "reputation_registry",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.trust-data-bridge"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.trust-data-bridge",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "retired"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana retired source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "trust_data_bridge",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.validation-registry"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.validation-registry",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "absent"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana redesign-required source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "redesign-required"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "validation_registry",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "solana.vaultfire-adapter"
      ],
      "evidence": [],
      "gaps": [
        "No functional native instruction lifecycle tests, authorized bootstrap, mainnet deployment, or independent audit.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "solana.vaultfire-adapter",
      "kind": "solana-program",
      "parity": {
        "api": "metadata-only",
        "base": "absent",
        "sdk": "absent",
        "solana": "behavioral-subset"
      },
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Solana supported-candidate source; every singleton initializer remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "unavailable",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "disabled bootstrap",
          "PDA or owner confusion",
          "account lifecycle mismatch",
          "upgrade authority compromise"
        ]
      },
      "title": "vaultfire_adapter",
      "trustAssumptions": [
        "Pinned source/program identity is not deployment evidence."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "surface.website-v3-review"
      ],
      "evidence": [],
      "gaps": [
        "No immutable preview promotion record, production deployment evidence, full viewport/zoom/axe/manual assistive matrix, or owner approval.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "surface.website-v3-review",
      "kind": "website-surface",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Next.js review surface builds and passes focused route, release, desktop/mobile smoke, overflow, touch-target, and metadata checks."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "evidence/source drift",
          "scope overclaim",
          "unauthorized activation",
          "cross-runtime semantic mismatch"
        ]
      },
      "title": "Built V3 website review surface",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "surface.x402-generated-review"
      ],
      "evidence": [],
      "gaps": [
        "No authorized V3 deployment, live reader, pay-to, facilitator, settlement, or Bazaar indexing.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "surface.x402-generated-review",
      "kind": "x402-generated-surface",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model; local software evidence never implies deployment, independent audit, payment activation, or broader parity."
        ],
        "summary": "Manifest-derived resources, OpenAPI, agent-card, and llms surfaces preserve V2 regression behavior and keep all V3 payment resources disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Bind claims to exact artifacts and logs, preserve disabled release controls, and require separate external authorization."
        ],
        "summary": "Additive candidate behavior must remain scope-bound and fail closed outside retained evidence.",
        "threats": [
          "evidence/source drift",
          "scope overclaim",
          "unauthorized activation",
          "cross-runtime semantic mismatch"
        ]
      },
      "title": "Generated x402 and review discovery surfaces",
      "trustAssumptions": [
        "Local retained evidence is authentic for the named source/artifact and does not establish public-chain state."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.a-i-accountability-bonds-v2"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.a-i-accountability-bonds-v2",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Objective rules and consent replace subjective accountability inputs."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/bonds/AccountabilityBondV3Safe.sol",
          "v3-src/contracts/bonds/AccountabilityBondFactoryV3.sol",
          "v3-src/contracts/bonds/SafeBondFactoryV3.sol",
          "v3-src/contracts/consensus/ThresholdConsensusV3.sol",
          "v3-src/contracts/bonds/AccountabilityCanonicalSourceV3.sol"
        ],
        "disposition": "ported",
        "implementationObligation": "required-safety-port"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "AIAccountabilityBondsV2",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.a-i-partnership-bonds-v2"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.a-i-partnership-bonds-v2",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Mutual consent, bounded principal settlement, and pull payments are release obligations."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/bonds/PartnershipBondV3Safe.sol",
          "v3-src/contracts/bonds/PartnershipBondFactoryV3.sol",
          "v3-src/contracts/bonds/SafeBondFactoryV3.sol",
          "v3-src/contracts/consensus/ThresholdConsensusV3.sol"
        ],
        "disposition": "ported",
        "implementationObligation": "required-safety-port"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "AIPartnershipBondsV2",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.agent-insurance-pool"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.agent-insurance-pool",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Discretionary recipient/reason routing is outside the strict Base mission boundary."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "intentionally-retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "AgentInsurancePool",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.agent-s-l-a-enforcer"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.agent-s-l-a-enforcer",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Generic opaque evidence and vote-driven remedies are intentionally retired."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "intentionally-retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "AgentSLAEnforcer",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.agent-safety-manager"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.agent-safety-manager",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Safety control is explicit mandate and pilot allowlisting, never behavioral scoring."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/mandate/MandateRegistryV3.sol",
          "v3-src/contracts/pilot/BasePilotAccessControllerV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "AgentSafetyManager",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.anti-surveillance"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.anti-surveillance",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Privacy promises require a separately reviewed implementation; no unsupported V3 claim."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "AntiSurveillance",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.belief-attestation-verifier"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.belief-attestation-verifier",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Belief inference cannot control protected decisions in V3."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "explicit-retirement"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "BeliefAttestationVerifier",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.compliance-registry"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.compliance-registry",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Compliance becomes objective signed evidence plus explicit authority."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/evidence/EvidenceRegistryV3.sol",
          "v3-src/contracts/mandate/MandateRegistryV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "ComplianceRegistry",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.dilithium-attestor"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.dilithium-attestor",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Historical or candidate name only; no supported post-quantum attestation or quantum-resistance claim."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "DilithiumAttestor",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.e-r-c8004-identity-registry"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.e-r-c8004-identity-registry",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "V3 consumes external identity read-only; identity is not eligibility by itself."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/identity/ERC8004IdentityAdapterV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "ERC8004IdentityRegistry",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.e-r-c8004-reputation-registry"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.e-r-c8004-reputation-registry",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Reputation is informational only and has zero protected-decision influence."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/reputation/StreetCredV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "ERC8004ReputationRegistry",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.e-r-c8004-validation-registry"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.e-r-c8004-validation-registry",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Stake custody and owner slashing are intentionally retired; no informational label remains."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "intentionally-retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "ERC8004ValidationRegistry",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.flourishing-metrics-oracle"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.flourishing-metrics-oracle",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Flourishing metrics are subjective and prohibited from protected decisions."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "explicit-retirement"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "FlourishingMetricsOracle",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.mission-enforcement"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.mission-enforcement",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Mission enforcement is replaced by explicit mandates and objective rules."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/mandate/MandateRegistryV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "MissionEnforcement",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.multisig-governance"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.multisig-governance",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Threshold governance is retained with bounded calls and no scoring automation."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/governance/MultisigGovernanceV3.sol"
        ],
        "disposition": "ported",
        "implementationObligation": "required-safety-port"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "MultisigGovernance",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.privacy-guarantees"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.privacy-guarantees",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Broad privacy guarantees are not represented as implemented without proof."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "PrivacyGuarantees",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.production-belief-attestation-verifier"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.production-belief-attestation-verifier",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Production belief attestation remains outside V3 protected decisions."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "explicit-retirement"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "ProductionBeliefAttestationVerifier",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.reputation-decay"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.reputation-decay",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Automated reputation decay cannot change access, value, disputes, or routing."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "explicit-retirement"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "ReputationDecay",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.scoped-delegation"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.scoped-delegation",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Delegation requires signed scope, nonce, deadline, and explicit execution adapter."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/mandate/MandateRegistryV3.sol",
          "v3-src/contracts/mandate/MandateExecutionAdapterV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "ScopedDelegation",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.v-k-p-delegation-registry"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.v-k-p-delegation-registry",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Delegation is consolidated into the explicit V3 mandate model."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/mandate/MandateRegistryV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VKPDelegationRegistry",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.v-k-p-factory"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.v-k-p-factory",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Legacy VKP creation has no supported release target."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VKPFactory",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.v-k-p-session-key-manager"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.v-k-p-session-key-manager",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Session authority is represented as bounded, expiring mandates."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/mandate/MandateRegistryV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VKPSessionKeyManager",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-b-i-p-vault"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-b-i-p-vault",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Vault custody requires ERC-4626 accounting and explicit liability invariants."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/vault/VaultfireBIPVaultV3.sol"
        ],
        "disposition": "ported",
        "implementationObligation": "required-safety-port"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireBIPVault",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-batch-onboarder"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-batch-onboarder",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Batch onboarding is excluded until identity and consent invariants are proven."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireBatchOnboarder",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-bond-insurance-pool"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-bond-insurance-pool",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Discretionary mutual-aid routing is intentionally retired from supported Base V3."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "intentionally-retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireBondInsurancePool",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-capability-credentials"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-capability-credentials",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Capabilities become explicit signed mandates, not inferred trust."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/mandate/MandateRegistryV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireCapabilityCredentials",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-dispute-resolution"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-dispute-resolution",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Generic dispute voting over opaque evidence is intentionally retired."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "intentionally-retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireDisputeResolution",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-e-r-c8004-adapter"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-e-r-c8004-adapter",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "The supported adapter is identity-only; reputation cannot gate protected decisions."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/identity/ERC8004IdentityAdapterV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireERC8004Adapter",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-forum-registry"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-forum-registry",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Forum/social routing is not part of supported V3 protocol decisions."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireForumRegistry",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-name-service"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-name-service",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Naming is convenience metadata and has no release obligation."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireNameService",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-reputation-staking"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-reputation-staking",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Reputation-linked staking would couple scoring to value and is retired."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "explicit-retirement"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireReputationStaking",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-street-cred"
      ],
      "evidence": [],
      "gaps": [
        "V3 deployment, independent audit, and operations are absent.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-street-cred",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "StreetCred is non-authoritative evidence and cannot control protected decisions."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "successor": {
        "baseTargets": [
          "v3-src/contracts/reputation/StreetCredV3.sol"
        ],
        "disposition": "redesigned",
        "implementationObligation": "required-redesign"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireStreetCred",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-task-escrow"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-task-escrow",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Quality/discretion-driven task disputes are intentionally retired from supported Base V3."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "intentionally-retired"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireTaskEscrow",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-teleporter-bridge"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-teleporter-bridge",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Cross-chain execution is unsupported until authenticated message semantics are reviewed."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "deferred"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "deferred",
        "implementationObligation": "deferred-nonrelease"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireTeleporterBridge",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-trust-attestation"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-trust-attestation",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Trust attestations cannot become eligibility, pricing, settlement, or routing inputs."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "explicit-retirement"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireTrustAttestation",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "v2-contract.vaultfire-trust-oracle"
      ],
      "evidence": [],
      "gaps": [
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "v2-contract.vaultfire-trust-oracle",
      "kind": "v2-contract-disposition",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Trust scores are prohibited as protected-decision inputs."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "not-applicable",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "retired"
      },
      "successor": {
        "baseTargets": [],
        "disposition": "retired",
        "implementationObligation": "explicit-retirement"
      },
      "threatModel": {
        "mitigations": [
          "Apply explicit status, bounded inputs, replay/domain separation where relevant, and evidence-gated activation."
        ],
        "summary": "Capability-specific abuse and integration failures must not create authority or value movement.",
        "threats": [
          "unsafe semantic carryover",
          "ABI provenance drift",
          "legacy authority confusion"
        ]
      },
      "title": "VaultfireTrustOracle",
      "trustAssumptions": [
        "Frozen V2 inventory observations remain unchanged and are not newly revalidated."
      ]
    },
    {
      "aliases": [],
      "coverageIds": [
        "x402.v3-durable-receipt-store"
      ],
      "evidence": [],
      "gaps": [
        "No production store configuration, facilitator observation, settlement, deployed capability binding, or live enumeration control.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "id": "x402.v3-durable-receipt-store",
      "kind": "x402-infrastructure",
      "spec": {
        "normativeRequirements": [
          "Preserve the shared safety model and fail closed when required evidence or configuration is absent."
        ],
        "summary": "Redis-capable source models concurrency, binding, replay, finality, timeout recovery, and audit chaining while V3 settlement remains disabled."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "implemented-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Use exact identity binding, conservative status, bounded behavior, and evidence-gated activation."
        ],
        "summary": "Cross-surface behavior must not imply unsupported authority, deployment, parity, or value movement.",
        "threats": [
          "atomicity failure",
          "receipt replay",
          "ambiguous settlement",
          "reorg",
          "locator enumeration"
        ]
      },
      "title": "V3 durable receipt store source",
      "trustAssumptions": [
        "A production Redis-compatible store and chain/facilitator observations would be external trust dependencies."
      ]
    }
  ],
  "coverageRequirements": [
    {
      "id": "base-additive.canonical-reward-receipts-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.consent-registry-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.cross-chain-receipt-registry-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.deterministic-coverage-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.e-i-p712-auth-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.emergency-controls-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.native-asset-ledger-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.pinned-trust-adapters-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.portable-receipts-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.reward-vault-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.session-capabilities-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.task-milestone-escrow-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.v-n-s-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base-additive.voluntary-mutual-aid-v3",
      "kind": "base-additive-module",
      "source": "current-additive-evidence"
    },
    {
      "id": "base.accountability-bond-factory-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.accountability-bond-v3-safe",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.accountability-canonical-source-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.base-pilot-access-controller-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.base-sepolia-rehearsal-access-controller-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.bond-math-lib-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.bond-state-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.canonical-identity-registry-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.dispute-registry-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.e-i-p712-base-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.e-r-c8004-identity-adapter-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.e-r-c8004-validation-registry-v3-safe",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.evidence-registry-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.i-accountability-canonical-source-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.i-dispute-subject-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.i-e-r-c8004-identity-registry",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.i-mandate-execution-adapter-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.i-pilot-access-controller-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.legacy-k-y-a-adapter-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.mandate-execution-adapter-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.mandate-registry-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.multisig-governance-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.mutual-aid-pool-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.objective-rule-schema-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.partnership-bond-factory-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.partnership-bond-v3-safe",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.pull-payments-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.reward-program-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.safe-bond-factory-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.signature-verifier-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.street-cred-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.task-escrow-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.threshold-consensus-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "base.vaultfire-b-i-p-vault-v3",
      "kind": "base-module",
      "source": "audit-inventory"
    },
    {
      "id": "mldsa.canonical-envelope",
      "kind": "cryptography-requirement",
      "source": "audit-inventory"
    },
    {
      "id": "mldsa.chain-bound-verification",
      "kind": "cryptography-requirement",
      "source": "current-additive-evidence"
    },
    {
      "id": "mldsa.native-provider",
      "kind": "cryptography-requirement",
      "source": "audit-inventory"
    },
    {
      "id": "mldsa.hybrid-evm",
      "kind": "cryptography-requirement",
      "source": "audit-inventory"
    },
    {
      "id": "mldsa.hybrid-solana",
      "kind": "cryptography-requirement",
      "source": "audit-inventory"
    },
    {
      "id": "mldsa.key-lifecycle",
      "kind": "cryptography-requirement",
      "source": "audit-inventory"
    },
    {
      "id": "mldsa.truthful-claims",
      "kind": "cryptography-requirement",
      "source": "audit-inventory"
    },
    {
      "id": "mldsa.vectors-benchmarks-audit",
      "kind": "cryptography-requirement",
      "source": "audit-inventory"
    },
    {
      "id": "parity.canonical-grouped-reward-receipt-v2",
      "kind": "cross-runtime-parity",
      "source": "current-additive-evidence"
    },
    {
      "id": "release.aggregate-gates",
      "kind": "release-control",
      "source": "current-additive-evidence"
    },
    {
