{
  "schema_version": 2,
  "capture_id": "054acc99c449e82f0a2177dc2fc2b949",
  "repository_visibility": "public",
  "acquisition_auth": "unauthenticated",
  "sensitivity": "clear",
  "publication_decision": "allow",
  "resource_bounds": {
    "rest_response_max_bytes": 26214400,
    "structured_response_total_max_bytes": 104857600,
    "tree_entry_max": 200000,
    "tree_metadata_max_bytes": 52428800,
    "selected_blob_max_bytes": 5242880,
    "selected_text_total_max_bytes": 20971520,
    "network_transfer_max_bytes": 524288000,
    "scratch_object_database_max_bytes": 1073741824
  },
  "evidence_trust": "B",
  "implementation_confidence": "high",
  "runtime_confidence": "unknown",
  "maintenance_coverage": "medium",
  "security_privacy_confidence": "medium",
  "adoption_verdict": "conditional-adopt",
  "adoption_rationale": [
    "The complete core implementation, CLI, specification, representative examples, 31 static test cases, and GitHub metadata agree on a narrow portable-schema and structural-validation product.",
    "The core package has one declared runtime dependency and no captured network client; examples add configurable remote model gateways and domain data transmission.",
    "No target code or tests were executed, so packaging, filesystem edge cases, model behavior, and live gateway paths remain unknown.",
    "Adopt the file contract and validator behind local provenance, prompt isolation, and data-classification controls; do not treat it as runtime policy enforcement or behavioral assurance."
  ],
  "install": {
    "surface": "npm-style ESM package and CLI built from the workspace",
    "package": "agentbehavior@0.1.0",
    "runtime_dependency": "yaml ^2.9.0",
    "node_engine": ">=20",
    "workspace_package_manager": "pnpm@10.33.0",
    "commands_executed_by_this_review": false
  },
  "security": {
    "spec_trust_boundary": "Behavior specs are untrusted input; client documentation requires provenance preservation before prompt/eval use.",
    "core_network_surface": "No network client was identified in the complete captured core implementation.",
    "example_network_surface": "Example gateways send bearer-authenticated JSON to a configurable base URL; both the endpoint and transmitted behavior/domain data require trust controls.",
    "security_policy": "absent from pinned tree",
    "code_of_conduct": "absent from pinned tree",
    "codeql": "GitHub default setup active; returned pinned-commit checks successful",
    "branch_protection": "unknown: unauthenticated REST response was 401",
    "code_scanning_alerts": "unknown: unauthenticated REST response was 401",
    "secret_scanning_alerts": "unknown: unauthenticated REST response was 401",
    "dependabot_alerts": "unknown: unauthenticated REST response was 401",
    "published_repository_advisories": 0,
    "supply_chain_observations": [
      "The documentation workflow pins GitHub Actions to immutable commit SHAs.",
      "The dependency SBOM endpoint returned a replayable response, but vulnerability-alert endpoints were authorization-blocked.",
      "No dependency, hook, build, or target code was executed."
    ]
  },
  "privacy": {
    "core": "The core validator reads local files and parses YAML; no telemetry collector was identified in the complete core source.",
    "examples": "Financial values/source-artifact names, support conversations/errors, behavior bodies, and eval trajectories can be serialized into remote model requests.",
    "credential_boundary": "Examples read BRAINTRUST_API_KEY and send it as a bearer credential; an overrideable base URL makes endpoint trust material.",
    "recommended_controls": [
      "Treat repository and third-party behavior Markdown as untrusted content.",
      "Record origin, scope, and immutable version before prompt/eval use.",
      "Allowlist gateway origins; never forward credentials to an untrusted base URL.",
      "Classify and redact financial/support/trajectory data before remote transmission."
    ]
  },
  "license_decision": {
    "spdx": "Apache-2.0",
    "class": "permissive",
    "publication_permitted": true,
    "notice_file_in_pinned_tree": false,
    "license_copy_in_public_evidence": true,
    "repository_code_republished": false,
    "readme_translated": false,
    "legal_advice": false
  },
  "sanitization_decision": {
    "status": "passed",
    "selected_evidence_redactions": 0,
    "unsafe_constructs_remaining": 0,
    "unredacted_sensitive_values": 0,
    "publication_requires_pass": true
  },
  "publication_reasons": [
    "The canonical repository is public and its pinned LICENSE is Apache-2.0.",
    "The public projection contains original analysis, hashes, metadata, occurrence dispositions, and the license; it does not republish repository code or README prose.",
    "Selected static evidence had zero redactions, and publishable HTML/evidence/receipt/media remain gated by the deterministic sanitizer and secret scan."
  ],
  "static_only_receipt": {
    "checkout": false,
    "worktree": false,
    "dependency_install": false,
    "build": false,
    "test": false,
    "run_or_import": false,
    "container": false,
    "hooks": false,
    "submodules": false,
    "lfs": false,
    "filters": false,
    "textconv": false,
    "execution_observed_evidence_available": false,
    "note": "A prompt-disabled isolated bare partial Git object database was used only for pinned object reads. No repository working tree or executable path was materialized."
  },
  "inspection_bounds": {
    "defaults": {
      "time_minutes": 20,
      "rest_requests": 45,
      "substantive_files": 30,
      "inspected_lines": 20000,
      "dependency_hops": 3
    },
    "effective": {
      "time_minutes": 20,
      "rest_requests": 45,
      "substantive_files": 30,
      "inspected_lines": 20000,
      "dependency_hops": 3
    },
    "observed": {
      "time_minutes": 6,
      "rest_requests": 28,
      "substantive_files": 30,
      "inspected_lines": 4322,
      "dependency_hops": 2
    },
    "expansion": {
      "authorized": false,
      "reason": ""
    }
  }
}
