# Project evidence register

## Hireability update — 2026-09-14

The [dated revision and evidence register](evidence/project-evidence-2026-09-14.md) is the current homepage authority. It supersedes the older sidecar-only pairing, adds SHAD0W and Evidence Strategy Skills, corrects Fracture maturity, and separates Truck-Ready historical workflow evidence from its current CSV regression. The frozen fixture oracle and AetherForge mock instrument remain independently scoped. No source-project tests were rerun for this update.

The older “current” headings below are historical records; their dates and pins control their scope.

## AetherForge admission instrument — 2026-09-13

The [focused source and execution record](evidence/aetherforge/verification.md) supersedes earlier AetherForge verification wording for this slice only. Remote HEAD remains `265c26769eba257ac40540a7e1da5378d7515532`. Four controlled `/system/strategy` probes and five existing route tests passed locally with documented mock isolation. The homepage shows strategy admission, insufficient switching benefit, forced thermal lock and exhausted semaphore capacity; values and responses are recorded in [scenarios.json](evidence/aetherforge/scenarios.json).

Timings are configured estimates. Physical GPU swapping and actual thermal events remain unverified. This is not a new hosted CI result or whole-workload execution claim. Other project evidence and historical audit records are unchanged.

## Current portfolio audit — 2026-09-11

The [source-pinned eight-project audit](evidence/portfolio-mastery-2026-09-11.md) is the current authority for the refreshed homepage. It records exact default branches, separately scoped feature work, implementation/test paths, captured results, hosted CI outcomes, limits and artifact choices. Earlier entries below remain historical records.

- **Flagship:** CipherLoop `f03a1e1` + TraceForge `25668c4`: offline capture harness → files → independent adapter/evaluator and fixture oracle. Two synthetic-response fixtures, not live audit certification. The adapter needs capture sidecars as well as the JSONL and metadata.
- **Current evidence:** committed toy/safe results both match their independent expectations. TraceForge hosted baseline workflow passed at the exact inspected main commit on 2026-09-09. Source, outputs and CI metadata inspected; project tests were not rerun in this portfolio pass.
- **Separate branch work:** CipherLoop `37fcbe4` production evidence contract is not integrated into TraceForge main. The existing case study remains explicitly scoped to `f03a1e1`. Unhinged hardware-prep `ea86997` and HVAC Ops recovery `d5ec623` are labeled and directly linked when used in homepage copy.
- **Hierarchy:** paired flagship → AetherForge mock control plane → Truck-Ready and Unhinged applied work → Sightglass/HVAC Ops prototypes → Fracture scaffold. Physical GPU/hardware and field outcomes remain unverified. Current AetherForge and Truck-Ready CI failures prevent a current passing-test claim. Sightglass is not an enforced approval or durable sync system.
- **Homepage publication wording:** source-supported, bounded descriptions approved by this audit within the user's authorized implementation scope. No deploy or push authorized. No new business, performance, adoption or security outcome claims.

---

This is a verification register, not a source of newly verified facts. Initial entries come from the supplied portfolio snapshot. Reinspect the current repositories before publishing case-study claims. Record the commit or date inspected, exact evidence, and remaining limitations. Do not silently promote README descriptions into demonstrated results.

## CipherLoop
Source: https://github.com/jayjz/CipherLoop
Snapshot status: Active development.
Snapshot description: local repository auditing with planner, local executor, and shared graph intended to preserve context over long investigations.
Verification needed: current implementation, actual execution boundaries, evidence storage, working audit paths, tests, reproducible findings, limitations, and screenshots.
Case-study status: source inspected at `f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`; deterministic tests passed. See the current CL-01–CL-11 claim ledger below. No live audit or production-readiness claim.

## AetherForge
Source: https://github.com/jayjz/aetherforge
Snapshot status: Active development — mock path verified.
Snapshot description: local-agent control plane for consumer GPUs. Live 8 GB swap remains research.
Verification needed: current mock tests, real hardware behavior, scheduling/admission semantics, failure handling, and measured results.
Do not claim live GPU swapping is verified unless current evidence supports it.

## Truck-Ready HVAC
Source: https://github.com/jayjz/truck-ready-hvac
Snapshot status: Active development.
Snapshot description: parts staging and offline JSON/printable PDF checklists.
Verification needed: current workflow, exports, test coverage, actual field usage, and screenshots. Do not invent customer adoption or time savings.