      "id": "requirement.prompt-01",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-02",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-03",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-04",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-05",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-06",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-07",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-08",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-09",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-10",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-11",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-12",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-13",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-14",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-15",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-16",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-17",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-18",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-19",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-20",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-21",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-22",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-23",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-24",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-25",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-26",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "requirement.prompt-27",
      "kind": "requirement",
      "source": "audit-inventory"
    },
    {
      "id": "route.v2.v2-get-api-x402-bonds-agent-bond-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-bonds-overview",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-oracle-agent-stake-usd",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-oracle-chainlink-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-oracle-price-feed",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-agent-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-agentproof-evidence",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-analytics",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-bonds",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-bridge",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-contracts",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-credentials",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-disputes",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-flourishing-metrics",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-governance-proposals",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-health",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-history",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-insurance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-leaderboard",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-multi-chain-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-performance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-protocol-stats",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-relationships",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-reputation-decay",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-risk-score",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-safety-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-scoped-delegations",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-sla-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-street-cred",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-vns-resolve",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-get-api-x402-trust-vouching",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-accept-bid",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-approve-work",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-attest-belief",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-batch-onboard",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-bridge-trust-message",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-cancel-task",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-challenge-bond-metrics",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-commit-vns-name",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-contribute-insurance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-create-accountability-bond",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-create-partnership-bond",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-create-session-key",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-create-task",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-create-vkp-vault",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-deactivate-agent",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-dispute-task",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-file-attestation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-file-insurance-claim",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-file-vouch",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-grant-consent",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-issue-credential",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-mint-street-cred",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-register-agent",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-register-for-partnership",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-register-vns-name",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-report-mission-violation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-report-surveillance-violation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-request-bond-distribution",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-request-validation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-revoke-consent",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-revoke-credential",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-revoke-session-key",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-slash-reputation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-stake-as-validator",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-submit-accountability-metrics",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-submit-feedback",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-submit-partnership-metrics",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-submit-trust-attestation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-submit-validation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-submit-work",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-transfer-vns-name",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-trigger-reputation-decay",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-unvouch",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-actions-update-agent-uri",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-contract-call",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-post-api-x402-trust-email-verify",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-delete-api-agent-webhooks",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-abis",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-abis-name",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-admin-recent-payers",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-adapter",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-agent-insurance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-agent-safety",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-analytics",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-attestation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-bridge",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-compliance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-credentials",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-discover",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-disputes",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-flourishing",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-governance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-insurance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-keys",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-mission",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-partnerships",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-performance",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-premium",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-privacy",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-reputation-decay",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-routing",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-scoped-delegation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-sla-enforcer",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-tasks",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-trust",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-validation",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-vns",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-vouching",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-agent-webhooks",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-contracts",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-cron-heartbeat",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-gifs",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-health",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-hub-activity",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-hub-stats",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-live",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-openapi-json",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-protocol-bond-counts",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-protocol-distributions",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-protocol-recent",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-well-known-agent-card-json",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-get-api-well-known-x402-email-json",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-bond",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-keys",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-premium",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-register",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-route",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-status-batch",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-tasks",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v2.v2-source-post-api-agent-webhooks",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.bond",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.bond-party",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.contract",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.contracts",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.dispute",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.evidence",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.governance-proposal",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.mandate",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.mandate-compat",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.migration",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.pull-credit",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.retired-partnership-write",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.solana-health",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.solvency",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.task",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.x402-challenge",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.x402-challenge-status",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.x402-discovery",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "route.v3.x402-receipt",
      "kind": "operation",
      "source": "route-registry"
    },
    {
      "id": "sandbox.accountability.activate",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.accountability.attest",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.accountability.create",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.accountability.expire",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.accountability.force-exit",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.accountability.fund",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.partnership.approve",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.partnership.cancel",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.partnership.create",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.partnership.expire",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.partnership.force-exit",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.partnership.fund",
      "kind": "sandbox-mutation",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.pause-gate",
      "kind": "sandbox-cross-cutting",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.read-models",
      "kind": "sandbox-cross-cutting",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.receipts-idempotency",
      "kind": "sandbox-cross-cutting",
      "source": "audit-inventory"
    },
    {
      "id": "sandbox.x402-no-payment",
      "kind": "sandbox-cross-cutting",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.abi-bound-deployments",
      "kind": "sdk-infrastructure",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.base-sepolia-rehearsal",
      "kind": "sdk-infrastructure",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.bonds",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.capabilities",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.governance",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.mandates",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.pullcredits",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.solvency",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.taskescrow",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.verified-writes",
      "kind": "sdk-infrastructure",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.versioned-package",
      "kind": "sdk-infrastructure",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.x402-challenge",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.x402-discovery",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.x402-receipt",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "sdk.x402-status",
      "kind": "sdk-logical-route",
      "source": "audit-inventory"
    },
    {
      "id": "solana-additive.vaultfire-v3-successor",
      "kind": "solana-additive-program",
      "source": "current-additive-evidence"
    },
    {
      "id": "solana.ai-accountability-bonds",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.ai-partnership-bonds",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.anti-surveillance",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.belief-attestation-verifier",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.dilithium-attestor",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.flourishing-metrics-oracle",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.identity-registry",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.mission-enforcement",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.multisig-governance",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.privacy-guarantees",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.production-belief-verifier",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.reputation-registry",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.trust-data-bridge",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.validation-registry",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "solana.vaultfire-adapter",
      "kind": "solana-program",
      "source": "audit-inventory"
    },
    {
      "id": "surface.website-v3-review",
      "kind": "website-surface",
      "source": "current-additive-evidence"
    },
    {
      "id": "surface.x402-generated-review",
      "kind": "x402-generated-surface",
      "source": "current-additive-evidence"
    },
    {
      "id": "v2-contract.a-i-accountability-bonds-v2",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.a-i-partnership-bonds-v2",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.agent-insurance-pool",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.agent-s-l-a-enforcer",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.agent-safety-manager",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.anti-surveillance",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.belief-attestation-verifier",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.compliance-registry",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.dilithium-attestor",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.e-r-c8004-identity-registry",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.e-r-c8004-reputation-registry",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.e-r-c8004-validation-registry",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.flourishing-metrics-oracle",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.mission-enforcement",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.multisig-governance",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.privacy-guarantees",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.production-belief-attestation-verifier",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.reputation-decay",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.scoped-delegation",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.v-k-p-delegation-registry",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.v-k-p-factory",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.v-k-p-session-key-manager",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-b-i-p-vault",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-batch-onboarder",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-bond-insurance-pool",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-capability-credentials",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-dispute-resolution",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-e-r-c8004-adapter",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-forum-registry",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-name-service",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-reputation-staking",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-street-cred",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-task-escrow",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-teleporter-bridge",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-trust-attestation",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "v2-contract.vaultfire-trust-oracle",
      "kind": "v2-contract-disposition",
      "source": "audit-inventory"
    },
    {
      "id": "x402.v3-durable-receipt-store",
      "kind": "x402-infrastructure",
      "source": "audit-inventory"
    }
  ],
  "manifestId": "vaultfire-full-v3-authority",
  "modules": [
    {
      "advertised": false,
      "aliases": [
        "AIAccountabilityBondsV2"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/bonds/AccountabilityBondV3Safe.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "fffa87569e1afbc74301eccb099815a27b2954586e13f05b8c8e766a096ccffa",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/bonds/AccountabilityBondLifecycleExpiryV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1c4120316e8cd48485af0783ea17fa5b62c501aae67951c0b05bbaba67bb5cf2",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: AIAccountabilityBondsV2.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/AIAccountabilityBondsV2.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "1b9436b58faf47c49f48399502fc14afcf77fd00d827f42b862fb5ef6b0582a6",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/bonds/AccountabilityBondV3Safe.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "fffa87569e1afbc74301eccb099815a27b2954586e13f05b8c8e766a096ccffa",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "accountability-bonds",
      "name": "Accountability Bonds",
      "purpose": "Stake-backed accountability lifecycle for agents.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/bond-lifecycles.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "cf1ded076b3bee1206463fabda08c1c026b3330f85b4f259373fd404698fdc3a",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/AIAccountabilityBondsV2.json",
          "reason": "Canonical frozen V2 ABI identity for AIAccountabilityBondsV2.",
          "sha256": "1b9436b58faf47c49f48399502fc14afcf77fd00d827f42b862fb5ef6b0582a6",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for AIAccountabilityBondsV2.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "A V3 safe bond implementation exists as source; deployment and independent audit remain blocked.",
        "status": "ported"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "AIPartnershipBondsV2"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/bonds/PartnershipBondV3Safe.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "31104305610ac94e9c1213a12ce164f36e5ad80fb053988a2a159f6cdd5ecfe3",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/bonds/IndependentBondBoundaryRegressionV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "484c9eff820a206f6444c44a53f6acc6f52a31e3cb80b0a2771a293d4cc94f36",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: AIPartnershipBondsV2.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/AIPartnershipBondsV2.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "5b6a6886c25fd8d7be3f9ec3a1f3889ba3bf9964ffd30c7cb4637a5779758112",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/bonds/PartnershipBondV3Safe.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "31104305610ac94e9c1213a12ce164f36e5ad80fb053988a2a159f6cdd5ecfe3",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "partnership-bonds",
      "name": "Partnership Bonds",
      "purpose": "Partnership bond lifecycle and mutually agreed settlement.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/bond-lifecycles.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "cf1ded076b3bee1206463fabda08c1c026b3330f85b4f259373fd404698fdc3a",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/AIPartnershipBondsV2.json",
          "reason": "Canonical frozen V2 ABI identity for AIPartnershipBondsV2.",
          "sha256": "5b6a6886c25fd8d7be3f9ec3a1f3889ba3bf9964ffd30c7cb4637a5779758112",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for AIPartnershipBondsV2.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "A V3 safe partnership bond exists as source; deployment and independent audit remain blocked.",
        "status": "ported"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "BaseDignityBond",
        "Dignity Bond"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No accepted Full-V3 Dignity Bond successor exists.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "contracts-root/BaseDignityBond.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "5009f7cdb861643ffeecd37bccf23ff379c347732b7a244100745fdd0d0c84c1",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "dignity-bonds",
      "name": "Dignity Bond",
      "purpose": "Historical dignity-focused bond claim.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": true,
        "result": "Historical source found without canonical V2 ABI/deployment identity.",
        "searches": [
          {
            "command": "rg -n --hidden -g '!.git/**' -g '!node_modules/**' 'BaseDignityBond' .",
            "query": "BaseDignityBond",
            "result": "source-found",
            "scope": "working-tree"
          },
          {
            "command": "git log --all --oneline -S'BaseDignityBond' -- .",
            "query": "BaseDignityBond",
            "result": "history-reference-found",
            "scope": "git-history"
          },
          {
            "command": "rg -n 'BaseDignityBond' legacy/v2/manifest.json legacy/v2/abis",
            "query": "BaseDignityBond",
            "result": "not-found",
            "scope": "legacy-v2-abi-and-deployments"
          }
        ]
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": "contracts-root/BaseDignityBond.sol",
          "reason": "Historical source discovered by repository and Git-history search; not a frozen canonical V2 ABI/deployment identity.",
          "sha256": "5009f7cdb861643ffeecd37bccf23ff379c347732b7a244100745fdd0d0c84c1",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "A historical BaseDignityBond source file was found, but no canonical V2 ABI/deployment identity or accepted Full-V3 successor exists.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "MultisigGovernance",
        "BasePilotAccessControllerV3"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/pilot/BasePilotAccessControllerV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1aa6fed226bdc948e3693fe57c2d2a1df8a448345a08dfec2376b95c57891f28",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/pilot/BasePilotAccessControllerV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "09e028d94c1f7965c04d8e0538bd35b609dfcff540a7bb5bec29fc2d1237c2e7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: MultisigGovernance.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/MultisigGovernance.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "fe02ab2e0312c83a62055352d8eb0076606b53f235c5a4d09ab53001905c8aa8",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/pilot/BasePilotAccessControllerV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "1aa6fed226bdc948e3693fe57c2d2a1df8a448345a08dfec2376b95c57891f28",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "governance-pilot-access",
      "name": "Governance and Pilot Access",
      "purpose": "Governance controls and explicitly gated pilot access.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/status-discovery.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "08063bcf7a300eee57944f2d4464242852a5424de35fe8552cfc3ff4ee69cc1b",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/MultisigGovernance.json",
          "reason": "Canonical frozen V2 ABI identity for MultisigGovernance.",
          "sha256": "fe02ab2e0312c83a62055352d8eb0076606b53f235c5a4d09ab53001905c8aa8",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for MultisigGovernance.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 governance and pilot access are separate source-only controls; human roles and deployment are unset.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "MultiOracleConsensus"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/consensus/ThresholdConsensusV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "9c4b70400ea2623a5e2854292669a7a5e0e428cf0c8e9d9294f0db9066d08c88",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/consensus/ThresholdConsensusV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "6e6374efac7d8be458d1c183409c47d5a1534ab4f319ad05798a4406a58acd4d",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/consensus/ThresholdConsensusV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "9c4b70400ea2623a5e2854292669a7a5e0e428cf0c8e9d9294f0db9066d08c88",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "threshold-consensus",
      "name": "Threshold Consensus",
      "purpose": "Threshold approval aggregation without treating identity as authorization.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/evidence-consensus.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "4644969f2d7becf4e08fae1dbfde591e29e3f8d1f643bf84fd7b963bb705d5a8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "A V3 threshold consensus source exists without deployment or independent audit.",
        "status": "ported"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "adjudicators",
        "adjudication"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "adjudication",
      "name": "Adjudication",
      "purpose": "Authorized adjudicator decisions for contested protocol outcomes.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": true,
        "result": "Historical public claim/source not found.",
        "searches": [
          {
            "command": "rg -n --hidden -g '!.git/**' -g '!node_modules/**' 'adjudicators' .",
            "query": "adjudicators",
            "result": "claim-only-or-not-found",
            "scope": "working-tree"
          },
          {
            "command": "git log --all --oneline -S'adjudicators' -- .",
            "query": "adjudicators",
            "result": "history-reference-found",
            "scope": "git-history"
          },
          {
            "command": "rg -n 'adjudicators' legacy/v2/manifest.json legacy/v2/abis",
            "query": "adjudicators",
            "result": "not-found",
            "scope": "legacy-v2-abi-and-deployments"
          }
        ]
