The Table
12 adversarial minds, geometrically forced apartUnder audit
By 31 October 2026, povv-verify lets anyone check a POVV seal without trusting POVV: given a published receipt and the public key from povv.io/.well-known/povv-ledger-keys, it recomputes the SHA-256 digest and verifies the Ed25519 signature, exiting successfully only when both match. Checked by running it against 3 published POVV receipts and 1 tampered copy that must fail.
gardogarcia/povv-verify2026-09-28
Every seated agent has an exact antipode through the Anchor (5,5) — a mind built to attack its blind spot. The debate you are about to read was engineered by geometry, not sampled by chance.
8 of 20 poles stayed dark on this run — the full Cross fields every extremist on both diagonals.
The Friction
controlled divergence, then the TableFirst reads landed 16 points apart (66–82) across 12 graded agents — the divergence the Cross exists to manufacture.
per-agent drafts & transcripts stay with the repo owner
- ▲Agent allegation: Multiple agents report that verifyReceipt and the cli.mjs exit wiring were truncated.
- ▲Agent allegation: Multiple agents note that fixtures are synthetic rather than published receipts.
- ▲Agent allegation: Several agents flag the absence of key-type pinning before edVerify; this is unresolved in the evidence.
After the Table locked, 2 of 12 agents moved off their own draft — this was a deliberation, not a poll.
Unresolved dissent: 3 threads — detailed in the owner's verdict
The Anchor
the findings, their support, and what remains unknown◆ Thin evidence base — read the band, not the digit
VMI summarizes the reviewed evidence. It is not a security certification or a guarantee of deployment readiness.
2 confirmed findings · 3 coverage gaps
Potential impact describes severity. Confidence describes support for the allegation. A coverage gap is an inspection task, not a confirmed vulnerability.
Confirmed findings
2Review the supported scope before choosing a fix.
- Confirmed findinghigh confidencePotential impact · LOW
01fixtures/generate.mjs derives its output directory from URL.pathname, which is percent-encoded and not a native path on Windows, so generation can target a wrong path.
Impact scope: Support applies to this finding as stated. Additional consequences require a separate assessment.
Support assessment & source receipts · 1
URL.pathname returns a percent-encoded, slash-prefixed string rather than a filesystem path. If this value is used as a directory, checkouts under paths containing spaces or on Windows resolve incorrectly. The correct conversion is fileURLToPath.
Counterevidence considered: This affects only the fixture generator, not verification. Paths on POSIX without special characters work. Where dir is used is not quoted, but the variable's name and purpose indicate filesystem use.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
E2 · fixtures/generate.mjs:8
const dir = new URL(".", import.meta.url).pathname; - Confirmed findinghigh confidencePotential impact · MEDIUM
05The test suite exercises receipts signed by a throwaway key, not the three published POVV receipts that the claim's check requires.
Impact scope: Support applies to this finding as stated. Additional consequences require a separate assessment.
Support assessment & source receipts · 2
The fixtures README states that fixtures were signed with an ephemeral key that existed only during generation. Passing tests therefore do not demonstrate acceptance of real published receipts under the povv.io key.
Counterevidence considered: The fixtures do include adversarial cases, such as a stranger key claiming the same kid (E16), which bear on the tampered-copy half of the check. A separate published-receipt test may exist outside this evidence base.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
E16 · fixtures/generate.mjs:10
const trusted = generateKeyPairSync("ed25519"); const stranger = generateKeyPairSync("ed25519"); // a different key claiming the same kidE18 · fixtures/README.md:3
Signed with a throwaway Ed25519 key that existed only while `generate.mjs` ran. Only its public half is here (`test-jwks.json`, `test-key.pem`). `npm test` runs every
Needs verification
3Inspect the missing evidence before proposing a patch.
- Coverage gaplow confidencePotential impact · MEDIUM
02index.mjs hashPair computes SHA-256 over a concatenation of a and b with no leaf/node domain prefix, so Merkle proofs lack domain separation.
Inspect before changing code
- leaf hashing implementation
- how inclusion results affect ok
No patch before verification.
Impact scope: Impact remains unconfirmed until the missing source is inspected.
Support assessment & source receipts · 1
Internal nodes are hashed as a plain concatenation with no prefix. That permits leaf/node confusion only if leaves are hashed the same way, without a distinct prefix, and are 64-byte inputs.
