{ "schema": "argonautworks.frantic_evidence.v1", "bounty": 68, "summary": "ArgonautWorks published and dogfooded list-hygiene-judge, a Runx 0.8.2 graph skill that reads a contact projection, records at most one compare-and-set consent transition, reads it back, and never sends. The public package, exact PR source, eight-case harness, production-signed post-publish receipt tree, independent verifier verdict, and operator report are all linked here.", "package": { "owner": "argonautworks", "name": "list-hygiene-judge", "version": "0.1.0", "registry_ref": "argonautworks/list-hygiene-judge@0.1.0", "registry_digest": "sha256:535eacd9b775a820ae2fe4b51872cb473f58e837a4f463bbcc47752bfa67c598", "profile_digest": "sha256:ff05ba1f238dcbcda6e0f87690a15c05f03b16083fcb13e0066f7e50119301fb", "public_url": "https://runx.ai/x/argonautworks/list-hygiene-judge@0.1.0" }, "source": { "revision": "a92103ee690beb068a4cb4b0af0d919f439ba06c", "source_url": "https://github.com/ArgonautWorks/runx/tree/a92103ee690beb068a4cb4b0af0d919f439ba06c/skills/list-hygiene-judge", "pr_url": "https://github.com/runxhq/runx/pull/383", "x_yaml": "https://raw.githubusercontent.com/ArgonautWorks/runx/a92103ee690beb068a4cb4b0af0d919f439ba06c/skills/list-hygiene-judge/X.yaml", "skill_md": "https://raw.githubusercontent.com/ArgonautWorks/runx/a92103ee690beb068a4cb4b0af0d919f439ba06c/skills/list-hygiene-judge/SKILL.md" }, "runx_version": "runx-cli 0.8.2", "publish": { "method": "purpose-scoped GitHub publish credential created by runx login --provider github --from-gh --for publish", "command": "runx registry publish ./skills/list-hygiene-judge/SKILL.md --registry https://api.runx.ai --version 0.1.0 --json", "status": "published", "owner": "argonautworks", "trust_tier": "community", "hosted_harness_status": "passed; the hosted registry publish gate completed and returned status published" }, "install": { "command": "runx add argonautworks/list-hygiene-judge@0.1.0 --registry https://api.runx.ai --digest 535eacd9b775a820ae2fe4b51872cb473f58e837a4f463bbcc47752bfa67c598 --to --json", "status": "installed", "clean_destination": true, "post_install_inspect": "ready", "runner_names": ["decide", "finalize", "judge"] }, "harness": { "command": "runx harness ./skills/list-hygiene-judge -R --json", "status": "passed", "case_count": 8, "assertion_error_count": 0, "cases": [ {"name": "sealed_decay_re_permission", "status": "sealed", "decision_state": "re_permission", "append_event_count": 1}, {"name": "sealed_hard_bounce_suppress", "status": "sealed", "decision_state": "suppress", "append_event_count": 1}, {"name": "stop_missing_or_stale_evidence", "status": "sealed", "decision_state": "human_review", "append_event_count": 0}, {"name": "stop_active_unsubscribe_marker", "status": "sealed", "decision_state": "human_review", "append_event_count": 0}, {"name": "reject_negative_engagement_metrics", "status": "refused", "append_event_count": 0}, {"name": "list-hygiene-decay-re-permission", "status": "sealed", "decision_state": "re_permission", "append_event_count": 1}, {"name": "list-hygiene-hard-bounce-suppress", "status": "sealed", "decision_state": "suppress", "append_event_count": 1}, {"name": "list-hygiene-stale-evidence-stops-without-append", "status": "sealed", "decision_state": "human_review", "append_event_count": 0} ] }, "dogfood": { "package": "argonautworks/list-hygiene-judge@0.1.0", "input": { "data_source_ref": "local://frantic-68/production-dogfood-a92103ee", "resource": "contact_consent_events", "aggregate_id": "contact:frantic-68:production-dogfood-a92103ee", "expected_version": 0, "idempotency_key": "contact:frantic-68:production-dogfood-a92103ee:consent:v1", "engagement_history": {"opens_count": 2, "clicks_count": 1, "hard_bounces": 1, "recency_days": 12}, "bounce_policy": {"hard_bounce_action": "suppress", "decay_threshold_days": 90}, "current_consent_state": {"state": "subscribed", "active_unsubscribe_marker": false, "evidence_status": "read", "evidence_version": 0} }, "command": "runx skill argonautworks/list-hygiene-judge@0.1.0 judge --registry https://api.runx.ai --digest 535eacd9b775a820ae2fe4b51872cb473f58e837a4f463bbcc47752bfa67c598 --inputs --non-interactive -R --json", "status": "sealed", "run_id": "run_judge_191d142687eb1ce4", "receipt_ref": "runx:receipt:sha256:1010ba48683038cb815b8efc0b8a74d2a86dfa0e1988c717743e1f6126d5e475", "receipt_path": "receipts/sha256-1010ba48683038cb815b8efc0b8a74d2a86dfa0e1988c717743e1f6126d5e475.json", "output_path": "dogfood-output.json", "verify_command": "RUNX_RECEIPT_VERIFY_KID=runx-demo-key