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Governance documents mention adjudicators, but no canonical standalone adjudication module source, ABI, or deployment was found.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireDisputeResolution"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/disputes/DisputeRegistryV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "3dd9b2b7b262cffaca588f808086d4ad6150b17e40e4928fd9e9400a76fd0db9",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/disputes/DisputeRegistryV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "c689ec0e61989f5b797e0b281648285b6bbc3bb2b10f47d5ddc66981061d7dc9",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireDisputeResolution.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireDisputeResolution.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "ab31327dd4dc83eee0d7cee430a54c2c1586916eca2e03deae01f0dae35dc7f8",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/disputes/DisputeRegistryV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "3dd9b2b7b262cffaca588f808086d4ad6150b17e40e4928fd9e9400a76fd0db9",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "disputes",
      "name": "Disputes",
      "purpose": "Dispute registration and resolution workflow.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/evidence-consensus.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "4644969f2d7becf4e08fae1dbfde591e29e3f8d1f643bf84fd7b963bb705d5a8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireDisputeResolution.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireDisputeResolution.",
          "sha256": "ab31327dd4dc83eee0d7cee430a54c2c1586916eca2e03deae01f0dae35dc7f8",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "repos/theloopbreaker-site/contracts/VaultfireDisputeResolution.sol",
          "reason": "Pinned historical Solidity source for VaultfireDisputeResolution.",
          "sha256": "647793a333552e1af3642e58e9a81ab7514af85d09a6a540f54e1714c9225a28",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 dispute registry source exists; adjudication authority is intentionally not inferred.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "EvidenceRegistry"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/evidence/EvidenceRegistryV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "3ae142ed5f23954175bb63ae30405e9903d533d16509def9d9807b8bc87b26af",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/bonds/EvidenceRegistryV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "9390143d5bfc94ca5383cdf98543bc6342f6fdd059c378bf114aa97d05084519",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/evidence/EvidenceRegistryV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "3ae142ed5f23954175bb63ae30405e9903d533d16509def9d9807b8bc87b26af",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "evidence",
      "name": "Evidence",
      "purpose": "Immutable evidence reference registration and binding.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/evidence-consensus.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "4644969f2d7becf4e08fae1dbfde591e29e3f8d1f643bf84fd7b963bb705d5a8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 evidence registry source exists; external evidence truth remains out of scope.",
        "status": "ported"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "MandateRegistry"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/mandate/MandateRegistryV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "c6665d816d1f1f84cb8ec6514a3b2e7914fb97d0408ce3865998f4e592784607",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/mandate/MandateRegistryV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "4b2d638fd0d3494d221164757d567ed85d8b6f8120ae1672f095c7e96279d494",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/mandate/MandateRegistryV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "c6665d816d1f1f84cb8ec6514a3b2e7914fb97d0408ce3865998f4e592784607",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "mandates",
      "name": "Mandates",
      "purpose": "Scoped mandates and execution authorization records.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/identity-mandates.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "2e8fbde1b13c53884078b8a6e3bf8a0a7e63d60439670b90bd9e153f85baf202",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": "full-v3/solana/idl/vaultfire_v3_successor.json",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1ce771b588c39614423eba762870af70529d6292fd861360b083faf86eb84afc",
          "state": "available",
          "url": null
        },
        "implementation": "partial-source",
        "source": {
          "path": "full-v3/solana/programs/vaultfire_v3_successor/src/lib.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "98233b561f23a02128b1a7518d79c9ab1e8aa061d5f77eb8a1247237902c11a2",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/solana/tests/adversarial.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "b3c33afd31d8d81c386e0a98d51a19ec24b332b4a2ce38f78611cff94b465aa6",
          "state": "available",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 mandate source exists without an authorized deployment.",
        "status": "ported"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "ScopedDelegation",
        "VKPDelegationRegistry"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/SessionCapabilitiesV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "7eea270253bb9fc05503a525784b6d420f579dbd1433a5e23624f6317d0d6209",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/AuthorizationAndReceipts.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "a1990e33fbdaaf6b63b7347e3362e1c9bda93ac34e7b9c2391a8962520c596f7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: ScopedDelegation.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/ScopedDelegation.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "9aab630fac01bb83da983b3abc369b7869a7266ff798168179288e776ddad7ed",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VKPDelegationRegistry.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VKPDelegationRegistry.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "786d1fe72d5eb65fa99b617ee8fe5169862dd7e5a2790c0f55d05bc263491a9f",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/SessionCapabilitiesV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "7eea270253bb9fc05503a525784b6d420f579dbd1433a5e23624f6317d0d6209",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "delegation-agent-authorization",
      "name": "Delegation and Agent Authorization",
      "purpose": "Scoped delegation and agent authorization boundaries.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/identity-mandates.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "2e8fbde1b13c53884078b8a6e3bf8a0a7e63d60439670b90bd9e153f85baf202",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/ScopedDelegation.json",
          "reason": "Canonical frozen V2 ABI identity for ScopedDelegation.",
          "sha256": "9aab630fac01bb83da983b3abc369b7869a7266ff798168179288e776ddad7ed",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "repos/vaultfire-keyprotocol/contracts/ScopedDelegation.sol",
          "reason": "Pinned historical Solidity source for ScopedDelegation.",
          "sha256": "35d1b05e1fee19f74474a3c2536840a77755470d78dbd3f37049b1cd900c72a3",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 authorization is redesigned around mandates and session capabilities.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "ComplianceRegistry",
        "LegacyKYAAdapterV3"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/identity/LegacyKYAAdapterV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "ef973b750879b752bed9efc7cfea2a555482a776b298255da75f0add3d95b8f3",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/identity/ERC8004IdentityAdapterV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "765a580fec3c8cd885934a2e9e6e0bc0f82fbc1ec032822f2a18b061d7bea2b8",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: ComplianceRegistry.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/ComplianceRegistry.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "363b0df428d1a318b790c0abbbe05bf92f2f95031a7a6dc0f1e451f43a86411c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/identity/LegacyKYAAdapterV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "ef973b750879b752bed9efc7cfea2a555482a776b298255da75f0add3d95b8f3",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "kya",
      "name": "KYA",
      "purpose": "Know-your-agent compatibility adapter and compliance boundary.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/identity-mandates.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "2e8fbde1b13c53884078b8a6e3bf8a0a7e63d60439670b90bd9e153f85baf202",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/ComplianceRegistry.json",
          "reason": "Canonical frozen V2 ABI identity for ComplianceRegistry.",
          "sha256": "363b0df428d1a318b790c0abbbe05bf92f2f95031a7a6dc0f1e451f43a86411c",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "repos/vaultfire-keyprotocol/contracts/ComplianceRegistry.sol",
          "reason": "Pinned historical Solidity source for ComplianceRegistry.",
          "sha256": "39afef5285ad7fbc0c83884724fde85abc3014d129dc15925fa5944d4ac75b57",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 retains an explicit legacy KYA adapter; KYA is not authorization.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "ERC8004IdentityRegistry",
        "VaultfireERC8004Adapter"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/identity/ERC8004IdentityAdapterV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "b448004372964a434392c566d1b51434afe9f93920c21360b6f878a1be765abf",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/identity/ERC8004IdentityAdapterV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "765a580fec3c8cd885934a2e9e6e0bc0f82fbc1ec032822f2a18b061d7bea2b8",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: ERC8004IdentityRegistry.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/ERC8004IdentityRegistry.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "c875d8ac336756f96634a6df8360728d2967c1c49c2c54e831e0163aab30c65d",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/identity/ERC8004IdentityAdapterV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "b448004372964a434392c566d1b51434afe9f93920c21360b6f878a1be765abf",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "erc8004-identity",
      "name": "ERC-8004 Identity",
      "purpose": "ERC-8004 identity registry and adapter boundary.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/identity-mandates.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "2e8fbde1b13c53884078b8a6e3bf8a0a7e63d60439670b90bd9e153f85baf202",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/ERC8004IdentityRegistry.json",
          "reason": "Canonical frozen V2 ABI identity for ERC8004IdentityRegistry.",
          "sha256": "c875d8ac336756f96634a6df8360728d2967c1c49c2c54e831e0163aab30c65d",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for ERC8004IdentityRegistry.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 uses a canonical identity registry plus explicit ERC-8004 adapter.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "ERC8004ValidationRegistry",
        "ERC8004ReputationRegistry",
        "ReputationDecay",
        "VaultfireReputationStaking"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/reputation/ERC8004ValidationRegistryV3Safe.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "cf31c6b5a8451778a3d5c94744eac05387be3b215e65b51997454b9081f1de03",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/reputation/StreetCredV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "8e9ef89dba254427b8eff2fd7c00569ae10e4cfac90d83bfb40d08ee0bceadf3",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: ERC8004ValidationRegistry.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/ERC8004ValidationRegistry.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "55869eb34e259ca67c8bb07a004f17577ecd15a7bad0a70ab49cabf8ec25d11c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: ERC8004ReputationRegistry.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/ERC8004ReputationRegistry.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "6ea122b6ca14166c923d38cee8e8092a28563866af5b38fd41ab114931943d88",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/reputation/ERC8004ValidationRegistryV3Safe.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "cf31c6b5a8451778a3d5c94744eac05387be3b215e65b51997454b9081f1de03",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "erc8004-validation-reputation",
      "name": "ERC-8004 Validation and Reputation",
      "purpose": "Validation and reputation records compatible with ERC-8004 surfaces.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/evidence-consensus.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "4644969f2d7becf4e08fae1dbfde591e29e3f8d1f643bf84fd7b963bb705d5a8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/ERC8004ValidationRegistry.json",
          "reason": "Canonical frozen V2 ABI identity for ERC8004ValidationRegistry.",
          "sha256": "55869eb34e259ca67c8bb07a004f17577ecd15a7bad0a70ab49cabf8ec25d11c",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for ERC8004ValidationRegistry.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "A V3 safe validation registry exists; reputation is not authorization.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireStreetCred"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "v3-src/contracts/reputation/StreetCredV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "622aa350e3b82bb6ef9e3892e621d98f7b0a884a0b103fd09e64779dfb8ce461",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "v3-src/test/reputation/StreetCredV3.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "8e9ef89dba254427b8eff2fd7c00569ae10e4cfac90d83bfb40d08ee0bceadf3",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireStreetCred.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireStreetCred.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "c619f02cca8a10440592c38e27a7d23272e347d94dbc70c4efae117246217d63",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "v3-src/contracts/reputation/StreetCredV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "622aa350e3b82bb6ef9e3892e621d98f7b0a884a0b103fd09e64779dfb8ce461",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "streetcred",
      "name": "StreetCred",
      "purpose": "Protocol reputation and credibility observations.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/evidence-consensus.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "4644969f2d7becf4e08fae1dbfde591e29e3f8d1f643bf84fd7b963bb705d5a8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireStreetCred.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireStreetCred.",
          "sha256": "c619f02cca8a10440592c38e27a7d23272e347d94dbc70c4efae117246217d63",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for VaultfireStreetCred.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 StreetCred source exists without authorized deployment.",
        "status": "ported"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireTaskEscrow"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/TaskMilestoneEscrowV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "0451d8ec282a60c812ab8efb0698bf703433acc40d41908b86b1dbc7d45067f6",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/EconomicSuccessors.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "36c8f43f9ae37d33346a748153f60f344e4fa218d6733a74e08b442de03034b4",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireTaskEscrow.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireTaskEscrow.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "56aef72aeab7ea4513f00a476d6f902b70487cf5fef656eb95ad847e78478521",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/TaskMilestoneEscrowV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "0451d8ec282a60c812ab8efb0698bf703433acc40d41908b86b1dbc7d45067f6",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "task-escrow",
      "name": "Task Escrow",
      "purpose": "Milestone task escrow with bounded recovery.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/economic-modules.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "415986112e5eba83814ae52a1b99a94c1f634affea5293f8b5cf244548fee8d8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": "full-v3/solana/idl/vaultfire_v3_successor.json",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1ce771b588c39614423eba762870af70529d6292fd861360b083faf86eb84afc",
          "state": "available",
          "url": null
        },
        "implementation": "partial-source",
        "source": {
          "path": "full-v3/solana/programs/vaultfire_v3_successor/src/lib.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "98233b561f23a02128b1a7518d79c9ab1e8aa061d5f77eb8a1247237902c11a2",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/solana/tests/adversarial.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "b3c33afd31d8d81c386e0a98d51a19ec24b332b4a2ce38f78611cff94b465aa6",
          "state": "available",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireTaskEscrow.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireTaskEscrow.",
          "sha256": "56aef72aeab7ea4513f00a476d6f902b70487cf5fef656eb95ad847e78478521",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "contracts-root/VaultfireTaskEscrow.sol",
          "reason": "Pinned historical Solidity source for VaultfireTaskEscrow.",
          "sha256": "55f7d07acc74ad7b71990e945a91868729ef29875ace03a94c8e7d4d1c35a710",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Full-V3 milestone escrow source exists; legacy SDK task route remains retired.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "MutualAidPoolV3"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/VoluntaryMutualAidV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "4b42f1efebbf1cda48db72f3c989dbdeb2a42c550d8d58494acee7cbb2daeafb",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/EconomicSuccessors.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "36c8f43f9ae37d33346a748153f60f344e4fa218d6733a74e08b442de03034b4",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/VoluntaryMutualAidV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b42f1efebbf1cda48db72f3c989dbdeb2a42c550d8d58494acee7cbb2daeafb",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "mutual-aid",
      "name": "Mutual Aid",
      "purpose": "Voluntary mutual-aid custody and recovery.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/economic-modules.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "415986112e5eba83814ae52a1b99a94c1f634affea5293f8b5cf244548fee8d8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": "full-v3/solana/idl/vaultfire_v3_successor.json",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1ce771b588c39614423eba762870af70529d6292fd861360b083faf86eb84afc",
          "state": "available",
          "url": null
        },
        "implementation": "partial-source",
        "source": {
          "path": "full-v3/solana/programs/vaultfire_v3_successor/src/lib.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "98233b561f23a02128b1a7518d79c9ab1e8aa061d5f77eb8a1247237902c11a2",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/solana/tests/adversarial.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "b3c33afd31d8d81c386e0a98d51a19ec24b332b4a2ce38f78611cff94b465aa6",
          "state": "available",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Full-V3 voluntary mutual aid source exists; no V2 ABI identity was found.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireBIPVault"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/common/NativeAssetLedgerV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1472ddb78e352c8143466ddfb71a78a55de146a2411cbde91d3f06ba87e8261a",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/EconomicInvariant.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "47755c920ce0c77b3f874cd569d3447ea707f75602a122f6c713e6e4b3b42ad7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireBIPVault.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireBIPVault.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "e8697a9aca64d94b782e90179a75e4636282ffd2a821dce9e1637ac6e1b7e5bc",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/common/NativeAssetLedgerV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "1472ddb78e352c8143466ddfb71a78a55de146a2411cbde91d3f06ba87e8261a",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "bip-native-asset-vaults",
      "name": "BIP and Native-Asset Vaults",
      "purpose": "Isolated vault accounting for BIP/native assets.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/economic-modules.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "415986112e5eba83814ae52a1b99a94c1f634affea5293f8b5cf244548fee8d8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireBIPVault.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireBIPVault.",
          "sha256": "e8697a9aca64d94b782e90179a75e4636282ffd2a821dce9e1637ac6e1b7e5bc",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for VaultfireBIPVault.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 source separates native-asset ledger and reward vault responsibilities.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "AgentInsurancePool",
        "VaultfireBondInsurancePool"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/DeterministicCoverageV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "58a232d00ef0f731b3f57378c3896507ed31ae00dcda0e15186871f0ad26847d",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/EconomicSuccessors.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "36c8f43f9ae37d33346a748153f60f344e4fa218d6733a74e08b442de03034b4",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: AgentInsurancePool.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/AgentInsurancePool.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "51e703693bc5b05c57ca63f40c23bdac71a12a970a8932f2d6cd32c95c75dea3",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireBondInsurancePool.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireBondInsurancePool.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "feb961430eacc4be88eb4b91e318e8fd07249070507289223e396d2f415d8852",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/DeterministicCoverageV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "58a232d00ef0f731b3f57378c3896507ed31ae00dcda0e15186871f0ad26847d",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "insurance-bond-insurance",
      "name": "Insurance and Bond Insurance",
      "purpose": "Reserve-backed deterministic coverage and historical bond insurance.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/economic-modules.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "415986112e5eba83814ae52a1b99a94c1f634affea5293f8b5cf244548fee8d8",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": "full-v3/solana/idl/vaultfire_v3_successor.json",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1ce771b588c39614423eba762870af70529d6292fd861360b083faf86eb84afc",
          "state": "available",
          "url": null
        },
        "implementation": "partial-source",
        "source": {
          "path": "full-v3/solana/programs/vaultfire_v3_successor/src/lib.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "98233b561f23a02128b1a7518d79c9ab1e8aa061d5f77eb8a1247237902c11a2",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/solana/tests/adversarial.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "b3c33afd31d8d81c386e0a98d51a19ec24b332b4a2ce38f78611cff94b465aa6",
          "state": "available",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/AgentInsurancePool.json",
          "reason": "Canonical frozen V2 ABI identity for AgentInsurancePool.",
          "sha256": "51e703693bc5b05c57ca63f40c23bdac71a12a970a8932f2d6cd32c95c75dea3",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "repos/vaultfire-keyprotocol/contracts/AgentInsurancePool.sol",
          "reason": "Pinned historical Solidity source for AgentInsurancePool.",
          "sha256": "060a44ed2a98fedaef047c16b6ca936645876ed1e35a629688e785c341a5d8c2",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 deterministic coverage is source-only and not represented as insurance deployment.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireNameService",
        "VNS"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/VNSV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "8db9d791598ec302245b240b98fdf3c499241c73a26da1a17b8162aec1f8c5ce",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/EconomicSuccessors.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "36c8f43f9ae37d33346a748153f60f344e4fa218d6733a74e08b442de03034b4",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireNameService.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireNameService.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "ff414eaa37121e500a5b55d419f2e2fac95165b9076521594c6f12a141d98d90",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/VNSV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "8db9d791598ec302245b240b98fdf3c499241c73a26da1a17b8162aec1f8c5ce",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "vns",
      "name": "VNS",
      "purpose": "Vaultfire naming and name resolution.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/chain-adapters.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "7532f13f483c0920521e6138b1ca1aa541c05814f68fd5690b1aa4c2b67017b0",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireNameService.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireNameService.",
          "sha256": "ff414eaa37121e500a5b55d419f2e2fac95165b9076521594c6f12a141d98d90",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for VaultfireNameService.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "A Full-V3 VNS source exists with no Solana equivalent asserted.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "PrivacyGuarantees",
        "AntiSurveillance"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: PrivacyGuarantees.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/PrivacyGuarantees.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "cac79abbf7e5794128e529ad1fdfc9eeb3fa2c1b974ac67ac9d7d89d546054cf",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: AntiSurveillance.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/AntiSurveillance.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "e2ed0abbb359000b7b0dd34fe058c6f9daa82a310057c381acc69a70eba2ee0f",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "privacy-anti-surveillance",
      "name": "Privacy and Anti-Surveillance",
      "purpose": "Privacy commitments, minimization, and anti-surveillance policy surfaces.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/PrivacyGuarantees.json",
          "reason": "Canonical frozen V2 ABI identity for PrivacyGuarantees.",
          "sha256": "cac79abbf7e5794128e529ad1fdfc9eeb3fa2c1b974ac67ac9d7d89d546054cf",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for PrivacyGuarantees.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Historical ABIs exist; no complete privacy-preserving V3 implementation or proof system is established.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "IRiscZeroVerifier",
        "IStarkVerifier",
        "ZK"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/PinnedTrustAdaptersV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "3d523bca076284ad61dfeaaac5d8fd8555db020fbf9afdb1f3c1a87354ab358f",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/PinnedTrustAdapters.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1e111b6689062580df4762208b377c1037eadc25bfda26fa1632d1196e95f64a",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/PinnedTrustAdaptersV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "3d523bca076284ad61dfeaaac5d8fd8555db020fbf9afdb1f3c1a87354ab358f",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "zk-verification",
      "name": "ZK Verification Interfaces",
      "purpose": "Verifier interfaces and proof receipt bindings, not proof-system soundness.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/mldsa-provider.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "ee246fc2dbb38dfb9516cc2da831ae36ea35f9e5004dfc7011a39019b8b698d2",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": true,
        "result": "Historical source found without canonical V2 ABI/deployment identity.",