## Unhinged Agent
Source: https://github.com/jayjz/unhinged-agent
Snapshot status: Proof of concept — software complete.
Snapshot description: private voice notes using a thin ESP32 client and local host; browser twin exists, physical hardware not yet verified in the snapshot.
Verification needed: current software tests, hardware status, privacy boundaries, audio pipeline, and reproducible demonstration.

## HVAC Ops
Source: https://github.com/jayjz/hvac-ops-agent
Snapshot status: Proof of concept — working demo.
Snapshot description: dispatch, inventory, and risk helpers using synthetic fallback and human approval before irreversible work.
Verification needed: current demo paths, data sources, approval boundaries, test results, and real-world deployment status.

## Fracture
Source: https://github.com/jayjz/fracture
Snapshot status: Scaffold / research harness.
Snapshot description: experiments with agent-graph failures and recovery.
Verification needed: implemented experiments, fixtures, metrics, results, and repeatability. Do not present it as a finished product.

## Evidence entry template
### Claim
- Proposed public wording:
- Repository and commit/date inspected:
- Evidence path or command:
- Observed result:
- Limitations:
- Verification status: verified / partially verified / unverified
- Approved for publication: yes / no

## Content rules
Use “prototype,” “research,” “mock path,” and “verified” precisely. Never fabricate metrics, users, customers, revenue, benchmark results, or live operational data. A GitHub link is a source pointer, not proof that every stated capability works. If evidence is missing, state the limitation or omit the claim.

## CipherLoop vertical slice — 2026-09-07

- Proposed public wording: “CipherLoop explores” repository investigation; the project brief describes a planner, local executor, and shared graph **intended** to carry context. Current execution paths and boundaries remain unverified.
- Repository and commit/date inspected: no source repository inspected in this milestone; existing portfolio snapshot and this evidence register read on 2026-09-07.
- Evidence path or command: local `docs/project-evidence.md` initial CipherLoop entry and baseline portfolio copy at `92eeb72`.
- Observed result: sufficient editorial context to build the layout and study outline, insufficient evidence to assert implemented capabilities.
- Limitations: no current tests, execution trace, security findings, privacy guarantee, performance result, or architecture mapping established.
- Verification status: unverified.
- Approved for publication: no verified technical capability wording approved. Both UI surfaces explicitly label the pending evidence; deployment remains a separate step.
- Illustration: original conceptual SVG, not an implementation diagram or telemetry. Its planning/inspection/evidence/review loop is an editorial model, not a new project claim.


## CipherLoop source-backed milestone — current claim ledger

Inspected 2026-09-07. Source repository: **jayjz/CipherLoop**. Every entry below refers to exact commit **`f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`**, verified as the clean local checkout and remote HEAD. This supersedes the earlier provisional entry for CipherLoop only. No CipherLoop source or tests were changed.

Verification levels distinguish **source inspection**, **executed unit test**, **mocked graph integration**, and **supplementary offline probe**. “Publish” means the exact scoped wording is suitable for the proposed portfolio diff; it does not authorize deployment. Full test output/environment and limitations: [deterministic demonstration](evidence/cipherloop/demonstration.md).

### CL-01 · Graph and maturity

- **Proposed public wording:** CipherLoop is an experimental hybrid-model framework with a six-node LangGraph investigation workflow.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/orchestrator/graph.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/orchestrator/graph.py#L10-L54), [src/cipherloop/orchestrator/nodes.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/orchestrator/nodes.py#L14-L64).
- **Test / inspection command:** Inspect graph.py/nodes.py; run tests/test_e2e_safe.py and tests/test_e2e_vulnerable.py.
- **Observed result:** Planner → local model; tool calls route through sandbox_tools back to local_model. No tool call routes to compressor → validator. Validator routes to planner or synthesizer, then END. Both deterministic graph tests passed.
- **Verification level:** Source inspection + mocked graph integration.
- **Limitations:** The graph tests mock planner, local model, compressor, and file reads; positive synthesis is mocked. No scanner/tool-node branch, live model, or Docker execution occurs in those tests.
- **Publication decision:** Publish this bounded architecture/maturity wording.