RUNX_RECEIPT_VERIFY_ED25519_PUBLIC_KEY_BASE64=IVL40Zt5HSRFMkLhXy6rbLfP+ntqXtMAl5YOBpiB2xI= runx verify --receipt receipts/sha256-1010ba48683038cb815b8efc0b8a74d2a86dfa0e1988c717743e1f6126d5e475.json --json", "verify_verdict": { "schema": "runx.verify_verdict.v1", "valid": true, "digest": "valid", "content_address": "valid", "signature": {"mode": "production", "status": "valid", "kid": "runx-demo-key"}, "findings": [] }, "tree_verify_verdict": {"valid": true, "signature_mode": "production", "receipt_count": 6, "parent_missing": null, "findings": []}, "harness_cases": [ {"name": "sealed_decay_re_permission", "status": "sealed"}, {"name": "sealed_hard_bounce_suppress", "status": "sealed"}, {"name": "stop_missing_or_stale_evidence", "status": "sealed"}, {"name": "reject_negative_engagement_metrics", "status": "refused"} ] }, "observations": [ {"id": "cli_version", "finding": "All final inspect, harness, publish, install, dogfood, and verification commands used runx-cli 0.8.2, which is newer than the required 0.6.14.", "evidence": "runx --version => runx-cli 0.8.2"}, {"id": "public_registry", "finding": "The live registry resolves argonautworks/list-hygiene-judge@0.1.0 with the submitted digest and ArgonautWorks as publisher.", "evidence": "runx registry read argonautworks/list-hygiene-judge@0.1.0 --registry https://api.runx.ai --json => success"}, {"id": "clean_install", "finding": "A digest-pinned install into a newly created temporary directory succeeded and the installed graph inspected as ready with no unresolved skill edges.", "evidence": "runx add returned status installed; post-install inspect returned status ok/readiness ready"}, {"id": "hosted_harness", "finding": "The registry's hosted publish gate accepted the package and published it after the package harness passed.", "evidence": "registry publish returned status success/published for 0.1.0"}, {"id": "consent_state_verdict", "finding": "The post-publish real input produced decision.state suppress because verified hard-bounce evidence requires suppression.", "evidence": "dogfood-output.json decision.state=suppress and reason=verified hard-bounce evidence requires suppression"}, {"id": "recorded_transition", "finding": "The dogfood append recorded new_state suppress for contact:frantic-68:production-dogfood-a92103ee with the supplied stable idempotency key, then read projection version 1 back.", "evidence": "dogfood-output.json recorded_transition state=suppress, before_version=0, after_version=1, recorded=true"}, {"id": "suppress_resource_binding", "finding": "The hard-bounce suppress decision is bound to data source local://frantic-68/production-dogfood-a92103ee and resource contact_consent_events.", "evidence": "dogfood input, append result, readback, and recorded_transition share the aggregate, data source, and resource"}, {"id": "stop_without_append", "finding": "The exact stop_missing_or_stale_evidence harness case returned human_review and emitted no append; active unsubscribe also stops without a write.", "evidence": "eight-case harness passed with zero assertion errors"}, {"id": "sealed_receipt", "finding": "The post-publish graph sealed as receipt sha256:1010ba48683038cb815b8efc0b8a74d2a86dfa0e1988c717743e1f6126d5e475 and its complete six-receipt tree is public in this repository.", "evidence": "receipt_ref=runx:receipt:sha256:1010ba48683038cb815b8efc0b8a74d2a86dfa0e1988c717743e1f6126d5e475"}, {"id": "independent_verification", "finding": "The root receipt and its full lineage verify with production-mode Ed25519 signatures using only Runx's documented public demo verification key; no signing seed or private credential is needed.", "evidence": "verification.json: single receipt valid=true; tree receipt_count=6 and valid=true"}, {"id": "send_boundary", "finding": "The skill never sends and never mints authority; downstream_send remains not_run and names send-as only as a future independent enforcer.", "evidence": "dogfood-output.json downstream_send.status=not_run"}, {"id": "current_data_contract", "finding": "The graph uses current native data.read_projection and data.append_event operations with expected_version and idempotency_key, then reads the projection back.", "evidence": "source X.yaml at revision a92103ee; dogfood trace steps read_contact, decide, append_transition, readback, finalize"} ], "verification_json": "verification.json in the same immutable evidence commit", "report": "report.md in the same immutable evidence commit", "safety": {"secrets_in_artifacts": false, "payments_or_wallets_touched": false, "outbound_messages_sent": false} }