{
  "attack_suite": {
    "attacks": [
      {
        "attack_type": "IDENTITY_SPOOFING",
        "category": "IDENTITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PRINCIPAL_SUBSTITUTION",
        "category": "IDENTITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CREDENTIAL_MISUSE",
        "category": "IDENTITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CREDENTIAL_REPLAY",
        "category": "IDENTITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "IDENTITY_CONTEXT_MISMATCH",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PRIVILEGE_ESCALATION",
        "category": "AUTHORITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "AUTHORITY_WIDENING",
        "category": "AUTHORITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "UNAUTHORIZED_DELEGATION",
        "category": "AUTHORITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "REVOKED_AUTHORITY_REUSE",
        "category": "AUTHORITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONFUSED_DEPUTY",
        "category": "DELEGATION",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "STALE_AUTHORIZATION",
        "category": "AUTHORITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "DELEGATION_ESCALATION",
        "category": "DELEGATION",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "REVOKED_AUTHORITY_REUSE",
        "category": "AUTHORITY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONFUSED_DEPUTY",
        "category": "DELEGATION",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "UNAUTHORIZED_SUBAGENT_AUTHORITY",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "DELEGATION_ATTENUATION_BYPASS",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "GRAPH_POISONING",
        "category": "GRAPH",
        "evidence": {
          "error": "'str' object has no attribute 'get'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "FALSE_DEPENDENCY_EDGE",
        "category": "GRAPH",
        "evidence": {
          "error": "'str' object has no attribute 'get'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "HIDDEN_RESOURCE",
        "category": "GRAPH",
        "evidence": {
          "error": "'str' object has no attribute 'get'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "UNKNOWN_RESOURCE_HIDING",
        "category": "GRAPH",
        "evidence": {
          "error": "'str' object has no attribute 'get'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "COUNTERFACTUAL_MANIPULATION",
        "category": "GRAPH",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_predictive_trust_decision",
          "positive_control": true,
          "recommendation": "deny",
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "POLICY_BYPASS",
        "category": "POLICY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "STALE_POLICY_EXPLOITATION",
        "category": "POLICY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "POLICY_VERSION_SUBSTITUTION",
        "category": "POLICY",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_trust_graph_edge",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "POLICY_DOWNGRADE",
        "category": "POLICY",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_trust_graph_edge",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "UNAUTHORIZED_POLICY_REFERENCE",
        "category": "POLICY",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_trust_graph_edge",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "POLICY_WEAKENING",
        "category": "POLICY",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_trust_graph_edge",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TRUST_MANIPULATION",
        "category": "TRUST",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TRUST_STATE_CONFUSION",
        "category": "TRUST",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "STALE_TRUST_STATE",
        "category": "TRUST",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "STALE_AUTHORITY",
        "category": "TRUST",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TRUST_ESCALATION",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "FAKE_POSITIVE_EVIDENCE",
        "category": "TRUST",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_trust_event_log",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "NEGATIVE_EVIDENCE_SUPPRESSION",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TRUST_STATE_REPLAY",
        "category": "TRUST",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_trust_state_engine",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TRUST_VERSION_MISMATCH",