### CL-02 · Positive and negative control

- **Proposed public wording:** The unchanged deterministic tests accept one fixture source-to-sink path and reject a constant-input fixture.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [tests/test_e2e_vulnerable.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/tests/test_e2e_vulnerable.py#L8-L82), [tests/test_e2e_safe.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/tests/test_e2e_safe.py#L8-L65), [fixtures/toy/app.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/fixtures/toy/app.py#L6-L11), [fixtures/safe/app.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/fixtures/safe/app.py#L9-L17).
- **Test / inspection command:** python -m pytest -v -p no:cacheprovider tests (full suite); boundary-probe.py reads fixtures as text.
- **Observed result:** 20/20 tests pass. Positive graph test asserts one VERIFIED finding and report mention; source request.args.get at app.py:8 flows through ip to subprocess.run at line 10. Safe candidate points at app.py:11 and produces zero verified findings plus the real no-findings synthesis branch.
- **Verification level:** Executed deterministic mocked integration; supplemental direct AST probe.
- **Limitations:** Fixture apps are not executed. Mocked compressor injects a formatted candidate; Semgrep never discovers it in this test. Positive report content is a test-generated string. The safe fixture uses a constant command, not sanitization.
- **Publication decision:** Publish with adjacent mock boundaries; reject “live autonomous audit” or “scan found a vulnerability.”

### CL-03 · Evidence threshold

- **Proposed public wording:** An exact-line Python AST pattern match gates the internal VERIFIED status.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/executor/validator.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/validator.py#L10-L173), [src/cipherloop/executor/validator.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/validator.py#L176-L240), [tests/test_validator.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/tests/test_validator.py#L17-L62).
- **Test / inspection command:** Full pytest suite; boundary-probe.py syntax and fixture probes; inspect validator.py.
- **Observed result:** Candidate parser expects [SEVERITY] path:line - description. The sandbox read boundary requests lines 1–1,000,000, ast.parse builds a tree, and the first matching source-to-sink trace at that sink line becomes a finding. Read errors, parse errors, or absent patterns yield no finding. Unrecognized severity becomes MEDIUM; confidence is fixed at 0.9; evidence_snippet is a location-path string, not a source slice.
- **Verification level:** Source inspection + unit tests + offline probes.
- **Limitations:** Only Python and a narrow name-based pattern set. No import/alias resolution, interprocedural propagation, control-flow feasibility, sanitizer semantics, shell=True requirement, argument-position semantics, or calibrated confidence. Unsupported or unparsed candidates may disappear rather than producing a coverage warning.
- **Publication decision:** Publish as an implementation threshold, never a universal exploitability or false-positive guarantee.

### CL-04 · Active messages and summaries

- **Proposed public wording:** At a completed local tool loop, the compressor summarizes tool responses and requests removal of messages with IDs.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/executor/local_node.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/local_node.py#L86-L124), [src/cipherloop/executor/compressor.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/compressor.py#L7-L81), [src/cipherloop/core/state.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/core/state.py#L23-L39), [tests/test_compressor.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/tests/test_compressor.py#L5-L44).
- **Test / inspection command:** Full pytest suite; boundary-probe.py applies add_messages to the returned RemoveMessage objects.
- **Observed result:** The real ToolNode returns raw ToolMessages to active state and the local model reads them before compression. Compressor removes every ID-bearing message, including plans/AI messages, after optionally logging raw ToolMessages and AI tool calls. Supplementary reducer probe: 2 messages → 0. Semgrep retains up to five ERROR/WARNING summaries, ERROR first. Generic output over 3,000 characters is clipped there; otherwise the first 15 lines are retained.
- **Verification level:** Source inspection + compressor unit tests + real reducer probe.
- **Limitations:** The long-output branch is character-limited, not also 15-line-limited. No cap exists inside a continuing local-model/tool loop. No proof of token/cost savings or prevented context collapse. Summaries are not passed back to local_model; planner sees counts and accepted finding metadata, not the full summaries.
- **Publication decision:** Publish periodic sweeping and per-response truncation; reject “bounded total context” as a demonstrated invariant.

### CL-05 · Accumulating state

- **Proposed public wording:** Compressed batches and verified findings accumulate in additive state fields.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/core/state.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/core/state.py#L28-L36), [src/cipherloop/executor/validator.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/validator.py#L191-L240), [src/cipherloop/orchestrator/nodes.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/orchestrator/nodes.py#L14-L36).
- **Test / inspection command:** Inspect reducers and validator loop; boundary-probe.py concatenates batches and runs validation twice against the same candidate.
- **Observed result:** Both fields use operator.add. Validator revisits all compressed batches each cycle and returns findings without deduplication. The same finding ID was emitted on the second probe validation. Two appended batches remain two batches.
- **Verification level:** Source inspection + supplementary offline probe.
- **Limitations:** No retention cap, replacement policy, or deduplication. This can grow state and repeat accepted findings/character counts; it does not establish long-horizon memory reliability.
- **Publication decision:** Publish as a documented limitation and separate engineering task.

