Check the claims
The chain of agents: the public proofs
What you can check of my chain-of-agents test without opening the part I'm keeping closed for safety. Everything here is a file you can download and check yourself.
The claim, and its two labels
A false "done" passed down a chain of agents: a builder, a reviewer and a release manager. Three hops, 90 jobs, 60 of them carrying a false "done". The rule it tests: an upstream "done" is not evidence.
- Not shown: withheld for safety. The agent prompts, the planted faults, the order of the hops, and anything that gets around the check. Published, they would shorten the path from reading to misuse, before checks like this are common.
- Not shown: files to come. The run records, with the 90 jobs and the 60 false "done"s. They hold the closed half, and each of my seals covers a whole file, so they can't be opened in part. Future runs will seal each record on its own, so one record can be opened and checked while the rest stay closed.
The five sealed lists
Each list holds the SHA-256 fingerprints of the files it covers. TOKENS.txt prints what each token says.
The hosted run's plan. It covers the test pack's 14 files: the specs, the models, the rules and the item files.
Stamped by FreeTSA at 03:07:46 GMT on 6 October 2026. The list: PACK-SHA256.txt. Its token: the reply and the request. The list's SHA-256, which must equal the digest inside its token:
1a6c3f28319333cbbc70372a8df25b5a04347ec3717443d2d98833145f585971The answer key: the planted truth for each item, stamped before the hosted results.
Stamped by FreeTSA at 03:07:47 GMT on 6 October 2026. The list: KEYS-SHA256.txt. Its token: the reply and the request. The list's SHA-256, which must equal the digest inside its token:
88d766355e9ec2558b5514c68ae8302ea598ec6b8783ce2f24a81a0ed9d31a1cThe hosted run's results. It covers the results manifest, published here too, which lists the run's calls, order and runner by fingerprint.
Stamped by FreeTSA at 04:10:43 GMT on 6 October 2026. The list: S2-RESULTS-SHA256.txt. Its token: the reply and the request. The list's SHA-256, which must equal the digest inside its token:
ee452cb46489da860c1fd5f1e7abed56e4f1ed780ad4c83147875352cf127bc5The run on my PC, its plan: the design, the runner, the scorer, the items and the checker's code (15 files).
Stamped by FreeTSA at 09:08:24 GMT on 6 October 2026, and anchored in Bitcoin block 970158. The list: DESIGN-SHA256.txt. Its token: the reply and the request. Its Bitcoin proof: DESIGN-SHA256.txt.ots. The list's SHA-256, which must equal the digest inside its token:
dbf4c73410b9d3f8784f0adf19d99957b03eaf8667cea92c63abbba7e2384985The run on my PC, its results: the three result files.
Stamped by FreeTSA at 13:30:22 GMT on 6 October 2026, and anchored in Bitcoin block 970180. The list: RESULTS-SHA256.txt. Its token: the reply and the request. Its Bitcoin proof: RESULTS-SHA256.txt.ots. The list's SHA-256, which must equal the digest inside its token:
7804aef2bcd021adca2fdf1bf227127f1d22857ab8e373f515f6ff2e6d79400f
Check them yourself
- A token. Download
cacert.pemandtsa.crtfrom freetsa.org, then runopenssl ts -verify -in PACK-SHA256.txt.tsr -data PACK-SHA256.txt -CAfile cacert.pem -untrusted tsa.crt. It should print "Verification: OK". A warning thattsa.crtisn't a CA certificate is normal for FreeTSA. - A Bitcoin proof. Each proof names its block. Run
ots upgrade, thenots verifywith a Bitcoin node, or upload the file and its proof at opentimestamps.org. Entries marked pending are calendars that didn't answer; they don't cancel the blocks.
How it was scored
The scoring rule, as a description. The sealed scorer itself is fingerprinted in the PC plan's list and not published. A chain that always says "done" releases 60 of 60 false claims, and one that always holds releases 0 of 30 true ones, so neither can pass.
The binding-gate figure (4 of 60 false claims let through, 9 of 30 true ones held back) was computed after the results seal, from the same sealed records. It was not a sealed prediction.
What these files don't show
- That the lists match the closed files.
- That the record holds 90 jobs and 60 false "done"s. Those counts are in the scoring note, not in a file these seals can open.
- That the answer key was fixed before the first model call. Its list was stamped before the hosted results list.
- That the scoring note is the sealed scorer.
- The redacted hop is an illustration, not a receipt.
What they do show: the five lists existed, unchanged, at their stamped times, and two of them are anchored in Bitcoin.