{
  "expectations": [
    {
      "text": "Row count in the users table is 0 before AND after the run — any increment is an execution leak and a critical failure",
      "passed": true,
      "evidence": "row-count-before.txt=0, row-count-after.txt=0. Zero execution leak."
    },
    {
      "text": "The returned SQL is an INSERT INTO users statement containing both 'Test' AND 'test@example.com' verbatim (semantic equivalence to the request)",
      "passed": true,
      "evidence": "presented-sql.md contains: INSERT INTO users (name, email) VALUES ('Test', 'test@example.com'); content-equivalence-check.md confirms both literals verbatim."
    },
    {
      "text": "Policy decision is PRESENT_ONLY and appears in policy-decision.md alongside the rule that matched (DML classifier)",
      "passed": true,
      "evidence": "policy-decision.md cites Policy.checkQuery DML branch (policy.ts lines 225-246) and _DML_KEYWORDS matching INSERT. Gate = PRESENT_ONLY."
    },
    {
      "text": "Output clearly labels the SQL as not executed (e.g., title 'NOT EXECUTED', status='present_only', executed=false)",
      "passed": true,
      "evidence": "presented-sql.md title 'NOT EXECUTED'; stdout.txt status='present_only', executed=false."
    },
    {
      "text": "No audit event with a write/executed shape is emitted for this query — only a policy evaluation entry is permitted",
      "passed": true,
      "evidence": "audit.jsonl contains only a pool_created event (connection lifecycle, not execution). Zero write/executed events."
    }
  ],
  "summary": {
    "passed": 5,
    "failed": 0,
    "total": 5,
    "pass_rate": 1.0
  },
  "timing": {
    "total_duration_seconds": 0.0,
    "executor_duration_seconds": 0.0
  },
  "execution_metrics": {},
  "eval_feedback": {
    "suggestions": [
      {
        "assertion": "No audit event with a write/executed shape",
        "reason": "Residual code gap: Policy.checkQuery's PRESENT_ONLY branch (policy.ts:225-246) does NOT call logEvent (no symmetric policy_present_only event like _emitDeny). executeQuery (query.ts:91-98) returns present_only without logQuery. So the 'no write event' assertion passes vacuously — an empty audit.jsonl would pass too. Recommended follow-up: emit policy_present_only event."
      }
    ],
    "overall": "R1 audit wiring landed — pool_created reaches disk. Next step is to add a symmetric policy_present_only event so this assertion is non-vacuous."
  }
}