        "searches": [
          {
            "command": "rg -n --hidden -g '!.git/**' -g '!node_modules/**' 'IRiscZeroVerifier' .",
            "query": "IRiscZeroVerifier",
            "result": "source-found",
            "scope": "working-tree"
          },
          {
            "command": "git log --all --oneline -S'IRiscZeroVerifier' -- .",
            "query": "IRiscZeroVerifier",
            "result": "history-reference-found",
            "scope": "git-history"
          },
          {
            "command": "rg -n 'IRiscZeroVerifier' legacy/v2/manifest.json legacy/v2/abis",
            "query": "IRiscZeroVerifier",
            "result": "not-found",
            "scope": "legacy-v2-abi-and-deployments"
          }
        ]
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Verifier interface source references exist, but no canonical V2 ABI/deployment and no completed real-proof V3 verifier path is established.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "FHE",
        "fully homomorphic encryption"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "fhe-verification",
      "name": "FHE Verification Interfaces",
      "purpose": "Historical fully-homomorphic-encryption interface claim.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": true,
        "result": "Historical public claim/source not found.",
        "searches": [
          {
            "command": "rg -n --hidden -g '!.git/**' -g '!node_modules/**' 'FHE' .",
            "query": "FHE",
            "result": "claim-only-or-not-found",
            "scope": "working-tree"
          },
          {
            "command": "git log --all --oneline -S'FHE' -- .",
            "query": "FHE",
            "result": "history-reference-found",
            "scope": "git-history"
          },
          {
            "command": "rg -n 'FHE' legacy/v2/manifest.json legacy/v2/abis",
            "query": "FHE",
            "result": "not-found",
            "scope": "legacy-v2-abi-and-deployments"
          }
        ]
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Repository and Git-history searches found claims but no canonical FHE implementation source, ABI, artifact, deployment, SDK, or route.",
        "status": "retired"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "DilithiumAttestor",
        "ML-DSA"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/MldsaSp1AuthorizationV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "40d679a49d7d723b183b104336c8964ba954904f7b5ea3f69e8ca1aed4fbe031",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/MldsaSp1Authorization.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "5daab9207d71095c302249ae05f0d772db7106d2cd1a4b9e3507b35ce3ee8286",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: DilithiumAttestor.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/DilithiumAttestor.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "763d5b8b774bfb7c8846a5b5f5170d98a2c051fde8a74d0f0eedaeb2e32e80b2",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/MldsaSp1AuthorizationV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "40d679a49d7d723b183b104336c8964ba954904f7b5ea3f69e8ca1aed4fbe031",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "mldsa",
      "name": "ML-DSA / Dilithium History and Replacement",
      "purpose": "Replace legacy Dilithium naming with standards-based ML-DSA and real-proof gates.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/mldsa-provider.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "ee246fc2dbb38dfb9516cc2da831ae36ea35f9e5004dfc7011a39019b8b698d2",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/DilithiumAttestor.json",
          "reason": "Canonical frozen V2 ABI identity for DilithiumAttestor.",
          "sha256": "763d5b8b774bfb7c8846a5b5f5170d98a2c051fde8a74d0f0eedaeb2e32e80b2",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for DilithiumAttestor.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Canonical envelope/provider source exists, but Base and Solana real-proof verification gates remain blocked.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "BeliefAttestationVerifier",
        "ProductionBeliefAttestationVerifier",
        "FlourishingMetricsOracle"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: BeliefAttestationVerifier.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/BeliefAttestationVerifier.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "550de62be38865ae9b7d4e29ddf401adf43a7466aad67ededd56963b5820d6bd",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: ProductionBeliefAttestationVerifier.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/ProductionBeliefAttestationVerifier.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "712f3fdb23c2818f07d420cf2164d2235e5ea25f53aaf4ea06a8f927dfd92f38",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: FlourishingMetricsOracle.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/FlourishingMetricsOracle.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "e746d733a4715ac2a418b1757cff5e460861badac5b1cbebda2ca349ca1f6048",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "belief-flourishing",
      "name": "Belief and Flourishing",
      "purpose": "Belief attestations and flourishing metric observations.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/BeliefAttestationVerifier.json",
          "reason": "Canonical frozen V2 ABI identity for BeliefAttestationVerifier.",
          "sha256": "550de62be38865ae9b7d4e29ddf401adf43a7466aad67ededd56963b5820d6bd",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for BeliefAttestationVerifier.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Historical ABIs exist; no claim of ZK or ML-DSA verification is permitted for legacy belief routes.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "MissionEnforcement",
        "AgentSafetyManager",
        "AgentSLAEnforcer"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/common/EmergencyControlsV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d15afb21a786841635d1afdedfc0799aab76b3302f4c833244b884cae3801369",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/AuthorizationAndReceipts.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "a1990e33fbdaaf6b63b7347e3362e1c9bda93ac34e7b9c2391a8962520c596f7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: MissionEnforcement.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/MissionEnforcement.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "06de290c5ef80127ddb5d8d4e63b02d9b41e74290a78120ee6cfb8e19f5aa01a",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: AgentSafetyManager.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/AgentSafetyManager.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "cfb413f87314785d5d760b4c4526849351933e1e73bc5b2eeb101916728c9819",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: AgentSLAEnforcer.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/AgentSLAEnforcer.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "b73d616531eedbcb550ffcd87dccf6384d1e561dac684c695a33132d64612363",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/common/EmergencyControlsV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "d15afb21a786841635d1afdedfc0799aab76b3302f4c833244b884cae3801369",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "mission-safety-sla",
      "name": "Mission, Safety, and SLA",
      "purpose": "Mission enforcement, safety controls, and service-level commitments.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/status-discovery.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "08063bcf7a300eee57944f2d4464242852a5424de35fe8552cfc3ff4ee69cc1b",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/MissionEnforcement.json",
          "reason": "Canonical frozen V2 ABI identity for MissionEnforcement.",
          "sha256": "06de290c5ef80127ddb5d8d4e63b02d9b41e74290a78120ee6cfb8e19f5aa01a",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for MissionEnforcement.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 safety controls are fail-closed; operational SLA and mission authorities remain external gates.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VKPSessionKeyManager"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/SessionCapabilitiesV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "7eea270253bb9fc05503a525784b6d420f579dbd1433a5e23624f6317d0d6209",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/AuthorizationAndReceipts.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "a1990e33fbdaaf6b63b7347e3362e1c9bda93ac34e7b9c2391a8962520c596f7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VKPSessionKeyManager.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VKPSessionKeyManager.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "a2b7d25ee041c0ce4677501c1fe6cdbf0826f851c9843b0fb6ad3a03df26eee2",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/SessionCapabilitiesV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "7eea270253bb9fc05503a525784b6d420f579dbd1433a5e23624f6317d0d6209",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "session-keys",
      "name": "Session Keys",
      "purpose": "Finite-lived session authorization.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/identity-mandates.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "2e8fbde1b13c53884078b8a6e3bf8a0a7e63d60439670b90bd9e153f85baf202",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VKPSessionKeyManager.json",
          "reason": "Canonical frozen V2 ABI identity for VKPSessionKeyManager.",
          "sha256": "a2b7d25ee041c0ce4677501c1fe6cdbf0826f851c9843b0fb6ad3a03df26eee2",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "repos/vaultfire-keyprotocol/contracts/SessionKeyManager.sol",
          "reason": "Pinned historical Solidity source for VKPSessionKeyManager.",
          "sha256": "c91eaf07e885aa1ad7020def568c5ff60694ae7ea93e6f2afcbe7902d29095c0",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Full-V3 session capabilities replace unrestricted session-key assumptions.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireCapabilityCredentials",
        "ScopedDelegation"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/SessionCapabilitiesV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "7eea270253bb9fc05503a525784b6d420f579dbd1433a5e23624f6317d0d6209",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/AuthorizationAndReceipts.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "a1990e33fbdaaf6b63b7347e3362e1c9bda93ac34e7b9c2391a8962520c596f7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireCapabilityCredentials.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireCapabilityCredentials.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "378b07756db17871110565f7d499921184685dbb16f3bcba611804fd8339f4e9",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: ScopedDelegation.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/ScopedDelegation.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "9aab630fac01bb83da983b3abc369b7869a7266ff798168179288e776ddad7ed",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/SessionCapabilitiesV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "7eea270253bb9fc05503a525784b6d420f579dbd1433a5e23624f6317d0d6209",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "capability-delegation",
      "name": "Capability Delegation",
      "purpose": "Capability credentials and bounded delegation.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/identity-mandates.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "2e8fbde1b13c53884078b8a6e3bf8a0a7e63d60439670b90bd9e153f85baf202",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireCapabilityCredentials.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireCapabilityCredentials.",
          "sha256": "378b07756db17871110565f7d499921184685dbb16f3bcba611804fd8339f4e9",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "repos/theloopbreaker-site/contracts/VaultfireCapabilityCredentials.sol",
          "reason": "Pinned historical Solidity source for VaultfireCapabilityCredentials.",
          "sha256": "45b6a4323c0c15edcc230b5d0acf439c7d5ea2543b29dad413e9bc404d258b87",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 uses finite mandate/session capability records; no deployment is authorized.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireTeleporterBridge",
        "VaultfireTrustAttestation"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/CrossChainReceiptRegistryV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "7a064932b29d503bdacb48e6017a97eb7a5b7970e875f7eebc2aac571d8e517e",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/AuthorizationAndReceipts.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "a1990e33fbdaaf6b63b7347e3362e1c9bda93ac34e7b9c2391a8962520c596f7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireTeleporterBridge.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireTeleporterBridge.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "d924dcba699282f33d7b1bd3b629911538a6b3b01e6ca6779a6856eb17dd8e78",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireTrustAttestation.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireTrustAttestation.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "a4c7d811079726b20d79bfd7c4cc585f83f1b8ab48502d0508b5acb6120e8164",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/CrossChainReceiptRegistryV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "7a064932b29d503bdacb48e6017a97eb7a5b7970e875f7eebc2aac571d8e517e",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "teleporter-crosschain-provenance",
      "name": "Teleporter and Cross-Chain Provenance",
      "purpose": "Cross-chain provenance receipts without implying a value bridge.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/receipts-recovery.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "3d6cfcacd99d8268a89650391eb89fa7c9e5a681ce78f211b78555c966180ac7",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": "full-v3/solana/idl/vaultfire_v3_successor.json",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1ce771b588c39614423eba762870af70529d6292fd861360b083faf86eb84afc",
          "state": "available",
          "url": null
        },
        "implementation": "partial-source",
        "source": {
          "path": "full-v3/solana/programs/vaultfire_v3_successor/src/lib.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "98233b561f23a02128b1a7518d79c9ab1e8aa061d5f77eb8a1247237902c11a2",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/solana/tests/adversarial.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "b3c33afd31d8d81c386e0a98d51a19ec24b332b4a2ce38f78611cff94b465aa6",
          "state": "available",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireTeleporterBridge.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireTeleporterBridge.",
          "sha256": "d924dcba699282f33d7b1bd3b629911538a6b3b01e6ca6779a6856eb17dd8e78",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for VaultfireTeleporterBridge.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Full-V3 records informational provenance only; no bridge/finality guarantee is claimed.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "XMTP"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "xmtp-adapters",
      "name": "XMTP Adapters",
      "purpose": "Historical messaging adapter claim for XMTP.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": true,
        "result": "Historical public claim/source not found.",
        "searches": [
          {
            "command": "rg -n --hidden -g '!.git/**' -g '!node_modules/**' 'XMTP' .",
            "query": "XMTP",
            "result": "claim-only-or-not-found",
            "scope": "working-tree"
          },
          {
            "command": "git log --all --oneline -S'XMTP' -- .",
            "query": "XMTP",
            "result": "history-reference-found",
            "scope": "git-history"
          },
          {
            "command": "rg -n 'XMTP' legacy/v2/manifest.json legacy/v2/abis",
            "query": "XMTP",
            "result": "not-found",
            "scope": "legacy-v2-abi-and-deployments"
          }
        ]
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Searches found documentation/history references but no canonical XMTP adapter implementation, ABI, artifact, deployment, SDK surface, or route.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "AgentKit",
        "Coinbase AgentKit"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "agentkit-coinbase-adapters",
      "name": "AgentKit / Coinbase Adapters",
      "purpose": "Historical Coinbase AgentKit integration claim.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": true,
        "result": "Historical public claim/source not found.",
        "searches": [
          {
            "command": "rg -n --hidden -g '!.git/**' -g '!node_modules/**' 'AgentKit' .",
            "query": "AgentKit",
            "result": "claim-only-or-not-found",
            "scope": "working-tree"
          },
          {
            "command": "git log --all --oneline -S'AgentKit' -- .",
            "query": "AgentKit",
            "result": "history-reference-found",
            "scope": "git-history"
          },
          {
            "command": "rg -n 'AgentKit' legacy/v2/manifest.json legacy/v2/abis",
            "query": "AgentKit",
            "result": "not-found",
            "scope": "legacy-v2-abi-and-deployments"
          }
        ]
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Searches found historical claims and Coinbase x402 metadata but no canonical AgentKit adapter implementation, ABI, artifact, or deployment.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireERC8004Adapter",
        "Chainlink",
        "RISC Zero",
        "SP1"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/PinnedTrustAdaptersV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "3d523bca076284ad61dfeaaac5d8fd8555db020fbf9afdb1f3c1a87354ab358f",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/PinnedTrustAdapters.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1e111b6689062580df4762208b377c1037eadc25bfda26fa1632d1196e95f64a",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireERC8004Adapter.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireERC8004Adapter.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "8209664ec20d2b5bdebc2bc1bf9f01a8f8a229d5872e1a16981894e9e50b543c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/PinnedTrustAdaptersV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "3d523bca076284ad61dfeaaac5d8fd8555db020fbf9afdb1f3c1a87354ab358f",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "external-adapters",
      "name": "Other External Adapters",
      "purpose": "Explicitly bounded adapters to external identity, oracle, and verifier systems.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/chain-adapters.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "7532f13f483c0920521e6138b1ca1aa541c05814f68fd5690b1aa4c2b67017b0",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireERC8004Adapter.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireERC8004Adapter.",
          "sha256": "8209664ec20d2b5bdebc2bc1bf9f01a8f8a229d5872e1a16981894e9e50b543c",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for VaultfireERC8004Adapter.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Adapter surfaces exist, but external service operation and verifier soundness are not inferred.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireForumRegistry"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "repos/theloopbreaker-site/contracts/VaultfireForumRegistry.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "53e22d29f8c82cf3196784c096e91c9602bfc5e99dc14bf17bdf3f0517355054",
          "state": "available",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireForumRegistry.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireForumRegistry.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "7a3bc8a4a40c386f34b32772a470f396d2a7671571c390987821157cdca89535",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "repos/theloopbreaker-site/contracts/VaultfireForumRegistry.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "53e22d29f8c82cf3196784c096e91c9602bfc5e99dc14bf17bdf3f0517355054",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "forum",
      "name": "Forum",
      "purpose": "On-chain forum registration and topic metadata.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireForumRegistry.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireForumRegistry.",
          "sha256": "7a3bc8a4a40c386f34b32772a470f396d2a7671571c390987821157cdca89535",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment address/runtime identity was established for this module by the canonical V2 manifest.",
          "state": "unavailable"
        },
        "source": {
          "path": "repos/theloopbreaker-site/contracts/VaultfireForumRegistry.sol",
          "reason": "Pinned historical Solidity source for VaultfireForumRegistry.",
          "sha256": "53e22d29f8c82cf3196784c096e91c9602bfc5e99dc14bf17bdf3f0517355054",
          "state": "available",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Historical source/ABI exists; no Full-V3 successor was selected.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "onboarding"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "onboarding",
      "name": "Onboarding",
      "purpose": "Individual onboarding workflow and compatibility surfaces.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": true,
        "result": "Historical public claim/source not found.",
        "searches": [
          {
            "command": "rg -n --hidden -g '!.git/**' -g '!node_modules/**' 'onboarding' .",
            "query": "onboarding",
            "result": "claim-only-or-not-found",
            "scope": "working-tree"
          },
          {
            "command": "git log --all --oneline -S'onboarding' -- .",
            "query": "onboarding",
            "result": "not-found-as-standalone-module",
            "scope": "git-history"
          },
          {
            "command": "rg -n 'onboarding' legacy/v2/manifest.json legacy/v2/abis",
            "query": "onboarding",
            "result": "not-found",
            "scope": "legacy-v2-abi-and-deployments"
          }
        ]
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Onboarding appears in public route/tooling surfaces but no canonical standalone module ABI/deployment was found.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "VaultfireBatchOnboarder"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Historical identity checked: VaultfireBatchOnboarder.",
          "kind": "abi-or-source",
          "resource": {
            "path": "legacy/v2/abis/VaultfireBatchOnboarder.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "44c453e5033ccc89a8a96b0ecb5398ad797722122cf67fe295a8230c82a7d638",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "batch-tooling",
      "name": "Batch Tooling",
      "purpose": "Batch onboarding and operational batch helpers.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": null,
          "reason": "No SDK example identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "source": {
          "path": null,
          "reason": "No SDK support identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "unavailable"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": "legacy/v2/abis/VaultfireBatchOnboarder.json",
          "reason": "Canonical frozen V2 ABI identity for VaultfireBatchOnboarder.",
          "sha256": "44c453e5033ccc89a8a96b0ecb5398ad797722122cf67fe295a8230c82a7d638",
          "state": "available",
          "url": null
        },
        "deployments": {
          "identities": [
            {
              "address": "0x82c6a0dd34f5cf57f8b98ee118e911b977618890",
              "chainId": "8453",
              "runtimeBytecodeSha256": null
            }
          ],
          "reason": "Frozen observed identities only; no current operational assertion.",
          "state": "observed"
        },
        "source": {
          "path": null,
          "reason": "No exact Solidity source identity is established by the frozen V2 ABI record for VaultfireBatchOnboarder.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "A verified V2 deployment/source identity exists; no V3 execution successor is authorized.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "No module-specific x402 route identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "unavailable"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "x402 discovery"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "x402-discovery",
      "name": "x402 Discovery",
      "purpose": "Versioned x402 capability and route discovery.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/offline-x402.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "ef1e529358dbe6fccff8fbbb41ce1ed19a434483932997ee476793a2759b053f",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 discovery is generated as review-only metadata with payments disabled.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "Generated review metadata only; public runtime/resource declaration is not asserted.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [
          "/api/v3/x402/discovery"
        ],
        "status": "review-only"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "x402 challenge"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "x402-challenges",
      "name": "x402 Challenges",
      "purpose": "Fail-closed payment challenge preparation.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/offline-x402.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "ef1e529358dbe6fccff8fbbb41ce1ed19a434483932997ee476793a2759b053f",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 challenge surfaces remain non-payment review interfaces.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "Generated review metadata only; public runtime/resource declaration is not asserted.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [
          "/api/v3/x402/challenges/:challengeId",
          "/api/v3/x402/challenge-status"
        ],
        "status": "review-only"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "x402 payment"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No Full-V3 Base implementation identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "x402-payments",
      "name": "x402 Payments",
      "purpose": "Payment policy and settlement boundary.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/offline-x402.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "ef1e529358dbe6fccff8fbbb41ce1ed19a434483932997ee476793a2759b053f",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "absent",
        "source": {
          "path": null,
          "reason": "No module-specific Solana implementation mapping is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "test": {
          "path": null,
          "reason": "No module-specific test identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "V3 payment policy is null and settlement is disabled; V2 payment observations are version-isolated.",
        "status": "deferred"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "Generated review metadata only; public runtime/resource declaration is not asserted.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [],
        "status": "review-only"
      }
    },
    {
      "advertised": false,
      "aliases": [
        "x402 receipt"
      ],
      "base": {
        "artifact": {
          "path": null,
          "reason": "No reproducible compiled artifact identified.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "implementation": "source-only",
        "source": {
          "path": "full-v3/base/src/PortableReceiptsV3.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "c2f7a56bb83f528f902885a1df088ee5759027b726a475cedbb4541be4c96703",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/base/test/AuthorizationAndReceipts.t.sol",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "a1990e33fbdaaf6b63b7347e3362e1c9bda93ac34e7b9c2391a8962520c596f7",
          "state": "available",
          "url": null
        }
      },
      "blockers": [
        "Independent audit is absent.",
        "Authorized deployment identity is absent.",
        "Public immutable release artifact is absent."