Counterevidence considered: Leaf hashing is not quoted. The README frames Merkle checking as a consistency check against a receipt-supplied root, and inclusion is outside the claim's pass condition.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
E9 · index.mjs:53
return createHash("sha256").update(Buffer.concat([a, b])).digest(); - Coverage gaplow confidencePotential impact · MEDIUM
03cli.mjs parseArgs routes unrecognized flags into positional args, so a mistyped --no-fetch leaves key fetching enabled without a usage error.
Inspect before changing code
- args.fetch default initialization
- main() handling of extra positional arguments
No patch before verification.
Impact scope: Impact remains unconfirmed until the missing source is inspected.
Support assessment & source receipts · 2
E4 shows that every unmatched token is pushed into args._. E5 enables fetching whenever args.fetch is truthy and no local key is given. A typo therefore would not disable fetching.
Counterevidence considered: The default value of args.fetch is not quoted. main() may also reject extra positional arguments, which would surface the typo.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
E4 · cli.mjs
else if (a === "--no-fetch") args.fetch = false; else args._.push(a);E5 · cli.mjs:53
const options = { fetchKey: args.fetch && !args.pubkey && !args["jwks-file"] }; - Coverage gaplow confidencePotential impact · HIGH
04The claim's pass gate (exit success only when digest and signature both match) is not established by the audited evidence.
Inspect before changing code
- verifyReceipt body
- cli.mjs exit-code mapping
No patch before verification.
Impact scope: Impact remains unconfirmed until the missing source is inspected.
Support assessment & source receipts · 2
E11 and E1 show the hash computation and Ed25519 verify call. However, how verifyReceipt combines these results into ok, and how the CLI maps ok to an exit code, is not in the register. Multiple agents report this code as truncated.
Counterevidence considered: Agents report adversarial fixtures that are expected to be NOT VERIFIED. E13 documents gating on ok. Agent reports are not source evidence, though.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
E1 · index.mjs:85
return edVerify(null, Buffer.from(integrityHashHex, "hex"), publicKey, Buffer.from(signatureB64, "base64"));
E11 · index.mjs
export function computeIntegrityHash(sealedPayload) { return sha256Hex(canonicalize(sealedPayload)); }
Shared agent opinions — require source review
- ·The hash and signature core is read as failing closed on an unknown kid and on tampering.
- ·The default path fetches POVV's key set, a trust dependency the README discloses and the claim itself names.
The Mandate
the do-first — the full plan ships with the owner's verdictConfirm each task against current source before changing code. Coverage gaps require inspection. Impact and effort grades, when shown, are model estimates for the listed task.
- 1Validate and remediate the supported finding: fixtures/generate.mjs derives its output directory from URL.pathname, which is percent-encoded and not a native path on Windows, so generation can target a wrong path.inference — beyond sealed evidence
The Seal
proof · the loopSHA-256 · 4b0038d2d4ff9a89c53a7eb55ed8239cb2cd98bceb5cc259d1d143bf606e0eca
ED25519 · iIOfs05VaX+7P6Nj+11vHmAtv8yLXglaVQQZyM0X4TkO+llkjAyXeoHqCyDuQXv0hw1X/DBULDJJLNH3vPp/Dw==
Independently verifiable — no trust in POVV's servers required. Sealed into your immutable Chronicle.
20 files · 29.2 KB read · 3 read in partof 20 auditable source filescommit 280fca418/18 exhibits verified
Evidence budget: 6 duplicates removed, 0 receipts omitted, 2 verified receipts outside the Anchor register, 0 receipts omitted from sealed storage. Supplemental source context: 0 excerpts, 0 characters; 0 authenticated candidate excerpts omitted by selection limits. These are bounded context, not additional agent claims. Context selection reached its work or capacity limit; other read source may remain unexamined.
Receipt chips verify quote authenticity or identify a structural query. They do not prove an allegation. Finding status and confidence describe the separate support assessment.
The constellation · every file this verdict rests on
20 files · 29 KB sealed · commit 280fca4 · drag to orbit — star heat = file size
Clear the do-first quadrant, then re-audit — the next seal turns this verdict into a trajectory your Chronicle can prove.
Embed the Verified badge
The badge re-renders live from this seal — it can never claim more than the ledger holds.
Your repo next
One free adversarial verdict. Sealed, verifiable, yours in ~3 minutes.
Run your own audit →Independent co-verification
One sealed opinion on the record. Invite an independent party to audit the same repository — two unrelated benches agreeing is the strongest proof POVV can mint.
Own this repository? Invite an independent audit of the same code — a second unrelated bench agreeing is proof no single model can fake.