        "category": "TRUST",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_trust_state_engine",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PREMATURE_TRUST_RECOVERY",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CROSS_TENANT_TRAVERSAL",
        "category": "CROSS_TENANT",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CROSS_TENANT_IDENTITY",
        "category": "CROSS_TENANT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CROSS_TENANT_AUTHORITY",
        "category": "CROSS_TENANT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CROSS_TENANT_GRAPH_TRAVERSAL",
        "category": "CROSS_TENANT",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_tenant_scoped_store",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CROSS_TENANT_EVIDENCE_ACCESS",
        "category": "CROSS_TENANT",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_fabric_decision_store",
          "positive_control": true,
          "scope_note": "fabric_decisions tenant-scoped accessors only; evidence_store.retrieve() has no tenant arg",
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CROSS_TENANT_TRUST_MANIPULATION",
        "category": "CROSS_TENANT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CROSS_TENANT_PROVENANCE_ACCESS",
        "category": "CROSS_TENANT",
        "evidence": {
          "attack_accepted": false,
          "fixture": "real_tenant_scoped_store",
          "positive_control": true,
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TRAJECTORY_REPLAY",
        "category": "TRAJECTORY",
        "evidence": {
          "error": "no such table: trajectory_outcomes"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TRAJECTORY_MANIPULATION",
        "category": "TRAJECTORY",
        "evidence": {
          "error": "no such table: trajectory_outcomes"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EFFECT_SPOOFING",
        "category": "TRAJECTORY",
        "evidence": {
          "error": "no such column: execution_id"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "DUPLICATE_EXECUTION",
        "category": "TRAJECTORY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "REPLAYED_EXECUTION",
        "category": "TRAJECTORY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "UNAUTHORIZED_EFFECT",
        "category": "TRAJECTORY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EXECUTION_TIMING_RACE",
        "category": "TRAJECTORY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EXECUTION_DUPLICATE_SEQUENCE",
        "category": "TRAJECTORY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MCP_SUBSTITUTION",
        "category": "MCP",
        "evidence": {
          "error": "No module named 'cain_mcp_proxy'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TOOL_SUBSTITUTION",
        "category": "MCP",
        "evidence": {
          "error": "No module named 'cain_mcp_proxy'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TOOL_IDENTITY_SPOOFING",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "UNAUTHORIZED_TOOL_INVOCATION",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MALICIOUS_TOOL_METADATA",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CAPABILITY_ESCALATION",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONFUSED_DEPUTY_MCP",
        "category": "IDENTITY",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PROVENANCE_VERSION_SUBSTITUTION",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PROVENANCE_CHAIN_TRUNCATION",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PROVENANCE_SIGNATURE_SUBSTITUTION",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PROVENANCE_EVIDENCE_REPLAY",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "TAMPERED_EVIDENCE",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EVIDENCE_SUBSTITUTION",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "ATTESTATION_REPLAY",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EXECUTION_IDENTITY_MISMATCH",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MODEL_VERSION_SUBSTITUTION",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "AGENT_BUILD_SUBSTITUTION",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "INCOMPLETE_PROVENANCE",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "DECISION_EFFECT_MISMATCH",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EXECUTION_EFFECT_SUBSTITUTION",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MEMORY_POISONING",
        "category": "MEMORY",
        "evidence": {
          "error": "'str' object has no attribute 'get'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MALICIOUS_TRUSTED_MEMORY_PROMOTION",
        "category": "MEMORY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MEMORY_STATE_CORRUPTION",