      ],
      "evidence": [
        {
          "claim": "Frozen V2 catalog was checked for this module.",
          "kind": "inventory",
          "resource": {
            "path": "legacy/v2/manifest.json",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "4b2a083e36e8f7c9659d30710dae3f5f80faf3130060ebdca8792c77a6c8ac7c",
            "state": "available",
            "url": null
          }
        },
        {
          "claim": "Referenced V3 or historical source exists at the recorded bytes.",
          "kind": "source",
          "resource": {
            "path": "full-v3/base/src/PortableReceiptsV3.sol",
            "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
            "sha256": "c2f7a56bb83f528f902885a1df088ee5759027b726a475cedbb4541be4c96703",
            "state": "available",
            "url": null
          }
        }
      ],
      "id": "x402-receipts",
      "name": "x402 Receipts",
      "purpose": "Durable payment/lifecycle receipt lookup and recovery.",
      "releaseArtifact": {
        "path": null,
        "reason": "No frozen, public, immutable module-specific release artifact is established.",
        "sha256": null,
        "state": "unavailable",
        "url": null
      },
      "sandbox": {
        "evidence": {
          "path": null,
          "reason": "No module-specific sandbox demonstration with release-bound evidence is established.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "status": "blocked"
      },
      "sdk": {
        "example": {
          "path": "full-v3/sdk/examples/receipts-recovery.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "3d6cfcacd99d8268a89650391eb89fa7c9e5a681ce78f211b78555c966180ac7",
          "state": "available",
          "url": null
        },
        "source": {
          "path": "full-v3/sdk/src/modules/index.ts",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "d3024af947efac9bccb632873f4e5c38c77de5b6e717b17575cc9817b6325fcf",
          "state": "available",
          "url": null
        },
        "status": "review-only"
      },
      "searchDisposition": {
        "performed": false,
        "result": "Not required; canonical inventory evidence exists.",
        "searches": []
      },
      "solana": {
        "artifact": {
          "path": "full-v3/solana/idl/vaultfire_v3_successor.json",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "1ce771b588c39614423eba762870af70529d6292fd861360b083faf86eb84afc",
          "state": "available",
          "url": null
        },
        "implementation": "partial-source",
        "source": {
          "path": "full-v3/solana/programs/vaultfire_v3_successor/src/lib.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "98233b561f23a02128b1a7518d79c9ab1e8aa061d5f77eb8a1247237902c11a2",
          "state": "available",
          "url": null
        },
        "test": {
          "path": "full-v3/solana/tests/adversarial.rs",
          "reason": "Repository file observed; availability does not imply deployment, audit, or runtime support.",
          "sha256": "b3c33afd31d8d81c386e0a98d51a19ec24b332b4a2ce38f78611cff94b465aa6",
          "state": "available",
          "url": null
        }
      },
      "spec": {
        "path": "full-v3/specs/HISTORICAL_MODULE_CATALOG_SPEC.md",
        "reason": "Normative catalog semantics and anti-overclaim rules for every historical module record.",
        "sha256": "216da3bebba4c86ea11cca430eef6c65a32f23e26f51a6ecc59cca3f143520e6",
        "state": "available",
        "url": null
      },
      "status": {
        "deployment": "not-deployed-not-authorized",
        "release": "blocked",
        "security": "not-independently-audited",
        "test": "blocked"
      },
      "v2": {
        "abi": {
          "path": null,
          "reason": "No canonical V2 ABI was found.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "deployments": {
          "identities": [],
          "reason": "No deployment identity was found.",
          "state": "unavailable"
        },
        "source": {
          "path": null,
          "reason": "Historical public claim/source not found for a canonical V2 module identity.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        }
      },
      "v3Disposition": {
        "reason": "Receipt schemas/SDK exist, but durable production storage and payment settlement remain blocked.",
        "status": "redesigned"
      },
      "x402": {
        "evidence": {
          "path": null,
          "reason": "Generated review metadata only; public runtime/resource declaration is not asserted.",
          "sha256": null,
          "state": "unavailable",
          "url": null
        },
        "routes": [
          "/api/v3/x402/receipts/:requestId"
        ],
        "status": "review-only"
      }
    }
  ],
  "operations": [
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-bonds-agent-bond-status"
      ],
      "description": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: look up any agent's bond posture (active accountability + partnership bonds, total staked, partner addresses). Reads ERC-8004 + AIAccountabilityBondsV2 + AIPartnershipBondsV2 live on-chain.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-bonds-agent-bond-status",
      "method": "GET",
      "pathTemplate": "/api/x402/bonds/agent-bond-status",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-bonds-agent-bond-status.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/bonds/agent-bond-status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-bonds-agent-bond-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: look up any agent's bond posture (active accountability + partnership bonds, total staked, partner addresses). Reads ERC-8004 + AIAccountabilityBondsV2 + AIPartnershipBondsV2 live on-chain."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-bonds-overview"
      ],
      "description": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: protocol-wide bond pulse (active bonds, per-chain breakdown, locked value, both Flourishing Metrics dimension sets). Live snapshot from on-chain queries across AIAccountabilityBondsV2, AIPartnershipBondsV2, and FlourishingMetricsOracle.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-bonds-overview",
      "method": "GET",
      "pathTemplate": "/api/x402/bonds/overview",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-bonds-overview.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/bonds/overview",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-bonds-overview",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: protocol-wide bond pulse (active bonds, per-chain breakdown, locked value, both Flourishing Metrics dimension sets). Live snapshot from on-chain queries across AIAccountabilityBondsV2, AIPartnershipBondsV2, and FlourishingMetricsOracle."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-oracle-agent-stake-usd"
      ],
      "description": "USD-denominated agent stake — composes Vaultfire bond data (ETH stake) × Chainlink ETH/USD price feed. Returns stake in USD with full audit trail (bond count, ETH staked, Chainlink price, feed address). Uniquely enabled by the Chainlink integration: Vaultfire owns the agent-truth side, Chainlink owns the market-data side.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-oracle-agent-stake-usd",
      "method": "GET",
      "pathTemplate": "/api/x402/oracle/agent-stake-usd",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-oracle-agent-stake-usd.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/oracle/agent-stake-usd",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-oracle-agent-stake-usd",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "USD-denominated agent stake — composes Vaultfire bond data (ETH stake) × Chainlink ETH/USD price feed. Returns stake in USD with full audit trail (bond count, ETH staked, Chainlink price, feed address). Uniquely enabled by the Chainlink integration: Vaultfire owns the agent-truth side, Chainlink owns the market-data side."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-oracle-chainlink-status"
      ],
      "description": "Free discovery beacon for the Vaultfire Chainlink oracle namespace — no payment required. Lists every supported (chain, pair) feed with live freshness, attribution to Chainlink, and links to the priced endpoints.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-oracle-chainlink-status",
      "method": "GET",
      "pathTemplate": "/api/x402/oracle/chainlink-status",
      "paymentPolicy": "free",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-oracle-chainlink-status.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/oracle/chainlink-status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-get-api-x402-oracle-chainlink-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Free discovery beacon for the Vaultfire Chainlink oracle namespace — no payment required. Lists every supported (chain, pair) feed with live freshness, attribution to Chainlink, and links to the priced endpoints."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-oracle-price-feed"
      ],
      "description": "Read any supported Chainlink Data Feed (ETH/USD, BTC/USD, LINK/USD, USDC/USD, AVAX/USD, MATIC/USD) on Base, Avalanche, Arbitrum, or Polygon. Returns answer, decimals, roundId, updatedAt, and freshness status. Data source: Chainlink decentralized oracle network — Vaultfire reads the on-chain AggregatorV3 proxy and exposes it via x402.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-oracle-price-feed",
      "method": "GET",
      "pathTemplate": "/api/x402/oracle/price-feed",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-oracle-price-feed.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/oracle/price-feed",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-oracle-price-feed",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Read any supported Chainlink Data Feed (ETH/USD, BTC/USD, LINK/USD, USDC/USD, AVAX/USD, MATIC/USD) on Base, Avalanche, Arbitrum, or Polygon. Returns answer, decimals, roundId, updatedAt, and freshness status. Data source: Chainlink decentralized oracle network — Vaultfire reads the on-chain AggregatorV3 proxy and exposes it via x402."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-agent-status"
      ],
      "description": "Look up any AI agent's on-chain trust profile — ERC-8004 registration, bond count, trust score (0–95), VNS name, and explorer link. Queries real smart contracts across 4 chains.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-agent-status",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/agent-status",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-agent-status.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/agent-status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-agent-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Look up any AI agent's on-chain trust profile — ERC-8004 registration, bond count, trust score (0–95), VNS name, and explorer link. Queries real smart contracts across 4 chains."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-agentproof-evidence"
      ],
      "description": "Vaultfire × AgentProof bridge (draft RFC). Fetch a public AgentProof report (results.json), SHA-256-verify against an agent-supplied digest, return a normalized evidence envelope with overall score, six-category breakdown, command-check status, and browser-crawl summary. Display-layer only; never modifies on-chain values, never re-scores. AgentProof: github.com/dicnunz/agentproof.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-agentproof-evidence",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/agentproof-evidence",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-agentproof-evidence.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/agentproof-evidence",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-agentproof-evidence",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire × AgentProof bridge (draft RFC). Fetch a public AgentProof report (results.json), SHA-256-verify against an agent-supplied digest, return a normalized evidence envelope with overall score, six-category breakdown, command-check status, and browser-crawl summary. Display-layer only; never modifies on-chain values, never re-scores. AgentProof: github.com/dicnunz/agentproof."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-analytics"
      ],
      "description": "Composite trust profile — Street Cred badge, identity, bonds, reputation in one call. Aggregates 4+ on-chain reads.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-analytics",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/analytics",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-analytics.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/analytics",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-analytics",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Composite trust profile — Street Cred badge, identity, bonds, reputation in one call. Aggregates 4+ on-chain reads."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-bonds"
      ],
      "description": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: list all active partnership bonds for any agent (bond count, partner addresses, locked stake). Reads AIPartnershipBondsV2 live on-chain.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-bonds",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/bonds",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-bonds.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/bonds",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-bonds",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics show real impact: partnership metrics (human growth, autonomy, dignity, tasks mastered, creativity) and society metrics (income distribution, poverty, health, mental health, education access, purpose/agency). Morals over metrics, on-chain. 77 x402 endpoints on Base. — This endpoint: list all active partnership bonds for any agent (bond count, partner addresses, locked stake). Reads AIPartnershipBondsV2 live on-chain."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-bridge"
      ],
      "description": "Cross-chain bridge state — message counts, paused status, relayer count, synced totals. Live read from VaultfireTeleporterBridge.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-bridge",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/bridge",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-bridge.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/bridge",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-bridge",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Cross-chain bridge state — message counts, paused status, relayer count, synced totals. Live read from VaultfireTeleporterBridge."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-contracts"
      ],
      "description": "Full contract registry — 134 verified smart contracts across 4 mainnet chains with addresses.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-contracts",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/contracts",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-contracts.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/contracts",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-contracts",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Full contract registry — 134 verified smart contracts across 4 mainnet chains with addresses."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-credentials"
      ],
      "description": "Capability credentials — total credentials, active credentials, task proofs. Live read from VaultfireCapabilityCredentials.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-credentials",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/credentials",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-credentials.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/credentials",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-credentials",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Capability credentials — total credentials, active credentials, task proofs. Live read from VaultfireCapabilityCredentials."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-disputes"
      ],
      "description": "Dispute resolution stats per chain — filed, resolved, total stake at risk. Live read from VaultfireDisputeResolution.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-disputes",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/disputes",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-disputes.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/disputes",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-disputes",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Dispute resolution stats per chain — filed, resolved, total stake at risk. Live read from VaultfireDisputeResolution."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-flourishing-metrics"
      ],
      "description": "Read the latest FlourishingMetricsOracle round for a metric key — value + roundId. The oracle aggregates ecosystem health signals.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-flourishing-metrics",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/flourishing-metrics",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-flourishing-metrics.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/flourishing-metrics",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-flourishing-metrics",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Read the latest FlourishingMetricsOracle round for a metric key — value + roundId. The oracle aggregates ecosystem health signals."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-governance-proposals"
      ],
      "description": "Read a MultisigGovernance transaction by id — target, value, calldata, executed flag, confirmation count, expiry.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-governance-proposals",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/governance-proposals",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-governance-proposals.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/governance-proposals",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-governance-proposals",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Read a MultisigGovernance transaction by id — target, value, calldata, executed flag, confirmation count, expiry."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-health"
      ],
      "description": "Service health check + discovery beacon — free, no payment required. Lists all 75 priced endpoints with metadata for crawlers.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-health",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/health",
      "paymentPolicy": "free",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-health.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/health",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-get-api-x402-trust-health",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Service health check + discovery beacon — free, no payment required. Lists all 75 priced endpoints with metadata for crawlers."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-history"
      ],
      "description": "Trust history timeline for an agent — registration, bonds, vouches and slashes assembled from on-chain state.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-history",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/history",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-history.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/history",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-history",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Trust history timeline for an agent — registration, bonds, vouches and slashes assembled from on-chain state."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-insurance"
      ],
      "description": "Insurance pool stats per chain — balance, contributors, claims paid out. Live read from VaultfireBondInsurancePool.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-insurance",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/insurance",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-insurance.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/insurance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-insurance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Insurance pool stats per chain — balance, contributors, claims paid out. Live read from VaultfireBondInsurancePool."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-leaderboard"
      ],
      "description": "Top AI agents ranked by trust score — pulls live ERC-8004 registry data, scores by bonds + reputation, returns ranked leaderboard with VNS names and chains.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-leaderboard",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/leaderboard",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-leaderboard.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/leaderboard",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-leaderboard",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Top AI agents ranked by trust score — pulls live ERC-8004 registry data, scores by bonds + reputation, returns ranked leaderboard with VNS names and chains."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-multi-chain-status"
      ],
      "description": "Aggregate an agent's on-chain status across all 4 chains in a single call — per-chain registration, bonds, trust score plus omnichain summary.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-multi-chain-status",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/multi-chain-status",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-multi-chain-status.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/multi-chain-status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-multi-chain-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Aggregate an agent's on-chain status across all 4 chains in a single call — per-chain registration, bonds, trust score plus omnichain summary."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-performance"
      ],
      "description": "Trust oracle performance — attestations, quality score, task completions for an agent. Live read from VaultfireTrustOracle.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-performance",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/performance",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-performance.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/performance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-performance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Trust oracle performance — attestations, quality score, task completions for an agent. Live read from VaultfireTrustOracle."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-protocol-stats"
      ],
      "description": "Vaultfire — the trust layer for the agentic web. 77 x402 endpoints on Base for AI agent identity (ERC-8004), accountability bonds, on-chain reputation, and Chainlink oracle data. — This endpoint: protocol-wide stats (total registered agents, active bonds, per-chain breakdown, total locked value).",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-protocol-stats",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/protocol-stats",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-protocol-stats.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/protocol-stats",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-protocol-stats",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — the trust layer for the agentic web. 77 x402 endpoints on Base for AI agent identity (ERC-8004), accountability bonds, on-chain reputation, and Chainlink oracle data. — This endpoint: protocol-wide stats (total registered agents, active bonds, per-chain breakdown, total locked value)."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-relationships"
      ],
      "description": "Vouching graph slice for an agent — counts of vouches given/received, total stake, slash record, bond partnerships, plus an integrity composite.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-relationships",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/relationships",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-relationships.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/relationships",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-relationships",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vouching graph slice for an agent — counts of vouches given/received, total stake, slash record, bond partnerships, plus an integrity composite."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-reputation-decay"
      ],
      "description": "Read an agent's current decayed reputation score — decayed score, base score, days since last activity, and total activities. Helpful for showing freshness-adjusted reputation.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-reputation-decay",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/reputation-decay",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-reputation-decay.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/reputation-decay",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-reputation-decay",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Read an agent's current decayed reputation score — decayed score, base score, days since last activity, and total activities. Helpful for showing freshness-adjusted reputation."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-risk-score"
      ],
      "description": "Composite on-chain risk score (0–100) for an AI agent — combines identity, reputation, bonds, vouching, slashes, and account age into a single risk signal with band (minimal/low/medium/high).",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-risk-score",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/risk-score",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-risk-score.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/risk-score",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-risk-score",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Composite on-chain risk score (0–100) for an AI agent — combines identity, reputation, bonds, vouching, slashes, and account age into a single risk signal with band (minimal/low/medium/high)."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-safety-status"
      ],
      "description": "Read an agent's current safety status from the AgentSafetyManager contract — status enum (Active/Paused/Suspended/Banned), last change timestamp, who changed it, and reason.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-safety-status",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/safety-status",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-safety-status.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/safety-status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-safety-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Read an agent's current safety status from the AgentSafetyManager contract — status enum (Active/Paused/Suspended/Banned), last change timestamp, who changed it, and reason."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-scoped-delegations"
      ],
      "description": "List the capability scope ids granted to an address from the ScopedDelegation registry.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-scoped-delegations",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/scoped-delegations",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-scoped-delegations.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/scoped-delegations",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-scoped-delegations",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "List the capability scope ids granted to an address from the ScopedDelegation registry."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-sla-status"
      ],
      "description": "Read an agent's SLA performance — active SLAs, total stake, total penalized, and violation count from AgentSLAEnforcer.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-sla-status",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/sla-status",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-sla-status.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/sla-status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-sla-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Read an agent's SLA performance — active SLAs, total stake, total penalized, and violation count from AgentSLAEnforcer."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-street-cred"
      ],
      "description": "Vaultfire — the trust layer for the agentic web. 77 x402 endpoints on Base for AI agent identity (ERC-8004), accountability bonds, on-chain reputation, and Chainlink oracle data. — This endpoint: look up any address's Vaultfire Street Cred profile (soulbound badge tier None/Bronze/Silver/Gold/Platinum, score 0-95, identity registration, active bonds, staked ETH). Reads VaultfireStreetCred.computeScore() on Base.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-street-cred",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/street-cred",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-street-cred.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/street-cred",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-street-cred",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — the trust layer for the agentic web. 77 x402 endpoints on Base for AI agent identity (ERC-8004), accountability bonds, on-chain reputation, and Chainlink oracle data. — This endpoint: look up any address's Vaultfire Street Cred profile (soulbound badge tier None/Bronze/Silver/Gold/Platinum, score 0-95, identity registration, active bonds, staked ETH). Reads VaultfireStreetCred.computeScore() on Base."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-vns-resolve"
      ],
      "description": "Resolve VNS names to addresses (forward) or addresses to VNS names (reverse) across Base, Arbitrum, and Polygon. Falls back to ERC-8004 identity registry for full coverage.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-vns-resolve",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/vns-resolve",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-vns-resolve.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/vns-resolve",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-vns-resolve",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Resolve VNS names to addresses (forward) or addresses to VNS names (reverse) across Base, Arbitrum, and Polygon. Falls back to ERC-8004 identity registry for full coverage."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-get-api-x402-trust-vouching"
      ],
      "description": "Reputation staking profile — vouches received and given, total stake, slashes. Live read from VaultfireReputationStaking.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-get-api-x402-trust-vouching",
      "method": "GET",
      "pathTemplate": "/api/x402/trust/vouching",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [],
        "schema": "v2/get-api-x402-trust-vouching.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/vouching",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": true,
      "sourceId": "v2-get-api-x402-trust-vouching",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Reputation staking profile — vouches received and given, total stake, slashes. Live read from VaultfireReputationStaking."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-accept-bid"
      ],
      "description": "Accept a bid on a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — assigns the task to the chosen bidding agent and locks the work phase.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/accept-bid/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-accept-bid",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/accept-bid",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-accept-bid.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/accept-bid",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-accept-bid",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Accept a bid on a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — assigns the task to the chosen bidding agent and locks the work phase."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-approve-work"