### CL-06 · Durable record and measurement

- **Proposed public wording:** A separate JSONL recorder retains selected tool-loop messages; final metadata aggregates character counts.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/core/trajectory.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/core/trajectory.py#L7-L75), [src/cipherloop/executor/compressor.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/compressor.py#L56-L81), [src/cipherloop/executor/validator.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/validator.py#L232-L240), [src/cipherloop/main.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/main.py#L125-L164), [tests/test_trajectory.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/tests/test_trajectory.py#L6-L24).
- **Test / inspection command:** Full pytest suite; inspect recorder call sites and serialization.
- **Observed result:** Compressor logs raw tool responses and AI messages with tool calls; validator logs parsed-candidate/accepted/rejected counts. finalize writes metadata after graph completion. Unit test adds synthetic 120+80 raw and 30+20 summarized characters and asserts 4.0. compressed_char_count measures json.dumps of a summary before adding the two metric fields; raw_char_count is Python len of raw text.
- **Verification level:** Source inspection + synthetic metadata unit test.
- **Limitations:** 4.0 is arithmetic over supplied numbers, not an audit benchmark. Counts omit active-message overhead and metric fields and are not tokens, bytes, money, or model quality. JSONL is disk persistence, not a complete DAG/WAL guarantee: no fsync/recovery protocol, no graph checkpoint, no automatic recording of every planner/synthesizer response. Raw outputs are only written when compressor runs; exceptions can bypass finalization.
- **Publication decision:** Publish exact recording/aggregation scope. Reject complete-trace, measured token-saving, and cost-saving claims.

### CL-07 · Model/data boundaries

- **Proposed public wording:** Tools execute locally, while configured cloud calls receive target and finding-derived information.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/orchestrator/nodes.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/orchestrator/nodes.py#L11-L64), [src/cipherloop/core/llm.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/core/llm.py#L8-L66), [src/cipherloop/executor/local_node.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/local_node.py#L86-L118), [src/cipherloop/main.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/main.py#L125-L143).
- **Test / inspection command:** Inspect construction of each model invoke payload; no model calls executed.
- **Observed result:** Planner receives target_directory, batch/accepted counts, accepted severity/ID/class. CLI supplies an absolute host target path. Synthesizer receives the full JSON list of internally VERIFIED findings, including file locations, taint_path, scanner-derived description and evidence_snippet. Local Ollama receives current plan plus active messages, including raw tool output. Host-side recorder may persist source-derived raw content.
- **Verification level:** Source inspection only.
- **Limitations:** Planner is not sent the full raw messages or full compressed summary text by this code, but accepted descriptions/paths can contain source-derived information. Ollama URL is configurable, not enforced loopback. No redaction, privacy assessment, or actual provider run. A local Docker mount does not establish confidentiality.
- **Publication decision:** Publish explicit hybrid boundaries; reject “repository never leaves the machine” and “fully private.”

### CL-08 · Sandbox controls

- **Proposed public wording:** Provisioning requests a read-only target mount and no container networking; reuse compares target mount identity.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/main.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/main.py#L36-L108), [src/cipherloop/tools/filesystem.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/tools/filesystem.py#L15-L92), [sandbox/Dockerfile](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/sandbox/Dockerfile#L1-L19), [docker-compose.yml](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/docker-compose.yml#L1-L12), [tests/test_sandbox_identity.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/tests/test_sandbox_identity.py#L14-L93).
- **Test / inspection command:** Full pytest suite; inspect Docker command construction, Compose and lexical path validation.
- **Observed result:** Two mocked subprocess tests cover matching-mount reuse and stale-target replacement; the replacement test asserts --network none and :ro. Tools use fixed executable argument lists through Docker SDK exec_run with a fixed workdir, not host shell execution. POSIX normalization rejects lexical paths outside WORKDIR.
- **Verification level:** Source inspection + mocked subprocess control tests.
- **Limitations:** Reuse checks source/destination but not actual read-only/network/image invariants. Lexical normalization is not symlink resolution; option boundaries are not consistently terminated with --. No explicit resource/time limits, non-root USER, capability dropping, or post-run cleanup; container persists and shares a fixed name. Host orchestrator still accesses Docker/cloud. No live containment or escape assessment.
- **Publication decision:** Publish implemented controls with mock/live distinction; reject escape-proof/air-gap confidentiality claims.