        "category": "MEMORY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MEMORY_TRAVERSAL_INJECTION",
        "category": "MEMORY",
        "evidence": {
          "error": "'str' object has no attribute 'get'"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MEMORY_EVICTION_BYPASS",
        "category": "MEMORY",
        "evidence": {},
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "MEMORY_REPLAY_INJECTION",
        "category": "MEMORY",
        "evidence": {
          "error": "no such table: trajectory_outcomes"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "WORM_HASH_COLLISION",
        "category": "WORM",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "WORM_TIMESTAMP_REPLAY",
        "category": "WORM",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "WORM_SIGNATURE_FORGERY",
        "category": "WORM",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "WORM_PROOF_BYPASS",
        "category": "WORM",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "WORM_AFFIDAVIT_TAMPERING",
        "category": "WORM",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EVIDENCE_POISONING",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "FALSE_PROVENANCE",
        "category": "PROVENANCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "FABRICATED_HISTORICAL_EVENT",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EVIDENCE_CHAIN_REORDERING",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EVIDENCE_HASH_PREIMAGE",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EVIDENCE_SEQUENCE_GAP",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EVIDENCE_DUPLICATE_INJECTION",
        "category": "EVIDENCE",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PREDICTION_POISONING",
        "category": "PREDICTIVE",
        "evidence": {
          "simulated": false
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PREDICTION_CONFIDENCE_INFLATION",
        "category": "PREDICTIVE",
        "evidence": {
          "simulated": false
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PREDICTION_BLAST_RADIUS_MANIPULATION",
        "category": "PREDICTIVE",
        "evidence": {
          "simulated": false
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PREDICTION_BLIND_SPOT_EXPLOITATION",
        "category": "PREDICTIVE",
        "evidence": {
          "simulated": false
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "PREDICTION_MODEL_POISONING",
        "category": "PREDICTIVE",
        "evidence": {
          "simulated": false
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "RESOURCE_SUBSTITUTION",
        "category": "PREDICTIVE",
        "evidence": {
          "error": "no_target_resource"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EXECUTION_OUTSIDE_SCOPE",
        "category": "PREDICTIVE",
        "evidence": {
          "error": "no_target_resource"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "EXECUTION_SCOPE_EXPANSION",
        "category": "PREDICTIVE",
        "evidence": {
          "error": "no_target_resource"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "RESOURCE_ALIAS_INJECTION",
        "category": "PREDICTIVE",
        "evidence": {
          "error": "no_target_resource"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "RESOURCE_WILDCARD_ESCAPAL",
        "category": "PREDICTIVE",
        "evidence": {
          "error": "no_target_resource"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "RESOURCE_SCOPE_WEAKENING",
        "category": "PREDICTIVE",
        "evidence": {
          "error": "no_target_resource"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "RESOURCE_TYPE_CONFUSION",
        "category": "PREDICTIVE",
        "evidence": {
          "error": "no_target_resource"
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_MUTATION",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_DELETION",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_SUBSTITUTION",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_WIDENING",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "STALE_CONTEXT",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "REPLAYED_CONTEXT",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "AUDIENCE_MISMATCH",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "INTENT_SUBSTITUTION",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_TOKEN_REPLAY",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_ENVELOPE_MUTATION",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_SESSION_FIXATION",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      },
      {
        "attack_type": "CONTEXT_AUDIENCE_ESCAPAL",
        "category": "CONTEXT",
        "evidence": {