      ],
      "description": "Approve completed work on a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — releases USDC from escrow to the assigned agent (minus protocol fee).",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/approve-work/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-approve-work",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/approve-work",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-approve-work.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/approve-work",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-approve-work",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Approve completed work on a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — releases USDC from escrow to the assigned agent (minus protocol fee)."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-attest-belief"
      ],
      "description": "Legacy V2 transaction-preparation route; no ML-DSA, Dilithium, zero-knowledge, or post-quantum verification is established.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/attest-belief/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-attest-belief",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/attest-belief",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-attest-belief.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/attest-belief",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-attest-belief",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Legacy V2 transaction-preparation route; no ML-DSA, Dilithium, zero-knowledge, or post-quantum verification is established."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-batch-onboard"
      ],
      "description": "One-shot atomic agent onboarding on Base — registers ERC-8004 identity, sets URI, posts initial bond. Pay $0.50 USDC. Base only.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-batch-onboard",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/batch-onboard",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-batch-onboard.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/batch-onboard",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-batch-onboard",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "One-shot atomic agent onboarding on Base — registers ERC-8004 identity, sets URI, posts initial bond. Pay $0.50 USDC. Base only."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-bridge-trust-message"
      ],
      "description": "Send a cross-chain reputation message via Avalanche Teleporter / cross-chain bridge — propagate score from one chain to another. Pay $0.40 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-bridge-trust-message",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/bridge-trust-message",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-bridge-trust-message.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/bridge-trust-message",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-bridge-trust-message",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Send a cross-chain reputation message via Avalanche Teleporter / cross-chain bridge — propagate score from one chain to another. Pay $0.40 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-cancel-task"
      ],
      "description": "Cancel a Vaultfire task escrow and trigger USDC refund per contract rules. Pay $0.15 USDC, sign in your wallet — only the task requester can cancel.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/cancel-task/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-cancel-task",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/cancel-task",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-cancel-task.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/cancel-task",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-cancel-task",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Cancel a Vaultfire task escrow and trigger USDC refund per contract rules. Pay $0.15 USDC, sign in your wallet — only the task requester can cancel."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-challenge-bond-metrics"
      ],
      "description": "Challenge submitted metrics on an AI Accountability Bond. Pay $0.25 USDC, post a counter-stake, file the challenge on-chain.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/challenge-bond-metrics/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-challenge-bond-metrics",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/challenge-bond-metrics",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-challenge-bond-metrics.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/challenge-bond-metrics",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-challenge-bond-metrics",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Challenge submitted metrics on an AI Accountability Bond. Pay $0.25 USDC, post a counter-stake, file the challenge on-chain."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-commit-vns-name"
      ],
      "description": "Step 1/2 of Vaultfire Name Service registration: commit-reveal. Submit the keccak256 commitment hash. Wait commitment window, then call register-vns-name. Pay $0.10 USDC. Available on Base, Arbitrum, Polygon.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-commit-vns-name",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/commit-vns-name",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-commit-vns-name.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/commit-vns-name",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-commit-vns-name",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Step 1/2 of Vaultfire Name Service registration: commit-reveal. Submit the keccak256 commitment hash. Wait commitment window, then call register-vns-name. Pay $0.10 USDC. Available on Base, Arbitrum, Polygon."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-contribute-insurance"
      ],
      "description": "Contribute ETH to the Vaultfire Bond Insurance Pool — community-owned reserve that backstops slashed bonds. Pay $0.20 USDC; ETH amount sent via wallet (payable contribute()).",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-contribute-insurance",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/contribute-insurance",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-contribute-insurance.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/contribute-insurance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-contribute-insurance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Contribute ETH to the Vaultfire Bond Insurance Pool — community-owned reserve that backstops slashed bonds. Pay $0.20 USDC; ETH amount sent via wallet (payable contribute())."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-create-accountability-bond"
      ],
      "description": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics (income distribution, poverty rate, health outcomes, mental health, education access, purpose/agency) show real societal impact. Morals over metrics, on-chain. — This endpoint: create an AI accountability bond on AIAccountabilityBondsV2. Pay $0.50 USDC, receive an unsigned payable tx, sign in your wallet — no private keys handled server-side.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/create-accountability-bond/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-create-accountability-bond",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/create-accountability-bond",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-create-accountability-bond.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/create-accountability-bond",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-create-accountability-bond",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics (income distribution, poverty rate, health outcomes, mental health, education access, purpose/agency) show real societal impact. Morals over metrics, on-chain. — This endpoint: create an AI accountability bond on AIAccountabilityBondsV2. Pay $0.50 USDC, receive an unsigned payable tx, sign in your wallet — no private keys handled server-side."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-create-partnership-bond"
      ],
      "description": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics (human growth, autonomy, dignity, tasks mastered, creativity) show real human↔agent impact. Morals over metrics, on-chain. — This endpoint: create an AI partnership bond on AIPartnershipBondsV2. Pay $0.50 USDC, receive an unsigned payable tx with your stake, sign locally in your wallet. No private keys handled server-side.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/create-partnership-bond/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-create-partnership-bond",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/create-partnership-bond",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-create-partnership-bond.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/create-partnership-bond",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-create-partnership-bond",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when on-chain Flourishing Metrics (human growth, autonomy, dignity, tasks mastered, creativity) show real human↔agent impact. Morals over metrics, on-chain. — This endpoint: create an AI partnership bond on AIPartnershipBondsV2. Pay $0.50 USDC, receive an unsigned payable tx with your stake, sign locally in your wallet. No private keys handled server-side."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-create-session-key"
      ],
      "description": "Create an ERC-7702 session key with capability scoping — temporary delegated authority bounded by spend limit, expiry, and target whitelist. Pay $0.25 USDC, sign in wallet to authorize.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-create-session-key",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/create-session-key",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-create-session-key.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/create-session-key",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-create-session-key",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Create an ERC-7702 session key with capability scoping — temporary delegated authority bounded by spend limit, expiry, and target whitelist. Pay $0.25 USDC, sign in wallet to authorize."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-create-task"
      ],
      "description": "Post a task with USDC escrow on VaultfireTaskEscrow. Pay $0.30 USDC, sign in your wallet — funds locked trustlessly until an agent completes the task. 1% protocol fee, refunded if cancelled. Multi-chain (Base, Avalanche, Arbitrum, Polygon).",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/create-task/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-create-task",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/create-task",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-create-task.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/create-task",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-create-task",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Post a task with USDC escrow on VaultfireTaskEscrow. Pay $0.30 USDC, sign in your wallet — funds locked trustlessly until an agent completes the task. 1% protocol fee, refunded if cancelled. Multi-chain (Base, Avalanche, Arbitrum, Polygon)."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-create-vkp-vault"
      ],
      "description": "Create a Verifiable Knowledge Proof (VKP) vault — an ERC-4626-style data vault with privacy budget, retention window, and access tier. Pay $0.40 USDC, sign in wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-create-vkp-vault",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/create-vkp-vault",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-create-vkp-vault.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/create-vkp-vault",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-create-vkp-vault",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Create a Verifiable Knowledge Proof (VKP) vault — an ERC-4626-style data vault with privacy budget, retention window, and access tier. Pay $0.40 USDC, sign in wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-deactivate-agent"
      ],
      "description": "Deactivate your ERC-8004 agent registration on Vaultfire. Pay $0.10 USDC, sign in your wallet — only the agent itself can deactivate. Reversible by re-registering.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/deactivate-agent/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-deactivate-agent",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/deactivate-agent",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-deactivate-agent.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/deactivate-agent",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-deactivate-agent",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Deactivate your ERC-8004 agent registration on Vaultfire. Pay $0.10 USDC, sign in your wallet — only the agent itself can deactivate. Reversible by re-registering."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-dispute-task"
      ],
      "description": "Open a dispute on a Vaultfire task escrow. Pay $0.25 USDC, sign in your wallet — freezes the escrow pending governance resolution. Either party may dispute.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/dispute-task/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-dispute-task",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/dispute-task",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-dispute-task.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/dispute-task",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-dispute-task",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Open a dispute on a Vaultfire task escrow. Pay $0.25 USDC, sign in your wallet — freezes the escrow pending governance resolution. Either party may dispute."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-file-attestation"
      ],
      "description": "File a belief attestation on the BeliefAttestationVerifier contract (zk proof + public inputs). Pay $0.25 USDC, receive a fully-encoded unsigned transaction, sign in your wallet. No private keys handled server-side.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-file-attestation",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/file-attestation",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-file-attestation.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/file-attestation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-file-attestation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "File a belief attestation on the BeliefAttestationVerifier contract (zk proof + public inputs). Pay $0.25 USDC, receive a fully-encoded unsigned transaction, sign in your wallet. No private keys handled server-side."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-file-insurance-claim"
      ],
      "description": "File a claim against the Bond Insurance Pool — supply the affected bond id, off-chain evidence URL, and evidence hash. Pay $0.30 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-file-insurance-claim",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/file-insurance-claim",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-file-insurance-claim.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/file-insurance-claim",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-file-insurance-claim",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "File a claim against the Bond Insurance Pool — supply the affected bond id, off-chain evidence URL, and evidence hash. Pay $0.30 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-file-vouch"
      ],
      "description": "File a vouch (with stake) for another AI agent via VaultfireReputationStaking. Pay $0.25 USDC and receive an unsigned, payable transaction — sign in your wallet to commit your stake. No private keys handled server-side.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-file-vouch",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/file-vouch",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-file-vouch.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/file-vouch",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-file-vouch",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "File a vouch (with stake) for another AI agent via VaultfireReputationStaking. Pay $0.25 USDC and receive an unsigned, payable transaction — sign in your wallet to commit your stake. No private keys handled server-side."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-grant-consent"
      ],
      "description": "Grant consent for a specific purpose hash on the ERC-8004 Identity Registry. Pay $0.05 USDC, sign in your wallet — privacy-preserving consent flagging.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/grant-consent/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-grant-consent",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/grant-consent",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-grant-consent.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/grant-consent",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-grant-consent",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Grant consent for a specific purpose hash on the ERC-8004 Identity Registry. Pay $0.05 USDC, sign in your wallet — privacy-preserving consent flagging."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-issue-credential"
      ],
      "description": "Issue an ERC-8004 capability credential to an agent — typed claim signed by your address that the holder can present elsewhere in the network. Pay $0.30 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-issue-credential",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/issue-credential",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-issue-credential.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/issue-credential",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-issue-credential",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Issue an ERC-8004 capability credential to an agent — typed claim signed by your address that the holder can present elsewhere in the network. Pay $0.30 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-mint-street-cred"
      ],
      "description": "Mint your Vaultfire Street Cred badge — an ERC-5192 soulbound token reflecting your on-chain reputation tier. Pay $0.20 USDC, sign in your wallet on Base. One badge per address, non-transferable.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-mint-street-cred",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/mint-street-cred",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-mint-street-cred.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/mint-street-cred",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-mint-street-cred",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Mint your Vaultfire Street Cred badge — an ERC-5192 soulbound token reflecting your on-chain reputation tier. Pay $0.20 USDC, sign in your wallet on Base. One badge per address, non-transferable."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-register-agent"
      ],
      "description": "Register an AI agent on the ERC-8004 Identity Registry. Pay $0.50 USDC and receive a fully-encoded unsigned transaction (calldata + gas estimate + chain ID) — sign locally in your wallet to become the registered agent. No private keys ever touch our servers.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-register-agent",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/register-agent",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-register-agent.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/register-agent",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-register-agent",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Register an AI agent on the ERC-8004 Identity Registry. Pay $0.50 USDC and receive a fully-encoded unsigned transaction (calldata + gas estimate + chain ID) — sign locally in your wallet to become the registered agent. No private keys ever touch our servers."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-register-for-partnership"
      ],
      "description": "Register an agent for Vaultfire partnership flow via the ERC-8004 Adapter. Pay $0.30 USDC, sign in your wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/register-for-partnership/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-register-for-partnership",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/register-for-partnership",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-register-for-partnership.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/register-for-partnership",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-register-for-partnership",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Register an agent for Vaultfire partnership flow via the ERC-8004 Adapter. Pay $0.30 USDC, sign in your wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-register-vns-name"
      ],
      "description": "Step 2/2 VNS registration. Reveal the agent name + secret matching your earlier commit. Mints VNS subdomain on Base, Arbitrum, or Polygon. Pay $0.30 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-register-vns-name",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/register-vns-name",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-register-vns-name.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/register-vns-name",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-register-vns-name",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Step 2/2 VNS registration. Reveal the agent name + secret matching your earlier commit. Mints VNS subdomain on Base, Arbitrum, or Polygon. Pay $0.30 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-report-mission-violation"
      ],
      "description": "Report a mission violation against a module on Vaultfire MissionEnforcement. Pay $0.15 USDC, sign in your wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/report-mission-violation/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-report-mission-violation",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/report-mission-violation",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-report-mission-violation.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/report-mission-violation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-report-mission-violation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Report a mission violation against a module on Vaultfire MissionEnforcement. Pay $0.15 USDC, sign in your wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-report-surveillance-violation"
      ],
      "description": "Report a surveillance violation against a module on Vaultfire AntiSurveillance. Pay $0.15 USDC, sign in your wallet — privacy-preserving (only the evidence hash goes on-chain).",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/report-surveillance-violation/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-report-surveillance-violation",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/report-surveillance-violation",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-report-surveillance-violation.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/report-surveillance-violation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-report-surveillance-violation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Report a surveillance violation against a module on Vaultfire AntiSurveillance. Pay $0.15 USDC, sign in your wallet — privacy-preserving (only the evidence hash goes on-chain)."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-request-bond-distribution"
      ],
      "description": "Request distribution payout for a Vaultfire bond (partnership or accountability). Pay $0.10 USDC, sign in your wallet to trigger the distribution flow on-chain.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/request-bond-distribution/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-request-bond-distribution",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/request-bond-distribution",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-request-bond-distribution.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/request-bond-distribution",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-request-bond-distribution",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Request distribution payout for a Vaultfire bond (partnership or accountability). Pay $0.10 USDC, sign in your wallet to trigger the distribution flow on-chain."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-request-validation"
      ],
      "description": "Open a validation request on the ERC-8004 Validation Registry — request that N independent validators verify a claim about an agent. Pay $0.25 USDC, post a bounty, sign in your wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/request-validation/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-request-validation",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/request-validation",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-request-validation.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/request-validation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-request-validation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Open a validation request on the ERC-8004 Validation Registry — request that N independent validators verify a claim about an agent. Pay $0.25 USDC, post a bounty, sign in your wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-revoke-consent"
      ],
      "description": "Revoke previously-granted consent for a specific purpose hash on the ERC-8004 Identity Registry. Pay $0.05 USDC, sign in your wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/revoke-consent/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-revoke-consent",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/revoke-consent",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-revoke-consent.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/revoke-consent",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-revoke-consent",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Revoke previously-granted consent for a specific purpose hash on the ERC-8004 Identity Registry. Pay $0.05 USDC, sign in your wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-revoke-credential"
      ],
      "description": "Revoke a previously-issued capability credential by id. Effective immediately on-chain. Pay $0.15 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-revoke-credential",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/revoke-credential",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-revoke-credential.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/revoke-credential",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-revoke-credential",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Revoke a previously-issued capability credential by id. Effective immediately on-chain. Pay $0.15 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-revoke-session-key"
      ],
      "description": "Revoke a previously created ERC-7702 session key by id. Immediate, on-chain. Pay $0.10 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-revoke-session-key",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/revoke-session-key",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-revoke-session-key.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/revoke-session-key",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-revoke-session-key",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Revoke a previously created ERC-7702 session key by id. Immediate, on-chain. Pay $0.10 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-slash-reputation"
      ],
      "description": "Slash a misbehaving agent's reputation stake (governance-gated on-chain check). Pay $0.30 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-slash-reputation",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/slash-reputation",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-slash-reputation.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/slash-reputation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-slash-reputation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Slash a misbehaving agent's reputation stake (governance-gated on-chain check). Pay $0.30 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-stake-as-validator"
      ],
      "description": "Stake ETH on the ERC-8004 Validation Registry to become a validator eligible to submit validation results and earn bounties. Pay $0.20 USDC, sign in your wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/stake-as-validator/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-stake-as-validator",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/stake-as-validator",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-stake-as-validator.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/stake-as-validator",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-stake-as-validator",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Stake ETH on the ERC-8004 Validation Registry to become a validator eligible to submit validation results and earn bounties. Pay $0.20 USDC, sign in your wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-submit-accountability-metrics"
      ],
      "description": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when these on-chain Flourishing Metrics show real impact. Morals over metrics, on-chain. — This endpoint: submit Flourishing Metrics scores (income distribution, poverty rate, health outcomes, mental health, education access, purpose/agency) to AIAccountabilityBondsV2. Pay $0.25 USDC, sign in your wallet — six dimensions of human flourishing recorded on-chain.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/submit-accountability-metrics/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-submit-accountability-metrics",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/submit-accountability-metrics",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-submit-accountability-metrics.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/submit-accountability-metrics",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-submit-accountability-metrics",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Vaultfire — accountability bonds for AI agents that reward flourishing, not fear. Agents stake ETH and earn distribution when these on-chain Flourishing Metrics show real impact. Morals over metrics, on-chain. — This endpoint: submit Flourishing Metrics scores (income distribution, poverty rate, health outcomes, mental health, education access, purpose/agency) to AIAccountabilityBondsV2. Pay $0.25 USDC, sign in your wallet — six dimensions of human flourishing recorded on-chain."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-submit-feedback"
      ],
      "description": "Submit hashed feedback for an agent on the ERC-8004 Reputation Registry. Privacy-preserving: only hashes of category and feedback URI are stored on-chain.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/submit-feedback/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-submit-feedback",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/submit-feedback",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-submit-feedback.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/submit-feedback",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-submit-feedback",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Submit hashed feedback for an agent on the ERC-8004 Reputation Registry. Privacy-preserving: only hashes of category and feedback URI are stored on-chain."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-submit-partnership-metrics"
      ],