### CL-09 · Actual fallback and gap

- **Proposed public wording:** Semgrep runs first; detected failure invokes a sandboxed ripgrep fallback with limited pattern coverage.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/executor/local_node.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/local_node.py#L21-L83), [src/cipherloop/tools/filesystem.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/tools/filesystem.py#L84-L90), [src/cipherloop/tools/fallback_tool.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/tools/fallback_tool.py#L12-L58), [tests/test_local_node.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/tests/test_local_node.py#L8-L68), [src/cipherloop/executor/compressor.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/executor/compressor.py#L17-L37).
- **Test / inspection command:** Full pytest suite; boundary-probe.py feeds mocked rg output through the real fallback serializer and compressor.
- **Observed result:** Wrapper handles exceptions, timeout exceptions, tool-error prefixes, malformed JSON, crash/return codes and errors fields. Both-tool failure becomes JSON with results=[], errors, fallback_used and original_error. Four tests mock scanner boundaries. Probe: one fallback regex result → zero compressor candidates because fallback results have no severity; structured errors are dropped by the compressor.
- **Verification level:** Source inspection + wrapper unit tests + supplementary mocked-output probe.
- **Limitations:** Regex covers selected subprocess/os.system/eval/exec/credential patterns, not equivalent Semgrep rules. No real rg/Semgrep execution tested. Docker tool execution has no configured timeout; tests inject timeout exceptions. Semgrep remote p/secrets and p/rce presets are not vendored in the network-disabled container, so live rule availability is unverified.
- **Publication decision:** Publish actual order and limited fallback; document lost signals/errors as a defect for separate source work.

### CL-10 · Completion and failure

- **Proposed public wording:** Completion depends on planner text or a planner-cycle count, not a measured scan-coverage state.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [src/cipherloop/orchestrator/graph.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/orchestrator/graph.py#L35-L54), [src/cipherloop/orchestrator/nodes.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/orchestrator/nodes.py#L14-L64), [src/cipherloop/main.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/main.py#L146-L164).
- **Test / inspection command:** Inspect routing, synthesis and CLI exception/finalization behavior; safe graph test exercises the empty-accepted-list branch.
- **Observed result:** After validation, retries>=25, an empty plan, or the substring complete routes to synthesis. retries counts planner invocations, not tool retries. An instruction containing “incomplete” also contains that substring. Planner is the entry node and ignores the CLI initial plan in its request payload. With no accepted findings, synthesis returns a fixed no-high-confidence-findings report without a cloud call.
- **Verification level:** Source inspection + negative graph test.
- **Limitations:** No explicit complete/partial/failed coverage state. Endless local tool calls do not increment planner retries. Dependency recursion limits are not a designed run budget. A zero-findings report does not distinguish no match from failed tools/lost fallback signals; uncaught graph/provider/parser/recorder errors may abort before finalize. No robust resume or report-file generation is demonstrated.
- **Publication decision:** Publish the ambiguity and next milestone; never translate “no verified findings” into “safe repository.”

### CL-11 · Documentation discrepancies

- **Proposed public wording:** The study follows source code where README/specification claims diverge.
- **Source repository / revision:** `jayjz/CipherLoop @ f03a1e186e491cf24aa0f0e0671cac766c1fa8ab`.
- **Source permalinks:** [README.md](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/README.md#L68-L103), [.codex/specs/auto-spec.md](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/.codex/specs/auto-spec.md#L18-L61), [docs/MEMORY_PROTOCOL.md](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/docs/MEMORY_PROTOCOL.md#L1-L19), [src/cipherloop/orchestrator/graph.py](https://github.com/jayjz/CipherLoop/blob/f03a1e186e491cf24aa0f0e0671cac766c1fa8ab/src/cipherloop/orchestrator/graph.py#L20-L54).
- **Test / inspection command:** Read README/specs alongside graph, compressor, validator and recorder call sites; compare Repomix text to recorded Git files.
- **Observed result:** README AST-first/Semgrep-fallback sections contradict the implemented Semgrep-first/ripgrep-fallback path. AST parse failure returns None; there is no AST-to-Semgrep fallback edge. Protocol prose about Markdown reflection is not a runtime write path found in inspected nodes. Specifications are intent, not test results.
- **Verification level:** Source inspection.
- **Limitations:** Repomix comparison covered 35 relevant text files; 34 matched ignoring trailing whitespace, README differed only by leading/trailing whitespace. This scoped match does not assert equality of an entire checkout or attachment.
- **Publication decision:** Do not repeat unsupported README/spec language; publish the corrected source-derived architecture.