          "simulated": true
        },
        "result": "ATTACK_BLOCKED"
      }
    ],
    "counts": {
      "ATTACK_BLOCKED": 114
    },
    "database": "fresh temporary sqlite; schema created by the modules' own init functions (reproducible)",
    "error": null,
    "handlers_added_in_this_work": [
      "POLICY_VERSION_SUBSTITUTION",
      "POLICY_DOWNGRADE",
      "UNAUTHORIZED_POLICY_REFERENCE",
      "POLICY_WEAKENING",
      "CROSS_TENANT_GRAPH_TRAVERSAL",
      "CROSS_TENANT_PROVENANCE_ACCESS",
      "TRUST_STATE_REPLAY",
      "TRUST_VERSION_MISMATCH",
      "COUNTERFACTUAL_MANIPULATION",
      "FAKE_POSITIVE_EVIDENCE",
      "CROSS_TENANT_EVIDENCE_ACCESS"
    ],
    "handlers_added_results": {
      "COUNTERFACTUAL_MANIPULATION": "ATTACK_BLOCKED",
      "CROSS_TENANT_EVIDENCE_ACCESS": "ATTACK_BLOCKED",
      "CROSS_TENANT_GRAPH_TRAVERSAL": "ATTACK_BLOCKED",
      "CROSS_TENANT_PROVENANCE_ACCESS": "ATTACK_BLOCKED",
      "FAKE_POSITIVE_EVIDENCE": "ATTACK_BLOCKED",
      "POLICY_DOWNGRADE": "ATTACK_BLOCKED",
      "POLICY_VERSION_SUBSTITUTION": "ATTACK_BLOCKED",
      "POLICY_WEAKENING": "ATTACK_BLOCKED",
      "TRUST_STATE_REPLAY": "ATTACK_BLOCKED",
      "TRUST_VERSION_MISMATCH": "ATTACK_BLOCKED",
      "UNAUTHORIZED_POLICY_REFERENCE": "ATTACK_BLOCKED"
    },
    "schema_init": {
      "adversarial_engine.init_adversarial_tables": "ok",
      "fabric_control_plane.init_db": "ok",
      "security_context.init_security_context_tables": "ok",
      "trust_graph.init_trust_graph_tables": "ok"
    },
    "total": 114
  },
  "bundle_sha256": "a0b61c6ba6abe55b36312feac3bff05de67aeb40448bf45f7c9b442a018329b3",
  "claims": [
    {
      "claim": "cainbench: an uncompilable regex checker registered with HTTP 200 and would 500 the run; now rejected at registration and fails closed at check time",
      "supported": true,
      "tests": {
        "tests/test_cainbench.py::test_check_bad_regex_fails_closed_instead_of_raising": "PASSED",
        "tests/test_cainbench.py::test_upsert_rejects_uncompilable_regex_at_registration": "PASSED"
      }
    },
    {
      "claim": "trust_state.compute_trust_deterministic works on a schema built from the modules' own init functions (it selected a column no schema defines and read tables nothing creates)",
      "supported": true,
      "tests": {
        "tests/test_trust_state_fresh_schema.py::test_computes_from_real_decision_rows": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_no_evidence_is_unknown_not_error": "PASSED"
      }
    },
    {
      "claim": "missing negative-evidence sources are disclosed and cap the state below TRUSTED; TRUSTED remains reachable when the sources exist (control); unrelated DB errors still raise",
      "supported": true,
      "tests": {
        "tests/test_trust_state_fresh_schema.py::test_missing_negative_evidence_sources_are_disclosed": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_never_trusted_when_negative_evidence_sources_are_missing": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_trusted_is_reachable_when_sources_present": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_unrelated_operational_errors_still_raise": "PASSED"
      }
    },
    {
      "claim": "a cached trust state is recomputed when newer decisions exist, and reused when none do",
      "supported": true,
      "tests": {
        "tests/test_trust_state_fresh_schema.py::test_cached_state_is_recomputed_when_newer_evidence_exists": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_cached_state_is_reused_when_no_newer_evidence": "PASSED"
      }
    },
    {
      "claim": "trust_version bumps only on material change and the returned value is the stored one",
      "supported": true,
      "tests": {
        "tests/test_trust_state_fresh_schema.py::test_returned_version_is_the_stored_version_and_bumps_only_on_change": "PASSED"
      }
    },
    {
      "claim": "verify_trust_snapshot rejects replayed, forged and version-mismatched snapshots and accepts the fresh one",
      "supported": true,
      "tests": {
        "tests/test_trust_state_fresh_schema.py::test_forged_snapshot_not_derivable_from_evidence_is_rejected": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_fresh_snapshot_verifies": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_replayed_snapshot_from_before_the_violations_is_rejected": "PASSED",
        "tests/test_trust_state_fresh_schema.py::test_version_mismatch_is_rejected_even_when_state_matches": "PASSED"
      }
    },
    {
      "claim": "trust attack types were mapped to the IDENTITY runner and stayed INCONCLUSIVE; they now reach the trust runner through the suite dispatch",