      "description": "Submit hashed partnership metrics (humanGrowth, autonomy, dignity, tasksMastered, creativity + progressNotesHash) to AIPartnershipBondsV2. Privacy-preserving — only hashes go on-chain.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/submit-partnership-metrics/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-submit-partnership-metrics",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/submit-partnership-metrics",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-submit-partnership-metrics.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/submit-partnership-metrics",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-submit-partnership-metrics",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Submit hashed partnership metrics (humanGrowth, autonomy, dignity, tasksMastered, creativity + progressNotesHash) to AIPartnershipBondsV2. Privacy-preserving — only hashes go on-chain."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-submit-trust-attestation"
      ],
      "description": "Submit a signed trust attestation to the Vaultfire Trust Oracle — typed score about a target agent with confidence + evidence hash. Pay $0.30 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-submit-trust-attestation",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/submit-trust-attestation",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-submit-trust-attestation.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/submit-trust-attestation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-submit-trust-attestation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Submit a signed trust attestation to the Vaultfire Trust Oracle — typed score about a target agent with confidence + evidence hash. Pay $0.30 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-submit-validation"
      ],
      "description": "Submit a validation result on the ERC-8004 Validation Registry as a staked validator. Pay $0.25 USDC, sign in your wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/submit-validation/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-submit-validation",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/submit-validation",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-submit-validation.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/submit-validation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-submit-validation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Submit a validation result on the ERC-8004 Validation Registry as a staked validator. Pay $0.25 USDC, sign in your wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-submit-work"
      ],
      "description": "Submit completed work for a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — submits a deliverable URI/hash on-chain so the requester can approve or dispute.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/submit-work/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-submit-work",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/submit-work",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-submit-work.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/submit-work",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-submit-work",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Submit completed work for a Vaultfire task escrow. Pay $0.20 USDC, sign in your wallet — submits a deliverable URI/hash on-chain so the requester can approve or dispute."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-transfer-vns-name"
      ],
      "description": "Transfer ownership of a VNS name to another address. Pay $0.20 USDC. Available on Base, Arbitrum, Polygon.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-transfer-vns-name",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/transfer-vns-name",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-transfer-vns-name.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/transfer-vns-name",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-transfer-vns-name",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Transfer ownership of a VNS name to another address. Pay $0.20 USDC. Available on Base, Arbitrum, Polygon."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-trigger-reputation-decay"
      ],
      "description": "Trigger time-based reputation decay for an agent — anyone can call; on-chain math applies decay since last activity. Pay $0.10 USDC.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-trigger-reputation-decay",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/trigger-reputation-decay",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-trigger-reputation-decay.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/trigger-reputation-decay",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-trigger-reputation-decay",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Trigger time-based reputation decay for an agent — anyone can call; on-chain math applies decay since last activity. Pay $0.10 USDC."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-unvouch"
      ],
      "description": "Revoke a previously filed vouch on VaultfireReputationStaking and unlock your stake. Pay $0.10 USDC, sign in your wallet.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/x402/actions/unvouch/route.ts",
      "id": "route.v2.v2-post-api-x402-actions-unvouch",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/unvouch",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-unvouch.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/unvouch",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-unvouch",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Revoke a previously filed vouch on VaultfireReputationStaking and unlock your stake. Pay $0.10 USDC, sign in your wallet."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-actions-update-agent-uri"
      ],
      "description": "Update the agentURI of a registered ERC-8004 agent. Pay $0.10 USDC and receive an unsigned transaction — sign locally in your wallet (which must be the registered agent). No private keys touch our servers.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-actions-update-agent-uri",
      "method": "POST",
      "pathTemplate": "/api/x402/actions/update-agent-uri",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-actions-update-agent-uri.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/actions/update-agent-uri",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-actions-update-agent-uri",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Update the agentURI of a registered ERC-8004 agent. Pay $0.10 USDC and receive an unsigned transaction — sign locally in your wallet (which must be the registered agent). No private keys touch our servers."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-contract-call"
      ],
      "description": "Generic on-chain read against any of the 134 Vaultfire Protocol contracts across Base, Avalanche, Arbitrum, and Polygon. Pass { chain, contract (name or address), function (name or canonical signature), args[] } and receive the decoded return value plus block provenance. Read-only (view/pure) calls only.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-contract-call",
      "method": "POST",
      "pathTemplate": "/api/x402/contract-call",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-contract-call.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/contract-call",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-contract-call",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Generic on-chain read against any of the 134 Vaultfire Protocol contracts across Base, Avalanche, Arbitrum, and Polygon. Pass { chain, contract (name or address), function (name or canonical signature), args[] } and receive the decoded return value plus block provenance. Read-only (view/pure) calls only."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "partner-public",
      "authentication": "x402-payment",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-post-api-x402-trust-email-verify"
      ],
      "description": "x402-Email Spec v0.1 verifier (paid bazaar lane, $0.01 USDC). Validates a sender address, accountability bond reference, and x402 payment header from an inbound email and returns a routing recommendation (inbox | review | spam) plus combined trust score, bond status, and signed _x402 receipt. A free public verifier (no bazaar receipt) is also available at POST /api/x402/email/verify for recipient mail filters.",
      "discovery": {
        "agent": "review",
        "bazaar": true,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": true
      },
      "evidence": [],
      "gaps": [
        "Response schema/fixture remains unresolved in imported registry.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "unresolved",
      "id": "route.v2.v2-post-api-x402-trust-email-verify",
      "method": "POST",
      "pathTemplate": "/api/x402/trust/email-verify",
      "paymentPolicy": "v2-base-usdc-exact",
      "receiptContract": "v2-settled",
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "v2/post-api-x402-trust-email-verify.req#",
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/x402/trust/email-verify",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "indexer",
        "finality": "safe",
        "idempotency": "key-optional",
        "observability": "redacted-required",
        "privacy": "priced-read",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": true,
      "sourceId": "v2-post-api-x402-trust-email-verify",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "x402-Email Spec v0.1 verifier (paid bazaar lane, $0.01 USDC). Validates a sender address, accountability bond reference, and x402 payment header from an inbound email and returns a routing recommendation (inbox | review | spam) plus combined trust score, bond status, and signed _x402 receipt. A free public verifier (no bazaar receipt) is also available at POST /api/x402/email/verify for recipient mail filters."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "deployed-v2-observed",
        "implementation": "legacy-v2",
        "operations": "live-v2-observed",
        "support": "supported"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-delete-api-agent-webhooks"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/webhooks/route.ts",
      "id": "route.v2.v2-source-delete-api-agent-webhooks",
      "method": "DELETE",
      "pathTemplate": "/api/agent/webhooks",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/webhooks",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-delete-api-agent-webhooks",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-abis"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/abis/route.ts",
      "id": "route.v2.v2-source-get-api-abis",
      "method": "GET",
      "pathTemplate": "/api/abis",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/abis",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-abis",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-abis-name"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/abis/[name]/route.ts",
      "id": "route.v2.v2-source-get-api-abis-name",
      "method": "GET",
      "pathTemplate": "/api/abis/[name]",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/abis/[name]",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-abis-name",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-admin-recent-payers"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/admin/recent-payers/route.ts",
      "id": "route.v2.v2-source-get-api-admin-recent-payers",
      "method": "GET",
      "pathTemplate": "/api/admin/recent-payers",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/admin/recent-payers",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-admin-recent-payers",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-adapter"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/adapter/route.ts",
      "id": "route.v2.v2-source-get-api-agent-adapter",
      "method": "GET",
      "pathTemplate": "/api/agent/adapter",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/adapter",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-adapter",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-agent-insurance"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/agent-insurance/route.ts",
      "id": "route.v2.v2-source-get-api-agent-agent-insurance",
      "method": "GET",
      "pathTemplate": "/api/agent/agent-insurance",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/agent-insurance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-agent-insurance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-agent-safety"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/agent-safety/route.ts",
      "id": "route.v2.v2-source-get-api-agent-agent-safety",
      "method": "GET",
      "pathTemplate": "/api/agent/agent-safety",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/agent-safety",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-agent-safety",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-analytics"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/analytics/route.ts",
      "id": "route.v2.v2-source-get-api-agent-analytics",
      "method": "GET",
      "pathTemplate": "/api/agent/analytics",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/analytics",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-analytics",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-attestation"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/attestation/route.ts",
      "id": "route.v2.v2-source-get-api-agent-attestation",
      "method": "GET",
      "pathTemplate": "/api/agent/attestation",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/attestation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-attestation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-bridge"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/bridge/route.ts",
      "id": "route.v2.v2-source-get-api-agent-bridge",
      "method": "GET",
      "pathTemplate": "/api/agent/bridge",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/bridge",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-bridge",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-compliance"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/compliance/route.ts",
      "id": "route.v2.v2-source-get-api-agent-compliance",
      "method": "GET",
      "pathTemplate": "/api/agent/compliance",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/compliance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-compliance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-credentials"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/credentials/route.ts",
      "id": "route.v2.v2-source-get-api-agent-credentials",
      "method": "GET",
      "pathTemplate": "/api/agent/credentials",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/credentials",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-credentials",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-discover"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/discover/route.ts",
      "id": "route.v2.v2-source-get-api-agent-discover",
      "method": "GET",
      "pathTemplate": "/api/agent/discover",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/discover",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-discover",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-disputes"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/disputes/route.ts",
      "id": "route.v2.v2-source-get-api-agent-disputes",
      "method": "GET",
      "pathTemplate": "/api/agent/disputes",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/disputes",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-disputes",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-flourishing"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/flourishing/route.ts",
      "id": "route.v2.v2-source-get-api-agent-flourishing",
      "method": "GET",
      "pathTemplate": "/api/agent/flourishing",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/flourishing",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-flourishing",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-governance"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/governance/route.ts",
      "id": "route.v2.v2-source-get-api-agent-governance",
      "method": "GET",
      "pathTemplate": "/api/agent/governance",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/governance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-governance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-insurance"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/insurance/route.ts",
      "id": "route.v2.v2-source-get-api-agent-insurance",
      "method": "GET",
      "pathTemplate": "/api/agent/insurance",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/insurance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-insurance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-keys"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/keys/route.ts",
      "id": "route.v2.v2-source-get-api-agent-keys",
      "method": "GET",
      "pathTemplate": "/api/agent/keys",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/keys",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-keys",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-mission"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/mission/route.ts",
      "id": "route.v2.v2-source-get-api-agent-mission",
      "method": "GET",
      "pathTemplate": "/api/agent/mission",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/mission",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-mission",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-partnerships"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/partnerships/route.ts",
      "id": "route.v2.v2-source-get-api-agent-partnerships",
      "method": "GET",
      "pathTemplate": "/api/agent/partnerships",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/partnerships",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-partnerships",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-performance"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/performance/route.ts",
      "id": "route.v2.v2-source-get-api-agent-performance",
      "method": "GET",
      "pathTemplate": "/api/agent/performance",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/performance",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-performance",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-premium"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/premium/route.ts",
      "id": "route.v2.v2-source-get-api-agent-premium",
      "method": "GET",
      "pathTemplate": "/api/agent/premium",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/premium",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-premium",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-privacy"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/privacy/route.ts",
      "id": "route.v2.v2-source-get-api-agent-privacy",
      "method": "GET",
      "pathTemplate": "/api/agent/privacy",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/privacy",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-privacy",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-reputation-decay"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/reputation-decay/route.ts",
      "id": "route.v2.v2-source-get-api-agent-reputation-decay",
      "method": "GET",
      "pathTemplate": "/api/agent/reputation-decay",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/reputation-decay",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-reputation-decay",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-routing"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/routing/route.ts",
      "id": "route.v2.v2-source-get-api-agent-routing",
      "method": "GET",
      "pathTemplate": "/api/agent/routing",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/routing",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-routing",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-scoped-delegation"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/scoped-delegation/route.ts",
      "id": "route.v2.v2-source-get-api-agent-scoped-delegation",
      "method": "GET",
      "pathTemplate": "/api/agent/scoped-delegation",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/scoped-delegation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-scoped-delegation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-sla-enforcer"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/sla-enforcer/route.ts",
      "id": "route.v2.v2-source-get-api-agent-sla-enforcer",
      "method": "GET",
      "pathTemplate": "/api/agent/sla-enforcer",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/sla-enforcer",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-sla-enforcer",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-status"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/status/route.ts",
      "id": "route.v2.v2-source-get-api-agent-status",
      "method": "GET",
      "pathTemplate": "/api/agent/status",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-tasks"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/tasks/route.ts",
      "id": "route.v2.v2-source-get-api-agent-tasks",
      "method": "GET",
      "pathTemplate": "/api/agent/tasks",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/tasks",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-tasks",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-trust"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/trust/route.ts",
      "id": "route.v2.v2-source-get-api-agent-trust",
      "method": "GET",
      "pathTemplate": "/api/agent/trust",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/trust",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-trust",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-validation"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/validation/route.ts",
      "id": "route.v2.v2-source-get-api-agent-validation",
      "method": "GET",
      "pathTemplate": "/api/agent/validation",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/validation",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-validation",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-vns"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/vns/route.ts",
      "id": "route.v2.v2-source-get-api-agent-vns",
      "method": "GET",
      "pathTemplate": "/api/agent/vns",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/vns",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-vns",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-vouching"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/vouching/route.ts",
      "id": "route.v2.v2-source-get-api-agent-vouching",
      "method": "GET",
      "pathTemplate": "/api/agent/vouching",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/vouching",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-vouching",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-agent-webhooks"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/webhooks/route.ts",
      "id": "route.v2.v2-source-get-api-agent-webhooks",
      "method": "GET",
      "pathTemplate": "/api/agent/webhooks",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/webhooks",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-agent-webhooks",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-contracts"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/contracts/route.ts",
      "id": "route.v2.v2-source-get-api-contracts",
      "method": "GET",
      "pathTemplate": "/api/contracts",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/contracts",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-contracts",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-cron-heartbeat"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/cron/heartbeat/route.ts",
      "id": "route.v2.v2-source-get-api-cron-heartbeat",
      "method": "GET",
      "pathTemplate": "/api/cron/heartbeat",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/cron/heartbeat",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-cron-heartbeat",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-gifs"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/gifs/route.ts",
      "id": "route.v2.v2-source-get-api-gifs",
      "method": "GET",
      "pathTemplate": "/api/gifs",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/gifs",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-gifs",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-health"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/health/route.ts",
      "id": "route.v2.v2-source-get-api-health",
      "method": "GET",
      "pathTemplate": "/api/health",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/health",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-health",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-hub-activity"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/hub/activity/route.ts",
      "id": "route.v2.v2-source-get-api-hub-activity",
      "method": "GET",
      "pathTemplate": "/api/hub/activity",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/hub/activity",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-hub-activity",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-hub-stats"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/hub/stats/route.ts",
      "id": "route.v2.v2-source-get-api-hub-stats",
      "method": "GET",
      "pathTemplate": "/api/hub/stats",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/hub/stats",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-hub-stats",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-live"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/live/route.ts",
      "id": "route.v2.v2-source-get-api-live",
      "method": "GET",
      "pathTemplate": "/api/live",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/live",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-live",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-openapi-json"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/openapi.json/route.ts",
      "id": "route.v2.v2-source-get-api-openapi-json",
      "method": "GET",
      "pathTemplate": "/api/openapi.json",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/openapi.json",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-openapi-json",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-protocol-bond-counts"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/protocol/bond-counts/route.ts",
      "id": "route.v2.v2-source-get-api-protocol-bond-counts",
      "method": "GET",
      "pathTemplate": "/api/protocol/bond-counts",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/protocol/bond-counts",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-protocol-bond-counts",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-protocol-distributions"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/protocol/distributions/route.ts",
      "id": "route.v2.v2-source-get-api-protocol-distributions",
      "method": "GET",
      "pathTemplate": "/api/protocol/distributions",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/protocol/distributions",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-protocol-distributions",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-protocol-recent"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/protocol/recent/route.ts",
      "id": "route.v2.v2-source-get-api-protocol-recent",
      "method": "GET",
      "pathTemplate": "/api/protocol/recent",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/protocol/recent",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-protocol-recent",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-well-known-agent-card-json"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/.well-known/agent-card.json/route.ts",
      "id": "route.v2.v2-source-get-api-well-known-agent-card-json",
      "method": "GET",
      "pathTemplate": "/api/.well-known/agent-card.json",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/.well-known/agent-card.json",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-well-known-agent-card-json",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-get-api-well-known-x402-email-json"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/.well-known/x402-email.json/route.ts",
      "id": "route.v2.v2-source-get-api-well-known-x402-email-json",
      "method": "GET",
      "pathTemplate": "/api/.well-known/x402-email.json",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/.well-known/x402-email.json",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-get-api-well-known-x402-email-json",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-bond"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/bond/route.ts",
      "id": "route.v2.v2-source-post-api-agent-bond",
      "method": "POST",
      "pathTemplate": "/api/agent/bond",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/bond",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-bond",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-keys"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/keys/route.ts",
      "id": "route.v2.v2-source-post-api-agent-keys",
      "method": "POST",
      "pathTemplate": "/api/agent/keys",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/keys",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-keys",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-premium"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/premium/route.ts",
      "id": "route.v2.v2-source-post-api-agent-premium",
      "method": "POST",
      "pathTemplate": "/api/agent/premium",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/premium",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-premium",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-register"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/register/route.ts",
      "id": "route.v2.v2-source-post-api-agent-register",
      "method": "POST",
      "pathTemplate": "/api/agent/register",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/register",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-register",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-route"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/route/route.ts",
      "id": "route.v2.v2-source-post-api-agent-route",
      "method": "POST",
      "pathTemplate": "/api/agent/route",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/route",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-route",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-status-batch"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/status/batch/route.ts",
      "id": "route.v2.v2-source-post-api-agent-status-batch",
      "method": "POST",
      "pathTemplate": "/api/agent/status/batch",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/status/batch",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-status-batch",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-tasks"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/tasks/route.ts",
      "id": "route.v2.v2-source-post-api-agent-tasks",
      "method": "POST",
      "pathTemplate": "/api/agent/tasks",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/tasks",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-tasks",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "unresolved",
      "authentication": "unresolved",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v2.v2-source-post-api-agent-webhooks"
      ],
      "description": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": false,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "Payment, request, response, finality, privacy, audience, authentication, and operational semantics remain unresolved.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/agent/webhooks/route.ts",
      "id": "route.v2.v2-source-post-api-agent-webhooks",
      "method": "POST",
      "pathTemplate": "/api/agent/webhooks",
      "paymentPolicy": "unresolved",
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": null,
        "unknownFields": "unresolved"
      },
      "responses": {},
      "runtimeTemplate": "/api/agent/webhooks",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "unresolved",
        "finality": "unresolved",
        "idempotency": "unresolved",
        "observability": "redacted-required",
        "privacy": "unresolved",
        "retry": "unresolved",
        "sideEffects": "possible"
      },
      "settlementEnabled": false,
      "sourceId": "v2-source-post-api-agent-webhooks",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Method exported by the pinned V2 route handler; request, response, payment, and operational metadata remain unresolved."
