Credibility hardening closeout — 2026-09-02#

Historical snapshot. The model-evaluation and self-teeth rows below describe the 2026-09-02 candidate and are superseded by STATUS.md, research/model-evaluation/protocol.v2.json, and docs/self-hosting.md. In particular, the claim-bearing 240-trial inputs are now explicitly unpopulated/unsealed rather than described as frozen, and the current self-blueprint has a real 38/38 source-mutation proof.

This is the closeout ledger for the 15 workstreams in the corresponding implementation plan. “Implemented” means present and locally verified in the candidate source tree; it does not turn an unmerged change into a release or an author-operated run into independent evidence.

#WorkstreamCandidate/source resultHonest remaining boundary
1Immutable releasesRepository immutable releases are enabled via the live GitHub API. Executable Action examples pin the v0.1.5 source commit.Historical release v0.1.5 still reports immutable:false. A later release must demonstrate the new setting.
2Vulnerability intakeGitHub private vulnerability reporting is live. SECURITY.md provides private-report and security-mailbox paths, safe-content guidance, and a seven-day acknowledgement target.A non-maintainer reporting-UI test and mailbox acknowledgement are external operator exercises.
3Independent adoptionA frozen target of three, closed record schema, structured issue intake, denominator reconciliation, and a negative control rejecting author-operated “independence” are release-gated.Zero journeys started and zero accepted independent witnesses. Recruitment and runs require other people.
4Independent reviewLive main protection requires six checks, enforces them for admins, and blocks deletion/force-push. Human approval, CODEOWNER, and release-review requirements are deliberately disabled so a one-human project remains operable. Governance and release state state this limitation explicitly.Independent review is unestablished. Activate second-person controls only when a distinct human accepts and can exercise the role; a nominal or maintainer-controlled account is not evidence.
5Controlled agent efficacyA frozen cross-harness protocol defines baseline/BCE arms, 240 minimum trials, intention-to-treat denominators, blinded dual adjudication, policy-mutation outcomes, Wilson intervals, and repository-cluster bootstraps. Analysis rejects missing trials and post-seal manifest edits.The task/repository manifest and exact client/model identities are deliberately unset, so readiness refuses. No causal benefit, cost, or escaped-defect result exists.
6Real-model/client evidenceDeterministic onboarding covers Agents, Claude, Cursor, and Codex layouts; one author-operated Codex sample is recorded. A refused Claude attempt is preserved rather than omitted. The future four-harness evaluation records exact client artifacts, model snapshots, tokens, cost, latency, failures, MCP use, and policy mutation.Claude inference did not run because of client-version and quota refusals; the controlled 240-trial evaluation has not run and no multi-family estimate exists.
7Supply chain/security settingsEvery executable Action reference is a reviewed full SHA; unknown owners and mutable tags are negative-tested. Live Actions policy permits GitHub-owned actions only and requires SHA pins. Dependabot updates, secret scanning, and push protection are live; npm audit is zero.GitHub reports non-provider patterns and validity checks disabled; they are not claimed.
8Reproducibility identityRuntime dependencies are exact, npm-shrinkwrap.json ships, evidence records identify lock digest/runtime/extractor provider, and two clean installs reproduce the production graph and report hash.Historical v0.1.5 evidence lacks the additive toolchain identity. A new release is required.
9Release adoption proofRelease gating now reruns deterministic Agent Skills/MCP adoption and a policy checker rejects its removal.The new release workflow has not yet executed at a new immutable tag.
10Detection and scaleA release-gated 2,000-file synthetic AST track enforces file coverage, 30-second p95, and an exact-line planted RED. The extractor was fixed from 48.8 seconds to 347.3 ms local p95 without reducing the track.No independently annotated held-out corpus or real-monorepo performance distribution exists. Python remains an explicitly bounded line-scan MVP.
11MCP compatibilityLocked Inspector 2.5.0 strict discovery, exact six-tool surface, version negotiation, framing limits, notification behavior, large output, and a 2-second discovery SLO are gated.Named-host compatibility beyond the recorded Codex sample is not inferred from Inspector. In-flight synchronous calls cannot be preempted.
12Claim consistencyMachine-readable release state and negative claim controls reconcile version, Action SHA, immutability history, schemas, GitLab status, listings, witnesses, and governance. Stale Lane-A and launch text was corrected.Claim checks cannot prove facts outside their explicit inputs; public links/settings must still be re-read at release time.
13Distribution listingsListing copy uses exact install pins, public URLs, strict plugin validation, and an explicit allowed-claims table. A native OpenAI .codex-plugin/plugin.json packages both skills as skills-only; BCE's validator and the canonical plugin-creator validator pass. A submission dossier contains the required five positive and three negative cases. State is machine-checked as unsubmitted.No OpenAI or Claude directory submission, review, listing URL, or clean-account listing install exists. OpenAI identity, legal URLs, final logo, regions, attestations, and portal publication remain operator-owned.
14External specification implementationThe 12-vector set is digest-frozen. A closed external-report schema, verifier, issue intake, and negative control rejecting BCE itself are present.Accepted external implementations: zero. No certification level or neutral governance is claimed.
15Portability and signed identityExact Node toolchains, a six-leg Ubuntu/macOS/Windows × Node 22.22.2/24.15.0 workflow, and keyless Sigstore release attestation with issuer/workflow constraints are configured. A network-denial hook proves validate, GREEN/RED gate, evidence verification, and MCP discovery remain local under hostile proxy and registry settings.The new public matrix has not run, successful installation from an enterprise private registry has not been exercised, and historical v0.1.5 has no Sigstore evidence bundle. Hashes prove integrity; authenticated producer identity awaits a new release.

Verification record#

Local verification used Node 22.22.2 unless stated otherwise:

The candidate is isolated on branch fix/credibility-hardening-2026-09-02 in a local commit so committed-revision proofs can execute. It is not pushed, reviewed, merged, published, or deployed by this record. Public release identifiers belong here only after the corresponding reviewed artifact exists; inventing them in advance would defeat the ledger.

Read Markdown · Source: docs/credibility-hardening-closeout-2026-09-02.md