      "supported": true,
      "tests": {
        "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_attacks_are_reachable_through_the_suite_dispatch[TRUST_STATE_REPLAY]": "PASSED",
        "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_attacks_are_reachable_through_the_suite_dispatch[TRUST_VERSION_MISMATCH]": "PASSED"
      }
    },
    {
      "claim": "a real escape from the new handlers survives execute_attack's honesty guard (previously such a result would have been downgraded to INCONCLUSIVE)",
      "supported": true,
      "tests": {
        "tests/test_adversarial_policy_binding_attacks.py::test_counterfactual_escape_survives_execute_attack": "PASSED",
        "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_escape_survives_execute_attack": "PASSED",
        "tests/test_adversarial_policy_binding_attacks.py::test_policy_escape_survives_execute_attack": "PASSED"
      }
    },
    {
      "claim": "predictive recommendation: critical unknowns can no longer be overwritten by a caller-supplied trusted+low into 'allow'; allow stays reachable with complete evidence (control)",
      "supported": true,
      "tests": {
        "tests/test_adversarial_policy_binding_attacks.py::test_counterfactual_manipulation_blocked_with_positive_control": "PASSED",
        "tests/test_adversarial_policy_binding_attacks.py::test_unknown_never_becomes_allow_even_with_claimed_trust": "PASSED"
      }
    },
    {
      "claim": "each new handler reports BLOCKED only after a positive control passes, INCONCLUSIVE if the control fails, SUCCEEDED if the defence is bypassed",
      "supported": true,
      "tests": {
        "tests/test_adversarial_policy_binding_attacks.py::test_accepting_verifier_is_reported_as_succeeded": "PASSED",
        "tests/test_adversarial_policy_binding_attacks.py::test_broken_control_is_inconclusive_not_blocked": "PASSED",
        "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_leak_is_reported_as_succeeded": "PASSED",
        "tests/test_adversarial_policy_binding_attacks.py::test_trust_attack_broken_control_is_inconclusive": "PASSED"
      }
    }
  ],
  "generated_at": "2026-09-21T15:52:29Z",
  "not_claimed": [
    "not production-ready; PRE-PRODUCTION",
    "single host, single process, no Byzantine cluster result",
    "the signing key is held by the same author: this is integrity since signing, not independent review",
    "no third party has reviewed this work",
    "the adversarial suite is not proof of security; it reports which implemented attacks were blocked",
    "the number of attack types (114) is what the engine enumerates, not a security score",
    "nothing here has been deployed by this bundle's author; deployment is a separate step"
  ],
  "open_findings": [
    "evidence_store.retrieve(evidence_id) takes no tenant argument (no non-test caller found); CROSS_TENANT_EVIDENCE_ACCESS covers only the tenant-scoped fabric_decisions accessors",
    "trust_graph.create_edge never persists the edge valid_until column, so binding expiry cannot be created through the API and the verifier's expiry branch is not exercised",
    "trust_graph defines predictive_trust_decision twice; the later definition is the live one",
    "16 attack types are listed under one category but mapped to another in _attack_type_to_category; several are deliberate, none were audited",
    "policy-binding handlers leave revoked fixture edges per worker cycle (revoked, not deleted); the cross-tenant and trust fixtures are reused",
    "several pre-existing verifiers are weak (for example _verify_tenant_isolation returns valid on exception); their BLOCKED results were not re-derived",
    "IDENTITY_CONTEXT_MISMATCH became BLOCKED because another session edited adversarial_engine.py; that change is not part of this work",
    "the wide regression run over every test file touching these modules was NOT re-run after the last handler edits (a run was interrupted); earlier runs of those files passed, and one file (test_adversarial_engine_evidence_handlers.py) failed once and then passed four times: cause unknown",
    "the statements about the production gateway.db (missing column and tables) were observed in-session on a read-only copy and cannot be reproduced from this bundle",
    "AGENTS.md figures (398/398 tests, 120/120 vectors, 200 invariants) were not re-verified"
  ],
  "repo_head": "6a773a6a2b6b800b60b987c7e33abdaf563764e7",
  "reproduce": [
    "git checkout <repo_head>",
    "python3 scripts/build_frontier_trust_bundle.py",
    "python3 scripts/verify_frontier_trust_bundle.py CAIN42_FRONTIER_TRUST_ENGINE_BUNDLE.json --files ."