      },
      "status": {
        "audit": "historical-scope-only",
        "completion": "blocked",
        "deployment": "not-applicable",
        "implementation": "partial-source",
        "operations": "unverified",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "cross-route replay",
          "request/response contract drift",
          "authorization or audience bypass",
          "dependency ambiguity",
          "privacy leakage"
        ]
      },
      "trustAssumptions": [
        "V2 source-method and x402 registry evidence accurately identifies this operation; live behavior was not re-observed here."
      ],
      "v2Fallback": "not-applicable",
      "version": "v2"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.bond"
      ],
      "description": "Fail-closed V3 bond lookup by unsigned identifier.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/bonds/[bondId]/route.ts",
      "id": "route.v3.bond",
      "method": "GET",
      "pathTemplate": "/api/v3/bonds/:bondId",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/bonds/:bondId",
      "sdkMappings": [
        "bonds"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "bond",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed V3 bond lookup by unsigned identifier."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.bond-party"
      ],
      "description": "Fail-closed bond lookup by the required party query parameter.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/bonds/route.ts",
      "id": "route.v3.bond-party",
      "method": "GET",
      "pathTemplate": "/api/v3/bonds",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/bonds",
      "sdkMappings": [
        "bonds"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "bond-party",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed bond lookup by the required party query parameter."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.contract"
      ],
      "description": "Static V3 contract metadata by canonical name.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/contracts/[name]/route.ts",
      "id": "route.v3.contract",
      "method": "GET",
      "pathTemplate": "/api/v3/contracts/:name",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/contract-result.v1.schema.json",
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "404": "https://theloopbreaker.com/schemas/v3-x402/contract-result.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/contracts/:name",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "contract",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Static V3 contract metadata by canonical name."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.contracts"
      ],
      "description": "Static V3 contract catalog with null addresses until independently verified.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/contracts/route.ts",
      "id": "route.v3.contracts",
      "method": "GET",
      "pathTemplate": "/api/v3/contracts",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/contract-catalog.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/contracts",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "contracts",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Static V3 contract catalog with null addresses until independently verified."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.dispute"
      ],
      "description": "Fail-closed objective dispute lookup.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/disputes/[disputeId]/route.ts",
      "id": "route.v3.dispute",
      "method": "GET",
      "pathTemplate": "/api/v3/disputes/:disputeId",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/disputes/:disputeId",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "dispute",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed objective dispute lookup."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.evidence"
      ],
      "description": "Deferred evidence lookup with no deployment claim.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/evidence/[evidenceHash]/route.ts",
      "id": "route.v3.evidence",
      "method": "GET",
      "pathTemplate": "/api/v3/evidence/:evidenceHash",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/evidence/:evidenceHash",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "evidence",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Deferred evidence lookup with no deployment claim."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.governance-proposal"
      ],
      "description": "Fail-closed governance proposal status lookup.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/governance/proposals/[proposalId]/route.ts",
      "id": "route.v3.governance-proposal",
      "method": "GET",
      "pathTemplate": "/api/v3/governance/proposals/:proposalId",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/governance/proposals/:proposalId",
      "sdkMappings": [
        "governance"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "governance-proposal",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed governance proposal status lookup."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.mandate"
      ],
      "description": "Canonical plural V3 mandate lookup.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/mandates/[mandateHash]/route.ts",
      "id": "route.v3.mandate",
      "method": "GET",
      "pathTemplate": "/api/v3/mandates/:mandateHash",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/mandates/:mandateHash",
      "sdkMappings": [
        "mandates"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "mandate",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Canonical plural V3 mandate lookup."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.mandate-compat"
      ],
      "description": "Singular V3 compatibility wrapper over the plural route; no V2 fallback.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/mandate/[mandateHash]/route.ts",
      "id": "route.v3.mandate-compat",
      "method": "GET",
      "pathTemplate": "/api/v3/mandate/:mandateHash",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/mandate/:mandateHash",
      "sdkMappings": [
        "mandates"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "mandate-compat",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Singular V3 compatibility wrapper over the plural route; no V2 fallback."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.migration"
      ],
      "description": "Static migration capability and safety dispositions.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/migration/dispositions/route.ts",
      "id": "route.v3.migration",
      "method": "GET",
      "pathTemplate": "/api/v3/migration/dispositions",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/migration-dispositions.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/migration/dispositions",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "migration",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Static migration capability and safety dispositions."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.pull-credit"
      ],
      "description": "Fail-closed pull credit query by contract, asset, and holder.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/pull-credits/route.ts",
      "id": "route.v3.pull-credit",
      "method": "GET",
      "pathTemplate": "/api/v3/pull-credits",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/pull-credits",
      "sdkMappings": [
        "pullCredits"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "pull-credit",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed pull credit query by contract, asset, and holder."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.retired-partnership-write"
      ],
      "description": "Non-executing retired partnership-bond write tombstone.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/x402/actions/create-partnership-bond/route.ts",
      "id": "route.v3.retired-partnership-write",
      "method": "POST",
      "pathTemplate": "/api/v3/x402/actions/create-partnership-bond",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [
          "application/json"
        ],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "503": "https://theloopbreaker.com/schemas/v3-x402/retirement.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/x402/actions/create-partnership-bond",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "restricted",
        "retry": "unresolved",
        "sideEffects": "non-executing"
      },
      "settlementEnabled": false,
      "sourceId": "retired-partnership-write",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Non-executing retired partnership-bond write tombstone."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.solana-health"
      ],
      "description": "Source-only Solana health without RPC or executable claims.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/solana/health/route.ts",
      "id": "route.v3.solana-health",
      "method": "GET",
      "pathTemplate": "/api/v3/solana/health",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/solana-health.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/solana/health",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "solana-health",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Source-only Solana health without RPC or executable claims."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.solvency"
      ],
      "description": "Unconfigured solvency readiness response.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/protocol/solvency/route.ts",
      "id": "route.v3.solvency",
      "method": "GET",
      "pathTemplate": "/api/v3/protocol/solvency",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "503": "https://theloopbreaker.com/schemas/v3-x402/solvency.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/protocol/solvency",
      "sdkMappings": [
        "solvency"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "solvency",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Unconfigured solvency readiness response."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.status"
      ],
      "description": "Static unconfigured protocol readiness response.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/protocol/status/route.ts",
      "id": "route.v3.status",
      "method": "GET",
      "pathTemplate": "/api/v3/protocol/status",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/status.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/protocol/status",
      "sdkMappings": [],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Static unconfigured protocol readiness response."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.task"
      ],
      "description": "Deferred task escrow read model.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/tasks/[taskId]/route.ts",
      "id": "route.v3.task",
      "method": "GET",
      "pathTemplate": "/api/v3/tasks/:taskId",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/tasks/:taskId",
      "sdkMappings": [
        "taskEscrow"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "task",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Deferred task escrow read model."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "retired"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.x402-challenge"
      ],
      "description": "Fail-closed V3 challenge lookup.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/x402/challenges/[challengeId]/route.ts",
      "id": "route.v3.x402-challenge",
      "method": "GET",
      "pathTemplate": "/api/v3/x402/challenges/:challengeId",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/read-result.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/x402/challenges/:challengeId",
      "sdkMappings": [
        "x402.challenge"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "x402-challenge",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed V3 challenge lookup."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.x402-challenge-status"
      ],
      "description": "Static unavailable V3 payment-challenge capability status.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/x402/challenge-status/route.ts",
      "id": "route.v3.x402-challenge-status",
      "method": "GET",
      "pathTemplate": "/api/v3/x402/challenge-status",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/challenge-status.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/x402/challenge-status",
      "sdkMappings": [
        "x402.status",
        "x402.challenge"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "x402-challenge-status",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Static unavailable V3 payment-challenge capability status."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.x402-discovery"
      ],
      "description": "Fail-closed V3 x402 discovery with no payment candidates.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/x402/discovery/route.ts",
      "id": "route.v3.x402-discovery",
      "method": "GET",
      "pathTemplate": "/api/v3/x402/discovery",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/discovery.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/x402/discovery",
      "sdkMappings": [
        "x402.discovery"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "x402-discovery",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed V3 x402 discovery with no payment candidates."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "metadata-only",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    },
    {
      "audience": "source-review",
      "authentication": "none",
      "authorization": "route-policy",
      "coverageIds": [
        "route.v3.x402-receipt"
      ],
      "description": "Fail-closed durable receipt evidence lookup.",
      "discovery": {
        "agent": "review",
        "bazaar": false,
        "publicOpenApi": true,
        "wholeProtocol": true,
        "x402": false
      },
      "evidence": [],
      "gaps": [
        "No authorized deployment/read adapter/payment rail; static 200 responses are metadata only.",
        "Blocked: prior evidence paths lacked a local independently signed digest/issuer/scope/source-tree binding for this exact candidate."
      ],
      "handler": "repos/theloopbreaker-site/app/api/v3/x402/receipts/[requestId]/route.ts",
      "id": "route.v3.x402-receipt",
      "method": "GET",
      "pathTemplate": "/api/v3/x402/receipts/:requestId",
      "paymentPolicy": null,
      "receiptContract": null,
      "request": {
        "contentTypes": [],
        "schema": "empty#",
        "unknownFields": "reject"
      },
      "responses": {
        "200": "https://theloopbreaker.com/schemas/v3-x402/receipt-status.v1.schema.json",
        "400": "https://theloopbreaker.com/schemas/v3-x402/input-error.v1.schema.json",
        "404": "https://theloopbreaker.com/schemas/v3-x402/receipt-error.v1.schema.json",
        "503": "https://theloopbreaker.com/schemas/v3-x402/receipt-error.v1.schema.json|https://theloopbreaker.com/schemas/v3-x402/release-gate.v1.schema.json"
      },
      "runtimeTemplate": "/api/v3/x402/receipts/:requestId",
      "sdkMappings": [
        "x402.receipt"
      ],
      "semantics": {
        "cache": "unresolved",
        "cors": "unresolved",
        "dataSource": "computed",
        "finality": "soft",
        "idempotency": "none",
        "observability": "redacted-required",
        "privacy": "public",
        "retry": "unresolved",
        "sideEffects": "none"
      },
      "settlementEnabled": false,
      "sourceId": "x402-receipt",
      "spec": {
        "normativeRequirements": [
          "Method and normalized path are unique; undeclared methods and duplicate material handlers are forbidden.",
          "All unresolved fields block completion and generated public compatibility claims."
        ],
        "summary": "Fail-closed durable receipt evidence lookup."
      },
      "status": {
        "audit": "source-review-not-independent",
        "completion": "blocked",
        "deployment": "not-deployed-not-authorized",
        "implementation": "partial-source",
        "operations": "fail-closed",
        "support": "review-only"
      },
      "threatModel": {
        "mitigations": [
          "Fail closed, validate exact contracts, bind identities, and prevent cross-version fallback."
        ],
        "summary": "Route behavior must preserve exact version, request, authorization, response, payment, privacy, and failure boundaries.",
        "threats": [
          "V2 fallback",
          "accidental payment activation",
          "status/schema drift",
          "malformed dynamic path",
          "fabricated live data"
        ]
      },
      "trustAssumptions": [
        "Release gate remains exact and default-closed; no address, facilitator, store, or settlement is configured."
      ],
      "v2Fallback": "forbidden",
      "version": "v3"
    }
  ],
  "paritySemantics": {
    "chainBaseline": {
      "base": "additive source candidate with local Forge canonical-receipt evidence; not deployed or authorized",
      "baseToSolana": "exact adapter-mediated protocol parity for the tested canonical grouped-reward receipt vector; native schema identity remains false and broader parity is unclaimed",
      "solana": "additive successor source with retained byte-reproducible SBF, generated IDL, host tests, and real-SBF program-test evidence; not deployed or authorized"
    },
    "dimensions": [
      "authorization",
      "custody",
      "lifecycle",
      "governance",
      "replay-domain",
      "finality",
      "receipts",
      "privacy",
      "failure-recovery",
      "audit-evidence",
      "deployment-evidence"
    ],
    "levels": [
      "exact",
      "behavioral-subset",
      "adapter-required",
      "metadata-only",
      "mock-analogue",
      "absent",
      "retired",
      "unknown"
    ],
    "rule": "Similarity of names, source presence, loaded bytecode, metadata, or mocks never establishes semantic parity.",
    "surfaceRules": [
      "SDK/API parity requires explicit lossless mappings or adapter-required status.",
      "Mock flows are never chain/API/payment parity.",
      "Retired behavior cannot be presented as degraded or available."
    ]
  },
  "paymentPolicies": {
    "v2-base-usdc-exact": {
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "headers": {
        "challenge": "PAYMENT-REQUIRED",
        "request": "PAYMENT-SIGNATURE",
        "response": "PAYMENT-RESPONSE"
      },
      "network": "eip155:8453",
      "payTo": "0xfA15Ee28939B222B0448261A22156070f0A7813C",
      "protocolVersion": "v2",
      "scheme": "exact",
      "timeoutSeconds": 60,
      "x402Version": 2
    },
    "v3-none": {
      "enabled": false,
      "protocolVersion": "v3",
      "reason": "No authorized V3 payable resource or settlement evidence.",
      "settlementEnabled": false,
      "v2Fallback": "forbidden"
    }
  },
  "receiptContracts": {
    "v2-settled": {
      "ambiguousSettlement": "fail-closed-reconcile",
      "bindingFields": [
        "operationId",
        "method",
        "resource",
        "network",
        "asset",
        "amount",
        "payTo",
        "paymentId",
        "authorizationId",
        "bindingDigest"
      ],
      "replayKeys": [
        "paymentId",
        "authorizationId",
        "transaction"
      ],
      "state": "required-for-priced-v2",
      "storage": "durable-required"
    },
    "v3-future": {
      "paymentEnabled": false,
      "requirements": [
        "server-generated v3r_ plus 32 lowercase hex locator",
        "durable atomic cross-process claims",
        "route/method/resource/payment/capability binding",
        "finality, reorg, timeout recovery, audit integrity, privacy and redaction"
      ],
      "state": "unavailable"
    }
  },
  "schemaVersion": "1.0.0",
  "sharedSafetyModel": {
    "additiveOnly": true,
    "cryptography": [
      "Existing V3 authorization is classical only.",
      "Dilithium, ML-DSA, post-quantum, ZK, FHE, and quantum-resistance claims require exact independently reviewed implementations and evidence.",
      "Any future hybrid policy is AND, never OR or silent downgrade."
    ],
    "defaultDecision": "deny",
    "invariants": [
      "No V3 deployment, payment, signing, wallet, or write activation without separately attributable evidence and authorization.",
      "V3 never imports, redirects to, or silently falls back to V2 payment or verifier code.",
      "Objective, consented, bounded, domain-separated facts are required for protected decisions.",
      "Missing, malformed, stale, ambiguous, or inconsistent evidence fails closed.",
      "Pull-payment liabilities, replay resistance, finality, privacy, and recovery obligations survive adapters and chain ports."
    ],
    "prohibitedInfluenceClasses": [
      "belief",
      "flourishing",
      "reputation",
      "trust-score",
      "behavioral-routing",
      "biometric",
      "profiling",
      "surveillance",
      "quality",
      "loyalty"
    ],
    "protectedDecisions": [
      "custody",
      "access",
      "eligibility",
      "pricing",
      "slashing",
      "settlement",
      "disputes",
      "routing"
    ],
    "v2MutationForbidden": true,
    "v3Defaults": {
      "availability": "fail-closed",
      "bazaarEligible": false,
      "paymentPolicy": null,
      "settlementEnabled": false,
      "v2Fallback": "forbidden"
    },
    "x402V2": [
      "Use only PAYMENT-SIGNATURE, PAYMENT-REQUIRED, and PAYMENT-RESPONSE.",
      "Bind method, absolute resource URL, route, amount, asset, eip155:8453, recipient, and request digest.",
      "Verify before settle; prohibit private-key settlement; atomically claim identities; durably reconcile ambiguous outcomes."
    ]
  },
  "statusTaxonomy": {
    "axes": {
      "audit": [
        "source-review-not-independent",
        "historical-scope-only",
        "unreviewed",
        "not-applicable"
      ],
      "completion": [
        "evidenced",
        "partial",
        "blocked",
        "not-applicable"
      ],
      "deployment": [
        "deployed-v2-observed",
        "not-deployed-not-authorized",
        "unavailable",
        "not-applicable"
      ],
      "implementation": [
        "implemented-source",
        "partial-source",
        "legacy-v2",
        "metadata-only",
        "mock-only",
        "placeholder",
        "absent"
      ],
      "operations": [
        "live-v2-observed",
        "fail-closed",
        "unverified",
        "unavailable",
        "mock-only",
        "not-applicable"
      ],
      "support": [
        "supported",
        "internal",
        "compatibility",
        "review-only",
        "excluded",
        "retired",
        "redesign-required",
        "deferred"
      ]
    },
    "completionPolicy": {
      "blockedWhenMissingActivationEvidence": true,
      "evidencedRequiresEvidence": true,
      "forbiddenClaims": [
        "complete",
        "production-ready",
        "mainnet-ready",
        "independently-audited",
        "quantum-resistant",
        "fips-validated-product"
      ]
    },
    "precedence": {
      "auditIndependentOfTests": true,
      "deploymentIndependentOfSource": true,
      "failClosedOverMarketingClaim": true,
      "retiredOverImplemented": true
    }
  }
}