  ],
  "schema": "cain42.frontier_trust_engine_bundle.v1",
  "signature": {
    "alg": "ed25519",
    "over": "bundle_sha256 (hex, ascii)",
    "public_key_b64": "70nbNHoJwhWrpFSqivAjaPwZypXtMNR6Wu1/1PnQOy4=",
    "signature_b64": "DyrZiJW8ZWqhfnH7m4qUhBoP+Y3hFfNmqmMZckXeEOOX7cJaDUCz9qjI07ezHLRtBRZa55dfRoRIWTSWios2Cg==",
    "signer_note": "key held by the same author; integrity since signing, not independent review"
  },
  "sources": [
    {
      "last_commit": "6a773a6",
      "modified_vs_HEAD": false,
      "path": "platform-gateway/trust_state.py",
      "sha256": "d4e5954e39849f9cc1d79f30356a01de764a216744696a9eba8021acfe9fa92f"
    },
    {
      "last_commit": "6a773a6",
      "modified_vs_HEAD": true,
      "path": "platform-gateway/adversarial_engine.py",
      "sha256": "170a03cef8feb5cbc973491700f2d0f3a487b6fdba01e93a5c5aba708da4c4c6"
    },
    {
      "last_commit": "4cee2db",
      "modified_vs_HEAD": true,
      "path": "platform-gateway/trust_graph.py",
      "sha256": "79e5fe3942c2c338eb042c33f768b9b5faba8dc35efff25346a5475150f8b584"
    },
    {
      "last_commit": "9cfe1a5",
      "modified_vs_HEAD": false,
      "path": "cainbench/main.py",
      "sha256": "7625c5613a1b164ef58388d6952eedd04c662d82e13d0f3a0d9f2f7136c30a54"
    },
    {
      "last_commit": "9cfe1a5",
      "modified_vs_HEAD": false,
      "path": "platform-gateway/cain_adversarial_worker.py",
      "sha256": "9d6217f25c47a67c14b01a171b2e0470981ce1db40687f6e05c3cd709084a61e"
    }
  ],
  "status": "PRE-PRODUCTION",
  "test_outcomes": {
    "tests/test_adversarial_policy_binding_attacks.py::test_accepting_verifier_is_reported_as_succeeded": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_blocked_with_positive_control[POLICY_DOWNGRADE]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_blocked_with_positive_control[POLICY_VERSION_SUBSTITUTION]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_blocked_with_positive_control[POLICY_WEAKENING]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_blocked_with_positive_control[UNAUTHORIZED_POLICY_REFERENCE]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_broken_control_is_inconclusive_not_blocked": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_counterfactual_escape_survives_execute_attack": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_counterfactual_leak_is_reported_as_succeeded": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_counterfactual_manipulation_blocked_with_positive_control": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_blocked_with_positive_control[CROSS_TENANT_GRAPH_TRAVERSAL]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_blocked_with_positive_control[CROSS_TENANT_PROVENANCE_ACCESS]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_escape_survives_execute_attack": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_evidence_blocked_with_positive_control": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_evidence_leak_is_a_reported_escape": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_fixture_is_reused_not_accumulated[CROSS_TENANT_GRAPH_TRAVERSAL]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_fixture_is_reused_not_accumulated[CROSS_TENANT_PROVENANCE_ACCESS]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_leak_is_reported_as_succeeded": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_cross_tenant_same_tenant_is_inconclusive": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_fake_positive_events_are_capped_and_actually_written": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_fake_positive_evidence_blocked_with_positive_control": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_fake_positive_evidence_that_moves_trust_is_a_reported_escape": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_fixture_edges_are_revoked_afterwards[POLICY_DOWNGRADE]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_fixture_edges_are_revoked_afterwards[POLICY_VERSION_SUBSTITUTION]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_fixture_edges_are_revoked_afterwards[POLICY_WEAKENING]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_fixture_edges_are_revoked_afterwards[UNAUTHORIZED_POLICY_REFERENCE]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_policy_escape_survives_execute_attack": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_replay_snapshot_was_genuinely_more_favourable": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_attack_accepting_verifier_is_reported_as_succeeded[TRUST_STATE_REPLAY]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_attack_accepting_verifier_is_reported_as_succeeded[TRUST_VERSION_MISMATCH]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_attack_broken_control_is_inconclusive": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_fixture_is_reused_not_accumulated[TRUST_STATE_REPLAY]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_fixture_is_reused_not_accumulated[TRUST_VERSION_MISMATCH]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_attack_blocked_with_positive_control[TRUST_STATE_REPLAY]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_attack_blocked_with_positive_control[TRUST_VERSION_MISMATCH]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_attacks_are_reachable_through_the_suite_dispatch[TRUST_STATE_REPLAY]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_attacks_are_reachable_through_the_suite_dispatch[TRUST_VERSION_MISMATCH]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_escape_survives_execute_attack[TRUST_STATE_REPLAY]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_trust_snapshot_escape_survives_execute_attack[TRUST_VERSION_MISMATCH]": "PASSED",
    "tests/test_adversarial_policy_binding_attacks.py::test_unknown_never_becomes_allow_even_with_claimed_trust": "PASSED",
    "tests/test_cainbench.py::test_check_bad_regex_fails_closed_instead_of_raising": "PASSED",
    "tests/test_cainbench.py::test_check_contains_and_regex": "PASSED",
    "tests/test_cainbench.py::test_check_exact_strips_whitespace": "PASSED",
    "tests/test_cainbench.py::test_check_json_subset_fails_closed_on_non_dict": "PASSED",
    "tests/test_cainbench.py::test_check_unknown_type_is_400_not_pass": "PASSED",
    "tests/test_cainbench.py::test_diff_detects_regression_fix_and_stable": "PASSED",
    "tests/test_cainbench.py::test_diff_errors": "PASSED",
    "tests/test_cainbench.py::test_diff_missing_case_is_not_silently_ok": "PASSED",
    "tests/test_cainbench.py::test_run_records_pass_fail_and_request_failure_is_fail": "PASSED",
    "tests/test_cainbench.py::test_run_unknown_suite_404_and_run_time_rebind_blocked": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_allows_public": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_blocks_if_any_resolved_address_is_private": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_blocks_non_public[<redacted-private-ip>]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_blocks_non_public[127.0.0.1]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_blocks_non_public[169.254.169.254]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_blocks_non_public[<redacted-private-ip>]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_blocks_non_public[<redacted-private-ip>]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_blocks_non_public[::1]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_rejects_bad_scheme_or_host[file:///etc/passwd]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_rejects_bad_scheme_or_host[ftp://x.example.com]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_rejects_bad_scheme_or_host[http://]": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_rejects_bad_scheme_or_host[not": "PASSED",
    "tests/test_cainbench.py::test_ssrf_guard_unresolvable_host_rejected": "PASSED",
    "tests/test_cainbench.py::test_upsert_rejects_empty_and_bad_checker": "PASSED",
    "tests/test_cainbench.py::test_upsert_rejects_internal_target": "PASSED",
    "tests/test_cainbench.py::test_upsert_rejects_uncompilable_regex_at_registration": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_cached_state_is_recomputed_when_newer_evidence_exists": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_cached_state_is_reused_when_no_newer_evidence": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_computes_from_real_decision_rows": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_forged_snapshot_not_derivable_from_evidence_is_rejected": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_fresh_snapshot_verifies": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_malformed_snapshot_is_rejected[None]": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_malformed_snapshot_is_rejected[bad1]": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_malformed_snapshot_is_rejected[bad2]": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_malformed_snapshot_is_rejected[bad4]": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_malformed_snapshot_is_rejected[trusted]": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_missing_negative_evidence_sources_are_disclosed": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_never_trusted_when_negative_evidence_sources_are_missing": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_no_evidence_is_unknown_not_error": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_replayed_snapshot_from_before_the_violations_is_rejected": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_returned_version_is_the_stored_version_and_bumps_only_on_change": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_tenant_isolation_of_computation": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_trusted_is_reachable_when_sources_present": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_unrelated_operational_errors_still_raise": "PASSED",
    "tests/test_trust_state_fresh_schema.py::test_version_mismatch_is_rejected_even_when_state_matches": "PASSED"
  },
  "test_runs": [
    {
      "file": "tests/test_cainbench.py",
      "returncode": 0,
      "seconds": 2.65,
      "sha256": "3c387a79e01647408140fa3dece87f6a674afd0f3349a2239aedced068587983",
      "summary": "============================== 26 passed in 0.95s =============================="
    },
    {
      "file": "tests/test_adversarial_policy_binding_attacks.py",
      "returncode": 0,
      "seconds": 3.96,
      "sha256": "24d9da68531c3d4fe487ddac8853dc778835b8d5b4ae46ff5877d32f5d8e0d31",
      "summary": "============================== 39 passed in 2.35s =============================="
    },
    {
      "file": "tests/test_trust_state_fresh_schema.py",
      "returncode": 0,
      "seconds": 3.31,
      "sha256": "0b359e30de1c98ae6d34be835e094f1090007154da4268a022bbf890bdb7f3f1",
      "summary": "============================== 19 passed in 1.92s =============================="
    }
  ]
}